|
Log-Analyse und Auswertung: GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner BefallWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.03.2016, 13:16 | #1 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Ich habe heute eine Mail von GiroPay24 bekommen, welche sich für mich erst im nachhinein als Spam/Phishing Mail rausstellte. Nun habe ich aber schon den Anhang in Form einer .zip Datei geladen und mit Winrar geöffnet gehabt. Die Datei die sich dort drinnen befand, habe ich nicht angerührt (weder entpackt noch Ausgeführt), und habe die zip Datei auch sofort wieder gelöscht. Nun bin ich mir aber unsicher ob ich nicht trotzdem einen Trojaner/Virus auf meinem Notebook habe und wollte hier einmal fragen ob Sie mir da helfen können dies her raus zu finden. Den FRST Scan habe ich schon gemacht: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 durchgeführt von Zajii (Administrator) auf ZAJI (30-03-2016 14:07:41) Gestartet von C:\Users\Zajii\Desktop Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji) Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe (Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe (Razer, Inc.) C:\Users\Zajii\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LU.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.15.22005.0_x64__8wekyb3d8bbwe\XboxApp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Valve Corporation) C:\Steam\Steam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Valve Corporation) C:\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) C:\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Steam\bin\steamwebhelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor) HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] () HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] () HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated) HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH) HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.) HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] () HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-28] (Valve Corporation) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software) ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30] ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1 ManualProxies: Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation) DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab FireFox: ======== FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] () FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc) FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare) FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26] FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25] FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden Chrome: ======= CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25] CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09] CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20] CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14] CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23] CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-12] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28] CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] () S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.) R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd) R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo) R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts) R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD) R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo) S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated) S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software) R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd) R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>) S3 gkernel; C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [31512 2016-01-14] () S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm)) R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc) S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation) S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek ) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated) S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS) S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert] S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] () S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] () S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] () S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.) R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation) S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-03-30 14:07 - 2016-03-30 14:08 - 00031900 _____ C:\Users\Zajii\Desktop\FRST.txt 2016-03-30 14:07 - 2016-03-30 14:07 - 00000000 ____D C:\FRST 2016-03-30 13:58 - 2016-03-30 13:58 - 00002879 _____ C:\Users\Zajii\Desktop\mbam2.txt 2016-03-30 13:58 - 2016-03-30 13:58 - 00002878 _____ C:\Users\Zajii\Desktop\mbam.txt 2016-03-30 13:52 - 2016-03-30 13:52 - 01610352 _____ (Malwarebytes) C:\Users\Zajii\Desktop\JRT.exe 2016-03-30 13:21 - 2016-03-30 13:21 - 00000000 ____D C:\AdwCleaner 2016-03-30 13:20 - 2016-03-30 14:07 - 02374144 _____ (Farbar) C:\Users\Zajii\Desktop\FRST64.exe 2016-03-30 13:20 - 2016-03-30 13:21 - 03102208 _____ C:\Users\Zajii\Desktop\AdwCleaner_5.107.exe 2016-03-30 13:06 - 2016-03-30 13:08 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-03-30 13:05 - 2016-03-30 13:59 - 00001180 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-03-30 13:05 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-03-30 13:05 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-03-30 13:05 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-03-30 12:59 - 2016-03-30 13:05 - 22851472 _____ (Malwarebytes ) C:\Users\Zajii\Desktop\mbam-setup-2.2.1.1043.exe 2016-03-30 12:34 - 2016-03-30 12:34 - 00000000 ____D C:\Program Files\Common Files\AV 2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions 2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions 2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc 2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer 2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer 2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer 2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple 2016-03-20 13:55 - 2016-03-26 00:28 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben 2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive 2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4 2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4 2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4 2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4 2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4 2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4 2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4 2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4 2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4 2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4 2016-03-18 03:28 - 2016-03-18 03:28 - 00003040 _____ C:\WINDOWS\System32\Tasks\avast! Windows 10 Start Menu helper 2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062 2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe 2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5 2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload 2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games 2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll 2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll 2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS 2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe 2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll 2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll 2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll 2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll 2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll 2016-03-07 23:56 - 2016-03-08 00:03 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers 2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-03-06 22:50 - 2016-03-06 22:50 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062_2016.03.06.20.52.54 2016-03-05 13:47 - 2016-03-30 13:03 - 00000000 ____D C:\Program Files\Defraggler 2016-03-05 01:50 - 2016-03-30 13:59 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk 2016-03-05 01:50 - 2016-03-30 13:58 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk 2016-03-05 01:49 - 2016-03-05 01:50 - 00000000 ____D C:\ProgramData\BlueStacksGameManager 2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\ProgramData\BlueStacks 2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\Program Files (x86)\BlueStacks 2016-03-05 01:46 - 2016-03-05 01:46 - 00000000 ____D C:\Users\Zajii\AppData\Local\Bluestacks 2016-03-02 11:52 - 2016-02-23 12:32 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-03-02 11:52 - 2016-02-23 11:38 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 13:25 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-03-02 11:51 - 2016-02-23 12:34 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 12:32 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-03-02 11:51 - 2016-02-23 12:32 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2016-03-02 11:51 - 2016-02-23 12:31 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-03-02 11:51 - 2016-02-23 12:31 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-03-02 11:51 - 2016-02-23 12:21 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-03-02 11:51 - 2016-02-23 11:45 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-03-02 11:51 - 2016-02-23 11:38 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2016-03-02 11:51 - 2016-02-23 11:38 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-03-02 11:51 - 2016-02-23 11:27 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-03-02 11:51 - 2016-02-23 10:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-03-02 11:51 - 2016-02-23 10:29 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll 2016-03-02 11:51 - 2016-02-23 10:28 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-03-02 11:51 - 2016-02-23 10:09 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-03-02 11:51 - 2016-02-23 10:00 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-03-02 11:51 - 2016-02-23 09:30 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-03-02 11:51 - 2016-02-23 09:24 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-03-02 11:51 - 2016-02-23 09:22 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-03-02 11:51 - 2016-02-23 09:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-03-02 11:51 - 2016-02-23 08:59 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-03-02 11:51 - 2016-02-23 08:55 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-03-02 11:51 - 2016-02-23 08:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-03-02 11:51 - 2016-02-23 08:50 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-03-02 11:51 - 2016-02-23 08:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-03-02 11:51 - 2016-02-23 08:39 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-03-02 11:51 - 2016-02-23 08:36 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-03-02 11:51 - 2016-02-23 08:30 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-03-02 11:51 - 2016-02-09 05:04 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-03-02 11:50 - 2016-02-23 13:29 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-03-02 11:50 - 2016-02-23 13:29 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-03-02 11:50 - 2016-02-23 13:27 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-03-02 11:50 - 2016-02-23 13:27 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-03-02 11:50 - 2016-02-23 13:25 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-03-02 11:50 - 2016-02-23 13:25 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2016-03-02 11:50 - 2016-02-23 13:15 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2016-03-02 11:50 - 2016-02-23 13:08 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-03-02 11:50 - 2016-02-23 12:34 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-03-02 11:50 - 2016-02-23 12:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-03-02 11:50 - 2016-02-23 12:32 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-03-02 11:50 - 2016-02-23 12:32 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 12:32 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 2016-03-02 11:50 - 2016-02-23 12:31 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 12:31 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2016-03-02 11:50 - 2016-02-23 12:31 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2016-03-02 11:50 - 2016-02-23 12:25 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-03-02 11:50 - 2016-02-23 12:22 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2016-03-02 11:50 - 2016-02-23 12:17 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys 2016-03-02 11:50 - 2016-02-23 11:40 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2016-03-02 11:50 - 2016-02-23 11:39 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2016-03-02 11:50 - 2016-02-23 11:37 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2016-03-02 11:50 - 2016-02-23 11:32 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2016-03-02 11:50 - 2016-02-23 11:30 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-03-02 11:50 - 2016-02-23 11:27 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll 2016-03-02 11:50 - 2016-02-23 11:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll 2016-03-02 11:50 - 2016-02-23 11:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-03-02 11:50 - 2016-02-23 11:19 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2016-03-02 11:50 - 2016-02-23 11:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2016-03-02 11:50 - 2016-02-23 11:06 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll 2016-03-02 11:50 - 2016-02-23 10:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-03-02 11:50 - 2016-02-23 10:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys 2016-03-02 11:50 - 2016-02-23 10:50 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2016-03-02 11:50 - 2016-02-23 10:40 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll 2016-03-02 11:50 - 2016-02-23 10:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll 2016-03-02 11:50 - 2016-02-23 10:38 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll 2016-03-02 11:50 - 2016-02-23 10:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-03-02 11:50 - 2016-02-23 10:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-03-02 11:50 - 2016-02-23 10:37 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-03-02 11:50 - 2016-02-23 10:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll 2016-03-02 11:50 - 2016-02-23 10:34 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll 2016-03-02 11:50 - 2016-02-23 10:34 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2016-03-02 11:50 - 2016-02-23 10:27 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll 2016-03-02 11:50 - 2016-02-23 10:26 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 2016-03-02 11:50 - 2016-02-23 10:22 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2016-03-02 11:50 - 2016-02-23 10:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 2016-03-02 11:50 - 2016-02-23 10:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2016-03-02 11:50 - 2016-02-23 10:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 10:19 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2016-03-02 11:50 - 2016-02-23 10:19 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2016-03-02 11:50 - 2016-02-23 10:18 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2016-03-02 11:50 - 2016-02-23 10:14 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll 2016-03-02 11:50 - 2016-02-23 10:12 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-03-02 11:50 - 2016-02-23 10:11 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-03-02 11:50 - 2016-02-23 10:10 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2016-03-02 11:50 - 2016-02-23 10:10 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-03-02 11:50 - 2016-02-23 10:09 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-03-02 11:50 - 2016-02-23 10:09 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-03-02 11:50 - 2016-02-23 10:06 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-03-02 11:50 - 2016-02-23 10:05 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-03-02 11:50 - 2016-02-23 10:04 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll 2016-03-02 11:50 - 2016-02-23 10:04 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2016-03-02 11:50 - 2016-02-23 10:04 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-03-02 11:50 - 2016-02-23 10:02 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2016-03-02 11:50 - 2016-02-23 10:02 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2016-03-02 11:50 - 2016-02-23 09:58 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll 2016-03-02 11:50 - 2016-02-23 09:52 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2016-03-02 11:50 - 2016-02-23 09:50 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2016-03-02 11:50 - 2016-02-23 09:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2016-03-02 11:50 - 2016-02-23 09:47 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2016-03-02 11:50 - 2016-02-23 09:38 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2016-03-02 11:50 - 2016-02-23 09:37 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2016-03-02 11:50 - 2016-02-23 09:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2016-03-02 11:50 - 2016-02-23 09:36 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll 2016-03-02 11:50 - 2016-02-23 09:36 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 09:35 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2016-03-02 11:50 - 2016-02-23 09:31 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2016-03-02 11:50 - 2016-02-23 09:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-03-02 11:50 - 2016-02-23 09:29 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-03-02 11:50 - 2016-02-23 09:28 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll 2016-03-02 11:50 - 2016-02-23 09:24 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-03-02 11:50 - 2016-02-23 09:24 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll 2016-03-02 11:50 - 2016-02-23 09:24 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2016-03-02 11:50 - 2016-02-23 09:21 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2016-03-02 11:50 - 2016-02-23 09:14 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2016-03-02 11:50 - 2016-02-23 09:11 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-03-02 11:50 - 2016-02-23 09:05 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2016-03-02 11:50 - 2016-02-23 09:01 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2016-03-02 11:50 - 2016-02-23 08:58 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll 2016-03-02 11:50 - 2016-02-23 08:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-03-02 11:50 - 2016-02-23 08:55 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-03-02 11:50 - 2016-02-23 08:53 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-03-02 11:50 - 2016-02-23 08:51 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-03-02 11:50 - 2016-02-23 08:42 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-03-02 11:50 - 2016-02-23 08:41 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2016-03-02 11:50 - 2016-02-23 08:36 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-03-02 11:50 - 2016-02-23 08:35 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-03-02 11:50 - 2016-02-23 08:33 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2016-03-02 11:50 - 2016-02-23 08:32 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-03-02 11:50 - 2016-02-23 08:28 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-03-02 11:50 - 2016-02-09 06:28 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2016-03-02 11:50 - 2016-02-09 06:13 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2016-03-02 11:50 - 2016-02-09 05:24 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-03-02 11:50 - 2016-02-09 05:18 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll 2016-03-02 11:50 - 2016-02-09 05:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll 2016-03-02 11:50 - 2016-02-09 05:07 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-03-02 11:50 - 2016-02-09 05:07 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-03-02 11:49 - 2016-02-23 12:33 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2016-03-02 11:49 - 2016-02-23 11:25 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2016-03-02 11:49 - 2016-02-23 11:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll 2016-03-02 11:49 - 2016-02-23 10:53 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll 2016-03-02 11:49 - 2016-02-23 10:52 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe 2016-03-02 11:49 - 2016-02-23 10:39 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2016-03-02 11:49 - 2016-02-23 10:31 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2016-03-02 11:49 - 2016-02-23 09:58 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2016-03-02 11:49 - 2016-02-23 09:49 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-03-02 11:49 - 2016-02-23 09:28 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll 2016-03-02 11:48 - 2016-02-23 11:12 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll 2016-03-02 11:48 - 2016-02-23 11:10 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll 2016-03-02 11:48 - 2016-02-23 11:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-03-02 11:48 - 2016-02-23 11:07 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll 2016-03-02 11:48 - 2016-02-23 11:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys 2016-03-02 11:48 - 2016-02-23 11:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll 2016-03-02 11:48 - 2016-02-23 10:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-03-02 11:48 - 2016-02-23 10:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2016-03-02 11:48 - 2016-02-23 10:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll 2016-03-02 11:48 - 2016-02-23 10:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll 2016-03-02 11:48 - 2016-02-23 10:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-03-02 11:48 - 2016-02-23 10:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll 2016-03-02 11:48 - 2016-02-23 10:33 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2016-03-02 11:48 - 2016-02-23 10:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-03-02 11:48 - 2016-02-23 10:23 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 2016-03-02 11:48 - 2016-02-23 10:20 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-03-02 11:48 - 2016-02-23 10:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-03-02 11:48 - 2016-02-23 10:06 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-03-02 11:48 - 2016-02-23 10:06 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2016-03-02 11:48 - 2016-02-23 10:02 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-03-02 11:48 - 2016-02-23 09:58 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2016-03-02 11:48 - 2016-02-23 09:58 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2016-03-02 11:48 - 2016-02-23 09:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll 2016-03-02 11:48 - 2016-02-23 09:36 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-03-02 11:48 - 2016-02-23 09:21 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-03-02 11:48 - 2016-02-23 09:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-03-30 14:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk 2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk 2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk 2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk 2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk 2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk 2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk 2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk 2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk 2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk 2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk 2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk 2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk 2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk 2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk 2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk 2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk 2016-03-30 13:58 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk 2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk 2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk 2016-03-30 13:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games 2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs 2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-03-30 13:07 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini 2016-03-30 13:07 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2016-03-30 13:07 - 2015-05-08 23:28 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media 2016-03-30 12:24 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-03-30 12:20 - 2014-12-12 23:08 - 00000000 ____D C:\Steam 2016-03-30 11:22 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0 2016-03-30 11:09 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-03-30 11:06 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat 2016-03-30 11:06 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat 2016-03-30 11:06 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-03-30 11:06 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-03-30 11:04 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2016-03-30 11:01 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update 2016-03-30 11:01 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-03-30 11:01 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager 2016-03-30 11:00 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-03-30 11:00 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles 2016-03-30 10:59 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2016-03-30 10:58 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-03-30 07:28 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-03-30 05:20 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc 2016-03-30 05:03 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype 2016-03-30 01:28 - 2015-12-16 22:25 - 00345848 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys 2016-03-30 01:27 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client 2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java 2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage 2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java 2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie 2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software 2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software 2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml 2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml 2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta 2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple 2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii 2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net 2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like 2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone 2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net 2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net 2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt 2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS 2016-03-12 19:25 - 2016-02-26 22:51 - 00011914 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods 2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood 2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt 2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames 2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys 2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys 2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games 2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-07 19:41 - 2015-11-14 16:27 - 00000000 ____D C:\Users\Zajii\AppData\Local\Skype 2016-03-07 19:41 - 2015-11-14 16:26 - 00000000 ____D C:\ProgramData\Skype 2016-03-05 05:22 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache 2016-03-05 01:49 - 2015-10-30 09:24 - 00000000 __RHD C:\Users\Public\Libraries 2016-03-05 01:44 - 2015-02-13 12:27 - 00000000 ____D C:\Users\Zajii\.VirtualBox 2016-03-03 13:44 - 2014-12-13 02:46 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-03-03 05:00 - 2015-10-30 20:44 - 00000000 ____D C:\Program Files\Windows Journal 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 __RSD C:\WINDOWS\Media 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-03-02 02:38 - 2015-02-19 19:12 - 00000000 ____D C:\Users\Zajii\AppData\Local\Steam 2016-03-01 01:44 - 2016-02-22 13:40 - 00000000 ____D C:\Users\Zajii\Desktop\Musik 2016-02-29 00:05 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log 2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg 2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip 2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Einige Dateien in TEMP: ==================== C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll C:\Users\Zajii\AppData\Local\Temp\7230fefd864f35e6569012bef46d88ae.dll C:\Users\Zajii\AppData\Local\Temp\7b71d939ac8f4f430ba02b964dfb5794.dll C:\Users\Zajii\AppData\Local\Temp\EslWireSetup-1.19.0.8185-x64.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u71-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u73-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\LSCSetup64.exe C:\Users\Zajii\AppData\Local\Temp\proxy_vole4465310535655270772.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole4974038499892493031.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole732673072298846164.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole8651342122685071258.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole9215304146252064412.dll C:\Users\Zajii\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-03-28 13:58 ==================== Ende von FRST.txt ============================ |
30.03.2016, 13:17 | #2 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Additional.txt
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 durchgeführt von Zajii (2016-03-30 14:09:11) Gestartet von C:\Users\Zajii\Desktop Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled) Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled) Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC) 7 Days to Die (HKLM-x32\...\Steam App 251570) (Version: - The Fun Pimps) 7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.) Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version: - Ensemble Studios) Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version: - Akamai Technologies, Inc) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation) Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment) Arms Dealer (HKLM-x32\...\Steam App 325630) (Version: - Case in Point Studios, LLC) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software) Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version: - DICE) Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC) Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation) BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version: - ) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com) Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe) CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version: - Eidos Montreal) Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version: - Splash Damage®) DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) Down To One (HKLM-x32\...\Steam App 334040) (Version: - Gadget Games) Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version: - ) Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version: - Eyedentity Games) Endless Space (HKLM-x32\...\Steam App 208140) (Version: - AMPLITUDE Studios) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo) Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version: - momoStorm Entertainment) ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version: - Turtle Entertainment GmbH) Europa Universalis IV (HKLM\...\Steam App 236850) (Version: - Paradox Development Studio) Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version: - ) Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups) Garena - Android Emulator (HKLM-x32\...\nox) (Version: - Garena Online Pte Ltd.) Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.) Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q) Garena+ (HKLM-x32\...\im) (Version: 2011 - Garena Online Pte Ltd.) Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Grim Dawn (HKLM-x32\...\Steam App 219990) (Version: - Crate Entertainment) Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version: - Trek Industries, Inc) GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - ) H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version: - Daybreak Game Company) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive) Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.) Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation) Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Kenshi (HKLM-x32\...\Steam App 233860) (Version: - Lo-Fi Games) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) KuaiZip (HKLM-x32\...\KuaiZip) (Version: - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.) Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.) Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab) Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo) Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo) Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation) Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech) Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version: - Arkavi Studios) Magic Duels (HKLM-x32\...\Steam App 316010) (Version: - Stainless Games Ltd.) Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - ) Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo) Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG) MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version: - BlueByte) Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version: - TaleWorlds Entertainment) Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT) Nightbanes (HKLM-x32\...\Steam App 338340) (Version: - Diviad) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team) NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version: - Haemimont Games) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.) osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software) Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version: - Ndemic Creations) Planet Explorers (HKLM-x32\...\Steam App 237870) (Version: - Pathea Games) Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version: - Uber Entertainment) Portal Knights (HKLM\...\Steam App 374040) (Version: - Keen Games) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version: - Millenway Studios) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru) Raptr (HKLM-x32\...\Raptr) (Version: - ) Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.) Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version: - EasyGameStation) Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version: - Ascaron) SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version: - Winged Cloud) Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH) Sengoku (HKLM-x32\...\Steam App 73210) (Version: - Paradox Development Studio) SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version: - Ironclad Games) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version: - United Front Games) Spellweaver (HKLM-x32\...\Steam App 429680) (Version: - Dream Reactor) Star Realms (HKLM\...\Steam App 438140) (Version: - White Wizard Games) Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version: - Little Green Men Games) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Survivalist (HKLM-x32\...\Steam App 340050) (Version: - Bob the Game Development Bot) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated) Tabletop Simulator (HKLM\...\Steam App 286160) (Version: - Berserk Games) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Tempest (HKLM-x32\...\Steam App 418180) (Version: - Lion's Shade) The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version: - KTX Software) The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version: - Virtual Basement LLC) Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH) Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS) Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Windows Driver Package - BigNox Corporation XQHDrv System (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation) Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll () ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated) Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software) Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo) Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.) Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\" Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\" Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires" Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software) Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation) Task: {F8887BAF-4E6A-45F7-B7D9-2140E874EBFB} - System32\Tasks\avast! Windows 10 Start Menu helper => c:\program files\avast software\avast\asww10mon.exe [2016-03-18] (AVAST Software) Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe 2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll 2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll 2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe 2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe 2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-03-29 11:43 - 2016-03-29 11:47 - 00016896 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-03-29 11:43 - 2016-03-29 11:47 - 17535488 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-03-04 12:15 - 2016-03-04 12:15 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-03-24 09:17 - 2016-03-24 09:19 - 00016384 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.15.22005.0_x64__8wekyb3d8bbwe\XboxApp.exe 2016-03-24 09:17 - 2016-03-24 09:19 - 35425280 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.15.22005.0_x64__8wekyb3d8bbwe\XboxApp.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-03-29 19:12 - 2016-03-29 19:12 - 02846208 _____ () C:\Program Files\AVAST Software\Avast\defs\16032901\algo.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-12-23 10:25 - 2016-03-30 11:01 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll 2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll 2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll 2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2014-01-07 15:03 - 2014-01-07 15:03 - 02440512 _____ () C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterFilter.ax 2014-12-12 23:20 - 2016-03-11 02:56 - 00783360 _____ () C:\Steam\SDL2.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 04962816 _____ () C:\Steam\v8.dll 2014-12-12 23:20 - 2016-03-28 23:34 - 02549840 _____ () C:\Steam\video.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00332800 _____ () C:\Steam\libavresample-2.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00491008 _____ () C:\Steam\libavformat-56.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 02549760 _____ () C:\Steam\libavcodec-56.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00442880 _____ () C:\Steam\libavutil-54.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00485888 _____ () C:\Steam\libswscale-3.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 01556992 _____ () C:\Steam\icui18n.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 01187840 _____ () C:\Steam\icuuc.dll 2014-12-12 23:20 - 2016-03-28 23:34 - 00829008 _____ () C:\Steam\bin\chromehtml.DLL 2016-03-09 12:09 - 2016-02-18 00:25 - 00281088 _____ () C:\Steam\openvr_api.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll 2015-12-05 12:29 - 2016-02-09 03:33 - 48400672 _____ () C:\Steam\bin\libcef.dll 2015-12-05 12:29 - 2015-09-25 01:56 - 00119208 _____ () C:\Steam\winh264.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com Da befinden sich 7866 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk" HKLM\...\StartupApproved\Run: => "PhoneCompanion" HKLM\...\StartupApproved\Run: => "LogMeIn GUI" HKLM\...\StartupApproved\Run: => "Connectify Hotspot" HKLM\...\StartupApproved\Run: => "Start WingMan Profiler" HKLM\...\StartupApproved\Run32: => "BlueStacks Agent" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Raptr" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [{381CD377-1188-4C89-A1C9-D083F12FE010}] => (Allow) C:\Users\Zajii\AppData\Roaming\Tencent\穿越火线\4D3FC433DB9BBD3BB0CC9DEB630740EA\TenioDL\TenioDL.exe FirewallRules: [{7E92482E-8282-49EC-8643-A8AE86E0612E}] => (Allow) C:\Users\Zajii\AppData\Roaming\Tencent\穿越火线\4D3FC433DB9BBD3BB0CC9DEB630740EA\TenioDL\TenioDL.exe FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [{61F44546-AF90-4052-BDC8-8C2BA3998852}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\PCMng\PCMLoader\QQPCDetector.exe FirewallRules: [{67430F27-84E3-4BCB-B13E-9FE5DB5F0422}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\PCMng\PCMLoader\QQPCDetector.exe FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [{38E9D37A-19CD-4C3D-9DA3-0DD35DBD4610}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{B23BAC6E-B86A-4175-AEA4-62C0A239B4DF}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Wiederherstellungspunkte ========================= 23-03-2016 17:25:55 Installed Windows 7 USB/DVD Download Tool 30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (03/30/2016 11:23:32 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (03/29/2016 09:00:08 PM) (Source: MsiInstaller) (EventID: 11722) (User: ZAJI) Description: Produkt: Java 8 Update 77 (64-bit) -- Fehler 1722. Es liegt ein Problem mit diesem Windows Installer-Paket vor. Ein Programm, das im Rahmen der Installation ausgeführt wurde, wurde nicht erfolgreich abgeschlossen. Wenden Sie sich an den Support oder den Hersteller des Pakets. Aktion: installexe, Pfad: C:\Program Files\Java\jre1.8.0_77\installer.exe, Befehl: /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_77\\" REPAIRMODE=0 ProductCode={26A24AE4-039D-4CA4-87B4-2F86418077F0} Error: (03/29/2016 08:59:55 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm jre-8u77-windows-au.exe, Version 8.0.770.3 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c1c Startzeit: 01d189ecd9e77df6 Beendigungszeit: 4294967295 Anwendungspfad: C:\Users\Zajii\AppData\Local\Temp\jds35309750.tmp\jre-8u77-windows-au.exe Berichts-ID: 6c29d6ce-f5e0-11e5-8326-54ee7517f830 Vollständiger Name des fehlerhaften Pakets: Auf das fehlerhafte Paket bezogene Anwendungs-ID: Error: (03/29/2016 08:06:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35 Name des fehlerhaften Moduls: igd10iumd64.dll, Version: 10.18.15.4279, Zeitstempel: 0x55db7ece Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000151c3a ID des fehlerhaften Prozesses: 0x2d90 Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0 Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1 Pfad des fehlerhaften Moduls: microsoftedgecp.exe2 Berichtskennung: microsoftedgecp.exe3 Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5 Error: (03/29/2016 04:20:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 44.0.2.5884, Zeitstempel: 0x56bbf417 Name des fehlerhaften Moduls: mozglue.dll, Version: 44.0.2.5884, Zeitstempel: 0x56bbe58e Ausnahmecode: 0x80000003 Fehleroffset: 0x0000ed3b ID des fehlerhaften Prozesses: 0x2890 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5 Error: (03/29/2016 04:20:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm firefox.exe, Version 44.0.2.5884 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1e44 Startzeit: 01d189bb993dce2a Beendigungszeit: 149 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 6c791c20-f5b9-11e5-8326-54ee7517f830 Vollständiger Name des fehlerhaften Pakets: Auf das fehlerhafte Paket bezogene Anwendungs-ID: Error: (03/29/2016 03:54:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZAJI) Description: Bei der Aktivierung der App „Microsoft.XboxApp_8wekyb3d8bbwe!Microsoft.XboxApp“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (03/28/2016 08:59:05 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 12 1.0.0.127.in-addr.arpa. PTR Zaji.local. Error: (03/28/2016 08:59:05 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 127.0.0.1:5353 14 1.0.0.127.in-addr.arpa. PTR Zaji-2.local. Error: (03/28/2016 08:58:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1171 Systemfehler: ============= Error: (03/30/2016 12:51:23 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 12:51:15 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 12:51:15 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 12:51:15 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 12:21:05 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 12:21:05 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 12:21:04 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 12:21:04 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (03/30/2016 11:24:56 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (03/30/2016 11:04:09 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Übermittlungsoptimierung" wurde nicht richtig gestartet. CodeIntegrity: =================================== Date: 2016-03-24 02:26:58.699 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-23 04:00:10.692 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-22 14:17:50.313 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 18:18:45.659 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 14:34:08.548 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-10 10:17:26.727 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-03 12:41:33.511 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-02 15:35:16.954 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 17:56:24.126 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 07:03:27.892 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz Prozentuale Nutzung des RAM: 33% Installierter physikalischer RAM: 12196.01 MB Verfügbarer physikalischer RAM: 8127.68 MB Summe virtueller Speicher: 12964.01 MB Verfügbarer virtueller Speicher: 8339.14 MB ==================== Laufwerke ================================ Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:402.4 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3) Partition: GPT. ==================== Ende von Addition.txt ============================ |
01.04.2016, 13:55 | #3 |
/// Malwareteam | GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner BefallMein Name ist Rafael und ich werde dir bei der Bereinigung helfen. Damit ich dir optimal helfen kann, halte dich bitte an folgende Regeln:
Also normal kann dabei nichts passieren. Machen wir einfach mal einen allgemeinen Scan, um ganz sicher zu gehen dass dein PC passt. Schritt 1 Lade dir folgendes Programm herunter und installiere es: Malwarebytes Anti-Malware Hier findest du dazu eine bebilderte Anleitung
Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen. Bitte poste in deiner nächsten Antwort also:
__________________ |
01.04.2016, 18:52 | #4 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Guten Tag, die mbam.txt haben wir hier: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 30.03.2016 Suchlaufzeit: 13:09 Protokolldatei: 123.txt Administrator: Ja Version: 2.2.1.1043 Malware-Datenbank: v2016.03.30.02 Rootkit-Datenbank: v2016.03.12.01 Lizenz: Testversion Malware-Schutz: Aktiviert Schutz vor bösartigen Websites: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: Zajii Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 495639 Abgelaufene Zeit: 48 Min., 23 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 5 PUP.Optional.APNToolBar.Gen, HKLM\SOFTWARE\WOW6432NODE\AskPartnerNetwork, , [ebff64297722e94d65ead2620ef5669a], PUP.Optional.HomeTab, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\HomeTab, , [df0b5637acedec4a76b51c04c53f6f91], PUP.Optional.SearchProtect.AppFlsh, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\SearchProtectWS, , [af3bb3da6930e452eb9abac91aea9868], PUP.Optional.Wajam, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\WajIEnhance, , [8961c5c8811824120e9b162dbd47ce32], PUP.Optional.Wajam, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\WajIntEnhance, , [d1192a63089182b46c3e4102c73d27d9], Registrierungswerte: 1 PUP.Optional.FFToolbar, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fftoolbar2014@etech.com, C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\066h65fl.default\extensions\fftoolbar2014@etech.com, , [76740984fd9c63d3ffeac753cc3827d9] Registrierungsdaten: 2 PUP.Optional.MyStartSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}),,[d713e2ab207957df326159cb3acbd927] PUP.Optional.MyStartSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}),,[9d4d3b52d9c069cd286bed37ae5758a8] Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v5.108 - Bericht erstellt am 01/04/2016 um 19:31:25 # Aktualisiert am 30/03/2016 von Xplode # Datenbank : 2016-03-30.1 [Server] # Betriebssystem : Windows 10 Home (x64) # Benutzername : Zajii - ZAJI # Gestartet von : C:\Users\Zajii\Downloads\adwcleaner_5.108.exe # Option : Löschen # Unterstützung : hxxp://toolslib.net/forum ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner gelöscht : C:\Program Files (x86)\tencent [-] Ordner gelöscht : C:\ProgramData\tencent [-] Ordner gelöscht : C:\Users\Zajii\AppData\Roaming\tencent [-] Ordner gelöscht : C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\tencent ***** [ Dateien ] ***** [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d2ixp54vc4byye.cloudfront.net_0.localstorage [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d2ixp54vc4byye.cloudfront.net_0.localstorage-journal [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d1733r3id7jrw5.cloudfront.net_0.localstorage [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d1733r3id7jrw5.cloudfront.net_0.localstorage-journal [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_dabfg7woo1qnr.cloudfront.net_0.localstorage [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_dabfg7woo1qnr.cloudfront.net_0.localstorage-journal [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_film.qq.com_0.localstorage [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_film.qq.com_0.localstorage-journal [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_v.qq.com_0.localstorage [-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_v.qq.com_0.localstorage-journal ***** [ DLLs ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\AndyAPK [-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\metnsd [-] Schlüssel gelöscht : HKCU\Software\Conduit [-] Schlüssel gelöscht : HKCU\Software\Kromtech [-] Schlüssel gelöscht : HKCU\Software\simplytech [-] Schlüssel gelöscht : HKLM\SOFTWARE\AIM Toolbar [-] Schlüssel gelöscht : HKLM\SOFTWARE\Conduit [-] Schlüssel gelöscht : HKLM\SOFTWARE\SearchProtect [-] Schlüssel gelöscht : HKLM\SOFTWARE\SpeedBit [-] Schlüssel gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IM [-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{381CD377-1188-4C89-A1C9-D083F12FE010}] [-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{7E92482E-8282-49EC-8643-A8AE86E0612E}] [-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{61F44546-AF90-4052-BDC8-8C2BA3998852}] [-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{67430F27-84E3-4BCB-B13E-9FE5DB5F0422}] [-] Schlüssel gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\image.tgp.qq.com [-] Schlüssel gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\qq.com [-] Schlüssel gelöscht : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d2ixp54vc4byye.cloudfront.net [-] Schlüssel gelöscht : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d2ixp54vc4byye.cloudfront.net ***** [ Internetbrowser ] ***** ************************* :: "Tracing" schlüssel löschen :: Proxy Einstellungen zurückgesetzt :: Winsock Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C1].txt - [4707 Bytes] - [01/04/2016 19:31:25] C:\AdwCleaner\AdwCleaner[S1].txt - [4743 Bytes] - [01/04/2016 19:26:07] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4853 Bytes] ########## Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 durchgeführt von Zajii (Administrator) auf ZAJI (01-04-2016 19:41:38) Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji) Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (NVIDIA Corporation) C:\Users\Zajii\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe (Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe (Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe (Razer, Inc.) C:\Users\Zajii\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.168_none_76587b40265ca57e\TiWorker.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor) HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] () HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] () HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated) HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH) HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.) HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] () HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software) ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30] ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1 ManualProxies: Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation) DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab FireFox: ======== FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] () FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc) FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare) FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26] FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25] FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden Chrome: ======= CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25] CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09] CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20] CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14] CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23] CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-12] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28] CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] () S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.) S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd) R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo) R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts) R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD) R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo) S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated) S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software) R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd) R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>) S3 gkernel; C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [31512 2016-01-14] () S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm)) R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation) S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek ) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated) S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS) S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert] S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] () S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] () S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] () S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.) R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation) S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-01 19:24 - 2016-04-01 19:24 - 03102720 _____ C:\Users\Zajii\Downloads\adwcleaner_5.108.exe 2016-04-01 14:48 - 2016-04-01 14:48 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Abrakam 2016-03-31 10:53 - 2016-03-31 12:54 - 00018188 _____ C:\Users\Zajii\Downloads\Wilhelma.odt 2016-03-31 10:53 - 2016-03-31 12:54 - 00018057 _____ C:\Users\Zajii\Downloads\Zoo Leipzig.odt 2016-03-31 10:52 - 2016-03-31 12:53 - 00018002 _____ C:\Users\Zajii\Downloads\Wildpark.odt 2016-03-31 10:52 - 2016-03-31 12:53 - 00017959 _____ C:\Users\Zajii\Downloads\Allwetterzoo.odt 2016-03-30 14:17 - 2016-04-01 19:40 - 00000000 ____D C:\Users\Zajii\Desktop\ANTI VIRUS 2016-03-30 14:07 - 2016-04-01 19:41 - 00000000 ____D C:\FRST 2016-03-30 13:52 - 2016-03-30 13:52 - 01610352 _____ (Malwarebytes) C:\Users\Zajii\Desktop\JRT.exe 2016-03-30 13:21 - 2016-04-01 19:31 - 00000000 ____D C:\AdwCleaner 2016-03-30 13:06 - 2016-04-01 19:16 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-03-30 13:05 - 2016-03-30 13:59 - 00001180 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-03-30 13:05 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-03-30 13:05 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-03-30 13:05 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-03-30 12:34 - 2016-03-30 12:34 - 00000000 ____D C:\Program Files\Common Files\AV 2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions 2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions 2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc 2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer 2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer 2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer 2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple 2016-03-20 13:55 - 2016-04-01 12:23 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben 2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive 2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4 2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4 2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4 2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4 2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4 2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4 2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4 2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4 2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4 2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4 2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062 2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe 2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5 2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload 2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games 2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll 2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll 2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS 2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe 2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll 2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll 2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll 2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll 2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll 2016-03-07 23:56 - 2016-03-08 00:03 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers 2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-03-06 22:50 - 2016-03-06 22:50 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062_2016.03.06.20.52.54 2016-03-05 01:50 - 2016-03-30 13:59 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk 2016-03-05 01:50 - 2016-03-30 13:58 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk 2016-03-05 01:49 - 2016-03-05 01:50 - 00000000 ____D C:\ProgramData\BlueStacksGameManager 2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\ProgramData\BlueStacks 2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\Program Files (x86)\BlueStacks 2016-03-05 01:46 - 2016-03-05 01:46 - 00000000 ____D C:\Users\Zajii\AppData\Local\Bluestacks 2016-03-02 11:52 - 2016-02-23 12:32 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-03-02 11:52 - 2016-02-23 11:38 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 13:25 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-03-02 11:51 - 2016-02-23 12:34 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 12:32 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-03-02 11:51 - 2016-02-23 12:32 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2016-03-02 11:51 - 2016-02-23 12:31 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-03-02 11:51 - 2016-02-23 12:31 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-03-02 11:51 - 2016-02-23 12:21 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-03-02 11:51 - 2016-02-23 11:45 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-03-02 11:51 - 2016-02-23 11:38 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2016-03-02 11:51 - 2016-02-23 11:38 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-03-02 11:51 - 2016-02-23 11:27 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-03-02 11:51 - 2016-02-23 10:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-03-02 11:51 - 2016-02-23 10:29 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll 2016-03-02 11:51 - 2016-02-23 10:28 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-03-02 11:51 - 2016-02-23 10:09 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-03-02 11:51 - 2016-02-23 10:00 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-03-02 11:51 - 2016-02-23 09:30 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-03-02 11:51 - 2016-02-23 09:24 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-03-02 11:51 - 2016-02-23 09:22 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-03-02 11:51 - 2016-02-23 09:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-03-02 11:51 - 2016-02-23 08:59 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-03-02 11:51 - 2016-02-23 08:55 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-03-02 11:51 - 2016-02-23 08:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-03-02 11:51 - 2016-02-23 08:50 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-03-02 11:51 - 2016-02-23 08:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-03-02 11:51 - 2016-02-23 08:39 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-03-02 11:51 - 2016-02-23 08:36 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-03-02 11:51 - 2016-02-23 08:30 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-03-02 11:51 - 2016-02-09 05:04 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-03-02 11:50 - 2016-02-23 13:29 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-03-02 11:50 - 2016-02-23 13:29 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-03-02 11:50 - 2016-02-23 13:27 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-03-02 11:50 - 2016-02-23 13:27 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-03-02 11:50 - 2016-02-23 13:25 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-03-02 11:50 - 2016-02-23 13:25 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2016-03-02 11:50 - 2016-02-23 13:15 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2016-03-02 11:50 - 2016-02-23 13:08 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-03-02 11:50 - 2016-02-23 12:34 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-03-02 11:50 - 2016-02-23 12:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-03-02 11:50 - 2016-02-23 12:32 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-03-02 11:50 - 2016-02-23 12:32 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 12:32 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 2016-03-02 11:50 - 2016-02-23 12:31 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 12:31 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2016-03-02 11:50 - 2016-02-23 12:31 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2016-03-02 11:50 - 2016-02-23 12:25 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-03-02 11:50 - 2016-02-23 12:22 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2016-03-02 11:50 - 2016-02-23 12:17 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys 2016-03-02 11:50 - 2016-02-23 11:40 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2016-03-02 11:50 - 2016-02-23 11:39 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2016-03-02 11:50 - 2016-02-23 11:38 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2016-03-02 11:50 - 2016-02-23 11:37 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2016-03-02 11:50 - 2016-02-23 11:32 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2016-03-02 11:50 - 2016-02-23 11:30 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-03-02 11:50 - 2016-02-23 11:27 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll 2016-03-02 11:50 - 2016-02-23 11:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll 2016-03-02 11:50 - 2016-02-23 11:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-03-02 11:50 - 2016-02-23 11:19 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2016-03-02 11:50 - 2016-02-23 11:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2016-03-02 11:50 - 2016-02-23 11:06 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll 2016-03-02 11:50 - 2016-02-23 10:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-03-02 11:50 - 2016-02-23 10:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys 2016-03-02 11:50 - 2016-02-23 10:50 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2016-03-02 11:50 - 2016-02-23 10:40 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll 2016-03-02 11:50 - 2016-02-23 10:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll 2016-03-02 11:50 - 2016-02-23 10:38 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll 2016-03-02 11:50 - 2016-02-23 10:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-03-02 11:50 - 2016-02-23 10:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-03-02 11:50 - 2016-02-23 10:37 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-03-02 11:50 - 2016-02-23 10:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll 2016-03-02 11:50 - 2016-02-23 10:34 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll 2016-03-02 11:50 - 2016-02-23 10:34 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2016-03-02 11:50 - 2016-02-23 10:27 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll 2016-03-02 11:50 - 2016-02-23 10:26 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 2016-03-02 11:50 - 2016-02-23 10:22 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2016-03-02 11:50 - 2016-02-23 10:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 2016-03-02 11:50 - 2016-02-23 10:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2016-03-02 11:50 - 2016-02-23 10:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 10:19 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2016-03-02 11:50 - 2016-02-23 10:19 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2016-03-02 11:50 - 2016-02-23 10:18 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2016-03-02 11:50 - 2016-02-23 10:14 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll 2016-03-02 11:50 - 2016-02-23 10:12 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-03-02 11:50 - 2016-02-23 10:11 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-03-02 11:50 - 2016-02-23 10:10 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2016-03-02 11:50 - 2016-02-23 10:10 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-03-02 11:50 - 2016-02-23 10:09 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-03-02 11:50 - 2016-02-23 10:09 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-03-02 11:50 - 2016-02-23 10:06 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-03-02 11:50 - 2016-02-23 10:05 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-03-02 11:50 - 2016-02-23 10:04 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll 2016-03-02 11:50 - 2016-02-23 10:04 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2016-03-02 11:50 - 2016-02-23 10:04 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-03-02 11:50 - 2016-02-23 10:02 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2016-03-02 11:50 - 2016-02-23 10:02 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2016-03-02 11:50 - 2016-02-23 09:58 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll 2016-03-02 11:50 - 2016-02-23 09:52 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2016-03-02 11:50 - 2016-02-23 09:50 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2016-03-02 11:50 - 2016-02-23 09:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2016-03-02 11:50 - 2016-02-23 09:47 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2016-03-02 11:50 - 2016-02-23 09:38 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2016-03-02 11:50 - 2016-02-23 09:37 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2016-03-02 11:50 - 2016-02-23 09:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2016-03-02 11:50 - 2016-02-23 09:36 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll 2016-03-02 11:50 - 2016-02-23 09:36 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-03-02 11:50 - 2016-02-23 09:35 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2016-03-02 11:50 - 2016-02-23 09:31 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2016-03-02 11:50 - 2016-02-23 09:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-03-02 11:50 - 2016-02-23 09:29 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-03-02 11:50 - 2016-02-23 09:28 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll 2016-03-02 11:50 - 2016-02-23 09:24 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-03-02 11:50 - 2016-02-23 09:24 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll 2016-03-02 11:50 - 2016-02-23 09:24 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2016-03-02 11:50 - 2016-02-23 09:21 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2016-03-02 11:50 - 2016-02-23 09:14 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2016-03-02 11:50 - 2016-02-23 09:11 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-03-02 11:50 - 2016-02-23 09:05 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2016-03-02 11:50 - 2016-02-23 09:01 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2016-03-02 11:50 - 2016-02-23 08:58 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll 2016-03-02 11:50 - 2016-02-23 08:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-03-02 11:50 - 2016-02-23 08:55 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-03-02 11:50 - 2016-02-23 08:53 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-03-02 11:50 - 2016-02-23 08:51 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-03-02 11:50 - 2016-02-23 08:42 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-03-02 11:50 - 2016-02-23 08:41 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2016-03-02 11:50 - 2016-02-23 08:36 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-03-02 11:50 - 2016-02-23 08:35 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-03-02 11:50 - 2016-02-23 08:33 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2016-03-02 11:50 - 2016-02-23 08:32 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-03-02 11:50 - 2016-02-23 08:28 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-03-02 11:50 - 2016-02-09 06:28 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2016-03-02 11:50 - 2016-02-09 06:13 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2016-03-02 11:50 - 2016-02-09 05:24 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-03-02 11:50 - 2016-02-09 05:18 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll 2016-03-02 11:50 - 2016-02-09 05:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll 2016-03-02 11:50 - 2016-02-09 05:07 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-03-02 11:50 - 2016-02-09 05:07 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-03-02 11:49 - 2016-02-23 12:33 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2016-03-02 11:49 - 2016-02-23 11:25 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2016-03-02 11:49 - 2016-02-23 11:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll 2016-03-02 11:49 - 2016-02-23 10:53 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll 2016-03-02 11:49 - 2016-02-23 10:52 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe 2016-03-02 11:49 - 2016-02-23 10:39 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2016-03-02 11:49 - 2016-02-23 10:31 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2016-03-02 11:49 - 2016-02-23 09:58 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2016-03-02 11:49 - 2016-02-23 09:49 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-03-02 11:49 - 2016-02-23 09:28 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll 2016-03-02 11:48 - 2016-02-23 11:12 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll 2016-03-02 11:48 - 2016-02-23 11:10 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll 2016-03-02 11:48 - 2016-02-23 11:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-03-02 11:48 - 2016-02-23 11:07 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll 2016-03-02 11:48 - 2016-02-23 11:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys 2016-03-02 11:48 - 2016-02-23 11:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll 2016-03-02 11:48 - 2016-02-23 10:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-03-02 11:48 - 2016-02-23 10:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2016-03-02 11:48 - 2016-02-23 10:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll 2016-03-02 11:48 - 2016-02-23 10:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll 2016-03-02 11:48 - 2016-02-23 10:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-03-02 11:48 - 2016-02-23 10:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll 2016-03-02 11:48 - 2016-02-23 10:33 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2016-03-02 11:48 - 2016-02-23 10:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-03-02 11:48 - 2016-02-23 10:23 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 2016-03-02 11:48 - 2016-02-23 10:20 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-03-02 11:48 - 2016-02-23 10:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-03-02 11:48 - 2016-02-23 10:06 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-03-02 11:48 - 2016-02-23 10:06 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2016-03-02 11:48 - 2016-02-23 10:02 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-03-02 11:48 - 2016-02-23 09:58 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2016-03-02 11:48 - 2016-02-23 09:58 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2016-03-02 11:48 - 2016-02-23 09:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll 2016-03-02 11:48 - 2016-02-23 09:36 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-03-02 11:48 - 2016-02-23 09:21 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-03-02 11:48 - 2016-02-23 09:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-01 19:41 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat 2016-04-01 19:41 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat 2016-04-01 19:41 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-04-01 19:41 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-04-01 19:38 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-04-01 19:36 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-04-01 19:36 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles 2016-04-01 19:36 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2016-04-01 19:35 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-04-01 19:34 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-04-01 19:23 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client 2016-04-01 19:14 - 2014-12-12 23:08 - 00000000 ____D C:\Steam 2016-04-01 19:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-04-01 18:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-04-01 13:38 - 2016-02-26 22:51 - 00011993 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods 2016-04-01 12:22 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-04-01 07:42 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-04-01 07:35 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2016-04-01 07:32 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager 2016-04-01 02:47 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype 2016-04-01 00:13 - 2015-12-16 22:25 - 00345848 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys 2016-03-31 13:00 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-03-31 13:00 - 2015-01-25 22:54 - 00000000 __RDO C:\Users\Zajii\OneDrive 2016-03-31 10:44 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update 2016-03-31 10:42 - 2015-05-08 23:28 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk 2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk 2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk 2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk 2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk 2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk 2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk 2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk 2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk 2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk 2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk 2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk 2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk 2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk 2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk 2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk 2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk 2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk 2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk 2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk 2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games 2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs 2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-03-30 13:07 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini 2016-03-30 13:07 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media 2016-03-30 11:22 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0 2016-03-30 05:20 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc 2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java 2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage 2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java 2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie 2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software 2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software 2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml 2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml 2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta 2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple 2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii 2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net 2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like 2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone 2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net 2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net 2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt 2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS 2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood 2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt 2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames 2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys 2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys 2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games 2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-07 19:41 - 2015-11-14 16:27 - 00000000 ____D C:\Users\Zajii\AppData\Local\Skype 2016-03-07 19:41 - 2015-11-14 16:26 - 00000000 ____D C:\ProgramData\Skype 2016-03-05 05:22 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache 2016-03-05 01:49 - 2015-10-30 09:24 - 00000000 __RHD C:\Users\Public\Libraries 2016-03-05 01:44 - 2015-02-13 12:27 - 00000000 ____D C:\Users\Zajii\.VirtualBox 2016-03-03 13:44 - 2014-12-13 02:46 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-03-03 05:00 - 2015-10-30 20:44 - 00000000 ____D C:\Program Files\Windows Journal 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 __RSD C:\WINDOWS\Media 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-03-02 02:38 - 2015-02-19 19:12 - 00000000 ____D C:\Users\Zajii\AppData\Local\Steam ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log 2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg 2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip 2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Einige Dateien in TEMP: ==================== C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll C:\Users\Zajii\AppData\Local\Temp\7230fefd864f35e6569012bef46d88ae.dll C:\Users\Zajii\AppData\Local\Temp\7b71d939ac8f4f430ba02b964dfb5794.dll C:\Users\Zajii\AppData\Local\Temp\EslWireSetup-1.19.0.8185-x64.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u71-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u73-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\libeay32.dll C:\Users\Zajii\AppData\Local\Temp\LSCSetup64.exe C:\Users\Zajii\AppData\Local\Temp\msvcr120.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole4465310535655270772.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole4974038499892493031.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole732673072298846164.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole8651342122685071258.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole9215304146252064412.dll C:\Users\Zajii\AppData\Local\Temp\sqlite3.dll C:\Users\Zajii\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-03-28 13:58 ==================== Ende von FRST.txt ============================ Geändert von Zaji (01.04.2016 um 18:43 Uhr) |
01.04.2016, 18:56 | #5 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall FRST Addition Log: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 durchgeführt von Zajii (2016-04-01 19:45:09) Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled) Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled) Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC) 7 Days to Die (HKLM-x32\...\Steam App 251570) (Version: - The Fun Pimps) 7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.) Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version: - Ensemble Studios) Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version: - Akamai Technologies, Inc) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation) Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment) Arms Dealer (HKLM-x32\...\Steam App 325630) (Version: - Case in Point Studios, LLC) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software) Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version: - DICE) Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC) Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation) BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version: - ) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com) Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe) CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version: - Eidos Montreal) Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version: - Splash Damage®) DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) Down To One (HKLM-x32\...\Steam App 334040) (Version: - Gadget Games) Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version: - ) Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version: - Eyedentity Games) Endless Space (HKLM-x32\...\Steam App 208140) (Version: - AMPLITUDE Studios) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo) Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version: - momoStorm Entertainment) ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version: - Turtle Entertainment GmbH) Europa Universalis IV (HKLM\...\Steam App 236850) (Version: - Paradox Development Studio) Faeria (HKLM\...\Steam App 397060) (Version: - Abrakam SA) Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version: - ) Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups) Garena - Android Emulator (HKLM-x32\...\nox) (Version: - Garena Online Pte Ltd.) Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.) Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q) Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Grim Dawn (HKLM-x32\...\Steam App 219990) (Version: - Crate Entertainment) Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version: - Trek Industries, Inc) GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - ) H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version: - Daybreak Game Company) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive) Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.) Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation) Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Kenshi (HKLM-x32\...\Steam App 233860) (Version: - Lo-Fi Games) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) KuaiZip (HKLM-x32\...\KuaiZip) (Version: - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.) Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.) Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab) Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo) Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo) Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation) Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech) Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version: - Arkavi Studios) Magic Duels (HKLM-x32\...\Steam App 316010) (Version: - Stainless Games Ltd.) Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - ) Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo) Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG) MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version: - BlueByte) Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version: - TaleWorlds Entertainment) Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT) Nightbanes (HKLM-x32\...\Steam App 338340) (Version: - Diviad) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team) NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version: - Haemimont Games) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.) osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software) Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version: - Ndemic Creations) Planet Explorers (HKLM-x32\...\Steam App 237870) (Version: - Pathea Games) Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version: - Uber Entertainment) Portal Knights (HKLM\...\Steam App 374040) (Version: - Keen Games) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version: - Millenway Studios) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru) Raptr (HKLM-x32\...\Raptr) (Version: - ) Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.) Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version: - EasyGameStation) Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version: - Ascaron) SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version: - Winged Cloud) Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH) Sengoku (HKLM-x32\...\Steam App 73210) (Version: - Paradox Development Studio) SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version: - Ironclad Games) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version: - United Front Games) Spellweaver (HKLM-x32\...\Steam App 429680) (Version: - Dream Reactor) Star Realms (HKLM\...\Steam App 438140) (Version: - White Wizard Games) Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version: - Little Green Men Games) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Survivalist (HKLM-x32\...\Steam App 340050) (Version: - Bob the Game Development Bot) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated) Tabletop Simulator (HKLM\...\Steam App 286160) (Version: - Berserk Games) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Tempest (HKLM-x32\...\Steam App 418180) (Version: - Lion's Shade) The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version: - KTX Software) The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version: - Virtual Basement LLC) Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH) Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS) Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Windows Driver Package - BigNox Corporation XQHDrv System (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation) Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll () ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated) Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software) Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo) Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.) Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\" Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\" Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires" Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software) Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation) Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe 2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll 2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll 2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-12-23 21:59 - 2015-12-07 06:59 - 03081568 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll 2015-12-23 21:59 - 2015-12-07 06:57 - 02394976 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe 2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe 2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-03-31 22:48 - 2016-03-31 22:48 - 02846208 _____ () C:\Program Files\AVAST Software\Avast\defs\16033102\algo.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2015-12-23 10:25 - 2016-04-01 19:37 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll 2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll 2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll 2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-09-25 23:48 - 2015-09-25 23:48 - 00043656 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32api.pyd 2015-09-25 23:47 - 2015-09-25 23:47 - 00061576 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pywintypes27.dll 2015-09-25 23:47 - 2015-09-25 23:47 - 00127624 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pythoncom27.dll 2015-09-25 23:48 - 2015-09-25 23:48 - 00024200 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_multiprocessing.pyd ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com Da befinden sich 7866 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk" HKLM\...\StartupApproved\Run: => "PhoneCompanion" HKLM\...\StartupApproved\Run: => "LogMeIn GUI" HKLM\...\StartupApproved\Run: => "Connectify Hotspot" HKLM\...\StartupApproved\Run: => "Start WingMan Profiler" HKLM\...\StartupApproved\Run32: => "BlueStacks Agent" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Raptr" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [{38E9D37A-19CD-4C3D-9DA3-0DD35DBD4610}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{B23BAC6E-B86A-4175-AEA4-62C0A239B4DF}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{124EAD6D-953A-40D4-B784-7094D523B660}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe FirewallRules: [{0213AE30-CEA2-43FB-A4CE-E09573D2B084}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe ==================== Wiederherstellungspunkte ========================= 30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (04/01/2016 01:34:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1063 Error: (04/01/2016 01:34:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1063 Error: (04/01/2016 01:34:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/01/2016 01:34:45 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (04/01/2016 12:30:31 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (04/01/2016 09:05:58 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (03/31/2016 01:48:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203 Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb Ausnahmecode: 0xc0000094 Fehleroffset: 0x00016a0c ID des fehlerhaften Prozesses: 0xc78 Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0 Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1 Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2 Berichtskennung: RazerIngameEngine.exe3 Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5 Error: (03/31/2016 07:59:03 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (03/30/2016 02:49:44 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (03/30/2016 11:23:32 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Systemfehler: ============= Error: (04/01/2016 07:39:24 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {784E29F4-5EBE-4279-9948-1E8FE941646D} Error: (04/01/2016 07:36:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "MBAMScheduler" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/01/2016 07:36:13 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MBAMScheduler erreicht. Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Razer Game Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Razer Game Scanner Service erreicht. Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "MBAMService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MBAMService erreicht. Error: (04/01/2016 07:36:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "BstHdUpdaterSvc" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/01/2016 07:36:10 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst BstHdUpdaterSvc erreicht. Error: (04/01/2016 07:34:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_4e6d0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2016-03-24 02:26:58.699 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-23 04:00:10.692 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-22 14:17:50.313 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 18:18:45.659 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 14:34:08.548 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-10 10:17:26.727 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-03 12:41:33.511 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-02 15:35:16.954 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 17:56:24.126 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 07:03:27.892 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz Prozentuale Nutzung des RAM: 25% Installierter physikalischer RAM: 12196.01 MB Verfügbarer physikalischer RAM: 9033.21 MB Summe virtueller Speicher: 24484.01 MB Verfügbarer virtueller Speicher: 20997.27 MB ==================== Laufwerke ================================ Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:394.86 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3) Partition: GPT. ==================== Ende von Addition.txt ============================ Ich will mich schon jetzt dafür bedanken dass Sie sich Zeit für mich genommen haben. |
02.04.2016, 19:48 | #6 |
/// Malwareteam | GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Leider hast du die Anleitung nicht genau befolgt: Starte bitte wieder Malwarebytes Anti-Malware
__________________ --> GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall |
03.04.2016, 01:32 | #7 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall So hier mein neuer scan: mbam Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 03.04.2016 Suchlaufzeit: 01:20 Protokolldatei: mbam.txt Administrator: Ja Version: 2.2.1.1043 Malware-Datenbank: v2016.04.02.06 Rootkit-Datenbank: v2016.03.30.01 Lizenz: Testversion Malware-Schutz: Aktiviert Schutz vor bösartigen Websites: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: Zajii Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 487225 Abgelaufene Zeit: 1 Std., 9 Min., 45 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 1 HackTool.Agent, C:\Users\Zajii\Desktop\Folder\alle möglichen dateien\1\wl.2.2.2.zip, In Quarantäne, [41cdc5e5e2b745f18ab139038a77857b], Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) |
04.04.2016, 01:50 | #8 |
/// Malwareteam | GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Schritt: 1 ESET Online Scanner
Hinweis: Dieser Scan kann schon einmal mehrere Stunden dauern... Schritt: 2 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen. Hast du noch irgendwelche Probleme mit deinem Rechner?
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
05.04.2016, 09:51 | #9 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall ESET-Log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=3aaf1d9009c61e488a7e0333c22ae738 # end=init # utc_time=2016-04-04 06:33:28 # local_time=2016-04-04 08:33:28 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 28905 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=3aaf1d9009c61e488a7e0333c22ae738 # end=updated # utc_time=2016-04-04 06:35:17 # local_time=2016-04-04 08:35:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=3aaf1d9009c61e488a7e0333c22ae738 # engine=28905 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2016-04-05 01:28:43 # local_time=2016-04-05 03:28:43 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='avast! Antivirus' # compatibility_mode=788 16777213 100 98 204887 20361712 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 2642231 13633866 0 0 # scanned=623155 # found=0 # cleaned=0 # scan_time=24806 Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 durchgeführt von Zajii (Administrator) auf ZAJI (05-04-2016 10:42:53) Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji) Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Users\Zajii\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Valve Corporation) C:\Steam\Steam.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe (Valve Corporation) C:\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe (Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe (Razer, Inc.) C:\Users\Zajii\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe (Valve Corporation) C:\Steam\bin\steamwebhelper.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avBugReport.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor) HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] () HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] () HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated) HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH) HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.) HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] () HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software) ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30] ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1 ManualProxies: Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation) DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab FireFox: ======== FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] () FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc) FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare) FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26] FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25] FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden Chrome: ======= CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25] CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09] CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20] CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14] CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23] CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-12] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02] CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] () S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.) R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd) R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo) R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited) S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts) R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD) R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo) R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated) S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software) R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd) R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>) S3 gkernel; C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [31512 2016-01-14] () S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm)) R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc) R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation) S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek ) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated) S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS) S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert] S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] () S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] () S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] () S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.) R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation) S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-04 20:33 - 2016-04-04 20:33 - 02870984 _____ (ESET) C:\Users\Zajii\Downloads\esetsmartinstaller_deu.exe 2016-04-04 20:33 - 2016-04-04 20:33 - 00000000 ____D C:\Program Files (x86)\ESET 2016-04-03 02:31 - 2016-04-03 02:31 - 00001291 _____ C:\Users\Zajii\Desktop\mbam.txt 2016-04-01 19:24 - 2016-04-01 19:24 - 03102720 _____ C:\Users\Zajii\Downloads\adwcleaner_5.108.exe 2016-04-01 14:48 - 2016-04-01 14:48 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Abrakam 2016-03-31 10:53 - 2016-03-31 12:54 - 00018188 _____ C:\Users\Zajii\Downloads\Wilhelma.odt 2016-03-31 10:53 - 2016-03-31 12:54 - 00018057 _____ C:\Users\Zajii\Downloads\Zoo Leipzig.odt 2016-03-31 10:52 - 2016-03-31 12:53 - 00018002 _____ C:\Users\Zajii\Downloads\Wildpark.odt 2016-03-31 10:52 - 2016-03-31 12:53 - 00017959 _____ C:\Users\Zajii\Downloads\Allwetterzoo.odt 2016-03-30 14:17 - 2016-04-01 19:46 - 00000000 ____D C:\Users\Zajii\Desktop\ANTI VIRUS 2016-03-30 14:07 - 2016-04-05 10:42 - 00000000 ____D C:\FRST 2016-03-30 13:21 - 2016-04-01 19:31 - 00000000 ____D C:\AdwCleaner 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-03-30 12:34 - 2016-03-30 12:34 - 00000000 ____D C:\Program Files\Common Files\AV 2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions 2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions 2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc 2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer 2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer 2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer 2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple 2016-03-20 13:55 - 2016-04-01 12:23 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben 2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive 2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4 2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4 2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4 2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4 2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4 2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4 2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4 2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4 2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4 2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4 2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062 2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe 2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5 2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload 2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games 2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll 2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll 2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS 2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe 2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll 2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll 2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll 2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll 2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll 2016-03-07 23:56 - 2016-03-08 00:03 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers 2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-03-06 22:50 - 2016-03-06 22:50 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062_2016.03.06.20.52.54 ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-05 10:41 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2016-04-05 10:40 - 2014-12-12 23:08 - 00000000 ____D C:\Steam 2016-04-05 10:38 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-04-05 10:38 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager 2016-04-05 10:37 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-04-05 10:37 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles 2016-04-05 10:36 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-04-05 10:36 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2016-04-05 04:40 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-04-05 04:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-04-05 03:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-04-05 02:01 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client 2016-04-04 14:45 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc 2016-04-04 02:37 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype 2016-04-04 01:52 - 2015-12-16 22:25 - 00307448 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys 2016-04-03 12:13 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini 2016-04-03 12:13 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2016-04-02 12:45 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat 2016-04-02 12:45 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat 2016-04-02 12:45 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-04-02 12:45 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-04-02 12:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-04-02 11:58 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update 2016-04-01 13:38 - 2016-02-26 22:51 - 00011993 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods 2016-04-01 07:42 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-03-31 13:00 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-03-31 13:00 - 2015-01-25 22:54 - 00000000 __RDO C:\Users\Zajii\OneDrive 2016-03-30 13:59 - 2016-03-05 01:50 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk 2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk 2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk 2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk 2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk 2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk 2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk 2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk 2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk 2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk 2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk 2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk 2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk 2016-03-30 13:58 - 2016-03-05 01:50 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk 2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk 2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk 2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk 2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk 2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk 2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk 2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk 2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk 2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games 2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs 2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media 2016-03-30 11:22 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0 2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java 2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage 2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java 2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie 2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software 2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software 2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml 2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml 2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta 2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple 2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii 2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net 2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like 2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone 2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net 2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net 2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt 2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS 2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood 2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt 2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames 2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys 2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys 2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games 2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-07 19:41 - 2015-11-14 16:27 - 00000000 ____D C:\Users\Zajii\AppData\Local\Skype 2016-03-07 19:41 - 2015-11-14 16:26 - 00000000 ____D C:\ProgramData\Skype ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log 2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg 2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip 2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Einige Dateien in TEMP: ==================== C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll C:\Users\Zajii\AppData\Local\Temp\7230fefd864f35e6569012bef46d88ae.dll C:\Users\Zajii\AppData\Local\Temp\7b71d939ac8f4f430ba02b964dfb5794.dll C:\Users\Zajii\AppData\Local\Temp\EslWireSetup-1.19.0.8185-x64.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u71-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u73-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Zajii\AppData\Local\Temp\libeay32.dll C:\Users\Zajii\AppData\Local\Temp\LSCSetup64.exe C:\Users\Zajii\AppData\Local\Temp\msvcr120.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole4465310535655270772.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole4974038499892493031.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole732673072298846164.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole8651342122685071258.dll C:\Users\Zajii\AppData\Local\Temp\proxy_vole9215304146252064412.dll C:\Users\Zajii\AppData\Local\Temp\sqlite3.dll C:\Users\Zajii\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-03-28 13:58 ==================== Ende von FRST.txt ============================ |
05.04.2016, 09:54 | #10 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Additional: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 durchgeführt von Zajii (2016-04-05 10:45:19) Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled) Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled) Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC) 7 Days to Die (HKLM-x32\...\Steam App 251570) (Version: - The Fun Pimps) 7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.) Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version: - Ensemble Studios) Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version: - Akamai Technologies, Inc) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation) Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment) Arms Dealer (HKLM-x32\...\Steam App 325630) (Version: - Case in Point Studios, LLC) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software) Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version: - DICE) Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC) Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation) BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version: - ) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com) Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe) CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version: - Eidos Montreal) Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version: - Splash Damage®) DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) Down To One (HKLM-x32\...\Steam App 334040) (Version: - Gadget Games) Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version: - ) Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version: - Eyedentity Games) Endless Space (HKLM-x32\...\Steam App 208140) (Version: - AMPLITUDE Studios) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo) Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version: - momoStorm Entertainment) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version: - Turtle Entertainment GmbH) Europa Universalis IV (HKLM\...\Steam App 236850) (Version: - Paradox Development Studio) Faeria (HKLM\...\Steam App 397060) (Version: - Abrakam SA) Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version: - ) Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups) Garena - Android Emulator (HKLM-x32\...\nox) (Version: - Garena Online Pte Ltd.) Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.) Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q) Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Grim Dawn (HKLM-x32\...\Steam App 219990) (Version: - Crate Entertainment) Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version: - Trek Industries, Inc) GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - ) H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version: - Daybreak Game Company) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive) Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.) Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation) Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Kenshi (HKLM-x32\...\Steam App 233860) (Version: - Lo-Fi Games) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) KuaiZip (HKLM-x32\...\KuaiZip) (Version: - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.) Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.) Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab) Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo) Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo) Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation) Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech) Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version: - Arkavi Studios) Magic Duels (HKLM-x32\...\Steam App 316010) (Version: - Stainless Games Ltd.) Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - ) Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo) Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG) MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version: - BlueByte) Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version: - TaleWorlds Entertainment) Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team) NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version: - Haemimont Games) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.) osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software) Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version: - Ndemic Creations) Planet Explorers (HKLM-x32\...\Steam App 237870) (Version: - Pathea Games) Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version: - Uber Entertainment) Portal Knights (HKLM\...\Steam App 374040) (Version: - Keen Games) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version: - Millenway Studios) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru) Raptr (HKLM-x32\...\Raptr) (Version: - ) Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.) Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version: - EasyGameStation) Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version: - Ascaron) SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version: - Winged Cloud) Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH) Sengoku (HKLM-x32\...\Steam App 73210) (Version: - Paradox Development Studio) SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version: - Ironclad Games) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version: - United Front Games) Spellweaver (HKLM-x32\...\Steam App 429680) (Version: - Dream Reactor) Star Realms (HKLM\...\Steam App 438140) (Version: - White Wizard Games) Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version: - Little Green Men Games) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Survivalist (HKLM-x32\...\Steam App 340050) (Version: - Bob the Game Development Bot) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated) Tabletop Simulator (HKLM\...\Steam App 286160) (Version: - Berserk Games) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Tempest (HKLM-x32\...\Steam App 418180) (Version: - Lion's Shade) The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version: - KTX Software) The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version: - Virtual Basement LLC) Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH) Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS) Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Windows Driver Package - BigNox Corporation XQHDrv System (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation) Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll () ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated) Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software) Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo) Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.) Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\" Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\" Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires" Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software) Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation) Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll 2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2015-11-05 02:11 - 2015-11-05 02:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe 2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll 2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe 2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe 2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-04-04 11:28 - 2016-04-04 11:28 - 02850816 _____ () C:\Program Files\AVAST Software\Avast\defs\16040400\algo.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-12-23 10:25 - 2016-04-05 10:38 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll 2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll 2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll 2014-12-12 23:20 - 2016-03-11 02:56 - 00783360 _____ () C:\Steam\SDL2.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 04962816 _____ () C:\Steam\v8.dll 2014-12-12 23:20 - 2016-03-31 22:55 - 02549840 _____ () C:\Steam\video.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 02549760 _____ () C:\Steam\libavcodec-56.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00491008 _____ () C:\Steam\libavformat-56.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00332800 _____ () C:\Steam\libavresample-2.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00442880 _____ () C:\Steam\libavutil-54.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00485888 _____ () C:\Steam\libswscale-3.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 01556992 _____ () C:\Steam\icui18n.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 01187840 _____ () C:\Steam\icuuc.dll 2014-12-12 23:20 - 2016-03-31 22:55 - 00829008 _____ () C:\Steam\bin\chromehtml.DLL 2016-03-09 12:09 - 2016-02-18 00:25 - 00281088 _____ () C:\Steam\openvr_api.dll 2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2015-12-05 12:29 - 2016-02-09 03:33 - 48400672 _____ () C:\Steam\bin\libcef.dll 2015-09-25 23:48 - 2015-09-25 23:48 - 00043656 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32api.pyd 2015-09-25 23:47 - 2015-09-25 23:47 - 00061576 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pywintypes27.dll 2015-09-25 23:47 - 2015-09-25 23:47 - 00127624 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pythoncom27.dll 2015-09-25 23:48 - 2015-09-25 23:48 - 00024200 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_multiprocessing.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00046728 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ctypes.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00027784 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32service.pyd 2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll 2015-12-05 12:29 - 2015-09-25 01:56 - 00119208 _____ () C:\Steam\winh264.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com Da befinden sich 7866 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk" HKLM\...\StartupApproved\Run: => "PhoneCompanion" HKLM\...\StartupApproved\Run: => "LogMeIn GUI" HKLM\...\StartupApproved\Run: => "Connectify Hotspot" HKLM\...\StartupApproved\Run: => "Start WingMan Profiler" HKLM\...\StartupApproved\Run32: => "BlueStacks Agent" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Raptr" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [{38E9D37A-19CD-4C3D-9DA3-0DD35DBD4610}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{B23BAC6E-B86A-4175-AEA4-62C0A239B4DF}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{124EAD6D-953A-40D4-B784-7094D523B660}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe FirewallRules: [{0213AE30-CEA2-43FB-A4CE-E09573D2B084}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe ==================== Wiederherstellungspunkte ========================= 30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (04/05/2016 04:39:18 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/05/2016 01:16:50 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203 Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb Ausnahmecode: 0xc0000094 Fehleroffset: 0x00016a0c ID des fehlerhaften Prozesses: 0x2354 Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0 Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1 Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2 Berichtskennung: RazerIngameEngine.exe3 Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5 Error: (04/04/2016 08:34:06 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/04/2016 08:33:23 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/04/2016 08:33:17 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/04/2016 08:33:16 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/04/2016 02:53:01 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (04/04/2016 12:29:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZAJI) Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (04/04/2016 12:29:30 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (04/04/2016 04:53:25 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Systemfehler: ============= Error: (04/05/2016 10:41:48 AM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/05/2016 10:41:48 AM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/05/2016 10:40:41 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Übermittlungsoptimierung" wurde nicht richtig gestartet. Error: (04/05/2016 10:39:58 AM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {784E29F4-5EBE-4279-9948-1E8FE941646D} Error: (04/05/2016 04:40:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Synchronisierungshost_573a3 erreicht. Error: (04/05/2016 04:40:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Benutzerdatenspeicher _573a3 erreicht. Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Synchronisierungshost_573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2016-03-24 02:26:58.699 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-23 04:00:10.692 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-22 14:17:50.313 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 18:18:45.659 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 14:34:08.548 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-10 10:17:26.727 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-03 12:41:33.511 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-02 15:35:16.954 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 17:56:24.126 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 07:03:27.892 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz Prozentuale Nutzung des RAM: 31% Installierter physikalischer RAM: 12196.01 MB Verfügbarer physikalischer RAM: 8330.16 MB Summe virtueller Speicher: 24484.01 MB Verfügbarer virtueller Speicher: 20213.86 MB ==================== Laufwerke ================================ Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:383.31 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3) Partition: GPT. ==================== Ende von Addition.txt ============================ |
07.04.2016, 01:13 | #11 |
/// Malwareteam | GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Schritt: 1 Deinstalliere bitte Spybot Search & Destroy - das Produkt ist nicht mehr, was es mal war. Schritt: 2 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM-x32\...\Run: [] => [X] Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt: 2 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
07.04.2016, 12:51 | #12 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Hier habe ich die gewünschten Logs Fixlog Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 durchgeführt von Zajii (2016-04-07 13:29:22) Run:1 Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS\FRST 2 Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** HKLM-x32\...\Run: [] => [X] Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG emptytemp: ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0022D505-89DC-4004-B6CF-3E97576D1FD5}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0022D505-89DC-4004-B6CF-3E97576D1FD5}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03D2038E-5F0B-4095-A307-BD3BE6727F06}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03D2038E-5F0B-4095-A307-BD3BE6727F06}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{385D07FE-CFED-4E3A-AB32-5BB218EE7ABF}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{385D07FE-CFED-4E3A-AB32-5BB218EE7ABF}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{408FCF42-4944-455C-8A72-DE33EB8B2D85}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{408FCF42-4944-455C-8A72-DE33EB8B2D85}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{50469B9C-E247-4829-9E2D-2E4855321279}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50469B9C-E247-4829-9E2D-2E4855321279}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C88E871-DE39-4E8F-AD06-9431B840223A}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C88E871-DE39-4E8F-AD06-9431B840223A}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{71A56DF0-B4F7-451D-A5D5-48DA2552F458}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71A56DF0-B4F7-451D-A5D5-48DA2552F458}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5A62FD1-C481-44EC-AAEC-48A50DD050DC}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5A62FD1-C481-44EC-AAEC-48A50DD050DC}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D21116EB-D486-463F-90C7-430EAAFAFE3F}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D21116EB-D486-463F-90C7-430EAAFAFE3F}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED0F84BF-9B51-4532-86E2-84DE21936120}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED0F84BF-9B51-4532-86E2-84DE21936120}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC7427EE-B27B-49A8-A899-0418E15003C9}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC7427EE-B27B-49A8-A899-0418E15003C9}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => Schlüssel erfolgreich entfernt EmptyTemp: => 3.3 GB temporäre Dateien entfernt. Das System musste neu gestartet werden. ==== Ende von Fixlog 13:34:05 ==== FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 durchgeführt von Zajii (Administrator) auf ZAJI (07-04-2016 13:39:52) Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS\FRST 2 Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji) Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe (Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\setup\instup.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe (NVIDIA Corporation) C:\Users\Zajii\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor) HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] () HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] () HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated) HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH) HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation) HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.) HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] () HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software) ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30] ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1 ManualProxies: Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation) DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab FireFox: ======== FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] () FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc) FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare) FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26] FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25] FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden Chrome: ======= CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25] CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09] CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20] CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14] CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23] CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-07] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02] CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] () S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.) R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd) R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo) R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited) S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts) R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD) R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo) R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated) S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software) R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd) R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>) S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm)) R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc) R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation) S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek ) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated) S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS) S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert] S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] () S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] () S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] () S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.) R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation) S3 gkernel; \??\C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [X] S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-06 17:21 - 2016-04-06 17:21 - 02103566 _____ C:\Users\Zajii\Downloads\matchmaking_server_picker_423.zip 2016-04-04 20:33 - 2016-04-04 20:33 - 00000000 ____D C:\Program Files (x86)\ESET 2016-04-03 02:31 - 2016-04-03 02:31 - 00001291 _____ C:\Users\Zajii\Desktop\mbam.txt 2016-04-01 14:48 - 2016-04-01 14:48 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Abrakam 2016-03-31 10:53 - 2016-03-31 12:54 - 00018188 _____ C:\Users\Zajii\Downloads\Wilhelma.odt 2016-03-31 10:53 - 2016-03-31 12:54 - 00018057 _____ C:\Users\Zajii\Downloads\Zoo Leipzig.odt 2016-03-31 10:52 - 2016-03-31 12:53 - 00018002 _____ C:\Users\Zajii\Downloads\Wildpark.odt 2016-03-31 10:52 - 2016-03-31 12:53 - 00017959 _____ C:\Users\Zajii\Downloads\Allwetterzoo.odt 2016-03-30 14:17 - 2016-04-07 13:28 - 00000000 ____D C:\Users\Zajii\Desktop\ANTI VIRUS 2016-03-30 14:07 - 2016-04-07 13:39 - 00000000 ____D C:\FRST 2016-03-30 13:21 - 2016-04-01 19:31 - 00000000 ____D C:\AdwCleaner 2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions 2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions 2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage 2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour 2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc 2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer 2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer 2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer 2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple 2016-03-20 13:55 - 2016-04-01 12:23 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben 2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive 2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4 2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4 2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4 2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4 2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4 2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4 2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4 2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4 2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4 2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4 2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062 2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe 2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5 2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download 2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload 2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games 2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll 2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll 2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS 2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe 2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll 2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll 2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll 2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll 2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll 2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll 2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll 2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll 2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll 2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll 2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll 2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll 2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll 2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll 2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll 2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll 2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll 2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll 2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll 2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll 2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll 2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-07 13:40 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2016-04-07 13:40 - 2014-12-12 23:08 - 00000000 ____D C:\Steam 2016-04-07 13:39 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-04-07 13:38 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update 2016-04-07 13:37 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-04-07 13:37 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles 2016-04-07 13:35 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-04-07 13:35 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2016-04-07 13:34 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-04-07 13:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-04-07 12:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-04-07 10:59 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-04-07 10:59 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-04-07 10:50 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager 2016-04-07 01:32 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client 2016-04-06 17:22 - 2016-02-19 12:40 - 00000000 ____D C:\Program Files\mmpicker 2016-04-06 14:21 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc 2016-04-06 13:44 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0 2016-04-06 05:24 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype 2016-04-06 04:52 - 2015-01-04 21:37 - 00000000 ____D C:\Users\Zajii\Desktop\Folder 2016-04-06 03:40 - 2015-12-16 22:25 - 00325880 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys 2016-04-05 23:27 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat 2016-04-05 23:27 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat 2016-04-05 23:27 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-04-05 23:27 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-04-05 15:55 - 2015-09-25 22:44 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2016-04-03 12:13 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini 2016-04-03 12:13 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2016-04-01 13:38 - 2016-02-26 22:51 - 00011993 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods 2016-03-31 13:00 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-03-31 13:00 - 2015-01-25 22:54 - 00000000 __RDO C:\Users\Zajii\OneDrive 2016-03-30 13:59 - 2016-03-05 01:50 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk 2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk 2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk 2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk 2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk 2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk 2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk 2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk 2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk 2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk 2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk 2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk 2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk 2016-03-30 13:58 - 2016-03-05 01:50 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk 2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk 2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk 2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk 2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk 2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk 2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk 2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk 2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk 2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk 2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk 2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games 2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs 2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media 2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java 2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage 2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java 2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie 2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software 2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software 2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml 2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml 2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta 2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple 2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii 2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net 2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like 2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone 2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net 2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net 2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt 2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS 2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood 2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt 2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames 2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys 2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys 2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games 2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-08 00:03 - 2016-03-07 23:56 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log 2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg 2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip 2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Einige Dateien in TEMP: ==================== C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-04-07 11:13 ==================== Ende von FRST.txt ============================ |
07.04.2016, 12:52 | #13 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Addition Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 durchgeführt von Zajii (2016-04-07 13:45:37) Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS\FRST 2 Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled) Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled) Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC) 7 Days to Die (HKLM-x32\...\Steam App 251570) (Version: - The Fun Pimps) 7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.) Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version: - Ensemble Studios) Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version: - Akamai Technologies, Inc) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation) Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment) Arms Dealer (HKLM-x32\...\Steam App 325630) (Version: - Case in Point Studios, LLC) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software) Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version: - DICE) Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC) Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation) BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version: - ) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com) Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe) CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version: - Eidos Montreal) Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version: - Splash Damage®) DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) Down To One (HKLM-x32\...\Steam App 334040) (Version: - Gadget Games) Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version: - ) Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version: - Eyedentity Games) Endless Space (HKLM-x32\...\Steam App 208140) (Version: - AMPLITUDE Studios) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo) Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version: - momoStorm Entertainment) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version: - Turtle Entertainment GmbH) Europa Universalis IV (HKLM\...\Steam App 236850) (Version: - Paradox Development Studio) Faeria (HKLM\...\Steam App 397060) (Version: - Abrakam SA) Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version: - ) Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups) Garena - Android Emulator (HKLM-x32\...\nox) (Version: - Garena Online Pte Ltd.) Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.) Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q) Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Grim Dawn (HKLM-x32\...\Steam App 219990) (Version: - Crate Entertainment) Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version: - Trek Industries, Inc) GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - ) H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version: - Daybreak Game Company) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive) Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.) Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation) Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Kenshi (HKLM-x32\...\Steam App 233860) (Version: - Lo-Fi Games) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) KuaiZip (HKLM-x32\...\KuaiZip) (Version: - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.) Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.) Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab) Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo) Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo) Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation) Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech) Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version: - Arkavi Studios) Magic Duels (HKLM-x32\...\Steam App 316010) (Version: - Stainless Games Ltd.) Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - ) Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo) Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG) MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version: - BlueByte) Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version: - TaleWorlds Entertainment) Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team) NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version: - Haemimont Games) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.) osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software) Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version: - Ndemic Creations) Planet Explorers (HKLM-x32\...\Steam App 237870) (Version: - Pathea Games) Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version: - Uber Entertainment) Portal Knights (HKLM\...\Steam App 374040) (Version: - Keen Games) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version: - Millenway Studios) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru) Raptr (HKLM-x32\...\Raptr) (Version: - ) Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.) Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version: - EasyGameStation) Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version: - Ascaron) SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version: - Winged Cloud) Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH) Sengoku (HKLM-x32\...\Steam App 73210) (Version: - Paradox Development Studio) SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version: - Ironclad Games) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version: - United Front Games) Spellweaver (HKLM-x32\...\Steam App 429680) (Version: - Dream Reactor) Star Realms (HKLM\...\Steam App 438140) (Version: - White Wizard Games) Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version: - Little Green Men Games) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Survivalist (HKLM-x32\...\Steam App 340050) (Version: - Bob the Game Development Bot) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated) Tabletop Simulator (HKLM\...\Steam App 286160) (Version: - Berserk Games) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Tempest (HKLM-x32\...\Steam App 418180) (Version: - Lion's Shade) The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version: - KTX Software) The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version: - Virtual Basement LLC) Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH) Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS) Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Windows Driver Package - BigNox Corporation XQHDrv System (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation) Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll () ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated) Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software) Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo) Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.) Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\" Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\" Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires" Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software) Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation) Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe 2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll 2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2015-11-05 02:11 - 2015-11-05 02:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll 2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe 2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe 2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-04-07 02:53 - 2016-04-07 02:53 - 02853376 _____ () C:\Program Files\AVAST Software\Avast\defs\16040603\algo.dll 2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-04-07 13:38 - 2016-04-07 13:38 - 02853376 _____ () C:\Program Files\AVAST Software\Avast\defs\16040700\algo.dll 2016-04-07 13:38 - 2016-04-07 13:38 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll 2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll 2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll 2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll 2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll 2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll 2014-12-12 23:20 - 2016-03-11 02:56 - 00783360 _____ () C:\Steam\SDL2.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 04962816 _____ () C:\Steam\v8.dll 2014-12-12 23:20 - 2016-03-31 22:55 - 02549840 _____ () C:\Steam\video.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 02549760 _____ () C:\Steam\libavcodec-56.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00491008 _____ () C:\Steam\libavformat-56.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00332800 _____ () C:\Steam\libavresample-2.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00442880 _____ () C:\Steam\libavutil-54.dll 2014-12-12 23:20 - 2016-02-09 01:14 - 00485888 _____ () C:\Steam\libswscale-3.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 01556992 _____ () C:\Steam\icui18n.dll 2015-01-20 15:51 - 2015-07-03 18:12 - 01187840 _____ () C:\Steam\icuuc.dll 2014-12-12 23:20 - 2016-03-31 22:55 - 00829008 _____ () C:\Steam\bin\chromehtml.DLL 2016-03-09 12:09 - 2016-02-18 00:25 - 00281088 _____ () C:\Steam\openvr_api.dll 2015-12-05 12:29 - 2016-02-09 03:33 - 48400672 _____ () C:\Steam\bin\libcef.dll 2015-12-05 12:29 - 2015-09-25 01:56 - 00119208 _____ () C:\Steam\winh264.dll 2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-09-25 23:48 - 2015-09-25 23:48 - 00043656 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32api.pyd 2015-09-25 23:47 - 2015-09-25 23:47 - 00061576 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pywintypes27.dll 2015-09-25 23:47 - 2015-09-25 23:47 - 00127624 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pythoncom27.dll 2015-09-25 23:48 - 2015-09-25 23:48 - 00024200 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_multiprocessing.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00046728 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ctypes.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00027784 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32service.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00024712 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\servicemanager.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00031368 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_socket.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00445064 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ssl.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00288904 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_hashlib.pyd 2015-09-25 23:48 - 2015-09-25 23:48 - 00019080 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\select.pyd 2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll 2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com Da befinden sich 7866 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk" HKLM\...\StartupApproved\Run: => "PhoneCompanion" HKLM\...\StartupApproved\Run: => "LogMeIn GUI" HKLM\...\StartupApproved\Run: => "Connectify Hotspot" HKLM\...\StartupApproved\Run: => "Start WingMan Profiler" HKLM\...\StartupApproved\Run32: => "BlueStacks Agent" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Raptr" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus" HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{124EAD6D-953A-40D4-B784-7094D523B660}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe FirewallRules: [{0213AE30-CEA2-43FB-A4CE-E09573D2B084}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe FirewallRules: [{8D462A59-4F7C-4668-A033-ACF56ECA0851}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{206966F0-FDBC-41DD-84C0-A12DAFAD471D}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe ==================== Wiederherstellungspunkte ========================= 30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool 05-04-2016 22:07:03 DirectX wurde installiert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (04/07/2016 01:53:51 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (04/06/2016 12:02:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203 Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb Ausnahmecode: 0xc0000094 Fehleroffset: 0x00016a0c ID des fehlerhaften Prozesses: 0x1c58 Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0 Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1 Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2 Berichtskennung: RazerIngameEngine.exe3 Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5 Error: (04/05/2016 11:28:06 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/05/2016 10:07:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (04/05/2016 08:09:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZAJI) Description: Bei der Aktivierung der App „Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (04/05/2016 05:27:46 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (04/05/2016 04:39:18 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/05/2016 01:16:50 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203 Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb Ausnahmecode: 0xc0000094 Fehleroffset: 0x00016a0c ID des fehlerhaften Prozesses: 0x2354 Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0 Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1 Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2 Berichtskennung: RazerIngameEngine.exe3 Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5 Error: (04/04/2016 08:34:06 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Error: (04/04/2016 08:33:23 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest. Systemfehler: ============= Error: (04/07/2016 01:43:45 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Manager für heruntergeladene Karten" wurde nicht richtig gestartet. Error: (04/07/2016 01:42:22 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:22 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:22 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 CodeIntegrity: =================================== Date: 2016-03-24 02:26:58.699 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-23 04:00:10.692 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-22 14:17:50.313 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 18:18:45.659 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 14:34:08.548 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-10 10:17:26.727 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-03 12:41:33.511 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-02 15:35:16.954 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 17:56:24.126 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-11 07:03:27.892 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz Prozentuale Nutzung des RAM: 25% Installierter physikalischer RAM: 12196.01 MB Verfügbarer physikalischer RAM: 9083.18 MB Summe virtueller Speicher: 24484.01 MB Verfügbarer virtueller Speicher: 20972.6 MB ==================== Laufwerke ================================ Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:445.34 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3) Partition: GPT. ==================== Ende von Addition.txt ============================ |
08.04.2016, 20:26 | #14 |
/// Malwareteam | GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Java Du hast eine veraltete Version von Java installiert. Bitte aktualisiere sie oder entferne Java gleich komplett von deinem PC. In nur sehr seltenen Fällen benötigt man das Programm wirklich auf dem Rechner - deshalb meine Empfehlung: Behalte Java nur auf deinem Computer wenn du es wirklich benötigst, dann halte es jedoch stets aktuell. Die Logs von deinem Rechner sehen jetzt für mich sauber aus: Herzlichen Glückwunsch - du bist Clean Zum Schluss müssen wir noch etwas aufräumen und ich gebe dir ein paar Hinweise mit auf den Weg: Wichtig: Entfernen der verwendeten Tools Die Reihenfolge ist hier entscheidend.
Malwarebytes Anti-Malware und ESET kannst du als Ergänzung zu deiner bestehenden Antivirus-Lösung auf dem Computer belassen und deinen Computer damit regelmäßig scannen. Persönliche Empfehlungen Das wichtigste zu erst:
Schutz vor unerwünschter Software Adware ist zu einer Art permanenten Bedrohung geworden, weil immer mehr Programme versuchen, einem beim Installieren noch was anderes unterzujubeln - und wie schnell hat man da ein Häkchen übersehen? Darum: pass auf, wenn du dir Software aus dem Internet herunterlädst! Viele Portale im Internet wie Chip, Softonic und Sourceforge versuchen häufig, dir Adware oder sonstige Downloader mit unerwünschten Programmen unterzujubeln. Downloade nach Möglichkeit immer direkt von der Herstellerseite oder alternativ von einem sauberen Download-Portal, wie von FilePony.de. Lese dir dazu auch folgenden Artikel durch: CHIP-Installer - was ist das? - Anleitungen Selbst wenn du ein Programm von einer seriösen Quelle heruntergeladen hast, ist das keine Garantie, dass dein Programm nicht doch versucht, unerwünschte Änderungen an deinem Computer vorzunehmen. So versuchen immer mehr Programme, durch modifizierte Installationsroutinen unerwünschte Programme mit auf deinen PC zu schleusen. Das klappt leider auch häufig, weil viele Anwender nicht lesen, was auf dem Bildschirm steht und stattdessen schnell durchklicken. Deshalb: Wenn du ein Programm installierst, wähle immer die benutzerdefinierte Installation und schaue, was du da gerade eigentlich alles mit einem Klick auf "Ok" oder "Weiter" abnickst - entferne entsprechend die Haken bei Dingen, die du nicht möchtest. Wer lesen kann, ist klar im Vorteil! Benutze keine Optimizer, Cleaner oder sonstige SpeedUp Wunder, da diese Tools fast nie einen auch nur messbaren Performancegewinn bringen. Du kannst jedoch regelmäßig auf deinem PC die Datenträgerbereinigung ausführen, so gewinnst du belegten Speicherplatz zurück. Aktiviere in deiner Virenschutzlösungen den "Schutz vor potentiell unerwünschter Software", um dich bestmöglich zu schützen. Guter Trick: Wenn du den kostenlosen Windows Defender benutzt (ab Windows 8), kannst du einen vergleichbaren Schutz durch einen kleinen Trick auch nutzen! Lese dazu folgenden Artikel um dich mehr zu informieren: Windows mit verstecktem Adware-Killer Zum aktivieren dieses "Tricks" lade einfach nur diese Datei und führe sie aus: MpEnablePlus.reg Tipps, um dein System sicherer zu machen Halte immer deine Plug-ins und Software, insbesondere deinen Browser aktuell. Deinstalliere wenn möglich Java und den Adobe Flashplayer von deinem Computer. Neuerdings benötigt man sie fast nie mehr und stellen darum nur mehr eine unnötige Sicherheitslücke auf deinem Computer dar. Wenn du sie doch unbedingt benötigst, halte sie aber unbedingt aktuell. Weiters kannst du dir Malwarebytes Anti-Exploit installieren. Es schützt gegen viele aktuelle Sicherheitslücken und erhöht so deine Sicherheit. Passwörter Ändere regelmäßig deine Passwörter! Zudem musst du sichere Passwörter benutzen, das bedeutet: mindestens 8 Zeichen, Groß- und Kleinbuchstaben und Sonderzeichen. Ganz wichtig: benutze pro Account ein anderes Passwort! Tipp: Benutze einen Spruch, den du dir leicht merken kannst, als Hilfe für ein Passwort! Zum Beispiel: Der Himmel ist blau und wenn es regnet?-grau ==> DHibuwer?-grau Unterstütze uns und empfiehl uns weiter Du kennst Freunde und Bekannte, die Probleme mit ihrem Computer haben? Schick sie doch zu uns auf das Trojaner Board, wir helfen gerne Wenn du uns mit einer Spende unterstützen möchtest, freuen wir uns sehr und dies kannst du hier tun: http://www.trojaner-board.de/79994-s...ndenkonto.html Herzlichen Dank dafür Wir machen diese Tätigkeit hier freiwillig, darum freue ich mich besonders über ein kurzes Danke, wenn du mit mir zufrieden warest oder sonst über Verbesserungsvorschläge - das kannst du gerne hier machen Besuche und like unsere Facebook-Seite! Danke für deine Mitarbeit und alles Gute! Bitte gib mir Bescheid, wenn du das alles gelesen hast und du keine weiteren Fragen mehr hast.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
09.04.2016, 00:46 | #15 |
| GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall Dass hört sich ja super an! Da lasse ich doch ein großes Danke da, vielen Dank dass ihr euch Zeit für mich genommen habt, TOP Arbeit! Ich werde definitiv ne kleine Spende da lassen MfG Zaji |
Themen zu GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall |
akamai, antivirus, avast, bluestacks, bonjour, computer, defender, dnsapi.dll, email, flash player, frage, giropay24, google, home, installation, kuaizip, mozilla, prozesse, realtek, registry, rundll, scan, security, software, svchost.exe, system, trojaner/virus, updates, windows, windowsapps, wlan |