|
Log-Analyse und Auswertung: Computer langsam ? laggt beim surfenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.04.2017, 00:16 | #1 |
| Computer langsam ? laggt beim surfen hallo mein computer ist langsam geworden und hakt oft beim surfen, als ob das internet laggen würde . ausserdem läuft er oft langsam, vor allem wenn mehrere office programme an sind hatte vor einem monat mal mit Malwarebytes pup enfternt seit dem nichts mehr gefunden. gerade win 10 creator update gemacht welches nicht automatisch zu starten ging. musste update file herunterladen. hatte vorher bitdefender security suite ,hat nie was gefunden,ist jetzt aber deinstalliert ist aber immer noch im programm ordner. hier der malwarbytes log und schonmal DANKE Code:
ATTFilter <?xml version="1.0" encoding="UTF-16" ?> <mbam-log> <header> <date>2017/03/10 04:03:16 +0100</date> <logfile>mbam-log-2017-03-10 (04-03-14).xml</logfile> <isadmin>yes</isadmin> </header> <engine> <version>2.2.1.1043</version> <malware-database>v2017.03.10.01</malware-database> <rootkit-database>v2017.02.27.01</rootkit-database> <license>trial</license> <file-protection>enabled</file-protection> <web-protection>enabled</web-protection> <self-protection>enabled</self-protection> </engine> <system> <hostname>CHAN-PC</hostname> <ip>192.168.178.89</ip> <osversion>Windows 10</osversion> <arch>x64</arch> <username>chan</username> <filesys>NTFS</filesys> </system> <summary> <type>hyper</type> <result>completed</result> <objects>308325</objects> <time>122</time> <processes>0</processes> <modules>0</modules> <keys>4</keys> <values>2</values> <datas>0</datas> <folders>23</folders> <files>220</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>disabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <key><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\gameo_update</path><vendor>PUP.Optional.Gameo</vendor><action>delete-on-reboot</action><hash>9bbe7c4cf5b3de58d765207116ed6a96</hash></key> <key><path>HKU\S-1-5-21-32524794-2794170151-1416143709-1000\SOFTWARE\Gameo</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>8ccd22a636720234d5655d3473903fc1</hash></key> <key><path>HKU\S-1-5-21-32524794-2794170151-1416143709-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\65828F17_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>43163d8b4167ca6c1a5206ece220d62a</hash></key> <key><path>HKU\S-1-5-21-32524794-2794170151-1416143709-1000\SOFTWARE\PRODUCTSETUP</path><vendor>PUP.Optional.ProductSetup</vendor><action>success</action><hash>0c4d05c3d4d420160cc0683549ba9c64</hash></key> <value><path>HKU\S-1-5-21-32524794-2794170151-1416143709-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\65828f17_0</path><valuename></valuename><vendor>PUP.Optional.Gameo</vendor><action>success</action><valuedata>{0.0.0.00000000}.{580b8777-c1f1-4ea2-891c-6af23db5a43e}|\Device\HarddiskVolume2\Users\chan\AppData\Roaming\Gameo\gameo.exe%b{00000000-0000-0000-0000-000000000000}</valuedata><hash>43163d8b4167ca6c1a5206ece220d62a</hash></value> <value><path>HKU\S-1-5-21-32524794-2794170151-1416143709-1000\SOFTWARE\PRODUCTSETUP</path><valuename>tb</valuename><vendor>PUP.Optional.ProductSetup</vendor><action>success</action><valuedata>0H1N1M</valuedata><hash>0c4d05c3d4d420160cc0683549ba9c64</hash></value> <folder><path>C:\Users\chan\AppData\Local\Gameo</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Local\Gameo\Cache</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Local\Gameo\Cache\index-dir</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Local\Gameo\databases</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Local\Gameo\GPUCache</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Local\Gameo\IndexedDB</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Local\Gameo\IndexedDB\file__0.indexeddb.leveldb</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Local\Gameo\Local Storage</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></folder> <folder><path>C:\Users\chan\AppData\Roaming\GoldenGate</path><vendor>PUP.Optional.GoldenGate</vendor><action>success</action><hash>a1b83e8a9a0ee6500ea7449b2cd721df</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugincontainer</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\2</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\2bak</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\3</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\4</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\5</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\5bak</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\6</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\8</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\plugins\8bak</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></folder> <folder><path>C:\Program Files (x86)\Common Files\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>69f04d7bddcb5fd7b76a06ce49b9a55b</hash></folder> <folder><path>C:\Program Files (x86)\Common Files\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\Updater</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>69f04d7bddcb5fd7b76a06ce49b9a55b</hash></folder> <file><path>C:\Users\chan\AppData\Local\Gameo\QuotaManager-journal</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\cookies</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\cookies-journal</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\QuotaManager</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Web Data</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Web Data-journal</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\website.ico</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\037b1711b483972a_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\04e650787c9493ed_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\06040b714e6df532_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\0a31c858c1723e7b_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\0b23ee7ae4338524_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\0b31489a8b814fef_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\0b5f116b35809707_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\1040957439cf4d70_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\112cbbdaf998834d_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\11de8d0fdfdfd465_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\13b38b0de97d906d_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\143cc5fd46615bfe_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7db7f87e533b8c96_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7e59f17cd4ed822e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7e73414543d6b29b_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7e90435a26a21615_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7fe6dca4e6920b6a_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\84a81dc9ccb122b0_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\84b4e56286f4f118_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\86285c0e2a5ab7a8_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\87b4e35dd0664b2b_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\87e2d1d65bea8481_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\880cc9eaf9073cab_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\8a2abd4eed83e9d6_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\8e2b7ae754f55bb1_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\45dd9072392168a0_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\47cff2ba15008159_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\4935992d14cf0dae_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\4e4bff99d47b434e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\4efa10dc5f349eaf_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\4f127f7b94bae832_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\4fc1d6c2f5c967dd_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5216403d02348b5c_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\527075832866b0f3_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\56bf662b067cd029_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\58666a1e0426b245_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\59f8199c46c0ac72_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5a7561d4b720db4f_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c44012a4351a17d1_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c588450d477c5347_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c5c41cbdc853292d_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c63d8bbef1db0b75_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c7e73a960e26aa70_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ca0797aa19545c8f_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\caaa9cb255e9ce7e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\cb75ee69024ee0ac_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\cb83286a7f819410_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\cbc7d3b924e92dec_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\cc9af08102830f10_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ccbf9667de008bfe_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\315a39b606bc4359_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\327e2f346370c855_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\330a3fe414a4c458_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\361e7863dafac2aa_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\3647e93441c23952_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\36a939fb2af3c946_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\384eac0b85c6c257_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\38628010c0fdbeaf_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\3c8061d447929b83_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\3ef6dd6fdd41d808_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\4192a20d93c859f3_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\41c05a76dba9e572_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\41e4ca011d6504cb_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\44433ab8a727945e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\de3ec9ddc2b44a14_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\e01b0e71315abed0_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\e34561ca25666f74_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\e4e9feec0f6d2c52_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\e532d9323f891b82_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\e685b2ebc644ef56_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\e72a61e004b0acdf_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\e954457bfde0c5bf_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ea34829245485817_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ea3f7af40099d544_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\eb2b0de35b16fce9_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ebe7efc9ef0db9f8_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ed8fa2499d113a16_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9f83b183fc917111_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\b00dad5727fcd5cb_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c4012c386409799f_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\cebb49743e00748f_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\dd2b26197bd067e5_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ef2390654d4fbd80_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\603ac246f9614238_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\60f42c7d1aaa31d9_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\610a8e26bd388e8e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\62a9c4818154cbaf_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\633ed391d1e267b6_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\65a62b5963989c81_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\65c5aba4a1a762e3_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\66e8f33bf747677e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\6b45256039d6c32e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\6c438609449d2325_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\a117c1c3948f71d4_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\a2c5893c95b0ff51_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\a3f099f5e1990d76_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\a682a844981d4e40_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\a878bba15ff02357_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ab4fd324065b70e8_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ad2b25828c049fcc_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ad6be9b6a8385bdf_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\aeae881e636350bb_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\1db2d19ba02a933a_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\21115f07886c0d78_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\213437fc3f4ebd89_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\22d68ddb9d068462_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\230fce1016bddea6_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\2385d6bca304945e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\23d8a4c92aa85584_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\24e8a1ef861f23a0_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\272e096687951257_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\2808bf21658ea820_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\2815c0f7ad99850c_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\281d45ddf5f82722_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\28cf1c5e8bffd1e6_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\2ab5a75357885dfa_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\2c5532589efbed57_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\2d258c87a5c38735_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\2f202314122f1979_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9368a8a2065decd4_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\958de824dbd2b7a1_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\95d1d660d1006295_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\95ddd53adf512dbc_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\97814d60229846ac_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\97e688e4ed1766bb_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9873f2673c3d8526_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9a0d4298c669f4d1_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9a1b2fc725613183_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9f0465a88e2c309b_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9f28cf3dd41932b9_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\9f2983a796006ecb_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5b9297c77ca7c67b_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5c200e49ac7f47ac_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5cc87711088fc9ad_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5cd23c07fa31be44_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5d637941bc60a57d_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5dcd47c52b77957c_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5e3037f02b1df4fb_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5e9ce5080aec3df5_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\5f787b798103fb2e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\cfc1d5580c32eb97_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d0dd3ff8448a7fd8_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d13deceedc6d7ef1_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d1767dcad90710d9_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d2676efa0ce1ef32_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d2b9e15099fea888_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d36e4249f673e831_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d3c58d3a88f5618a_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d71ebf43ce50c9a1_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\d992a503918fae25_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\dbb7724dc21d3e2e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\f243f9d8f492add5_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\f3418edc49e42b97_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\f384f59f33d37f59_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\f715ef236161cc7e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\f777d4a0de8ce29b_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\fa8f4973df93a255_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\fb35cf784be698c4_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\fd07de0d3bcf7f69_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\ff21211a37a791e8_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\index</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\16faf646f7a5bb00_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\177800ce49aee9e2_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\1820023f2dcafde2_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\18d31f0fee9c169e_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\1927acefd1bd6bff_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\1936a443bb82fae4_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\19a3a72d39c9f85c_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\1bb1462a1af79cba_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\1cef2627706a6519_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\b444a8a935dcc6aa_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\b6ac6b29fe0c3445_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\b725f7621101701a_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\b76db973d5cc9c5d_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\b7d9b7f701f935ef_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\b9e16e6f77b2e62d_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\bc5db12a9d0394c7_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\be8ae48b1c5673cf_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\bf2e5331ecd9d653_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c1aad3e247c8b661_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c23615c591b37dd2_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\c2e3dd3c7a3e10d1_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\6e08677f0e4fd2d9_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\70b7b3fb919ae398_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\72bfda8de35109fa_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7317fde847e700e2_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\74f9359651f1e9b6_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7524ac7e1e158775_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\752d2419d5e8ae7d_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\78df687beac05a3b_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\78eeb4a115a036f6_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\7c68b76f6abc17cc_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Cache\index-dir\the-real-index</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\databases\Databases.db</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\databases\Databases.db-journal</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\GPUCache\data_0</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\GPUCache\data_1</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\GPUCache\data_2</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\GPUCache\data_3</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\GPUCache\index</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\IndexedDB\file__0.indexeddb.leveldb\000003.log</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\IndexedDB\file__0.indexeddb.leveldb\CURRENT</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\IndexedDB\file__0.indexeddb.leveldb\LOCK</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\IndexedDB\file__0.indexeddb.leveldb\LOG</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000002</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Local Storage\file__0.localstorage</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Users\chan\AppData\Local\Gameo\Local Storage\file__0.localstorage-journal</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>1841408833751323aa8eb7da27dc54ac</hash></file> <file><path>C:\Windows\System32\Tasks\gameo_update</path><vendor>PUP.Optional.Gameo</vendor><action>success</action><hash>2138d0f897112a0c9e9b543d7f842ad6</hash></file> <file><path>C:\Users\chan\AppData\Roaming\GoldenGate\6a0d2960fee21d62ac3c5c61a9244f4a.logic.db</path><vendor>PUP.Optional.GoldenGate</vendor><action>success</action><hash>a1b83e8a9a0ee6500ea7449b2cd721df</hash></file> <file><path>C:\Users\chan\AppData\Roaming\GoldenGate\6a0d2960fee21d62ac3c5c61a9244f4a.data.db</path><vendor>PUP.Optional.GoldenGate</vendor><action>success</action><hash>a1b83e8a9a0ee6500ea7449b2cd721df</hash></file> <file><path>C:\Users\chan\AppData\Roaming\GoldenGate\6a0d2960fee21d62ac3c5c61a9244f4a.events.db</path><vendor>PUP.Optional.GoldenGate</vendor><action>success</action><hash>a1b83e8a9a0ee6500ea7449b2cd721df</hash></file> <file><path>C:\Users\chan\AppData\Roaming\GoldenGate\6a0d2960fee21d62ac3c5c61a9244f4a.user.db</path><vendor>PUP.Optional.GoldenGate</vendor><action>success</action><hash>a1b83e8a9a0ee6500ea7449b2cd721df</hash></file> <file><path>C:\ProgramData\8708eaaa-1c2b-4faa-8923-a6c9f88eeb0e\temp</path><vendor>PUP.Optional.DigitalMore</vendor><action>success</action><hash>a1b85c6cedbb1f17a17f973dbd45936d</hash></file> </items> </mbam-log> Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 23-04-2017 01 durchgeführt von chan1 (Administrator) auf CHAN-PC (24-04-2017 00:51:36) Gestartet von C:\Users\chan\Desktop Geladene Profile: chan & chan1 (Verfügbare Profile: chan & chan1 & DefaultAppPool) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Micro-Star INT'L CO., LTD.) C:\MSI\MSIRegister\MSIRegisterService.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (The OpenVPN Project) C:\Program Files\OpenVPN\bin\openvpnserv.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe (Microsoft Corporation) C:\Windows\System32\SecurityHealthService.exe (Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe (Creative Technology Ltd.) C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1794704 2015-02-20] (NVIDIA Corporation) HKLM-x32\...\Run: [Sound Blaster Tactic3D Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe [2091008 2014-07-03] (Creative Technology Ltd) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-06-16] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1944576 2013-03-07] (Brother Industries, Ltd.) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH) HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [13396944 2017-02-07] (Micro-Star INT'L CO., LTD.) HKLM-x32\...\Run: [MSIRegister] => C:\MSI\MSIRegister\MSIRegister.exe [1258448 2016-11-09] (Micro-Star INT'L CO., LTD.) HKLM-x32\...\Run: [ControlCenterCount] => C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [872448 2012-03-26] (MSI CO.,LTD.) HKLM\...\RunOnce: [Windows10UpgraderApp.exe] => C:\Windows10Upgrade\Windows10UpgraderApp.exe [1237192 2017-04-14] (Microsoft Corporation) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIJE.EXE [283232 2014-12-16] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Run: [Spotify Web Helper] => C:\Users\chan\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1431664 2017-02-04] (Spotify Ltd) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Run: [Spotify] => C:\Users\chan\AppData\Roaming\Spotify\Spotify.exe [6987376 2017-02-04] (Spotify Ltd) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-19] (Valve Corporation) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Run: [GoogleChromeAutoLaunch_3232C9E79A4420FE8FD45F0D0C66E2CC] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [941912 2017-03-29] (Google Inc.) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [615040 2017-03-22] () HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\RunOnce: [Uninstall 17.3.6799.0327\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\chan\AppData\Local\Microsoft\OneDrive\17.3.6799.0327\amd64" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\RunOnce: [Uninstall 17.3.6799.0327] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\chan\AppData\Local\Microsoft\OneDrive\17.3.6799.0327" HKU\S-1-5-21-32524794-2794170151-1416143709-1001\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517120 2017-03-18] (Microsoft Corporation) HKU\S-1-5-18\...\Winlogon: [Shell] C:\WINDOWS\explorer.exe [4847928 2017-03-18] (Microsoft Corporation) <==== ACHTUNG ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei Startup: C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SCS-VPN.exe [2014-05-15] (Schapfl OHG) GroupPolicy: Beschränkung - Chrome <======= ACHTUNG CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{241baf31-2998-4935-965f-207fd094031d}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-32524794-2794170151-1416143709-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-03-06] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-03-06] (Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: 7f2sv1kt.default FF ProfilePath: C:\Users\chan1\AppData\Roaming\Mozilla\Firefox\Profiles\7f2sv1kt.default [2017-04-23] FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-28] [ist nicht signiert] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-23] () FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-23] () FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-03-06] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-29] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-29] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-06] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-06] (Google Inc.) ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [Datei ist nicht signiert] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3737792 2017-03-26] (Microsoft Corporation) R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2011-10-19] (Creative Technology Ltd) [Datei ist nicht signiert] R2 MSIREGISTER_MR; C:\MSI\MSIRegister\MSIRegisterService.exe [132048 2016-10-07] (Micro-Star INT'L CO., LTD.) R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2286544 2017-02-07] (Micro-Star INT'L CO., LTD.) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation) S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv2.exe [15872 2016-11-25] ( ) [Datei ist nicht signiert] R2 OpenVPNServiceInteractive; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72320 2017-03-22] (The OpenVPN Project) S3 OpenVPNServiceLegacy; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72320 2017-03-22] (The OpenVPN Project) R2 postgresql-x64-9.3; C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe [90624 2015-07-13] (PostgreSQL Global Development Group) [Datei ist nicht signiert] R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1230824 2017-02-22] (Bitdefender) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-18] (TeamViewer GmbH) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) S3 wlpasvc; C:\WINDOWS\System32\lpasvc.dll [1295360 2017-03-18] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 iaLPSS2i_GPIO2_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [85504 2017-03-18] (Intel Corporation) S3 iaLPSS2i_I2C_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [168448 2017-03-18] (Intel Corporation) S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MSI) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvlddmkm.sys [14199224 2017-01-04] (NVIDIA Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek ) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () R3 UHSfiltv; C:\WINDOWS\system32\drivers\UHSfiltv.sys [32264 2015-07-22] (Creative Technology Ltd.) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) U3 idsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) NETSVCx32: TokenBroker -> C:\Windows\SysWOW64\TokenBroker.dll (Microsoft Corporation) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-04-24 01:05 - 2017-04-24 01:05 - 23680512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 23675392 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 20505600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 19334144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 11869696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 08319392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-04-24 01:05 - 2017-04-24 01:05 - 08247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 06756920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 03672064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-04-24 01:05 - 2017-04-24 01:05 - 02957824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-04-24 01:05 - 2017-04-24 01:05 - 02444184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-04-24 01:05 - 2017-04-24 01:05 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01604312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01411640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01323880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-04-24 01:05 - 2017-04-24 01:05 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 01024416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-04-24 01:05 - 2017-04-24 01:05 - 00986592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-04-24 01:05 - 2017-04-24 01:05 - 00626520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-04-24 01:05 - 2017-04-24 01:05 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-04-24 01:05 - 2017-04-24 01:05 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2017-04-24 01:05 - 2017-04-24 01:05 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-04-24 01:05 - 2017-04-24 01:05 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00205728 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-04-24 01:05 - 2017-04-24 01:05 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-04-24 01:05 - 2017-04-24 01:05 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin 2017-04-24 01:05 - 2017-04-24 01:05 - 00000000 ____D C:\Windows.old 2017-04-24 01:04 - 2017-04-24 01:04 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-04-24 01:04 - 2017-04-24 01:04 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2017-04-24 01:04 - 2017-04-24 01:04 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2017-04-24 01:04 - 2017-04-24 00:07 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2017-04-24 01:04 - 2017-03-17 23:00 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll 2017-04-24 01:04 - 2017-03-17 22:59 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll 2017-04-24 01:04 - 2017-03-17 22:48 - 06348288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll 2017-04-24 01:04 - 2017-03-17 22:43 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll 2017-04-24 01:04 - 2017-03-17 22:35 - 05484544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\WINDOWS\system32\msmq 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\WINDOWS\system32\BestPractices 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\Program Files\Reference Assemblies 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\Program Files\MSBuild 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\Program Files (x86)\MSBuild 2017-04-24 01:03 - 2017-04-24 01:03 - 00000000 ____D C:\inetpub 2017-04-24 01:03 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2017-04-24 01:03 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2017-04-24 01:03 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2017-04-24 01:03 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2017-04-24 01:03 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2017-04-24 01:03 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2017-04-24 00:51 - 2017-04-24 00:51 - 00017953 _____ C:\Users\chan\Desktop\FRST.txt 2017-04-24 00:51 - 2017-04-24 00:51 - 00000000 ____D C:\Users\chan\AppData\Local\DBG 2017-04-24 00:44 - 2017-04-24 00:44 - 00000020 ___SH C:\Users\chan1\ntuser.ini 2017-04-24 00:22 - 2017-04-24 00:22 - 00000000 ____D C:\ProgramData\USOShared 2017-04-24 00:18 - 2017-04-24 00:18 - 00000000 ___HD C:\OneDriveTemp 2017-04-24 00:18 - 2017-04-24 00:18 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2017-04-24 00:17 - 2017-04-24 00:17 - 00000020 ___SH C:\Users\chan\ntuser.ini 2017-04-24 00:14 - 2017-04-24 00:15 - 00015243 _____ C:\WINDOWS\diagwrn.xml 2017-04-24 00:14 - 2017-04-24 00:15 - 00015243 _____ C:\WINDOWS\diagerr.xml 2017-04-24 00:13 - 2017-04-24 00:18 - 00003272 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-04-24 00:13 - 2017-04-24 00:13 - 00003556 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-04-24 00:13 - 2017-04-24 00:13 - 00003332 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-04-24 00:13 - 2017-04-24 00:13 - 00003332 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2017-04-24 00:13 - 2017-04-24 00:13 - 00003292 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{55C7DEFC-6776-4393-B435-447C54AF2D1D} 2017-04-24 00:13 - 2017-04-24 00:13 - 00002668 _____ C:\WINDOWS\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 2017-04-24 00:13 - 2017-04-24 00:13 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-04-24 00:13 - 2017-04-24 00:13 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD 2017-04-24 00:11 - 2017-04-24 00:11 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-04-24 00:10 - 2017-04-24 00:10 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines 2017-04-24 00:09 - 2017-04-24 00:44 - 00000000 ____D C:\Users\chan1 2017-04-24 00:09 - 2017-04-24 00:18 - 00000000 ____D C:\Users\chan 2017-04-24 00:09 - 2017-04-24 00:12 - 00000000 ____D C:\Users\DefaultAppPool 2017-04-24 00:09 - 2017-04-24 00:11 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Vorlagen 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Startmenü 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Netzwerkumgebung 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Lokale Einstellungen 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Eigene Dateien 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Druckumgebung 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Documents\Eigene Videos 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Documents\Eigene Musik 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Documents\Eigene Bilder 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\AppData\Local\Verlauf 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\AppData\Local\Anwendungsdaten 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan1\Anwendungsdaten 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Vorlagen 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Startmenü 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Netzwerkumgebung 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Lokale Einstellungen 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Eigene Dateien 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Druckumgebung 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Documents\Eigene Videos 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Documents\Eigene Musik 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Documents\Eigene Bilder 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\AppData\Local\Verlauf 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\AppData\Local\Anwendungsdaten 2017-04-24 00:09 - 2017-04-24 00:09 - 00000000 _SHDL C:\Users\chan\Anwendungsdaten 2017-04-24 00:08 - 2017-04-24 00:17 - 02106252 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-04-24 00:08 - 2017-04-24 00:10 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-04-24 00:08 - 2017-04-24 00:10 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-04-24 00:08 - 2017-04-24 00:10 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-04-24 00:08 - 2017-04-24 00:08 - 02011386 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2017-04-24 00:08 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2017-04-24 00:08 - 2016-12-29 14:44 - 06386232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2017-04-24 00:08 - 2016-12-29 14:44 - 02477624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2017-04-24 00:08 - 2016-12-29 14:44 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2017-04-24 00:08 - 2016-12-29 14:44 - 00546752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2017-04-24 00:08 - 2016-12-29 14:44 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2017-04-24 00:08 - 2016-12-29 14:44 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2017-04-24 00:08 - 2016-12-29 14:44 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2017-04-24 00:08 - 2016-12-19 09:26 - 07651057 _____ C:\WINDOWS\system32\nvcoproc.bin 2017-04-24 00:07 - 2017-04-24 00:12 - 00217120 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-04-24 00:07 - 2017-04-24 00:08 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-04-23 23:41 - 2017-04-23 23:41 - 00029942 _____ C:\Users\chan\Downloads\Addition.txt 2017-04-23 23:40 - 2017-04-24 00:51 - 00000000 ____D C:\FRST 2017-04-23 23:40 - 2017-04-23 23:41 - 00090278 _____ C:\Users\chan\Downloads\FRST.txt 2017-04-23 23:39 - 2017-04-23 23:40 - 02426368 _____ (Farbar) C:\Users\chan\Desktop\FRST64.exe 2017-04-23 23:22 - 2017-04-24 00:17 - 00000000 ___DC C:\WINDOWS\Panther 2017-04-23 23:22 - 2017-04-23 23:27 - 00000000 ___HD C:\$WINDOWS.~BT 2017-04-23 23:03 - 2017-04-23 23:03 - 00241360 _____ C:\ProgramData\1492981398.bdinstall.bin 2017-04-23 23:03 - 2017-04-23 23:03 - 00000000 ____D C:\Users\chan1\AppData\Local\Mozilla 2017-04-23 22:48 - 2017-04-23 22:48 - 00142950 ____T C:\WINDOWS\mnd87C2.diagerr.mdmp 2017-04-23 22:45 - 2017-04-23 23:22 - 00000036 _____ C:\WINDOWS\progress.ini 2017-04-23 22:31 - 2017-04-23 22:31 - 00000000 ____D C:\ProgramData\bdch 2017-04-23 22:30 - 2017-04-23 22:30 - 00000000 ____D C:\Users\chan1\AppData\Roaming\QuickScan 2017-04-23 22:29 - 2017-04-23 22:32 - 00000000 ____D C:\Users\chan\AppData\Local\Adobe 2017-04-23 22:29 - 2017-04-23 22:31 - 00000000 ____D C:\Users\chan1\AppData\Local\Adobe 2017-04-23 22:08 - 2017-04-24 00:16 - 00000000 ___HD C:\$GetCurrent 2017-04-23 22:08 - 2017-04-23 23:30 - 00000000 ____D C:\Windows10Upgrade 2017-04-23 22:08 - 2017-04-23 22:08 - 06385872 _____ (Microsoft Corporation) C:\Users\chan\Downloads\Windows10Upgrade9252.exe 2017-04-23 22:08 - 2017-04-23 22:08 - 00000731 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10-Upgrade-Assistent.lnk 2017-04-23 22:08 - 2017-04-23 22:08 - 00000719 _____ C:\Users\chan1\Desktop\Windows 10-Upgrade-Assistent.lnk 2017-04-23 13:37 - 2017-04-23 13:37 - 00000000 ____D C:\Users\chan1\AppData\Roaming\Mozilla 2017-04-22 19:56 - 2017-04-22 19:56 - 00000000 ____D C:\Users\chan\AppData\Local\Macromedia 2017-04-20 18:14 - 2017-04-21 17:43 - 00000000 ____D C:\Users\chan\Desktop\christian 2017-04-20 16:26 - 2017-04-20 16:26 - 00002048 _____ C:\Users\chan1\AppData\Roaming\Microsoft\Windows\Start Menu\888poker.lnk 2017-04-20 16:26 - 2017-04-20 16:26 - 00002024 _____ C:\Users\chan1\Desktop\888poker.lnk 2017-04-20 16:26 - 2017-04-20 16:26 - 00000000 ____D C:\Users\chan1\AppData\Roaming\pacificpoker 2017-04-20 16:26 - 2017-04-20 16:26 - 00000000 ____D C:\Users\chan1\AppData\Roaming\Macromedia 2017-04-20 16:26 - 2017-04-20 16:26 - 00000000 ____D C:\Users\chan1\AppData\Roaming\InstallShield Installation Information 2017-04-20 16:26 - 2017-04-20 16:26 - 00000000 ____D C:\Users\chan1\AppData\Roaming\Adobe 2017-04-20 16:26 - 2017-04-20 16:26 - 00000000 ____D C:\Users\chan1\AppData\Local\Downloaded Installations 2017-04-20 16:26 - 2017-04-20 16:26 - 00000000 ____D C:\Program Files (x86)\PacificPoker 2017-04-20 16:25 - 2017-04-20 16:26 - 00000000 ____D C:\Users\chan1\Documents\PokerInstallerLogs 2017-04-20 16:25 - 2017-04-20 16:25 - 00641192 _____ (Random-Logic) C:\Users\chan\Downloads\888poker_installer.exe 2017-04-20 05:55 - 2017-04-20 05:55 - 988334149 _____ C:\Users\chan\Downloads\20160822_s12v55_jk_3m.zip 2017-04-20 05:09 - 2017-04-20 05:09 - 911322515 _____ C:\Users\chan\Downloads\s12v55_jk_3m-ota-1476234294.zip 2017-04-20 04:21 - 2017-04-20 04:23 - 870300063 _____ C:\Users\chan\Downloads\s12v55_jk_3m-ota-1477383173.zip 2017-04-20 01:56 - 2017-04-20 01:56 - 00069182 _____ C:\Users\chan\Downloads\Techvorlage-2015-2016.dotx 2017-04-18 18:39 - 2017-03-28 07:37 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DdcWnsListener.dll 2017-04-18 18:39 - 2017-03-28 07:28 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2017-04-06 13:52 - 2017-04-06 13:52 - 00017711 _____ C:\Users\chan\Downloads\radar.html 2017-04-05 06:27 - 2017-04-05 06:27 - 00379671 _____ C:\Users\chan\Desktop\schutt.pdf 2017-04-05 06:25 - 2017-04-05 06:25 - 00234759 _____ C:\Users\chan\Desktop\zuchtung.pdf 2017-04-05 06:23 - 2017-04-05 06:23 - 00381833 _____ C:\Users\chan\Desktop\kultur.pdf 2017-04-05 06:20 - 2017-04-05 06:20 - 00447971 _____ C:\Users\chan\Desktop\Ausarbeitung ROH Semester 1 Klausur.pdf 2017-04-01 13:53 - 2017-04-01 13:53 - 00219904 _____ C:\Users\chan\Downloads\KBA-Anfrageformular_pdf.pdf 2017-04-01 12:47 - 2017-04-01 12:47 - 00650068 _____ C:\Users\chan\Downloads\geschaftsbericht_2001.pdf 2017-03-30 23:43 - 2017-04-24 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-03-30 23:43 - 2017-03-30 23:43 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-03-30 23:42 - 2017-03-30 23:42 - 01631704 _____ (Skype Technologies S.A.) C:\Users\chan\Downloads\SkypeSetup.exe 2017-03-28 22:40 - 2017-03-28 22:40 - 00000000 ____D C:\Users\chan\AppData\Roaming\dvdcss 2017-03-28 04:10 - 2017-04-24 00:11 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\partypoker 2017-03-28 04:10 - 2017-04-24 00:11 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2017-03-28 04:10 - 2017-03-28 04:10 - 00001545 _____ C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\partypoker.lnk 2017-03-28 04:10 - 2017-03-28 04:10 - 00000000 ____D C:\Users\chan\AppData\Roaming\cef3-cache 2017-03-28 03:32 - 2017-03-28 03:33 - 00000000 ____D C:\Users\chan1\AppData\Local\PokerTracker 4 ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-04-24 01:07 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2017-04-24 01:05 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup 2017-04-24 01:05 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-04-24 01:04 - 2017-03-20 06:36 - 00000000 ____D C:\WINDOWS\OCR 2017-04-24 01:03 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2017-04-24 01:03 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI 2017-04-24 01:03 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2017-04-24 01:03 - 2017-03-18 22:59 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb 2017-04-24 01:03 - 2017-03-18 22:59 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb 2017-04-24 01:03 - 2017-03-18 22:59 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb 2017-04-24 01:03 - 2017-03-18 22:59 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb 2017-04-24 01:03 - 2017-03-18 22:59 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe 2017-04-24 01:03 - 2017-03-18 22:59 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe 2017-04-24 01:03 - 2017-03-18 22:59 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll 2017-04-24 01:03 - 2017-03-18 22:59 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof 2017-04-24 01:03 - 2017-03-18 22:56 - 01380352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll 2017-04-24 01:03 - 2017-03-18 22:56 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll 2017-04-24 01:03 - 2017-03-18 22:56 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll 2017-04-24 01:03 - 2017-03-18 22:56 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll 2017-04-24 01:03 - 2017-03-18 22:56 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll 2017-04-24 01:03 - 2017-03-18 22:56 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys 2017-04-24 01:03 - 2017-03-18 22:56 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll 2017-04-24 01:03 - 2017-03-18 22:56 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb 2017-04-24 01:03 - 2017-03-18 22:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb 2017-04-24 01:03 - 2017-03-18 22:56 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb 2017-04-24 01:03 - 2017-03-18 22:56 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe 2017-04-24 01:03 - 2017-03-18 22:56 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb 2017-04-24 01:03 - 2017-03-18 22:56 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe 2017-04-24 01:03 - 2017-03-18 22:56 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll 2017-04-24 01:03 - 2017-03-18 22:56 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof 2017-04-24 00:49 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-04-24 00:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-04-24 00:33 - 2016-05-04 09:42 - 00000000 ____D C:\Users\chan\AppData\Local\Packages 2017-04-24 00:33 - 2015-04-14 03:24 - 00000000 ____D C:\Users\chan\AppData\Roaming\vlc 2017-04-24 00:25 - 2017-03-01 23:43 - 00000000 ____D C:\Users\chan\AppData\LocalLow\Mozilla 2017-04-24 00:22 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate 2017-04-24 00:18 - 2016-05-04 09:45 - 00002417 _____ C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-04-24 00:18 - 2016-05-04 09:45 - 00000000 ___RD C:\Users\chan\OneDrive 2017-04-24 00:17 - 2017-03-20 06:35 - 00896422 _____ C:\WINDOWS\system32\perfh007.dat 2017-04-24 00:17 - 2017-03-20 06:35 - 00199792 _____ C:\WINDOWS\system32\perfc007.dat 2017-04-24 00:17 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-04-24 00:17 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-04-24 00:17 - 2016-06-16 09:15 - 00000000 ____D C:\Program Files\Bitdefender Agent 2017-04-24 00:17 - 2016-02-13 19:30 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-04-24 00:17 - 2015-04-14 01:48 - 00002264 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-04-24 00:17 - 2015-04-14 01:48 - 00002252 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-04-24 00:16 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT 2017-04-24 00:16 - 2015-04-15 03:38 - 00000306 __RSH C:\ProgramData\ntuser.pol 2017-04-24 00:15 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2017-04-24 00:15 - 2017-03-18 13:40 - 00065536 _____ C:\WINDOWS\system32\config\ELAM 2017-04-24 00:14 - 2017-03-20 06:37 - 00000000 ____D C:\WINDOWS\HoloShell 2017-04-24 00:14 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration 2017-04-24 00:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2017-04-24 00:13 - 2017-03-18 23:03 - 00000000 __RSD C:\WINDOWS\Media 2017-04-24 00:13 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries 2017-04-24 00:13 - 2016-05-04 09:29 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat 2017-04-24 00:12 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-04-24 00:12 - 2017-03-18 13:40 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-04-24 00:12 - 2016-10-08 03:51 - 00000000 ____D C:\ProgramData\NVIDIA 2017-04-24 00:11 - 2017-03-24 02:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN 2017-04-24 00:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-04-24 00:11 - 2017-03-01 23:24 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JonDoFox 2017-04-24 00:11 - 2017-02-27 21:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2017-04-24 00:11 - 2017-02-24 19:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Edraw Mind Map 7.9 2017-04-24 00:11 - 2017-02-21 13:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools 2017-04-24 00:11 - 2016-06-06 20:43 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi 2017-04-24 00:11 - 2016-04-17 07:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 9.3 2017-04-24 00:11 - 2016-04-17 07:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerTracker 4 2017-04-24 00:11 - 2016-03-09 18:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother 2017-04-24 00:11 - 2016-02-06 20:28 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2017-04-24 00:11 - 2016-02-06 20:28 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps 2017-04-24 00:11 - 2016-02-03 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player 2017-04-24 00:11 - 2015-12-10 19:57 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-04-24 00:11 - 2015-12-10 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2017-04-24 00:11 - 2015-10-27 19:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FTPRush 2017-04-24 00:11 - 2015-10-22 14:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhonerLite 2017-04-24 00:11 - 2015-09-19 09:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\partypoker 2017-04-24 00:11 - 2015-06-17 22:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative 2017-04-24 00:11 - 2015-04-25 09:53 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-04-24 00:11 - 2015-04-25 09:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-04-24 00:11 - 2015-04-15 21:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.EU 2017-04-24 00:11 - 2015-04-14 03:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-04-24 00:11 - 2015-04-14 03:12 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader 2017-04-24 00:11 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-04-24 00:10 - 2017-03-24 02:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files\Windows Sidebar 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\IME 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\schemas 2017-04-24 00:10 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-04-24 00:10 - 2017-02-27 02:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI 2017-04-24 00:10 - 2017-02-17 19:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-04-24 00:10 - 2016-03-30 19:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 2017-04-24 00:10 - 2015-08-18 10:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2017-04-24 00:10 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games 2017-04-24 00:09 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2017-04-24 00:09 - 2016-10-30 15:49 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2017-04-24 00:09 - 2016-04-18 18:04 - 00000000 ____D C:\Users\chan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TP-LINK 2017-04-24 00:09 - 2009-07-14 05:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy 2017-04-24 00:08 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Help 2017-04-24 00:08 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2017-04-23 23:32 - 2017-02-21 13:36 - 00000000 ____D C:\Users\chan\AppData\Local\CrashDumps 2017-04-23 23:15 - 2017-03-10 05:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-04-23 23:03 - 2016-06-16 09:21 - 00020127 _____ C:\bdlog.txt 2017-04-23 23:03 - 2015-04-14 08:53 - 00000000 ____D C:\Users\chan\AppData\Roaming\Skype 2017-04-23 22:32 - 2016-05-17 17:48 - 00000000 ____D C:\Users\chan\AppData\Roaming\Wireshark 2017-04-23 22:32 - 2010-11-21 05:27 - 00532136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2017-04-23 02:43 - 2015-04-15 21:49 - 00000000 ____D C:\Users\chan\AppData\Local\PokerStars.EU 2017-04-23 00:47 - 2015-04-14 03:12 - 00000000 ____D C:\Users\chan\AppData\Local\JDownloader v2.0 2017-04-21 20:05 - 2017-03-01 23:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-04-20 02:22 - 2016-07-11 12:26 - 00000000 ____D C:\Users\chan\Downloads\extracted 2017-04-18 18:43 - 2015-04-14 01:38 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-04-18 18:41 - 2015-04-14 01:38 - 148601744 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-04-07 00:40 - 2017-03-23 04:54 - 00000000 ____D C:\Users\chan1\AppData\Local\PokerStars.EU 2017-04-04 22:04 - 2016-06-06 20:48 - 00000000 ____D C:\Users\chan\AppData\Roaming\Kodi 2017-04-01 11:27 - 2015-04-14 09:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-30 23:43 - 2015-04-14 08:53 - 00002642 _____ C:\Users\Public\Desktop\Skype.lnk 2017-03-30 23:43 - 2015-04-14 08:52 - 00000000 ____D C:\ProgramData\Skype 2017-03-30 23:42 - 2016-05-17 17:46 - 00000000 ____D C:\ProgramData\Package Cache 2017-03-30 22:56 - 2017-02-21 13:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-03-28 04:10 - 2015-09-19 09:34 - 00001521 _____ C:\Users\chan\Desktop\partypoker.lnk 2017-03-28 03:32 - 2016-04-17 07:33 - 00000000 ____D C:\Program Files (x86)\PokerTracker 4 ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-04-23 23:03 - 2017-04-23 23:03 - 0241360 _____ () C:\ProgramData\1492981398.bdinstall.bin 2016-04-17 07:33 - 2016-04-17 07:33 - 0004986 _____ () C:\ProgramData\flwjycbm.bab 2016-04-17 07:33 - 2016-04-17 07:33 - 0000016 _____ () C:\ProgramData\mntemp ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-04-24 00:07 ==================== Ende von FRST.txt ============================ |
24.04.2017, 00:18 | #2 |
| Computer langsam ? laggt beim surfen addition
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 23-04-2017 01 durchgeführt von chan1 (24-04-2017 00:52:05) Gestartet von C:\Users\chan\Desktop Windows 10 Home Version 1703 (X64) (2017-04-23 22:16:56) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-32524794-2794170151-1416143709-500 - Administrator - Disabled) chan (S-1-5-21-32524794-2794170151-1416143709-1000 - Limited - Enabled) => C:\Users\chan chan1 (S-1-5-21-32524794-2794170151-1416143709-1001 - Administrator - Enabled) => C:\Users\chan1 DefaultAccount (S-1-5-21-32524794-2794170151-1416143709-503 - Limited - Disabled) Gast (S-1-5-21-32524794-2794170151-1416143709-501 - Limited - Disabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov) 888poker (HKU\S-1-5-21-32524794-2794170151-1416143709-1001\...\InstallShield_{9BABBBA5-D456-471B-A821-0C832267B5C2}) (Version: 7.2.30039 - 888) 888poker (x32 Version: 7.2.30039 - 888) Hidden Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated) Anno 2205 (HKLM-x32\...\Uplay Install 1253) (Version: - Ubisoft) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 20.0.28.1503 - Bitdefender) Brother MFL-Pro Suite MFC-J4420DW (HKLM-x32\...\{7FC49664-DAA4-4E7C-ADD0-614ABB43691B}) (Version: 1.0.5.0 - Brother Industries, Ltd.) Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version: - Colossal Order Ltd.) ControlCenter (HKLM-x32\...\{AF14F0CD-5307-4134-BDFA-15974473C1EE}_is1) (Version: 2.5.060 - MSI) Creative Systeminformationen (HKLM-x32\...\SysInfo) (Version: 1.10 - Creative Technology Limited) Edraw Mind Map 7.9 (HKLM-x32\...\Edraw Mind Map Freeware_is1) (Version: - EdrawSoft) EPSON XP-402 403 405 406 Series Printer Uninstall (HKLM\...\EPSON XP-402 403 405 406 Series) (Version: - SEIKO EPSON Corporation) FTPRush 2.1.8 (HKLM-x32\...\FTP Rush_is1) (Version: 2.1.8 - wftpserver.com) GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.76.5239 - Gretech Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.) Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Kodi (HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Kodi) (Version: - XBMC-Foundation) Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.7870.2031 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\OneDriveSetup.exe) (Version: 17.3.6816.0313 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 52.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 52.0.2 (x86 de)) (Version: 52.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.2.6291 - Mozilla) Mozilla Thunderbird 45.8.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 45.8.0 (x86 de)) (Version: 45.8.0 - Mozilla) MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.2.0.08 - MSI) MSI Smart Tool (HKLM-x32\...\{DDCCA038-DAB1-4D09-B85C-848020AA75D6}}_is1) (Version: 1.0.0.10 - MSI) MSIRegister (HKLM-x32\...\{80B995A4-3A86-4690-98A6-563F1A788835}_is1) (Version: 2.0.0.05 - MSI) NVIDIA 3D Vision Treiber 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.53 - NVIDIA Corporation) NVIDIA Grafiktreiber 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.53 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7870.2024 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden OpenVPN 2.4.1-I601 (HKLM\...\OpenVPN) (Version: 2.4.1-I601 - OpenVPN Technologies, Inc.) partypoker (HKLM-x32\...\PartyPoker) (Version: - PartyGaming) partypoker (HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\PartyPoker) (Version: - ) PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PhonerLite 2.28 (HKLM-x32\...\PhonerLite_is1) (Version: 2.28 - Heiko Sommerfeldt) PokerStars.eu (HKLM-x32\...\PokerStars.eu) (Version: - PokerStars.eu) PokerTracker 4 (remove only) (HKLM-x32\...\PokerTracker4) (Version: - ) PostgreSQL 9.3 (HKLM\...\PostgreSQL 9.3) (Version: 9.3 - PostgreSQL Global Development Group) PowerLine Utility (HKLM-x32\...\{1A5E91E0-20BD-423B-ABD4-7683A30D3C2F}) (Version: 2.0.1431 - TP-LINK) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.90.826.2014 - Realtek) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Sound Blaster Tactic(3D) (HKLM-x32\...\{92000C16-939B-44CA-802F-0D552019D7C8}) (Version: 1.0 - Creative Technology Limited) Spotify (HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\Spotify) (Version: 1.0.42.151.g19de0aa6 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - ) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.43879 - TeamViewer) Uplay (HKLM-x32\...\Uplay) (Version: 24.0 - Ubisoft) VLC media player (HKLM\...\VLC media player) (Version: 2.2.0 - VideoLAN) Windows 10-Upgrade-Assistent (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17387 - Microsoft Corporation) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Wireshark 2.0.3 (64-bit) (HKLM-x32\...\Wireshark) (Version: 2.0.3 - The Wireshark developer community, hxxps://www.wireshark.org) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {04D52602-A7E2-44ED-87B2-84CEA21A2022} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {07A6E1DD-8942-472D-B5F9-A98652F5DE27} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {0CCA7D48-D8A5-4D64-B1EF-87B16E37329D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {0EE92C60-0C95-452C-B6D9-BDE93A704489} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-14] (Google Inc.) Task: {11FBA011-FEEB-4A2D-8D7B-849FB303F298} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe Task: {14A95F9A-7947-4271-9C82-A88E753A4833} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe Task: {15B82CB9-3520-4219-B44C-40669B9A7A3C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe Task: {1C893105-2F99-4011-A25E-C8251B266ABB} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG Task: {1CCCC4C4-66A4-4BDF-9862-C691C1CCF322} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {23CA45E4-0563-48E8-8F8D-7BDC6CC37185} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-03-26] (Microsoft Corporation) Task: {2C96741B-FD5B-4A43-8236-CB182F22478C} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {365A6CAF-60DE-46A7-9347-5C4BD428BECB} - \gameo_update -> Keine Datei <==== ACHTUNG Task: {384B286B-FDEE-40C6-89F5-5234B32ABA1E} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe Task: {3F9258EB-1700-46E3-A997-AFFE047D0600} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate.exe Task: {464D64C1-09B9-4558-975E-889B97F57112} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-03-26] (Microsoft Corporation) Task: {4D0C72ED-FEE8-4284-B612-C72A33F2F3F2} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe Task: {4FE68388-BB2F-4B17-A29C-1C9BB7263A64} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {594A675D-B84F-4591-BEFC-7E9216F1B729} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2017-02-02] (Bitdefender) Task: {5AEA9491-739D-410C-BEC6-2214C0584EFC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {5DD6077D-634D-46C3-9690-256CD36B948B} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe Task: {5DF07D70-7FDE-4833-88E7-89681C6B9929} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe Task: {5EB4D810-5FED-4ACF-93E6-142375C635CC} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe Task: {637FF3EA-500C-463D-9D45-216611F8AB59} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {784F52E3-A3C9-49A3-A719-DF925B4402D7} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec.exe Task: {7B922887-2B97-4D9D-8043-8E2121873B21} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe Task: {7BB13EF4-2A4E-4436-9F4F-CABA42146612} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-03-26] (Microsoft Corporation) Task: {80F11910-3BF9-44CE-99AC-1A65AB3EFD26} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-23] (Adobe Systems Incorporated) Task: {83B4DD3E-476D-4D07-95AE-325050AFD961} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {89AD2BFC-A251-4398-9257-564C7A5DC181} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {89B68582-951D-4B0B-88F8-FFFB744FD526} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {90960E58-3352-471B-B7F9-11E6B4003F21} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {968CBB54-5876-4A04-85C8-4E13A6DBA0C8} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {9906E8CA-0EC9-4FA1-89DF-70D0537E1F07} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe Task: {A0FE10AC-7262-4DF5-8803-0A27FE298ED6} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe Task: {B04F7D69-DFF4-4711-8D25-E434B02B4EEE} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe Task: {B060667B-67CD-42C3-A33E-FAE3347B19B8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe Task: {B510246F-5D38-4CF6-8C2E-A1CE34A0D86F} - System32\Tasks\OneDrive Standalone Update Task v2 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {B7AB4A84-E957-4AD1-8437-0E268DFDA146} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe Task: {B840CAA8-B3E7-4372-B45E-E574CB59A18A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe Task: {BA034EB4-E9E5-4D48-9F60-737120661A1F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-14] (Google Inc.) Task: {C04C7E01-5243-4BA8-90FA-AAA7E7B83EE9} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {D384C0F2-00C8-47E5-952C-B3424CF12B88} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe Task: {EE224A03-3789-4015-99A0-D017386FC898} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {F06F0440-7D33-4476-93DB-F8958DAC5AD8} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {F6F59794-B52C-48C6-AFF1-7A1313F776DA} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-04-24 00:08 - 2016-12-29 14:44 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-04-17 07:35 - 2015-07-13 09:07 - 00179200 _____ () C:\Program Files\PostgreSQL\9.3\bin\LIBPQ.dll 2016-03-09 18:33 - 2005-04-22 06:36 - 00143360 _____ () C:\WINDOWS\system32\BrSNMP64.dll 2016-04-17 07:35 - 2014-02-05 11:16 - 01336832 _____ () C:\Program Files\PostgreSQL\9.3\bin\libxml2.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-03-18 22:59 - 2017-03-20 06:36 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00047616 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 02328576 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 02836480 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll 2017-02-27 02:35 - 2005-07-18 14:43 - 00160256 _____ () C:\Program Files (x86)\MSI\Live Update\unrar.dll 2016-03-09 18:33 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\chan\.DS_Store:AFP_AfpInfo [122] AlternateDataStreams: C:\Users\chan\Downloads\.DS_Store:AFP_AfpInfo [122] AlternateDataStreams: C:\Users\chan\Downloads\888poker_installer.exe:BDU [0] AlternateDataStreams: C:\Users\chan\Downloads\ccsetup525.exe:BDU [0] AlternateDataStreams: C:\Users\chan\Downloads\mbar-1.09.3.1001.exe:BDU [0] AlternateDataStreams: C:\Users\chan\Downloads\openvpn-install-2.4.1-I601.exe:BDU [0] AlternateDataStreams: C:\Users\chan\Downloads\SkypeSetup.exe:BDU [0] AlternateDataStreams: C:\Users\chan\Downloads\Windows10Upgrade9252.exe:BDU [0] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2017-04-23 22:59 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-32524794-2794170151-1416143709-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg HKU\S-1-5-21-32524794-2794170151-1416143709-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "PDFPrint" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\StartupFolder: => "SCS-VPN.exe" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\Run: => "EPLTarget\P0000000000000000" HKU\S-1-5-21-32524794-2794170151-1416143709-1000\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_3232C9E79A4420FE8FD45F0D0C66E2CC" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{EFA2CB86-A12E-44AA-A701-5B391B3CE115}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{F2D397FB-E10B-4E1D-BCFE-705E4C6C0866}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{37483618-EDA4-4D6D-8E6A-829F2E03F99E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{92B314DD-6E6B-437D-8F74-F5085D1031C4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{5A24AC90-26F3-4231-9399-5F2FA9D8B8F6}] => (Allow) LPort=54925 FirewallRules: [{C8E4F795-686A-4AC1-A9DC-737E330F1B18}] => (Allow) C:\Program Files (x86)\Brother\Brmfl14e\FAXRX.EXE FirewallRules: [{23EA4AC7-28EA-44DA-BB0E-C7B8E95EAD9B}] => (Allow) C:\Program Files (x86)\WinZip Driver Updater\winzipdu.exe FirewallRules: [{34BD06C6-3C3B-47BD-B6CD-759F869FE94D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe FirewallRules: [{4A0C7146-8C9E-4F67-8420-09AADE43C893}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe FirewallRules: [{FE891A75-51E8-49B9-9445-19D4F03AAE99}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{D8E841F7-0386-4CA7-BC49-AAA9BE5C19A4}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{B6FABF68-C666-4266-9403-CBC55D49E5DC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{59A0B4B8-B458-44F9-AAE8-4C808929DFE3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{4226EA48-33B1-426B-8E65-0D914018762D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{81B6B2C7-0BB9-4AF6-98EB-608519FAB101}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{9EF06111-354D-4DCC-8DF0-C8A6B9D5B0CF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{F5E2D180-9737-4078-ADB1-9F0BDD57043A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{3EB673A2-B0DF-4D79-B2B7-7490A39BA878}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{E90E6D34-2EBE-49D6-A4B2-E43F34B644AE}C:\program files (x86)\hobbyist software\vlc streamer\mdnsresponder.exe] => (Block) C:\program files (x86)\hobbyist software\vlc streamer\mdnsresponder.exe FirewallRules: [UDP Query User{8E5DD812-7B68-4FB0-822B-932E39D9B239}C:\program files (x86)\hobbyist software\vlc streamer\mdnsresponder.exe] => (Block) C:\program files (x86)\hobbyist software\vlc streamer\mdnsresponder.exe FirewallRules: [TCP Query User{F89D07E5-B96A-4B20-85E3-5FF1FFA1C2C4}C:\program files (x86)\hobbyist software\vlc streamer\vlc streamer configuration.exe] => (Block) C:\program files (x86)\hobbyist software\vlc streamer\vlc streamer configuration.exe FirewallRules: [UDP Query User{0A438475-0489-4183-8ADA-C840F6CFE9E8}C:\program files (x86)\hobbyist software\vlc streamer\vlc streamer configuration.exe] => (Block) C:\program files (x86)\hobbyist software\vlc streamer\vlc streamer configuration.exe FirewallRules: [{7B00B5EA-B135-4B12-83B2-23F614E9F545}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{C7938867-0BD5-4AF0-B11D-2DFBE0719873}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (04/24/2017 12:51:43 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: nvtray.exe, Version: 7.17.13.7653, Zeitstempel: 0x5864fb53 Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.15063.0, Zeitstempel: 0xb79b6ddb Ausnahmecode: 0xc0000374 Fehleroffset: 0x00000000000f775f ID des fehlerhaften Prozesses: 0x1f3c Startzeit der fehlerhaften Anwendung: 0x01d2bc7f57fbb455 Pfad der fehlerhaften Anwendung: C:\Program Files\NVIDIA Corporation\Display\nvtray.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll Berichtskennung: 12507c6e-9436-4191-9080-94f53900ab9d Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (04/24/2017 12:18:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: chan-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (04/24/2017 12:18:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: chan-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (04/24/2017 12:18:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: chan-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (04/24/2017 12:18:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: chan-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (04/24/2017 12:18:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: chan-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927148. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (04/24/2017 12:13:58 AM) (Source: MSDTC Client 2) (EventID: 4104) (User: ) Description: Fehler beim Abrufen des Status des Clusterknotens: .Zurückgegebener Fehlercode: 0x8007085A Error: (04/24/2017 12:13:55 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT-AUTORITÄT) Description: Vom Ereignisanbieter "wsp_sr" wurde versucht, die Abfrage "select * from WSP_ReplicationGroupModificationEvent" zu registrieren, deren Zielklasse "WSP_ReplicationGroupModificationEvent" im Namespace "//./root/Microsoft/Windows/Storage/Providers_v2" nicht vorhanden ist. Die Abfrage wird ignoriert. Error: (04/24/2017 12:13:55 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT-AUTORITÄT) Description: Vom Ereignisanbieter "wsp_sr" wurde versucht, die Abfrage "select * from WSP_ReplicationGroupDepartureEvent" zu registrieren, deren Zielklasse "WSP_ReplicationGroupDepartureEvent" im Namespace "//./root/Microsoft/Windows/Storage/Providers_v2" nicht vorhanden ist. Die Abfrage wird ignoriert. Error: (04/24/2017 12:13:55 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT-AUTORITÄT) Description: Vom Ereignisanbieter "wsp_sr" wurde versucht, die Abfrage "select * from WSP_ReplicationGroupArrivalEvent" zu registrieren, deren Zielklasse "WSP_ReplicationGroupArrivalEvent" im Namespace "//./root/Microsoft/Windows/Storage/Providers_v2" nicht vorhanden ist. Die Abfrage wird ignoriert. Systemfehler: ============= Error: (04/24/2017 12:33:19 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Computerstandard" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} und der APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (04/24/2017 12:33:19 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} und der APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (04/24/2017 12:33:19 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Computerstandard" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} und der APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (04/24/2017 12:33:19 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} und der APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (04/24/2017 12:18:22 AM) (Source: DCOM) (EventID: 10001) (User: chan-PC) Description: Ein DCOM-Server konnte nicht gestartet werden: Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca als Nicht verfügbar/Nicht verfügbar. Fehler: "31" Aufgetreten beim Start dieses Befehls: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca Error: (04/24/2017 12:15:19 AM) (Source: NETLOGON) (EventID: 3095) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (04/24/2017 12:14:46 AM) (Source: WinRM) (EventID: 10142) (User: ) Description: Der WinRM-Dienst kann den Listener mit der Adresse * und der Transporteinstellung "HTTP" nicht migrieren. Ein Listener mit dieser Adress- und Transportkonfiguration ist bereits vorhanden. Error: (04/24/2017 12:12:33 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Error: (04/24/2017 12:12:32 AM) (Source: Microsoft-Windows-Eventlog) (EventID: 22) (User: NT-AUTORITÄT) Description: Der Ereignisprotokollierungsdienst hat einen Fehler beim Initialisieren der Veröffentlichung von Ressourcen für Kanal "AirSpaceChannel" erkannt. Falls ein direkter Kanal festgelegt ist, kann dies ein Hinweis darauf sein, dass auch das Protokollieren der Ressourcen nicht initialisiert werden konnte. Error: (04/24/2017 12:12:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz Prozentuale Nutzung des RAM: 31% Installierter physikalischer RAM: 8162.12 MB Verfügbarer physikalischer RAM: 5587.3 MB Summe virtueller Speicher: 16354.12 MB Verfügbarer virtueller Speicher: 11923.23 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:476.4 GB) (Free:221.28 GB) NTFS Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive e: (2000) (Fixed) (Total:2028.54 GB) (Free:512.22 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 476.9 GB) (Disk ID: ABA9B99F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=476.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 6594A802) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=2028.5 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
25.04.2017, 12:28 | #3 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Computer langsam ? laggt beim surfen Malwarebytes Anti-Rootkit (MBAR)
__________________Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
25.04.2017, 15:33 | #4 |
| Computer langsam ? laggt beim surfen hm nix gefunden Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2017.04.25.04 rootkit: v2017.04.02.01 Windows 10 x64 NTFS Internet Explorer 11.0.15063.0 chan1 :: CHAN-PC [administrator] 25.04.2017 16:19:14 mbar-log-2017-04-25 (16-19-14).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 370837 Time elapsed: 10 minute(s), 50 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
25.04.2017, 21:42 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Computer langsam ? laggt beim surfen Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ Logfiles bitte immer in CODE-Tags posten |
25.04.2017, 22:39 | #6 |
| Computer langsam ? laggt beim surfenCode:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2017.04.25.04 rootkit: v2017.04.02.01 Windows 10 x64 NTFS Internet Explorer 11.0.15063.0 chan1 :: CHAN-PC [administrator] 25.04.2017 16:19:14 mbar-log-2017-04-25 (16-19-14).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 370837 Time elapsed: 10 minute(s), 50 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.3 (04.10.2017) Operating System: Windows 10 Home x64 Ran by chan1 (Administrator) on 25.04.2017 at 23:35:49,34 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 0 Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 25.04.2017 at 23:36:26,09 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
25.04.2017, 22:55 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Computer langsam ? laggt beim surfen adwCleaner solltest du machen, nicht MBAR.
__________________ Logfiles bitte immer in CODE-Tags posten |
25.04.2017, 23:04 | #8 |
| Computer langsam ? laggt beim surfen hatte ich auch gemacht nur verpeilt beim posten AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v6.045 - Bericht erstellt am 25/04/2017 um 23:29:48 # Aktualisiert am 28/03/2017 von Malwarebytes # Datenbank : 2017-04-25.1 [Server] # Betriebssystem : Windows 10 Home (X64) # Benutzername : chan1 - CHAN-PC # Gestartet von : C:\Users\chan\Desktop\AdwCleaner_6.045.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** ***** [ Dateien ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: "Prefetch" Dateien gelöscht :: Proxy Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht :: Chrome Einstellungen zurückgesetzt: C:\Users\chan\AppData\Local\Google\Chrome\User Data\Default ************************* \AdwCleaner\AdwCleaner[C0].txt - [1058 Bytes] - [25/04/2017 23:29:48] \AdwCleaner\AdwCleaner[S0].txt - [1333 Bytes] - [25/04/2017 23:27:22] ########## EOF - \AdwCleaner\AdwCleaner[C0].txt - [1200 Bytes] ########## |
25.04.2017, 23:06 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Computer langsam ? laggt beim surfen Daist ja garnix an Funden. Du hast ein anderes Problem. Mach ein neues Thema im Windowsbreich hier auf.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Computer langsam ? laggt beim surfen |
computer, defender, explorer, firefox, flash player, google, help, helper, home, installation, internet, internet explorer, langsam, logfile, mozilla, prozesse, realtek, scan, security, services.exe, software, starten, system, temp, windows |