|
Plagegeister aller Art und deren Bekämpfung: Ständige Soundschleifen und Standbilder bei SpielenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.07.2016, 23:16 | #1 |
| Ständige Soundschleifen und Standbilder bei Spielen Hallo! Ich habe schon seit längerer Zeit das Problem, wenn ich z.B. Hearthstone spiele, ständig eine Soundschleife mit einem Standbild bekomme. Dann ist leider gar nichts mehr möglich. Ich kann nur noch den Power-Knopf benutzen um den Rechner neu zu starten. Ab und zu zeigt mir der Taskmanager auch sehr hohe Auslastungen (bei CPU, Arbeitsspeicher und Datenträger teilweise bis 99%) an. Habt ihr vielleicht eine Ahnung woran das liegen könnte? FRST: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 02-07-2016 durchgeführt von Kamali (Administrator) auf KAMALI-PC (08-07-2016 00:11:14) Gestartet von C:\Users\Kamali\Downloads Geladene Profile: Kamali (Verfügbare Profile: Kamali & Paimonah) Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDWebCam.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPictureViewer.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMovieViewer.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDYT.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.424_none_767fbf7a263fc7d3\TiWorker.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\cnext.exe [4926664 2016-02-26] (Advanced Micro Devices, Inc.) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15818872 2016-04-29] (Logitech Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597016 2016-03-31] (Oracle Corporation) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [226816 2016-05-23] (Geek Software GmbH) HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\Run: [Innkeeper] => C:\Users\Kamali\AppData\Local\Innkeeper\Update.exe --processStart Innkeeper.exe --process-start-args="-startup" ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Keine Datei ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => Keine Datei ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => Keine Datei ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Keine Datei ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => Keine Datei ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => Keine Datei GroupPolicy: Beschränkung - Chrome <======= ACHTUNG CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{ef39b2f2-a92d-4ebd-8724-ae4a0dd1edcb}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_92\bin\ssv.dll [2016-06-25] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_92\bin\jp2ssv.dll [2016-06-25] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_92\bin\ssv.dll [2016-06-25] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_92\bin\jp2ssv.dll [2016-06-25] (Oracle Corporation) Edge: ====== Edge HomeButtonPage: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001 -> hxxp://www.google.de/ FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_192.dll [2016-06-30] () FF Plugin: @java.com/DTPlugin,version=11.92.2 -> C:\Program Files\Java\jre1.8.0_92\bin\dtplugin\npDeployJava1.dll [2016-06-25] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.92.2 -> C:\Program Files\Java\jre1.8.0_92\bin\plugin2\npjp2.dll [2016-06-25] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_192.dll [2016-06-30] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw.dll [2016-02-19] (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.92.2 -> C:\Program Files (x86)\Java\jre1.8.0_92\bin\dtplugin\npDeployJava1.dll [2016-06-25] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.92.2 -> C:\Program Files (x86)\Java\jre1.8.0_92\bin\plugin2\npjp2.dll [2016-06-25] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-26] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-26] (Google Inc.) Chrome: ======= CHR Profile: C:\Users\Kamali\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Kamali\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-23] CHR Extension: (YouTube) - C:\Users\Kamali\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-23] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Kamali\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-23] CHR Extension: (Google Mail) - C:\Users\Kamali\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-23] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-04-29] (Logitech Inc.) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [23240 2016-02-26] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [101376 2016-06-14] (Advanced Micro Devices) S3 cpuz138; C:\Users\Kamali\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [27320 2016-06-27] (CPUID) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-06-14] (REALiX(tm)) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\Windows\system32\drivers\LGJoyXlCore.sys [85160 2016-04-19] (Logitech Inc.) R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-06-19] (Malwarebytes) S3 MEMSWEEP2; C:\WINDOWS\system32\C33D.tmp [6144 2009-06-18] (Sophos Plc) [Datei ist nicht signiert] S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) S4 IMFFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [X] S3 RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [X] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2016.SP1\WNt600x64\Sandra.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-07-08 00:11 - 2016-07-08 00:12 - 00010968 _____ C:\Users\Kamali\Downloads\FRST.txt 2016-07-04 15:24 - 2016-07-04 15:24 - 02390016 _____ (Farbar) C:\Users\Kamali\Downloads\FRST64.exe 2016-07-04 14:56 - 2016-07-04 14:56 - 00005346 _____ C:\Users\Kamali\AppData\Local\recently-used.xbel 2016-07-04 14:01 - 2016-07-04 14:01 - 00001163 _____ C:\Users\Public\Desktop\PDF24.lnk 2016-07-04 14:01 - 2016-07-04 14:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 2016-07-04 13:17 - 2016-07-04 14:01 - 00000000 ____D C:\Program Files (x86)\PDF24 2016-07-04 13:16 - 2016-07-04 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ghostscript 2016-07-04 13:16 - 2016-07-04 13:16 - 00000000 ____D C:\Program Files\gs 2016-07-04 13:15 - 2016-07-04 13:15 - 00000909 _____ C:\Users\Public\Desktop\Scribus 1.4.6.lnk 2016-07-04 13:15 - 2016-07-04 13:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scribus 1.4.6 2016-07-04 13:14 - 2016-07-04 13:15 - 00000000 ____D C:\Program Files\Scribus 1.4.6 2016-07-02 08:54 - 2016-07-08 00:11 - 00000000 ____D C:\FRST 2016-07-02 08:39 - 2016-07-02 08:39 - 00040972 __RSH C:\ProgramData\ntuser.pol 2016-07-02 08:34 - 2016-07-02 09:38 - 00000000 ____D C:\ProgramData\TEMP 2016-07-02 08:34 - 2012-05-02 12:17 - 01070152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCTL.OCX 2016-07-02 08:34 - 2009-03-24 13:52 - 00129872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSSTDFMT.DLL 2016-06-30 13:13 - 2016-06-30 11:39 - 00000030 _____ C:\AVScanner.ini 2016-06-30 11:39 - 2016-06-30 11:39 - 00000000 ____D C:\ProgramData\McAfee 2016-06-30 11:38 - 2016-06-30 11:39 - 00000000 ____D C:\Users\Kamali\AppData\Local\Adobe 2016-06-30 08:52 - 2016-06-30 08:52 - 00001851 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Lucky Nugget Casino.lnk 2016-06-30 08:52 - 2016-06-30 08:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lucky Nugget Casino 2016-06-30 08:43 - 2016-06-30 08:44 - 00001892 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Mummys Gold Casino.lnk 2016-06-30 08:43 - 2016-06-30 08:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mummys Gold Casino 2016-06-30 08:18 - 2016-06-30 08:18 - 00001844 _____ C:\ProgramData\Microsoft\Windows\Start Menu\River Belle Online Casino.lnk 2016-06-30 08:18 - 2016-06-30 08:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\River Belle Online Casino 2016-06-30 08:03 - 2016-06-30 08:05 - 00001842 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Royal Vegas.lnk 2016-06-30 07:55 - 2016-06-30 07:55 - 00001863 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Golden Riviera Casino.lnk 2016-06-27 19:41 - 2016-06-27 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2016-06-27 19:40 - 2016-06-27 19:42 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2016-06-26 10:19 - 2016-06-26 10:19 - 00000000 ____D C:\Users\Kamali\AppData\Local\ActiveSync 2016-06-26 10:13 - 2016-06-26 10:13 - 00000000 ____D C:\Program Files (x86)\obs-studio 2016-06-26 10:06 - 2016-06-26 10:06 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\.mono 2016-06-26 09:51 - 2016-07-07 23:59 - 00000000 ____D C:\Users\Kamali\AppData\Local\Battle.net 2016-06-26 09:51 - 2016-06-26 09:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2016-06-26 09:49 - 2016-07-07 19:08 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-06-26 09:49 - 2016-07-01 18:07 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\Battle.net 2016-06-26 09:31 - 2014-07-22 13:25 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll 2016-06-26 09:31 - 2014-07-22 13:25 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll 2016-06-26 09:31 - 2014-07-22 13:25 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll 2016-06-26 01:00 - 2016-07-08 00:05 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-06-26 01:00 - 2016-07-08 00:02 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-06-26 00:55 - 2016-06-26 00:55 - 00002342 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-06-26 00:55 - 2016-06-26 00:55 - 00002330 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-06-26 00:54 - 2016-06-26 01:00 - 00004196 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-06-26 00:54 - 2016-06-26 01:00 - 00003964 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-06-26 00:38 - 2009-06-18 12:54 - 00006144 ____N (Sophos Plc) C:\WINDOWS\system32\C33D.tmp 2016-06-26 00:11 - 2016-06-26 00:11 - 00003018 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Kamali) 2016-06-25 23:10 - 2016-06-25 23:10 - 00000000 ____D C:\Users\Kamali\AppData\IObit 2016-06-25 23:10 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll 2016-06-25 22:52 - 2014-10-16 10:27 - 00027424 _____ (IObit) C:\WINDOWS\system32\RegistryDefragBootTime.exe 2016-06-25 22:41 - 2016-06-25 22:41 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\Apple Computer 2016-06-25 22:37 - 2009-06-18 12:54 - 00006144 ____N (Sophos Plc) C:\WINDOWS\system32\8C49.tmp 2016-06-25 22:33 - 2016-06-25 22:33 - 00001663 _____ C:\AiOLog.txt 2016-06-25 22:32 - 2016-06-25 22:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-06-25 22:31 - 2016-06-25 22:31 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe 2016-06-25 22:31 - 2016-06-25 22:31 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-06-25 22:31 - 2016-06-25 22:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-06-25 22:22 - 2016-06-25 22:22 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2016-06-25 22:22 - 2016-06-25 22:22 - 00000000 ____D C:\Program Files\Java 2016-06-25 22:22 - 2016-06-25 22:21 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-06-25 22:21 - 2016-06-25 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-06-25 22:21 - 2016-06-25 22:21 - 00000000 ____D C:\Program Files (x86)\Java 2016-06-25 22:20 - 2016-06-27 19:34 - 00000000 ____D C:\Program Files (x86)\Sophos 2016-06-25 22:20 - 2009-06-18 12:54 - 00006144 ____N (Sophos Plc) C:\WINDOWS\system32\9549.tmp 2016-06-25 22:09 - 2016-06-25 22:09 - 00000000 ____D C:\WINDOWS\LastGood 2016-06-25 21:27 - 2016-06-25 21:27 - 00000000 ____D C:\ProgramData\ATI 2016-06-25 17:58 - 2016-06-25 23:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro 2016-06-25 17:58 - 2016-06-25 17:58 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\HD Tune Pro 2016-06-25 11:04 - 2016-06-25 11:04 - 00000000 ____D C:\WINDOWS\LastGood.Tmp 2016-06-19 21:32 - 2016-06-19 21:32 - 00004296 _____ C:\WINDOWS\System32\Tasks\AMD Updater 2016-06-19 21:15 - 2016-06-19 21:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings 2016-06-19 21:06 - 2016-02-26 23:00 - 13408208 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 08089248 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdva.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 01506000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 01237200 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00458472 _____ C:\WINDOWS\system32\amdmiracast.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00152056 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiuxp64.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00133016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00120656 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiu9p64.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00102616 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiu9pag.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll 2016-06-19 21:06 - 2016-02-26 23:00 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll 2016-06-19 21:06 - 2016-02-26 22:59 - 10963496 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd64.dll 2016-06-19 21:06 - 2016-02-26 22:59 - 09176928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdag.dll 2016-06-19 21:06 - 2016-02-26 22:59 - 09017808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd6a.dll 2016-06-19 21:06 - 2016-02-26 22:57 - 00296648 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\amdacpksd.sys 2016-06-19 21:06 - 2016-02-26 22:54 - 00023240 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\amdkmafd.sys 2016-06-19 21:06 - 2016-02-26 22:53 - 23981568 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmdag.sys 2016-06-19 21:06 - 2016-02-26 22:48 - 49988096 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl64.dll 2016-06-19 21:06 - 2016-02-26 22:48 - 00235008 _____ C:\WINDOWS\system32\clinfo.exe 2016-06-19 21:06 - 2016-02-26 22:45 - 00065024 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2016-06-19 21:06 - 2016-02-26 22:45 - 00059392 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2016-06-19 21:06 - 2016-02-26 22:44 - 27596288 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl12cl64.dll 2016-06-19 21:06 - 2016-02-26 22:23 - 00693248 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll 2016-06-19 21:06 - 2016-02-26 22:23 - 00574464 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll 2016-06-19 21:06 - 2016-02-26 22:23 - 00127488 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll 2016-06-19 21:06 - 2016-02-26 22:22 - 06644224 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmantle64.dll 2016-06-19 21:06 - 2016-02-26 22:22 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll 2016-06-19 21:06 - 2016-02-26 22:18 - 05223936 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmantle32.dll 2016-06-19 21:06 - 2016-02-26 22:15 - 00134656 _____ C:\WINDOWS\system32\amdhdl64.dll 2016-06-19 21:06 - 2016-02-26 22:15 - 00123392 _____ C:\WINDOWS\SysWOW64\amdhdl32.dll 2016-06-19 21:06 - 2016-02-26 22:14 - 31378944 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atio6axx.dll 2016-06-19 21:06 - 2016-02-26 22:14 - 00096256 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll 2016-06-19 21:06 - 2016-02-26 22:14 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll 2016-06-19 21:06 - 2016-02-26 22:13 - 08008192 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll 2016-06-19 21:06 - 2016-02-26 22:11 - 09804288 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll 2016-06-19 21:06 - 2016-02-26 22:11 - 00865280 _____ (AMD) C:\WINDOWS\system32\coinst_15.30.dll 2016-06-19 21:06 - 2016-02-26 22:11 - 00686208 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb 2016-06-19 21:06 - 2016-02-26 22:11 - 00686208 _____ C:\WINDOWS\system32\atiapfxx.blb 2016-06-19 21:06 - 2016-02-26 22:11 - 00367104 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe 2016-06-19 21:06 - 2016-02-26 22:11 - 00062464 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalrt64.dll 2016-06-19 21:06 - 2016-02-26 22:10 - 15711744 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticaldd64.dll 2016-06-19 21:06 - 2016-02-26 22:10 - 00055808 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalcl64.dll 2016-06-19 21:06 - 2016-02-26 22:10 - 00052224 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalrt.dll 2016-06-19 21:06 - 2016-02-26 22:10 - 00049152 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalcl.dll 2016-06-19 21:06 - 2016-02-26 22:08 - 00050688 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmmcl6.dll 2016-06-19 21:06 - 2016-02-26 22:08 - 00039424 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmmcl.dll 2016-06-19 21:06 - 2016-02-26 22:06 - 03437632 _____ C:\WINDOWS\system32\atiumd6a.cap 2016-06-19 21:06 - 2016-02-26 22:04 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll 2016-06-19 21:06 - 2016-02-26 22:04 - 00224256 _____ C:\WINDOWS\system32\dgtrayicon.exe 2016-06-19 21:06 - 2016-02-26 22:04 - 00209920 _____ C:\WINDOWS\system32\GameManager64.dll 2016-06-19 21:06 - 2016-02-26 22:04 - 00204800 _____ C:\WINDOWS\system32\amdgfxinfo64.dll 2016-06-19 21:06 - 2016-02-26 22:04 - 00189952 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll 2016-06-19 21:06 - 2016-02-26 22:04 - 00186368 _____ C:\WINDOWS\SysWOW64\GameManager32.dll 2016-06-19 21:06 - 2016-02-26 22:04 - 00162304 _____ C:\WINDOWS\system32\atieah64.exe 2016-06-19 21:06 - 2016-02-26 22:04 - 00145408 _____ C:\WINDOWS\SysWOW64\atieah32.exe 2016-06-19 21:06 - 2016-02-26 22:04 - 00078336 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll 2016-06-19 21:06 - 2016-02-26 22:03 - 00562688 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe 2016-06-19 21:06 - 2016-02-26 22:03 - 00249344 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe 2016-06-19 21:06 - 2016-02-26 22:03 - 00190976 _____ (AMD) C:\WINDOWS\system32\atitmm64.dll 2016-06-19 21:06 - 2016-02-26 22:02 - 03471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap 2016-06-19 21:06 - 2016-02-26 21:58 - 01272832 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll 2016-06-19 21:06 - 2016-02-26 21:58 - 00941568 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll 2016-06-19 21:06 - 2016-02-26 21:58 - 00941568 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll 2016-06-19 21:06 - 2016-02-26 21:58 - 00674816 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmpag.sys 2016-06-19 21:06 - 2016-02-26 21:58 - 00157696 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll 2016-06-19 21:06 - 2016-02-26 21:58 - 00142336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll 2016-06-19 21:06 - 2016-02-26 21:58 - 00075776 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6pxx.dll 2016-06-19 21:06 - 2016-02-26 21:58 - 00070144 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiglpxx.dll 2016-06-19 21:06 - 2016-02-26 21:58 - 00070144 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiglpxx.dll 2016-06-19 21:06 - 2016-02-26 21:57 - 00195072 _____ C:\WINDOWS\system32\hsa-thunk64.dll 2016-06-19 21:06 - 2016-02-26 21:57 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\ati2erec.dll 2016-06-19 21:06 - 2016-02-26 21:56 - 00174592 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll 2016-06-19 21:06 - 2016-02-01 09:19 - 00853477 _____ C:\WINDOWS\system32\amdicdxx.dat 2016-06-19 21:06 - 2015-10-20 18:14 - 00007112 _____ C:\WINDOWS\system32\AMDKernelEvents.man 2016-06-19 21:06 - 2015-10-16 20:19 - 00166560 _____ C:\WINDOWS\system32\amde34a.dat 2016-06-19 21:06 - 2015-10-15 23:08 - 00100832 _____ C:\WINDOWS\system32\ativce02.dat 2016-06-19 21:06 - 2015-10-15 23:04 - 00177344 _____ C:\WINDOWS\system32\ativce03.dat 2016-06-19 21:06 - 2015-10-15 22:59 - 00175648 _____ C:\WINDOWS\system32\amde31a.dat 2016-06-19 21:06 - 2015-10-14 20:50 - 00261920 _____ C:\WINDOWS\system32\ativvaxy_stn_nd.dat 2016-06-19 21:06 - 2015-10-14 20:48 - 00258464 _____ C:\WINDOWS\system32\ativvaxy_cz_nd.dat 2016-06-19 21:06 - 2015-10-14 20:46 - 00252628 _____ C:\WINDOWS\system32\ativvaxy_FJ.dat 2016-06-19 21:06 - 2015-10-14 20:44 - 00249680 _____ C:\WINDOWS\system32\ativvaxy_FJ_nd.dat 2016-06-19 21:06 - 2015-09-22 21:21 - 00323588 _____ C:\WINDOWS\system32\ativvaxy_el.dat 2016-06-19 21:06 - 2015-09-22 21:19 - 00320992 _____ C:\WINDOWS\system32\ativvaxy_el_nd.dat 2016-06-19 21:06 - 2015-09-22 19:38 - 00322740 _____ C:\WINDOWS\system32\ativvaxy_vi.dat 2016-06-19 21:06 - 2015-09-22 19:36 - 00321072 _____ C:\WINDOWS\system32\ativvaxy_vi_nd.dat 2016-06-19 21:06 - 2015-09-22 19:28 - 00234292 _____ C:\WINDOWS\system32\ativvaxy_cik.dat 2016-06-19 21:06 - 2015-09-22 19:27 - 00232624 _____ C:\WINDOWS\system32\ativvaxy_cik_nd.dat 2016-06-19 21:06 - 2014-09-03 14:55 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll 2016-06-19 21:06 - 2014-09-03 14:55 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll 2016-06-19 21:06 - 2013-04-10 17:34 - 00332800 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe 2016-06-19 21:06 - 2013-04-10 17:34 - 00051200 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe 2016-06-19 20:21 - 2016-07-03 10:52 - 00000000 ____D C:\AdwCleaner 2016-06-19 20:07 - 2016-06-19 20:07 - 00002860 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2016-06-19 20:07 - 2016-06-19 20:07 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-06-19 20:07 - 2016-06-19 20:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-06-19 20:07 - 2016-06-19 20:07 - 00000000 ____D C:\Program Files\CCleaner 2016-06-19 19:53 - 2016-06-19 21:34 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-06-19 19:52 - 2016-06-19 19:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-06-18 12:44 - 2016-06-18 13:03 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\HearthstoneDeckTracker 2016-06-17 20:19 - 2016-06-14 20:33 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-06-17 20:19 - 2016-06-14 20:33 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-06-16 14:48 - 2016-06-16 14:48 - 00000939 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2016-06-16 14:47 - 2016-06-16 14:48 - 00000000 ____D C:\Program Files\GIMP 2 2016-06-15 08:13 - 2016-06-15 08:13 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2016-06-15 08:13 - 2016-06-15 08:13 - 00000000 ____D C:\Program Files\Reference Assemblies 2016-06-15 08:13 - 2016-06-15 08:13 - 00000000 ____D C:\Program Files\MSBuild 2016-06-15 08:13 - 2016-06-15 08:13 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-06-15 08:13 - 2016-06-15 08:13 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-06-15 08:11 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2016-06-15 08:11 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2016-06-15 08:11 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2016-06-15 08:11 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2016-06-15 08:11 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2016-06-15 08:11 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2016-06-14 20:36 - 2016-05-28 08:13 - 01401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2016-06-14 20:36 - 2016-05-28 08:13 - 01184960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2016-06-14 20:36 - 2016-05-28 08:13 - 00514752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2016-06-14 20:36 - 2016-05-28 08:13 - 00290496 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2016-06-14 20:36 - 2016-05-28 08:13 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2016-06-14 20:36 - 2016-05-28 08:13 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2016-06-14 20:36 - 2016-05-28 07:25 - 04268880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll 2016-06-14 20:36 - 2016-05-28 07:23 - 00388384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll 2016-06-14 20:36 - 2016-05-28 07:23 - 00312160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll 2016-06-14 20:36 - 2016-05-28 07:22 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-06-14 20:36 - 2016-05-28 07:22 - 04387680 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll 2016-06-14 20:36 - 2016-05-28 07:22 - 00428896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2016-06-14 20:36 - 2016-05-28 07:22 - 00211296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2016-06-14 20:36 - 2016-05-28 07:22 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-06-14 20:36 - 2016-05-28 07:20 - 00430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll 2016-06-14 20:36 - 2016-05-28 07:18 - 00357216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll 2016-06-14 20:36 - 2016-05-28 07:16 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2016-06-14 20:36 - 2016-05-28 07:09 - 00501600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-06-14 20:36 - 2016-05-28 07:09 - 00170848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.exe 2016-06-14 20:36 - 2016-05-28 07:09 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-06-14 20:36 - 2016-05-28 07:08 - 00693600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-06-14 20:36 - 2016-05-28 07:08 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys 2016-06-14 20:36 - 2016-05-28 07:08 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2016-06-14 20:36 - 2016-05-28 07:07 - 03675512 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-06-14 20:36 - 2016-05-28 07:07 - 02921880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-06-14 20:36 - 2016-05-28 07:07 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-06-14 20:36 - 2016-05-28 07:07 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-06-14 20:36 - 2016-05-28 07:07 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-06-14 20:36 - 2016-05-28 07:07 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-06-14 20:36 - 2016-05-28 07:07 - 00331616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-06-14 20:36 - 2016-05-28 07:06 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-06-14 20:36 - 2016-05-28 07:06 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-06-14 20:36 - 2016-05-28 07:06 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2016-06-14 20:36 - 2016-05-28 07:06 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-06-14 20:36 - 2016-05-28 07:06 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-06-14 20:36 - 2016-05-28 07:05 - 04515264 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-06-14 20:36 - 2016-05-28 07:04 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-06-14 20:36 - 2016-05-28 07:04 - 00431296 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll 2016-06-14 20:36 - 2016-05-28 07:04 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2016-06-14 20:36 - 2016-05-28 07:04 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2016-06-14 20:36 - 2016-05-28 07:04 - 00111064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll 2016-06-14 20:36 - 2016-05-28 07:04 - 00097096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll 2016-06-14 20:36 - 2016-05-28 07:03 - 00131248 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll 2016-06-14 20:36 - 2016-05-28 06:58 - 01996640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-06-14 20:36 - 2016-05-28 06:58 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-06-14 20:36 - 2016-05-28 06:57 - 02548944 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2016-06-14 20:36 - 2016-05-28 06:57 - 02195632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2016-06-14 20:36 - 2016-05-28 06:57 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2016-06-14 20:36 - 2016-05-28 06:57 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2016-06-14 20:36 - 2016-05-28 06:57 - 00649792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-06-14 20:36 - 2016-05-28 06:57 - 00636304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-06-14 20:36 - 2016-05-28 06:57 - 00577376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-06-14 20:36 - 2016-05-28 06:57 - 00546456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-06-14 20:36 - 2016-05-28 06:57 - 00521664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-06-14 20:36 - 2016-05-28 06:57 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-06-14 20:36 - 2016-05-28 06:35 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdlrecover.exe 2016-06-14 20:36 - 2016-05-28 06:35 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2016-06-14 20:36 - 2016-05-28 06:35 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsdport.sys 2016-06-14 20:36 - 2016-05-28 06:31 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdlrecover.exe 2016-06-14 20:36 - 2016-05-28 06:31 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-06-14 20:36 - 2016-05-28 06:31 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll 2016-06-14 20:36 - 2016-05-28 06:29 - 22379008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-06-14 20:36 - 2016-05-28 06:29 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll 2016-06-14 20:36 - 2016-05-28 06:29 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-06-14 20:36 - 2016-05-28 06:29 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll 2016-06-14 20:36 - 2016-05-28 06:28 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2016-06-14 20:36 - 2016-05-28 06:28 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-06-14 20:36 - 2016-05-28 06:28 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll 2016-06-14 20:36 - 2016-05-28 06:27 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll 2016-06-14 20:36 - 2016-05-28 06:27 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2016-06-14 20:36 - 2016-05-28 06:26 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-06-14 20:36 - 2016-05-28 06:26 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2016-06-14 20:36 - 2016-05-28 06:26 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2016-06-14 20:36 - 2016-05-28 06:26 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-06-14 20:36 - 2016-05-28 06:26 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-06-14 20:36 - 2016-05-28 06:25 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpscript.dll 2016-06-14 20:36 - 2016-05-28 06:25 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-06-14 20:36 - 2016-05-28 06:24 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-06-14 20:36 - 2016-05-28 06:24 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys 2016-06-14 20:36 - 2016-05-28 06:24 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-06-14 20:36 - 2016-05-28 06:24 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-06-14 20:36 - 2016-05-28 06:24 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-06-14 20:36 - 2016-05-28 06:24 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-06-14 20:36 - 2016-05-28 06:24 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll 2016-06-14 20:36 - 2016-05-28 06:24 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FwRemoteSvr.dll 2016-06-14 20:36 - 2016-05-28 06:23 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 2016-06-14 20:36 - 2016-05-28 06:23 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll 2016-06-14 20:36 - 2016-05-28 06:22 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2016-06-14 20:36 - 2016-05-28 06:22 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2016-06-14 20:36 - 2016-05-28 06:22 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys 2016-06-14 20:36 - 2016-05-28 06:22 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-06-14 20:36 - 2016-05-28 06:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2016-06-14 20:36 - 2016-05-28 06:22 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-06-14 20:36 - 2016-05-28 06:22 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-06-14 20:36 - 2016-05-28 06:22 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsvc.dll 2016-06-14 20:36 - 2016-05-28 06:22 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-06-14 20:36 - 2016-05-28 06:21 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-06-14 20:36 - 2016-05-28 06:21 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrokerLib.dll 2016-06-14 20:36 - 2016-05-28 06:21 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-06-14 20:36 - 2016-05-28 06:21 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2016-06-14 20:36 - 2016-05-28 06:21 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpscript.dll 2016-06-14 20:36 - 2016-05-28 06:20 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-06-14 20:36 - 2016-05-28 06:20 - 00511488 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll 2016-06-14 20:36 - 2016-05-28 06:20 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\polstore.dll 2016-06-14 20:36 - 2016-05-28 06:20 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll 2016-06-14 20:36 - 2016-05-28 06:20 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GnssAdapter.dll 2016-06-14 20:36 - 2016-05-28 06:20 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll 2016-06-14 20:36 - 2016-05-28 06:20 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll 2016-06-14 20:36 - 2016-05-28 06:19 - 24605696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-06-14 20:36 - 2016-05-28 06:19 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-06-14 20:36 - 2016-05-28 06:19 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2016-06-14 20:36 - 2016-05-28 06:19 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-06-14 20:36 - 2016-05-28 06:19 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll 2016-06-14 20:36 - 2016-05-28 06:19 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 07977472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPSECSVC.DLL 2016-06-14 20:36 - 2016-05-28 06:18 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2016-06-14 20:36 - 2016-05-28 06:18 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 00963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2016-06-14 20:36 - 2016-05-28 06:17 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2016-06-14 20:36 - 2016-05-28 06:16 - 19344384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-06-14 20:36 - 2016-05-28 06:16 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-06-14 20:36 - 2016-05-28 06:16 - 00684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll 2016-06-14 20:36 - 2016-05-28 06:16 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll 2016-06-14 20:36 - 2016-05-28 06:16 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2016-06-14 20:36 - 2016-05-28 06:16 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2016-06-14 20:36 - 2016-05-28 06:16 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\polstore.dll 2016-06-14 20:36 - 2016-05-28 06:16 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 00794624 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll 2016-06-14 20:36 - 2016-05-28 06:15 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2016-06-14 20:36 - 2016-05-28 06:14 - 18674176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 01716736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 00606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-06-14 20:36 - 2016-05-28 06:14 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2016-06-14 20:36 - 2016-05-28 06:13 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-06-14 20:36 - 2016-05-28 06:13 - 00990208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-06-14 20:36 - 2016-05-28 06:13 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll 2016-06-14 20:36 - 2016-05-28 06:13 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-06-14 20:36 - 2016-05-28 06:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-06-14 20:36 - 2016-05-28 06:13 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll 2016-06-14 20:36 - 2016-05-28 06:12 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-06-14 20:36 - 2016-05-28 06:12 - 00614400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2016-06-14 20:36 - 2016-05-28 06:12 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 01445888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2016-06-14 20:36 - 2016-05-28 06:11 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll 2016-06-14 20:36 - 2016-05-28 06:09 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-06-14 20:36 - 2016-05-28 06:08 - 13385728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-06-14 20:36 - 2016-05-28 06:08 - 06295552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-06-14 20:36 - 2016-05-28 06:06 - 12128256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-06-14 20:36 - 2016-05-28 06:06 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-06-14 20:36 - 2016-05-28 06:06 - 01339904 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll 2016-06-14 20:36 - 2016-05-28 06:05 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-06-14 20:36 - 2016-05-28 06:05 - 03664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-06-14 20:36 - 2016-05-28 06:05 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-06-14 20:36 - 2016-05-28 06:05 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-06-14 20:36 - 2016-05-28 06:04 - 06973952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-06-14 20:36 - 2016-05-28 06:04 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll 2016-06-14 20:36 - 2016-05-28 06:04 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll 2016-06-14 20:36 - 2016-05-28 06:03 - 05323776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-06-14 20:36 - 2016-05-28 06:03 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-06-14 20:36 - 2016-05-28 06:03 - 02609664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-06-14 20:36 - 2016-05-28 06:03 - 01185280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFramework.dll 2016-06-14 20:36 - 2016-05-28 06:03 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll 2016-06-14 20:36 - 2016-05-28 06:03 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-06-14 20:36 - 2016-05-28 06:02 - 03590144 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-06-14 20:36 - 2016-05-28 06:02 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-06-14 20:36 - 2016-05-28 06:02 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll 2016-06-14 20:36 - 2016-05-28 06:02 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2016-06-14 20:36 - 2016-05-28 06:01 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-06-14 20:36 - 2016-05-28 06:01 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-06-14 20:36 - 2016-05-28 06:01 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-06-14 20:36 - 2016-05-28 06:01 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 02230272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 01730560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-06-14 20:36 - 2016-05-28 06:00 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-06-14 20:36 - 2016-05-28 05:59 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-06-14 20:36 - 2016-05-28 05:58 - 07832576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-06-14 20:36 - 2016-05-28 05:58 - 04896256 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-06-14 20:36 - 2016-05-28 05:58 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-06-14 20:36 - 2016-05-28 05:58 - 02066432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-06-14 20:36 - 2016-05-28 05:58 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-06-14 20:36 - 2016-05-28 05:57 - 02281472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-06-14 20:36 - 2016-05-28 05:55 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-06-14 20:36 - 2016-05-28 05:53 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll 2016-06-14 11:55 - 2016-06-14 11:55 - 05316608 _____ C:\WINDOWS\system32\config\DRIVERS.iobit 2016-06-14 11:41 - 2016-06-14 11:41 - 69066752 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit 2016-06-14 11:41 - 2016-06-14 11:41 - 00700416 _____ C:\WINDOWS\system32\config\DEFAULT.iobit 2016-06-14 11:41 - 2016-06-14 11:41 - 00073728 _____ C:\WINDOWS\system32\config\SAM.iobit 2016-06-14 11:41 - 2016-06-14 11:41 - 00028672 _____ C:\WINDOWS\system32\config\SECURITY.iobit 2016-06-14 11:24 - 2016-06-27 19:34 - 00000000 ____D C:\Program Files (x86)\SuperBoost 2016-06-14 11:24 - 2016-06-14 11:24 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\SuperBoost 2016-06-14 11:24 - 2016-06-14 11:24 - 00000000 ____D C:\ProgramData\SuperBoost 2016-06-14 11:24 - 2016-03-22 11:02 - 00036824 _____ (IObit) C:\WINDOWS\system32\SmartDefragBootTime.exe 2016-06-14 11:20 - 2016-06-14 11:20 - 00000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} 2016-06-14 11:13 - 2016-06-14 11:14 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\ProductData 2016-06-14 11:13 - 2016-06-14 11:13 - 00000000 ____D C:\WINDOWS\Tasks\ImCleanDisabled 2016-06-14 11:13 - 2016-06-14 11:13 - 00000000 ____D C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} 2016-06-14 08:19 - 2016-06-14 08:19 - 01077248 _____ C:\WINDOWS\system32\AmRdrIco.icl 2016-06-14 08:19 - 2016-06-14 08:19 - 00084480 _____ (Alcor Micro, Corp.) C:\WINDOWS\system32\Drivers\AmUStor.sys 2016-06-14 08:19 - 2016-06-14 08:19 - 00019066 _____ C:\WINDOWS\system32\AmUStor.ini 2016-06-14 08:19 - 2016-06-14 08:19 - 00012800 _____ (Alcor Micro, Corp.) C:\WINDOWS\system32\AmUStor2.dll 2016-06-14 08:19 - 2016-06-14 08:19 - 00000008 _____ C:\WINDOWS\system32\CardDetect6420.bin 2016-06-14 08:19 - 2016-06-14 08:19 - 00000008 _____ C:\WINDOWS\system32\CardDetect6366.bin 2016-06-14 08:19 - 2016-06-14 08:19 - 00000008 _____ C:\WINDOWS\system32\CardDetect6362.bin 2016-06-14 08:19 - 2016-06-14 08:19 - 00000008 _____ C:\WINDOWS\system32\CardDetect6361.bin 2016-06-14 08:18 - 2016-06-14 08:18 - 00103424 _____ (Advanced Micro Devices) C:\WINDOWS\system32\DelayAPO.dll 2016-06-14 08:18 - 2016-06-14 08:18 - 00101376 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\AtihdWT6.sys 2016-06-14 08:18 - 2016-06-14 08:18 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2016-06-14 08:17 - 2016-06-14 08:17 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2016-06-14 08:17 - 2016-06-14 08:17 - 00000000 ____D C:\WINDOWS\system32\DAX2 2016-06-14 08:17 - 2016-06-14 08:17 - 00000000 ____D C:\Program Files\Realtek 2016-06-14 08:16 - 2016-06-14 08:16 - 15202040 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE3.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 07172920 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 06402440 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV3apo.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 05776968 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 05593616 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 05085952 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2016-06-14 08:16 - 2016-06-14 08:16 - 03299824 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 03199232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 03094704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 02725392 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 02477520 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 02190992 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 02110600 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 02060032 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 01847888 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 01435152 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 01382240 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 01355616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 01336544 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 01023240 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 01003864 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00965032 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00962056 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00927424 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00923744 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00873472 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00716112 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00677672 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00589072 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.DLL 2016-06-14 08:16 - 2016-06-14 08:16 - 00582016 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00570096 _____ (Intel Corporation) C:\WINDOWS\system32\tbb_waves.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00532384 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00467168 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00450128 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00447728 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00447104 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00387320 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00381416 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00341152 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00341152 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00258864 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00231920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00221976 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00214832 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00209544 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00192984 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00166208 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00158704 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00151792 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00134208 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00110984 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00090920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00088352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00088328 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00084624 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00075544 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll 2016-06-14 08:16 - 2016-06-14 08:16 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll 2016-06-14 08:15 - 2016-06-14 08:16 - 12988344 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO4064.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat 2016-06-14 08:15 - 2016-06-14 08:15 - 24399536 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRenderAVX64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 24310136 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRender64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 17359672 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioCapture64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 14057256 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRealtek64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 13122584 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO3064.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 10512448 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSSTAPO.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 07096192 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 06264640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 05989809 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2016-06-14 08:15 - 2016-06-14 08:15 - 05804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat 2016-06-14 08:15 - 2016-06-14 08:15 - 05339552 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 03282544 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 03181209 _____ C:\WINDOWS\system32\Drivers\rtkSSTsetting.dat 2016-06-14 08:15 - 2016-06-14 08:15 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl 2016-06-14 08:15 - 2016-06-14 08:15 - 02825112 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO7064.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 02437760 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 02050176 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01965816 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01959608 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01780624 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01608128 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01591064 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01508936 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01422928 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO6064.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01334384 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01213664 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01186824 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSstCApoPropPage.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01166160 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 01061120 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00999864 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00931624 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00743968 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00727440 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00708320 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00678192 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00618184 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00574760 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00514528 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00504312 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00500560 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00472312 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00445400 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00441272 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00428232 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00416512 _____ (Harman) C:\WINDOWS\system32\HMUI.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00371456 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00366128 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00362056 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00360352 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00330568 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00327456 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00310424 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00272720 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00253904 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00253864 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00252880 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00203848 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00190936 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00190936 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00179600 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00154368 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00122328 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00118600 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00118600 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll 2016-06-14 08:15 - 2016-06-14 08:15 - 00105312 _____ C:\WINDOWS\system32\audioLibVc.dll 2016-06-14 08:10 - 2016-06-26 00:43 - 00000000 ____D C:\ProgramData\ProductData 2016-06-14 08:10 - 2016-06-14 08:10 - 00000000 ____D C:\WINDOWS\IObit 2016-06-14 08:09 - 2016-06-26 00:34 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\IObit 2016-06-14 08:09 - 2016-06-25 22:41 - 00000000 ____D C:\Users\Kamali\AppData\LocalLow\IObit 2016-06-14 08:09 - 2016-06-14 21:07 - 00000000 ____D C:\ProgramData\IObit 2016-06-14 08:09 - 2016-06-14 08:09 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS 2016-06-13 00:23 - 2016-06-13 00:23 - 00002309 _____ C:\Users\Kamali\Desktop\Innkeeper.lnk 2016-06-13 00:23 - 2016-06-13 00:23 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Innkeeper 2016-06-13 00:22 - 2016-06-18 12:18 - 00000000 ____D C:\Users\Kamali\AppData\Local\Innkeeper 2016-06-12 22:39 - 2016-06-12 22:39 - 00000000 ____D C:\Users\Kamali\AppData\Local\Mega Limited 2016-06-12 16:20 - 2016-06-25 22:29 - 00000000 ____D C:\ProgramData\Package Cache 2016-06-12 10:12 - 2016-07-03 13:16 - 00000000 ____D C:\Users\Kamali\AppData\Local\CrashDumps 2016-06-12 10:11 - 2016-06-26 10:13 - 00001281 _____ C:\Users\Public\Desktop\OBS Studio.lnk 2016-06-12 00:52 - 2016-06-30 13:11 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-06-12 00:52 - 2016-06-30 11:39 - 00003872 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-06-12 00:52 - 2016-06-26 00:40 - 00000946 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-06-12 00:52 - 2016-06-26 00:11 - 00004088 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier 2016-06-11 18:37 - 2016-06-11 18:37 - 00000000 ____D C:\Users\Kamali\Documents\freewowpanels 2016-06-11 18:36 - 2016-06-11 18:36 - 00000000 ____D C:\Program Files\7-Zip 2016-06-11 10:56 - 2016-06-11 12:59 - 00000000 ____D C:\ProgramData\Norton 2016-06-11 10:56 - 2016-06-11 10:56 - 00000000 ____D C:\ProgramData\NortonInstaller 2016-06-11 07:46 - 2016-06-27 19:34 - 00000000 ____D C:\WINDOWS\system32\appmgmt 2016-06-10 22:53 - 2016-06-14 16:00 - 00000000 ____D C:\Users\Kamali\Documents\Neuer Ordner 2016-06-10 12:19 - 2016-06-10 12:19 - 00000000 ____D C:\Users\Kamali\AppData\LocalLow\Temp 2016-06-09 12:07 - 2016-06-09 12:07 - 00000000 ____D C:\Users\Kamali\AppData\Local\ElevatedDiagnostics ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-07-08 00:05 - 2016-04-17 00:09 - 01799166 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-07-08 00:05 - 2016-02-13 18:59 - 00761816 _____ C:\WINDOWS\system32\perfh007.dat 2016-07-08 00:05 - 2016-02-13 18:59 - 00151322 _____ C:\WINDOWS\system32\perfc007.dat 2016-07-08 00:05 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-07-08 00:01 - 2016-04-16 23:58 - 00000000 ____D C:\Users\Kamali 2016-07-08 00:01 - 2016-02-13 19:26 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-07-07 21:00 - 2016-04-17 12:46 - 00000000 ____D C:\Program Files (x86)\Hearthstone 2016-07-07 02:39 - 2016-04-17 12:09 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2016-07-07 01:09 - 2016-06-06 16:48 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\obs-studio 2016-07-05 17:08 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-07-04 14:56 - 2016-05-10 15:44 - 00000000 ____D C:\Users\Kamali\.gimp-2.8 2016-07-04 14:55 - 2016-05-10 15:46 - 00000000 ____D C:\Users\Kamali\AppData\Local\gtk-2.0 2016-07-03 17:30 - 2016-04-18 08:52 - 00007601 _____ C:\Users\Kamali\AppData\Local\Resmon.ResmonCfg 2016-07-03 17:24 - 2016-04-16 21:14 - 00000000 ____D C:\Users\Kamali\AppData\Local\Packages 2016-07-03 17:24 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-07-03 17:24 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-07-02 08:35 - 2013-08-22 17:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy 2016-07-02 08:34 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2016-06-30 08:32 - 2016-06-01 22:45 - 00001842 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Spin Palace Casino.lnk 2016-06-30 08:32 - 2016-06-01 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spin Palace Casino 2016-06-30 08:05 - 2016-04-21 07:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Royal Vegas 2016-06-30 07:55 - 2016-04-21 07:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Golden Riviera Casino 2016-06-27 19:32 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\System 2016-06-27 12:25 - 2016-04-25 21:09 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm 2016-06-27 08:03 - 2016-05-04 13:37 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2016-06-26 00:55 - 2016-04-16 21:52 - 00000000 ____D C:\Program Files (x86)\Google 2016-06-26 00:02 - 2016-05-10 12:15 - 00000000 ____D C:\Program Files\paint.net 2016-06-26 00:02 - 2016-04-17 13:02 - 00000000 ____D C:\Program Files (x86)\AMD 2016-06-26 00:02 - 2016-04-16 23:55 - 00000000 ____D C:\Program Files\AMD 2016-06-25 22:31 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-06-25 22:22 - 2016-06-04 20:17 - 00000000 ____D C:\Users\Kamali\.oracle_jre_usage 2016-06-25 19:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-06-25 16:23 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\Registration 2016-06-25 11:00 - 2016-04-16 22:02 - 00000000 ____D C:\AMD 2016-06-23 20:27 - 2016-06-04 20:34 - 00000000 ____D C:\Users\Kamali\AppData\Roaming\InnkeeperUI 2016-06-23 07:50 - 2016-04-16 21:52 - 00000000 ____D C:\Users\Kamali\AppData\Local\Google 2016-06-20 09:23 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-06-19 21:15 - 2016-04-17 12:44 - 00000000 ____D C:\Users\Kamali\AppData\Local\AMD 2016-06-19 21:13 - 2016-04-16 23:56 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2016-06-19 20:49 - 2016-05-10 12:10 - 00000000 ____D C:\Program Files (x86)\Tinypic 2016-06-19 20:38 - 2016-05-17 13:57 - 00000000 ____D C:\WINDOWS\Minidump 2016-06-16 14:44 - 2016-05-10 12:37 - 00001634 _____ C:\Users\Kamali\Desktop\GIMP 2.lnk 2016-06-15 11:58 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache 2016-06-15 08:13 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2016-06-15 08:13 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\MUI 2016-06-14 20:55 - 2016-02-13 19:32 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-06-14 20:54 - 2016-02-13 10:22 - 00227912 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-06-14 20:52 - 2015-10-30 09:24 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2016-06-14 20:52 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2016-06-14 20:52 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-06-14 20:41 - 2016-04-17 12:07 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-06-14 20:36 - 2016-04-17 12:07 - 142482544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-06-14 16:54 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-06-14 11:41 - 2016-06-01 22:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxy Palace Online Casino 2016-06-14 11:41 - 2016-05-09 08:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lucky 247 2016-06-14 11:41 - 2016-04-30 08:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoWild Casino 2016-06-14 11:41 - 2016-04-21 07:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wild Jackpots 2016-06-14 11:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Common Files\System 2016-06-14 11:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-06-14 11:19 - 2016-04-17 00:53 - 00000000 ___DC C:\WINDOWS\Panther 2016-06-13 21:58 - 2016-04-22 16:58 - 00000000 ____D C:\Users\Kamali\AppData\Local\VirtualStore 2016-06-13 00:23 - 2016-06-04 20:34 - 00000000 ____D C:\Users\Kamali\AppData\Local\SquirrelTemp 2016-06-11 12:57 - 2015-10-30 09:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2016-06-11 12:57 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-04-18 06:47 - 2016-04-18 06:51 - 0000115 _____ () C:\Users\Kamali\AppData\Roaming\LogFile.txt 2016-07-04 14:56 - 2016-07-04 14:56 - 0005346 _____ () C:\Users\Kamali\AppData\Local\recently-used.xbel 2016-04-18 08:52 - 2016-07-03 17:30 - 0007601 _____ () C:\Users\Kamali\AppData\Local\Resmon.ResmonCfg 2016-06-14 08:18 - 2016-06-14 08:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Einige Dateien in TEMP: ==================== C:\Users\Kamali\AppData\Local\Temp\GPU-Z.exe C:\Users\Kamali\AppData\Local\Temp\gpuz_installer.exe C:\Users\Kamali\AppData\Local\Temp\raptr_stub.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-06-29 17:04 ==================== Ende von FRST.txt ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 02-07-2016 durchgeführt von Kamali (2016-07-08 00:12:40) Gestartet von C:\Users\Kamali\Downloads Windows 10 Pro Version 1511 (X64) (2016-04-16 22:09:30) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2200811352-4099371485-2068763530-500 - Administrator - Enabled) DefaultAccount (S-1-5-21-2200811352-4099371485-2068763530-503 - Limited - Disabled) Gast (S-1-5-21-2200811352-4099371485-2068763530-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2200811352-4099371485-2068763530-1003 - Limited - Enabled) Kamali (S-1-5-21-2200811352-4099371485-2068763530-1001 - Administrator - Enabled) => C:\Users\Kamali Paimonah (S-1-5-21-2200811352-4099371485-2068763530-1006 - Limited - Enabled) => C:\Users\Paimonah ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 16.02 (HKLM-x32\...\7-Zip) (Version: 16.02 - Igor Pavlov) 7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.192 - Adobe Systems Incorporated) Adobe Flash Player 22 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 22.0.0.192 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\{C1F3739C-D31D-4062-8788-29261C4A2A68}) (Version: 12.2.4.194 - Adobe Systems, Inc) AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Catalyst Control Center Next Localization BR (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.18 - Piriform) FastStone Image Viewer 5.5 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.5 - FastStone Soft) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) Golden Riviera Casino (HKLM-x32\...\goldenriviera) (Version: 16.11.1.4250 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.106 - Google Inc.) Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden GoWild Casino (HKLM-x32\...\gowild) (Version: 16.10.3.2234 - ) GPL Ghostscript (HKLM\...\GPL Ghostscript 9.19) (Version: 9.19 - Artifex Software Inc.) HD Tune Pro 5.60 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) Innkeeper (HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\Innkeeper) (Version: 0.2.9 - Curse Inc.) Java 8 Update 92 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418092F0}) (Version: 8.0.920.14 - Oracle Corporation) Java 8 Update 92 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218092F0}) (Version: 8.0.920.14 - Oracle Corporation) Logitech Gaming Software 8.83 (HKLM\...\Logitech Gaming Software) (Version: 8.83.85 - Logitech Inc.) Lucky 247 (HKLM-x32\...\luckytwofourseven) (Version: 16.10.3.2234 - ) Lucky Nugget Casino (HKLM-x32\...\luckynugget) (Version: 16.11.1.4250 - ) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Mummys Gold Casino (HKLM-x32\...\mummysgold) (Version: 16.11.1.4250 - ) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.14.2 - OBS Project) OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation) paint.net (HKLM\...\{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C}) (Version: 4.0.9 - dotPDN LLC) PDF24 Creator 7.8.1 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7829 - Realtek Semiconductor Corp.) River Belle Online Casino (HKLM-x32\...\riverbelle) (Version: 16.11.1.4250 - ) Roxy Palace Online Casino (HKLM-x32\...\roxypalace) (Version: 16.10.3.2234 - ) Royal Vegas (HKLM-x32\...\royalvegas) (Version: 16.10.3.2234 - ) Scribus 1.4.6 (64bit) (HKLM\...\Scribus 1.4.6) (Version: 1.4.6 - The Scribus Team) Spin Palace Casino (HKLM-x32\...\spinpalace) (Version: 16.11.1.4250 - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Tinypic 3.18 (HKLM-x32\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.18 - E. Fiedler) Wild Jack Kasino (HKLM-x32\...\wildjack) (Version: 16.10.3.2234 - ) Wild Jackpots (HKLM-x32\...\wildjackpotsviper) (Version: 16.10.3.2234 - ) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Kamali\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {078C0ABB-02A9-47F9-9A09-556372F5CBF4} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-03-21] (Advanced Micro Devices, Inc.) Task: {3E8B6BA9-0310-4006-82EE-7B5DBB962AF7} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {64F7414A-9088-4344-8271-DF089B02EB59} - System32\Tasks\Driver Booster SkipUAC (Kamali) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {6A2D3425-D05A-4691-9EA7-9B1C1A15F590} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-26] (Google Inc.) Task: {A4BF4758-0997-40BD-A9EA-19C0D4780714} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {AC2BC0F5-3CE4-4395-AF6A-EF730D846E80} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-26] (Google Inc.) Task: {C8F65639-2F24-4D9A-BA85-1584E5CFD21C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-06-01] (Piriform Ltd) Task: {D6EE02AD-575B-437F-BC46-9553E275CCBE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {D970AEBC-2DB4-4A5D-840B-9B989F1F9C64} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-06-30] (Adobe Systems Incorporated) Task: {EBE58079-243C-4544-A924-CFD79439239F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {F8C8A136-B675-4647-B39A-F58B707B79FE} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {FDFCD949-A2B5-4FE0-8BDF-13ABD3901E86} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_22_0_0_192_pepper.exe [2016-06-17] (Adobe Systems Incorporated) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_22_0_0_192_pepper.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-04-17 00:47 - 2016-04-17 00:47 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-17 00:47 - 2016-04-17 00:47 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-05-24 06:05 - 2016-05-24 06:05 - 00959168 _____ () C:\Users\Kamali\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2016-02-13 19:02 - 2016-02-13 19:02 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-05-10 21:05 - 2016-04-23 06:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-06-14 20:36 - 2016-05-28 05:59 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-06-14 20:36 - 2016-05-28 05:53 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-06-14 20:36 - 2016-05-28 05:54 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-06-14 20:36 - 2016-05-28 05:56 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-04-29 00:49 - 2016-04-29 00:49 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-04-29 00:49 - 2016-04-29 00:49 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2016-06-26 00:55 - 2016-06-23 15:26 - 02336584 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.106\libglesv2.dll 2016-06-26 00:55 - 2016-06-23 15:25 - 00107336 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.106\libegl.dll 2016-07-04 14:01 - 2016-05-23 09:25 - 00075264 _____ () C:\Program Files (x86)\PDF24\zlib.dll 2016-07-04 14:01 - 2016-05-23 09:24 - 00053248 _____ () C:\Program Files (x86)\PDF24\OperationUI.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\0411dd.com -> 0411dd.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\0511zfhl.com -> 0511zfhl.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\0632qyw.com -> 0632qyw.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\1001movie.com -> 1001movie.com Da befinden sich 6128 mehr Seiten. ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2016-06-30 13:13 - 2016-06-30 13:13 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kamali\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{6a49ed97-5049-4ccb-845d-37b3e5263a02}.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\...\StartupApproved\Run: => "StartCN" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-2200811352-4099371485-2068763530-1001\...\StartupApproved\Run: => "Innkeeper" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [TCP Query User{757BE37D-495A-46D1-8F82-86049C99BB7B}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{7D592FDD-C608-4A59-BC1B-A7E35E74A493}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{97D3CDCD-4BFA-4972-8B03-A222515A000B}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{AFD295A0-236D-42AC-8D23-5A383D5F5CD9}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [{356FB27C-6512-49DE-B755-946E6A59C6AD}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2016.SP1\WNt600x64\RpcSandraSrv.exe FirewallRules: [{D8FEA2C5-4AE7-407A-A915-38889F544B35}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{6DF5433D-86F6-4F8A-A9AE-BAE98659F8A9}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{ABF51A50-6E77-47A0-AD15-7803450F374D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{144AB3FF-3C74-4BBC-8679-432504EF4757}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{B3527B6A-D720-4E4D-9493-FB261289D4DC}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe FirewallRules: [{E105CF82-3B48-4304-BCC9-1A4428C97A09}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe FirewallRules: [{AEA9E202-F7A1-46DD-80D2-79351358A1FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Wiederherstellungspunkte ========================= 26-06-2016 00:45:07 SiSoftware Sandra Lite 27-06-2016 19:32:57 Removed Microsoft Silverlight 07-07-2016 07:44:35 Geplanter Prüfpunkt ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (07/07/2016 07:44:44 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (07/03/2016 01:16:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: ShellExperienceHost.exe, Version: 10.0.10586.306, Zeitstempel: 0x571afaa5 Name des fehlerhaften Moduls: StartUI.dll, Version: 10.0.10586.306, Zeitstempel: 0x571af976 Ausnahmecode: 0xc000041d Fehleroffset: 0x0000000000298cf8 ID des fehlerhaften Prozesses: 0xdd8 Startzeit der fehlerhaften Anwendung: 0xShellExperienceHost.exe0 Pfad der fehlerhaften Anwendung: ShellExperienceHost.exe1 Pfad des fehlerhaften Moduls: ShellExperienceHost.exe2 Berichtskennung: ShellExperienceHost.exe3 Vollständiger Name des fehlerhaften Pakets: ShellExperienceHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ShellExperienceHost.exe5 Error: (07/03/2016 01:16:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: ShellExperienceHost.exe, Version: 10.0.10586.306, Zeitstempel: 0x571afaa5 Name des fehlerhaften Moduls: StartUI.dll, Version: 10.0.10586.306, Zeitstempel: 0x571af976 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000298cf8 ID des fehlerhaften Prozesses: 0xdd8 Startzeit der fehlerhaften Anwendung: 0xShellExperienceHost.exe0 Pfad der fehlerhaften Anwendung: ShellExperienceHost.exe1 Pfad des fehlerhaften Moduls: ShellExperienceHost.exe2 Berichtskennung: ShellExperienceHost.exe3 Vollständiger Name des fehlerhaften Pakets: ShellExperienceHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ShellExperienceHost.exe5 Error: (07/03/2016 09:23:16 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Kamali-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/03/2016 09:23:16 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Kamali-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023174. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/03/2016 09:23:16 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Kamali-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/03/2016 09:23:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: backgroundTaskHost.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d8f0 Name des fehlerhaften Moduls: Cortana.BackgroundTask.dll, Version: 0.0.0.0, Zeitstempel: 0x57491660 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000046ab5 ID des fehlerhaften Prozesses: 0x132c Startzeit der fehlerhaften Anwendung: 0xbackgroundTaskHost.exe0 Pfad der fehlerhaften Anwendung: backgroundTaskHost.exe1 Pfad des fehlerhaften Moduls: backgroundTaskHost.exe2 Berichtskennung: backgroundTaskHost.exe3 Vollständiger Name des fehlerhaften Pakets: backgroundTaskHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: backgroundTaskHost.exe5 Error: (07/02/2016 09:40:24 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: ShellExperienceHost.exe, Version: 10.0.10586.306, Zeitstempel: 0x571afaa5 Name des fehlerhaften Moduls: StartUI.dll, Version: 10.0.10586.306, Zeitstempel: 0x571af976 Ausnahmecode: 0xc000041d Fehleroffset: 0x0000000000298cf8 ID des fehlerhaften Prozesses: 0xe74 Startzeit der fehlerhaften Anwendung: 0xShellExperienceHost.exe0 Pfad der fehlerhaften Anwendung: ShellExperienceHost.exe1 Pfad des fehlerhaften Moduls: ShellExperienceHost.exe2 Berichtskennung: ShellExperienceHost.exe3 Vollständiger Name des fehlerhaften Pakets: ShellExperienceHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ShellExperienceHost.exe5 Error: (07/02/2016 09:40:20 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: ShellExperienceHost.exe, Version: 10.0.10586.306, Zeitstempel: 0x571afaa5 Name des fehlerhaften Moduls: StartUI.dll, Version: 10.0.10586.306, Zeitstempel: 0x571af976 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000298cf8 ID des fehlerhaften Prozesses: 0xe74 Startzeit der fehlerhaften Anwendung: 0xShellExperienceHost.exe0 Pfad der fehlerhaften Anwendung: ShellExperienceHost.exe1 Pfad des fehlerhaften Moduls: ShellExperienceHost.exe2 Berichtskennung: ShellExperienceHost.exe3 Vollständiger Name des fehlerhaften Pakets: ShellExperienceHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ShellExperienceHost.exe5 Error: (07/01/2016 11:08:09 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: casinogame.exe, Version: 25.0.0.12127, Zeitstempel: 0x509b9a1d Name des fehlerhaften Moduls: atiumdva.dll_unloaded, Version: 8.14.10.533, Zeitstempel: 0x56d0af80 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0044be5f ID des fehlerhaften Prozesses: 0x1b34 Startzeit der fehlerhaften Anwendung: 0xcasinogame.exe0 Pfad der fehlerhaften Anwendung: casinogame.exe1 Pfad des fehlerhaften Moduls: casinogame.exe2 Berichtskennung: casinogame.exe3 Vollständiger Name des fehlerhaften Pakets: casinogame.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: casinogame.exe5 Systemfehler: ============= Error: (07/08/2016 12:04:45 AM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {784E29F4-5EBE-4279-9948-1E8FE941646D} Error: (07/08/2016 12:01:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 = Das System kann die angegebene Datei nicht finden. Error: (07/08/2016 12:01:28 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 07.07.2016 um 23:58:50 unerwartet heruntergefahren. Error: (07/07/2016 11:48:36 PM) (Source: DCOM) (EventID: 10016) (User: Kamali-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Kamali-PCKamaliS-1-5-21-2200811352-4099371485-2068763530-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (07/07/2016 11:48:35 PM) (Source: DCOM) (EventID: 10016) (User: Kamali-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Kamali-PCKamaliS-1-5-21-2200811352-4099371485-2068763530-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (07/07/2016 11:18:35 PM) (Source: DCOM) (EventID: 10016) (User: Kamali-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Kamali-PCKamaliS-1-5-21-2200811352-4099371485-2068763530-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (07/07/2016 11:18:35 PM) (Source: DCOM) (EventID: 10016) (User: Kamali-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Kamali-PCKamaliS-1-5-21-2200811352-4099371485-2068763530-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (07/07/2016 11:03:35 PM) (Source: DCOM) (EventID: 10016) (User: Kamali-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Kamali-PCKamaliS-1-5-21-2200811352-4099371485-2068763530-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (07/07/2016 11:03:35 PM) (Source: DCOM) (EventID: 10016) (User: Kamali-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Kamali-PCKamaliS-1-5-21-2200811352-4099371485-2068763530-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (07/07/2016 10:03:37 PM) (Source: DCOM) (EventID: 10016) (User: Kamali-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Kamali-PCKamaliS-1-5-21-2200811352-4099371485-2068763530-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 CodeIntegrity: =================================== Date: 2016-07-04 15:25:30.668 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 15:25:30.655 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 15:25:30.631 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 13:51:51.665 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 13:51:51.649 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 13:51:51.622 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 13:00:46.264 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 13:00:46.249 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-04 13:00:46.201 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-03 09:19:43.895 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz Prozentuale Nutzung des RAM: 38% Installierter physikalischer RAM: 4094.91 MB Verfügbarer physikalischer RAM: 2535.5 MB Summe virtueller Speicher: 4862.91 MB Verfügbarer virtueller Speicher: 3307.88 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:931.07 GB) (Free:881.08 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: ED752067) Partition 1: (Active) - (Size=931.1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=449 MB) - (Type=27) ==================== Ende von Addition.txt ============================ |
09.07.2016, 09:15 | #2 |
| Ständige Soundschleifen und Standbilder bei Spielen Kann mir hier denn keiner helfen?
__________________Ich habe mich extra in diesem Forum angemeldet wegen diesem Problem und habe mir Hilfe erhofft. Seit 7 Tagen keinerlei Hilfe-Stellung. Nur verweise in anderen Unterforen die dann auch wieder falsch waren. Ich hoffe hier bin ich richtig mit meinem Problem. Oder benötigt ihr vorerst noch andere Infos? Ist nicht alles aus den Log's ersichtlich? Bitte laßt mich nicht dumm sterben ;-) Ich könnte echt |
13.07.2016, 15:12 | #3 |
| Ständige Soundschleifen und Standbilder bei Spielen /push
__________________ |
16.07.2016, 07:58 | #4 |
| Ständige Soundschleifen und Standbilder bei Spielen /push |
28.07.2016, 15:10 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständige Soundschleifen und Standbilder bei Spielen Hinweise nicht gelesen? Wenn du nach drei Tagen keine AW bekommst, kannst du im Erinnerungsthread eine Erinnerung absetzen. Wenn du dir selbst auf dein Thema antwortest verschwindet dein Anliegen aus der Helferansicht der offenen (unbeantworteten) Themen und so bekommste folgerichtig später eine AW. Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Ständige Soundschleifen und Standbilder bei Spielen |
administrator, adobe flash player, cpu, defender, desktop, dnsapi.dll, driver booster, explorer, flash player, google, helper, launch, malwarebytes, microsoft, neu, ordner, pdf, problem, prozesse, scan, services.exe, software, svchost.exe, system, taskmanager, temp, visual c++ 2015, windows, winlogon.exe |