|
Log-Analyse und Auswertung: Laptop Windows 10 - ziemlich vollgemüllt!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.09.2016, 07:05 | #1 |
| Laptop Windows 10 - ziemlich vollgemüllt! Hallo Trojaner, ein Bekannter von mir, bat mich, mal nach seinem Laptop zu sehen, der u.a. beim Hochfahren, Spielen, Öffnen von Programmen sehr bzw. ziemlich langsam ist. Das Betriebssystem wurde von Win 7 auf Win 10 "upgegraded" (was bei dem Laptop vielleicht ein Fehler war). Beim durchstöbern der installierten Programme und Googlen der Funde war einiges dabei, was sehr gut Malware sein könnte, darum bitte ich euch mir zu helfen. Außerdem sehr merkwürdig ist, dass seit einem Windows Update vom 03.09.16 im Revo Uninstaller der 03.09.16 bei vielen Programmen als Installationsdatum angegeben ist, obwohl diese deutlich später installiert wurden. Also ließ ich erstmal ESET durchlaufen - ~15 infizierte Dateien, Toolbars und evt. Trojaner! - in die Quarantäne o.ä. verschoben habe ich nichts, das überlass' ich Euch. Die Logs der Scans von ESET und FRST sind beigefügt: FRST.txt Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016 durchgeführt von MM (Administrator) auf SECURITY-SERVIC (04-09-2016 07:47:56) Gestartet von C:\Users\MM\Desktop Geladene Profile: MM (Verfügbare Profile: MM) Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_3.6.23981.0_x64__8wekyb3d8bbwe\Music.UI.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor) HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-16] (NVIDIA Corporation) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-07-16] (Microsoft Corporation) HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.) HKLM-x32\...\Run: [] => [X] Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\MM\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29494400 2016-07-13] (Skype Technologies S.A.) HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd) HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2857248 2016-08-23] (Valve Corporation) HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\Explorer: [NoLogOff] 0 HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\MountPoints2: {60a0c8d8-c050-11e4-8957-1c7508363078} - "E:\SETUP.EXE" AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [175368 2015-12-16] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWoW64\nvinit.dll => C:\WINDOWS\SysWoW64\nvinit.dll [153208 2015-12-16] (NVIDIA Corporation) ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: 127.0.0.1 secure.tune-up.com Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{ed735836-3afc-4360-8600-80e0ea9c88ea}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q= HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q= HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q= HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q= SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {D7D76D1E-238F-460F-B08C-8DD2E10C0ECB} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {F41EB89B-2688-4F5A-897C-7E40717AB1E9} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {FDA48F1C-BDD5-4B3B-ADB0-534AA741BAD1} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {FF1D2452-E87F-4192-A05E-3F5811BC9DA9} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-06-30] (Sun Microsystems, Inc.) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default FF DefaultSearchEngine: Google Default FF SearchEngineOrder.1: FF SelectedSearchEngine: Bing FF Homepage: about:home FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2011-05-04] (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation) FF Plugin-x32: @thrixxx.com/WebLaunch -> C:\Program Files (x86)\thriXXX\WebLaunch\Binaries\npWebLaunch.dll [2006-08-09] ( ) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-09-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1669543924-1338975548-1525228061-1001: @thrixxx.com/WebLaunch -> C:\Program Files (x86)\thriXXX\WebLaunch\Binaries\npWebLaunch.dll [2006-08-09] ( ) FF Plugin HKU\S-1-5-21-1669543924-1338975548-1525228061-1001: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll [2013-05-05] (The Happy Cloud) FF Plugin HKU\S-1-5-21-1669543924-1338975548-1525228061-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei] FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2011-05-04] (Sun Microsystems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2011-09-05] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npWebLaunch.dll [2006-08-09] ( ) FF SearchPlugin: C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\searchplugins\google-default.xml [2015-06-04] FF SearchPlugin: C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\searchplugins\youtube.xml [2015-12-21] FF Extension: (Adblock Plus) - C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28] FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25] FF Extension: (DVDVideoSoft YouTube MP3 and Video Download) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2014-12-15] [ist nicht signiert] FF HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\extensions\cliqz@cliqz.com => nicht gefunden Chrome: ======= CHR Profile: C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-14] CHR Extension: (Google Docs) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-14] CHR Extension: (Google Drive) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-14] CHR Extension: (YouTube) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-14] CHR Extension: (Google-Suche) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-14] CHR Extension: (Google Tabellen) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-14] CHR Extension: (Avira Browserschutz) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-06-14] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-14] CHR Extension: (Google Wallet) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-14] CHR Extension: (Google Mail) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-14] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25] Opera: ======= StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1392648 2016-07-26] () R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-16] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Datei ist nicht signiert] S4 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-16] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-16] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-16] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-02-01] (Electronic Arts) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1310448 2016-08-14] (Overwolf LTD) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-17] (TeamViewer GmbH) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7585280 2016-07-16] (Broadcom Corporation) S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30352 2015-03-01] (Disc Soft Ltd) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2013-11-16] (Huawei Technologies Co., Ltd.) [Datei ist nicht signiert] S3 ew_hwusbdev; C:\Windows\System32\DRIVERS\ew_hwusbdev.sys [117248 2013-11-16] (Huawei Technologies Co., Ltd.) [Datei ist nicht signiert] S3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [121600 2013-11-16] (Huawei Technologies Co., Ltd.) [Datei ist nicht signiert] S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-16] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-12-16] (NVIDIA Corporation) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) U3 idsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-09-04 07:47 - 2016-09-04 07:51 - 00021458 _____ C:\Users\MM\Desktop\FRST.txt 2016-09-04 07:47 - 2016-09-04 07:47 - 00000000 ____D C:\FRST 2016-09-04 00:52 - 2016-09-04 00:52 - 03955544 _____ (Crystal Dew World ) C:\Users\MM\Downloads\CrystalDiskInfo7_0_3-en.exe 2016-09-04 00:26 - 2016-09-04 07:46 - 02397696 _____ (Farbar) C:\Users\MM\Desktop\FRST64.exe 2016-09-04 00:08 - 2016-09-04 00:08 - 01875208 _____ (Malwarebytes ) C:\Users\MM\Downloads\mbae-setup-1.08.1.2572.exe 2016-09-04 00:08 - 2016-09-04 00:08 - 00563880 _____ C:\Users\MM\Downloads\noscript-2.9.0.14.zip 2016-09-04 00:01 - 2016-09-04 00:02 - 05660313 _____ (Swearware) C:\Users\MM\Downloads\ComboFix.exe 2016-09-04 00:00 - 2016-09-04 00:01 - 16563352 _____ (Malwarebytes Corp.) C:\Users\MM\Downloads\mbar-1.09.3.1001.exe 2016-09-03 23:01 - 2016-09-03 23:02 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-09-03 23:01 - 2016-09-03 23:01 - 00001179 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\Program Files (x86)\ESET 2016-09-03 23:01 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-09-03 23:01 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-09-03 23:01 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-09-03 22:59 - 2016-09-03 23:01 - 02870984 _____ (ESET) C:\Users\MM\Downloads\esetsmartinstaller_deu.exe 2016-09-03 22:59 - 2016-09-03 23:00 - 22851472 _____ (Malwarebytes ) C:\Users\MM\Downloads\mbam-setup-2.2.1.1043.exe 2016-09-03 22:37 - 2016-09-04 00:30 - 00000000 ____D C:\Users\MM\Desktop\RevoUninstaller_Portable 2016-09-03 22:36 - 2016-09-03 22:36 - 09256439 _____ C:\Users\MM\Downloads\RevoUninstaller_Portable_2.0.zip 2016-09-03 22:18 - 2016-09-03 22:18 - 00000000 ____D C:\ProgramData\AirportMania 2016-09-03 22:09 - 2016-09-03 22:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-09-03 21:05 - 2016-09-03 21:10 - 00000000 ____D C:\AdwCleaner 2016-09-03 21:05 - 2016-09-03 21:05 - 03826240 _____ C:\Users\MM\Desktop\AdwCleaner_6.010.exe 2016-09-03 21:05 - 2016-09-03 21:05 - 01610560 _____ (Malwarebytes) C:\Users\MM\Desktop\JRT.exe 2016-09-03 20:55 - 2016-09-03 20:55 - 00206966 _____ C:\Users\MM\Documents\cc_20160903_205536-03.09.2016.reg 2016-09-03 10:59 - 2016-09-03 20:43 - 00000000 ____D C:\Users\MM\AppData\Local\ConnectedDevicesPlatform 2016-09-03 10:57 - 2016-09-03 10:57 - 00000020 ___SH C:\Users\MM\ntuser.ini 2016-09-03 05:01 - 2016-09-03 20:57 - 00000000 ___DC C:\WINDOWS\Panther 2016-09-03 04:58 - 2016-09-03 04:58 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2016-09-03 04:57 - 2016-09-03 04:58 - 00000000 ____D C:\Windows.old 2016-09-03 04:56 - 2016-09-03 04:56 - 23682560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 22571008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 22218808 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 20965240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 19423232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 19418624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 13433856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 13080576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 12345344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 12174336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL 2016-09-03 04:56 - 2016-09-03 04:56 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL 2016-09-03 04:56 - 2016-09-03 04:56 - 09128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 08124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 07814488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 07624192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 05622600 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 04612096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 04130944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 03893376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 03299328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2016-09-03 04:56 - 2016-09-03 04:56 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2016-09-03 04:56 - 2016-09-03 04:56 - 02745224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 02264064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 02257248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 02251432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2016-09-03 04:56 - 2016-09-03 04:56 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-09-03 04:56 - 2016-09-03 04:56 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01906176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01780736 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01595904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01469120 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01453992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01377008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01349120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-09-03 04:56 - 2016-09-03 04:56 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01316352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01163696 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 01106944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01066096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01046976 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-09-03 04:56 - 2016-09-03 04:56 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00955008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00885832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00590952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00450400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00381760 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00321280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL 2016-09-03 04:56 - 2016-09-03 04:56 - 00224096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00204288 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS 2016-09-03 04:56 - 2016-09-03 04:56 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00151224 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00141824 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2016-09-03 04:56 - 2016-09-03 04:56 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL 2016-09-03 04:56 - 2016-09-03 04:56 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL 2016-09-03 04:56 - 2016-09-03 04:56 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe 2016-09-03 04:56 - 2016-09-03 04:56 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx 2016-09-03 04:56 - 2016-09-03 04:56 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx 2016-09-03 04:56 - 2016-09-03 04:56 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 17187328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 05722312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 03245056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 03116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 02913104 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02846208 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02711040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02680832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02422784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02315264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02289664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 02143232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01875456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01694200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01430200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01279328 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01264912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01099608 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 01062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01014784 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 01006080 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00987992 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00942424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi 2016-09-03 04:55 - 2016-09-03 04:55 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00852824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00846552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00807776 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00681312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00658776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00587968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00509784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00361096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL 2016-09-03 04:55 - 2016-09-03 04:55 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00077664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00050880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys 2016-09-03 04:55 - 2016-09-03 04:55 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2016-09-03 04:55 - 2016-09-03 04:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2016-09-03 04:55 - 2016-09-03 04:55 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL 2016-09-03 04:55 - 2016-09-03 04:55 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL 2016-09-03 04:55 - 2016-09-03 04:55 - 00000000 ____D C:\ProgramData\USOShared 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Vorlagen 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Startmenü 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2016-09-03 04:51 - 2016-09-03 04:51 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2016-09-03 04:48 - 2016-09-03 04:52 - 00007623 _____ C:\WINDOWS\diagwrn.xml 2016-09-03 04:48 - 2016-09-03 04:52 - 00007623 _____ C:\WINDOWS\diagerr.xml 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\system32\msmq 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\system32\BestPractices 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files\Reference Assemblies 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files\MSBuild 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\inetpub 2016-09-03 04:44 - 2016-05-25 15:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2016-09-03 04:44 - 2016-05-25 15:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2016-09-03 04:44 - 2016-05-25 15:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2016-09-03 04:44 - 2016-05-25 12:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2016-09-03 04:44 - 2016-05-25 12:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2016-09-03 04:44 - 2016-05-25 12:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2016-09-03 04:43 - 2016-09-03 04:43 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys 2016-09-03 04:39 - 2016-09-03 22:26 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-09-03 04:39 - 2016-09-03 09:29 - 00003626 _____ C:\WINDOWS\System32\Tasks\FileAdvisorCheck 2016-09-03 04:39 - 2016-09-03 04:39 - 00003662 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-09-03 04:39 - 2016-09-03 04:39 - 00003438 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-09-03 04:39 - 2016-09-03 04:39 - 00003142 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-09-03 04:39 - 2016-09-03 04:39 - 00003110 _____ C:\WINDOWS\System32\Tasks\Java Update Scheduler 2016-09-03 04:39 - 2016-09-03 04:39 - 00003100 _____ C:\WINDOWS\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2016-09-03 04:39 - 2016-09-03 04:39 - 00002978 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2016-09-03 04:39 - 2016-09-03 04:39 - 00002818 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task 2016-09-03 04:39 - 2016-09-03 04:39 - 00002702 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Deskjet 2540 series 2016-09-03 04:39 - 2016-09-03 04:39 - 00002672 _____ C:\WINDOWS\System32\Tasks\FileAdvisorUpdate 2016-09-03 04:39 - 2016-09-03 04:39 - 00002668 _____ C:\WINDOWS\System32\Tasks\Overwolf Updater Task 2016-09-03 04:39 - 2016-09-03 04:39 - 00002484 _____ C:\WINDOWS\System32\Tasks\{32D6F56B-7833-457F-9718-457689953BF1} 2016-09-03 04:39 - 2016-09-03 04:39 - 00002472 _____ C:\WINDOWS\System32\Tasks\{F3EA1D55-FD45-431E-B847-554D475A3F6C} 2016-09-03 04:39 - 2016-09-03 04:39 - 00002306 _____ C:\WINDOWS\System32\Tasks\{067A521F-C03C-4F1A-A33C-E4B44A20E46A} 2016-09-03 04:39 - 2016-09-03 04:39 - 00002212 _____ C:\WINDOWS\System32\Tasks\{46FDBF1B-2F00-4BEB-910C-C50DB49D1A4E} 2016-09-03 04:39 - 2016-09-03 04:39 - 00002198 _____ C:\WINDOWS\System32\Tasks\{71547766-FA89-4004-9203-F3F410888270} 2016-09-03 04:39 - 2016-09-03 04:39 - 00002164 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2016-09-03 04:39 - 2016-09-03 04:39 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD 2016-09-03 04:39 - 2016-09-03 04:39 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform 2016-09-03 04:27 - 2016-09-03 04:27 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs 2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs 2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2016-09-03 04:17 - 2016-09-03 04:17 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines 2016-09-03 04:16 - 2016-09-03 04:28 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2016-09-03 04:14 - 2016-09-03 21:11 - 00000000 ____D C:\Users\MM 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Vorlagen 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Startmenü 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Netzwerkumgebung 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Lokale Einstellungen 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Eigene Dateien 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Druckumgebung 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Documents\Eigene Videos 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Documents\Eigene Musik 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Documents\Eigene Bilder 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\AppData\Local\Verlauf 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\AppData\Local\Anwendungsdaten 2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Anwendungsdaten 2016-09-03 04:11 - 2016-09-03 20:46 - 01792596 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-09-03 04:11 - 2016-09-03 04:11 - 01604148 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2016-09-03 04:07 - 2016-09-03 04:28 - 00000000 ____D C:\WINDOWS\SysWOW64\NV 2016-09-03 04:07 - 2016-09-03 04:28 - 00000000 ____D C:\WINDOWS\system32\NV 2016-09-03 04:07 - 2016-09-03 04:18 - 00000000 ____D C:\ProgramData\NVIDIA 2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____D C:\Program Files\Synaptics 2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____D C:\Program Files\Realtek 2016-09-03 04:07 - 2015-12-16 16:54 - 06359672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2016-09-03 04:07 - 2015-12-16 16:54 - 02985264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2016-09-03 04:07 - 2015-12-16 16:54 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2016-09-03 04:07 - 2015-12-16 16:54 - 01256240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2016-09-03 04:07 - 2015-12-16 16:54 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2016-09-03 04:07 - 2015-12-16 16:54 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2016-09-03 04:07 - 2015-12-16 16:54 - 00075056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2016-09-03 04:07 - 2015-12-16 16:54 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2016-09-03 04:07 - 2015-12-16 16:49 - 06090019 _____ C:\WINDOWS\system32\nvcoproc.bin 2016-09-03 04:06 - 2016-09-03 04:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-09-03 04:06 - 2016-07-16 13:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2016-09-03 04:05 - 2016-09-03 04:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-09-03 04:05 - 2016-09-03 04:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-09-03 04:03 - 2016-09-04 07:45 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-09-03 04:03 - 2016-09-03 10:55 - 00298928 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-09-03 04:03 - 2016-09-03 04:03 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2016-08-31 12:14 - 2016-08-31 12:16 - 00000000 ___HD C:\$SysReset 2016-08-24 09:54 - 2016-08-14 09:41 - 00000000 ____D C:\Users\MM\Desktop\VA-TOP100_Single_Charts_vom_12-08-2016-CannaPower 2016-08-24 09:49 - 2016-08-24 09:52 - 201710165 _____ C:\Users\MM\Downloads\VA-TOP100_Single_Charts_vom_12-08-2016_02-CannaPower.zip 2016-08-24 09:46 - 2016-08-24 09:48 - 199614156 _____ C:\Users\MM\Downloads\VA-TOP100_Single_Charts_vom_12-08-2016_01-CannaPower.zip 2016-08-24 09:46 - 2016-08-24 09:46 - 08834489 _____ C:\Users\MM\Downloads\VA-TOP100_Single_Charts_vom_12-08-2016_05-CannaPower.zip 2016-08-09 21:34 - 2016-08-09 21:34 - 00084648 _____ C:\Users\MM\Documents\businessplan(2).pdf 2016-08-05 19:24 - 2016-08-05 19:24 - 00000000 ____D C:\Users\MM\Documents\League of Legends 2016-08-05 19:23 - 2016-08-05 19:23 - 00000000 ____D C:\Users\MM\AppData\Roaming\LolClient 2016-08-05 18:13 - 2016-08-05 18:13 - 00000000 ____D C:\ProgramData\Riot Games 2016-08-05 13:05 - 2016-09-03 04:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2016-08-05 13:05 - 2016-08-05 18:05 - 00000000 ____D C:\rads 2016-08-05 13:05 - 2016-08-05 13:05 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-08-05 13:05 - 2016-08-05 13:05 - 00000000 ____D C:\Riot Games 2016-08-05 13:05 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2016-08-05 13:05 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2016-08-05 13:05 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2016-08-05 13:02 - 2016-08-05 13:05 - 00000000 ____D C:\Users\MM\AppData\Roaming\Riot Games 2016-08-05 13:01 - 2016-08-05 13:02 - 31001328 _____ (Riot Games) C:\Users\MM\Documents\LeagueofLegends_EUW_Installer_2016_05_13.exe ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-09-04 07:39 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps 2016-09-04 07:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-09-04 03:35 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\appcompat 2016-09-03 22:57 - 2010-08-30 11:03 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-09-03 22:55 - 2010-08-30 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GameZone 2016-09-03 22:55 - 2010-08-30 11:12 - 00000000 ____D C:\Program Files (x86)\Acer GameZone 2016-09-03 22:55 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-09-03 22:54 - 2014-09-02 10:16 - 00000000 ____D C:\Program Files (x86)\Softland 2016-09-03 22:54 - 2014-08-15 08:45 - 00000000 ____D C:\ProgramData\Package Cache 2016-09-03 22:52 - 2014-09-02 10:16 - 00000000 ____D C:\Program Files\Softland 2016-09-03 22:51 - 2012-11-12 11:30 - 00000000 ____D C:\Users\MM\AppData\Local\Cyberlink 2016-09-03 22:51 - 2012-11-12 11:29 - 00000000 ____D C:\Users\MM\AppData\Roaming\CyberLink 2016-09-03 22:50 - 2012-11-12 11:29 - 00000000 ____D C:\ProgramData\CyberLink 2016-09-03 22:48 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF 2016-09-03 22:45 - 2016-01-19 10:18 - 00000000 ____D C:\Program Files (x86)\Steam 2016-09-03 22:42 - 2016-07-16 13:47 - 00000000 __RHD C:\Users\Public\Libraries 2016-09-03 22:33 - 2014-05-01 00:34 - 00000000 ____D C:\ProgramData\Avira 2016-09-03 22:26 - 2016-07-16 08:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI 2016-09-03 22:26 - 2012-06-08 19:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-09-03 22:25 - 2014-05-01 00:41 - 00000000 ____D C:\Users\MM\AppData\Roaming\Avira 2016-09-03 22:23 - 2015-02-09 12:52 - 00000000 ____D C:\ProgramData\Apple 2016-09-03 22:23 - 2015-02-09 12:52 - 00000000 ____D C:\Program Files\Common Files\Apple 2016-09-03 22:18 - 2010-11-16 21:24 - 00000000 ____D C:\ProgramData\Temp 2016-09-03 22:17 - 2014-04-06 14:56 - 00000000 ____D C:\Users\MM\Documents\My Games 2016-09-03 22:10 - 2011-03-08 02:14 - 00504488 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2016-09-03 21:39 - 2011-03-14 17:28 - 00000000 ____D C:\Users\MM\AppData\Local\ElevatedDiagnostics 2016-09-03 21:09 - 2015-06-02 12:48 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2016-09-03 21:09 - 2015-06-02 12:47 - 00000000 ____D C:\Users\MM\AppData\Roaming\Lavasoft 2016-09-03 21:09 - 2015-06-02 12:47 - 00000000 ____D C:\ProgramData\Lavasoft 2016-09-03 20:46 - 2016-07-17 00:51 - 00630074 _____ C:\WINDOWS\system32\perfh007.dat 2016-09-03 20:46 - 2016-07-17 00:51 - 00136552 _____ C:\WINDOWS\system32\perfc007.dat 2016-09-03 11:39 - 2015-12-20 07:16 - 00000000 ____D C:\Users\MM\AppData\Local\Packages 2016-09-03 11:15 - 2015-12-20 07:28 - 00002427 _____ C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-09-03 11:15 - 2015-12-20 07:28 - 00000000 ___RD C:\Users\MM\OneDrive 2016-09-03 11:02 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2016-09-03 10:59 - 2015-12-20 07:16 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-09-03 09:29 - 2014-02-28 09:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor 2016-09-03 09:29 - 2014-02-28 09:31 - 00000000 ____D C:\Program Files (x86)\File Type Advisor 2016-09-03 07:11 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-09-03 05:01 - 2016-07-16 13:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\dsc 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\et-EE 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\es-MX 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\en-GB 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Provisioning 2016-09-03 04:55 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\USOPrivate 2016-09-03 04:54 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache 2016-09-03 04:53 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows NT 2016-09-03 04:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2016-09-03 04:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Registration 2016-09-03 04:47 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\MUI 2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2016-09-03 04:45 - 2016-07-16 13:44 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb 2016-09-03 04:45 - 2016-07-16 13:44 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb 2016-09-03 04:45 - 2016-07-16 13:44 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb 2016-09-03 04:45 - 2016-07-16 13:44 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb 2016-09-03 04:45 - 2016-07-16 13:44 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe 2016-09-03 04:45 - 2016-07-16 13:44 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll 2016-09-03 04:45 - 2016-07-16 13:44 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof 2016-09-03 04:45 - 2016-07-16 13:43 - 01414144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys 2016-09-03 04:45 - 2016-07-16 13:43 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb 2016-09-03 04:45 - 2016-07-16 13:43 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb 2016-09-03 04:45 - 2016-07-16 13:43 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb 2016-09-03 04:45 - 2016-07-16 13:43 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe 2016-09-03 04:45 - 2016-07-16 13:43 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb 2016-09-03 04:45 - 2016-07-16 13:43 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe 2016-09-03 04:45 - 2016-07-16 13:43 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe 2016-09-03 04:45 - 2016-07-16 13:43 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe 2016-09-03 04:45 - 2016-07-16 13:43 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe 2016-09-03 04:45 - 2016-07-16 13:43 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe 2016-09-03 04:45 - 2016-07-16 13:43 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof 2016-09-03 04:45 - 2016-07-16 13:43 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll 2016-09-03 04:45 - 2016-07-16 13:43 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll 2016-09-03 04:39 - 2016-07-16 13:47 - 00000000 __RSD C:\WINDOWS\Media 2016-09-03 04:39 - 2015-12-19 18:42 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat 2016-09-03 04:28 - 2016-08-01 16:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emergency 2016 2016-09-03 04:28 - 2016-04-06 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft Classic 2016-09-03 04:28 - 2016-01-25 17:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2016-09-03 04:28 - 2016-01-19 10:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2016-09-03 04:28 - 2016-01-15 14:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-09-03 04:28 - 2015-10-30 20:44 - 00000000 ____D C:\WINDOWS\ShellNew 2016-09-03 04:28 - 2015-06-02 12:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4 2016-09-03 04:28 - 2015-03-01 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-09-03 04:28 - 2015-02-09 12:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2016-09-03 04:28 - 2014-12-16 13:48 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Happy Cloud 2016-09-03 04:28 - 2014-03-30 20:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ITHau.Faktura 2016-09-03 04:28 - 2014-02-28 09:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free M4a to MP3 Converter 2016-09-03 04:28 - 2013-08-03 00:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-09-03 04:28 - 2013-08-02 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2016-09-03 04:28 - 2012-12-30 14:55 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2016-09-03 04:28 - 2012-12-30 13:35 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-09-03 04:28 - 2012-12-30 13:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-09-03 04:28 - 2012-12-02 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MixMeister 2016-09-03 04:28 - 2012-11-12 11:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt 2016-09-03 04:28 - 2012-03-17 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player Classic - Home Cinema 2016-09-03 04:28 - 2011-08-15 16:11 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2016-09-03 04:28 - 2011-03-08 20:01 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.2 2016-09-03 04:28 - 2010-11-16 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Media Maker 9 2016-09-03 04:28 - 2010-11-16 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live 2016-09-03 04:28 - 2010-11-16 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye webcam 2016-09-03 04:28 - 2010-11-16 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem 2016-09-03 04:28 - 2010-08-30 11:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Backup Manager 2016-09-03 04:28 - 2010-08-30 11:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer 2016-09-03 04:28 - 2010-08-30 11:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2016-09-03 04:27 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-09-03 04:27 - 2015-10-30 08:28 - 00000000 ____D C:\Users\Default.migrated 2016-09-03 04:21 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2016-09-03 04:21 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-09-03 04:21 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\spool 2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\IME 2016-09-03 04:20 - 2012-04-08 21:22 - 00000000 ____D C:\WINDOWS\system32\SPReview 2016-09-03 04:20 - 2012-01-30 21:19 - 00000000 ____D C:\WINDOWS\system32\EventProviders 2016-09-03 04:18 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\schemas 2016-09-03 04:18 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2016-09-03 04:18 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-09-03 04:18 - 2016-03-29 20:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2016-09-03 04:18 - 2015-12-19 14:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-09-03 04:18 - 2015-06-02 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2016-09-03 04:18 - 2013-11-14 22:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft 2016-09-03 04:18 - 2012-12-30 14:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com 2016-09-03 04:18 - 2010-08-30 11:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EgisTec 2016-09-03 04:18 - 2009-07-14 09:44 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-09-03 04:17 - 2016-07-16 13:47 - 00000000 __SHD C:\Program Files\Windows Sidebar 2016-09-03 04:17 - 2016-07-16 13:47 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2016-09-03 04:17 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-09-03 04:17 - 2010-08-30 11:01 - 00000000 ____D C:\Program Files (x86)\Intel 2016-09-03 04:17 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games 2016-09-03 04:15 - 2016-01-25 17:24 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2016-09-03 04:10 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-09-03 04:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog 2016-09-03 04:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\MiracastView 2016-09-03 04:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-09-03 04:07 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Help 2016-09-03 03:18 - 2016-07-17 01:55 - 00000000 ___HD C:\$WINDOWS.~BT 2016-09-03 03:00 - 2015-06-14 23:43 - 00001150 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-09-03 02:59 - 2013-11-17 18:21 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-09-03 02:00 - 2015-06-14 23:43 - 00001146 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-09-02 11:15 - 2016-08-01 17:14 - 00004096 _____ C:\Users\Public\Documents\0000D07B.LCS 2016-09-02 08:32 - 2014-03-02 09:31 - 00000000 ____D C:\Users\MM\AppData\Roaming\FileAdvisor 2016-08-30 16:29 - 2011-02-26 23:09 - 00000000 ____D C:\ProgramData\boost_interprocess 2016-08-29 21:50 - 2015-07-05 13:51 - 00000000 ____D C:\Users\MM\AppData\Roaming\Skype 2016-08-29 14:19 - 2016-04-07 10:07 - 00000000 ____D C:\Users\MM\Desktop\SSA 2016-08-26 07:43 - 2016-07-16 13:49 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-08-26 07:43 - 2016-07-16 13:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-08-17 17:24 - 2016-01-25 17:23 - 00000000 ____D C:\Program Files (x86)\Overwolf 2016-08-15 19:23 - 2016-08-01 17:14 - 00000000 ____D C:\Users\MM\AppData\Roaming\Promotion Software GmbH 2016-08-15 13:49 - 2014-03-12 21:49 - 00000000 ____D C:\ProgramData\Electronic Arts 2016-08-15 13:42 - 2016-02-23 11:12 - 00000000 ____D C:\Users\MM\AppData\Local\CrashDumps 2016-08-15 13:40 - 2014-06-29 08:02 - 00000000 ____D C:\Users\MM\Desktop\Neuer Ordner (3) 2016-08-10 07:26 - 2013-11-17 11:16 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-08-10 07:15 - 2011-06-06 10:19 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-08-09 16:34 - 2015-12-19 14:22 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-08-09 16:34 - 2015-07-05 13:50 - 00000000 ____D C:\ProgramData\Skype 2016-08-08 23:03 - 2015-06-14 23:44 - 00002268 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2011-03-14 17:06 - 2011-03-14 17:06 - 32742184 _____ () C:\Program Files\Virtualdj_home_v7.0.3.msi 2015-12-23 17:17 - 2015-12-23 17:17 - 0000218 _____ () C:\Users\MM\AppData\Local\recently-used.xbel 2016-03-29 20:04 - 2016-03-29 20:04 - 0000057 _____ () C:\ProgramData\Ament.ini 2010-08-30 11:12 - 2010-03-03 00:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe Einige Dateien in TEMP: ==================== C:\Users\MM\AppData\Local\Temp\avgnt.exe C:\Users\MM\AppData\Local\Temp\libeay32.dll C:\Users\MM\AppData\Local\Temp\msvcr120.dll C:\Users\MM\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-09-03 04:02 ==================== Ende von FRST.txt ============================ |
04.09.2016, 07:05 | #2 |
| Laptop Windows 10 - ziemlich vollgemüllt! Addition.txt
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 31-08-2016 durchgeführt von MM (04-09-2016 07:53:53) Gestartet von C:\Users\MM\Desktop Windows 10 Home Version 1607 (X64) (2016-09-03 02:53:46) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1669543924-1338975548-1525228061-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1669543924-1338975548-1525228061-503 - Limited - Disabled) Gast (S-1-5-21-1669543924-1338975548-1525228061-501 - Limited - Disabled) MM (S-1-5-21-1669543924-1338975548-1525228061-1001 - Administrator - Enabled) => C:\Users\MM ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) µTorrent (HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\uTorrent) (Version: 3.4.6.42094 - BitTorrent Inc.) Acer Backup Manager (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems) Acer Crystal Eye webcam (HKLM-x32\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 1.0.4.5 - Liteon) Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3005 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0707.2010 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Ad-Aware Web Companion (x32 Version: 2.0.1013.2086 - Lavasoft) Hidden Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Adobe Reader X (10.1.1) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.1 - Adobe Systems Incorporated) Age of Wonders III (HKLM\...\Steam App 226840) (Version: - Triumph Studios) Backup Manager Basic (x32 Version: 2.0.0.68 - NewTech Infosystems) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform) EMERGENCY 2016 (HKLM\...\EMERGENCY 2016) (Version: - Sixteen Tons Entertainment) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) File Type Advisor 1.4 (HKLM-x32\...\File Type Advisor_is1) (Version: - filetypeadvisor.com) Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media) GEAR driver installer for AMD64 and Intel EM64T (HKLM\...\{50CBBEC7-1010-41C5-8718-A1A6FEDD9C3A}) (Version: 2.003.1 - GEAR Software, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Happy Cloud Client (HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\HappyCloud) (Version: 4.28 - Happy Cloud, Inc.) Heroes of Hellas (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}) (Version: - Oberon Media) HP Deskjet 2540 series - Grundlegende Software für das Gerät (HKLM\...\{333E22D7-9F56-4482-A13C-1B9D35B9D641}) (Version: 32.2.188.47710 - Hewlett-Packard Co.) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated) Inkscape 0.91 (HKLM-x32\...\Inkscape) (Version: 0.91 - ) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2182 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) ITHau.Faktura 2013.11.20 (HKLM-x32\...\Freeware Faktura) (Version: 2013.11.20 - IT-Service Christian Hau) iTunes (HKLM\...\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.) Java(TM) 6 Update 26 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216018FF}) (Version: 6.0.260 - Sun Microsystems, Inc.) Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 4.0.14 - Acer Inc.) LavasoftTcpService (x32 Version: 2.3.4.2 - Lavasoft) Hidden League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games) League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version: - Oberon Media) Microsoft Office Excel Viewer (HKLM-x32\...\{95120000-003F-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Business 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Mozilla Firefox 48.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 48.0.2 (x86 de)) (Version: 48.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 48.0.2.6079 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyWinLocker (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.212.0 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8939 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8939 - NTI Corporation) Hidden NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5997 - NVIDIA Corporation) NVIDIA Grafiktreiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) OpenOffice.org 3.2 (HKLM-x32\...\{192A107E-C6B9-41B9-BDBF-38E3AA226054}) (Version: 3.2.9483 - OpenOffice.org) Opera Stable 20.0.1387.91 (HKLM-x32\...\Opera 20.0.1387.91) (Version: 20.0.1387.91 - Opera Software ASA) Origin (HKLM-x32\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.97.31.0 - Overwolf Ltd.) Poker Pop (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}) (Version: - Oberon Media) ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.14 - ProtectDisc Software GmbH) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30122 - Realtek Semiconductor Corp.) Screensaver for POS (x32 Version: 1.0.0 - Storecast GmbH, Germany) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden Shredder (Version: 2.0.8.3 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.3 - Egis Technology Inc.) Hidden Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation) Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.) Songr (HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Songr) (Version: 2.0.2378 - Xamasoft) Spin & Win (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}) (Version: - Oberon Media) Stardew Valley (HKLM-x32\...\Steam App 413150) (Version: - ConcernedApe) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Studie zur Verbesserung von HP Deskjet 2540 series (HKLM\...\{98802D44-4885-41EA-9BA8-96A117ECF223}) (Version: 32.2.188.47710 - Hewlett-Packard Co.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.39052 - TeamViewer) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) thriXXX 3DSexVilla2-153.001 (HKLM-x32\...\3DSexVilla2-153.001) (Version: - thriXXX Software GmbH) thriXXX WebLaunch (HKLM-x32\...\thriXXX WebLaunch) (Version: 1.0 - thriXXX) TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3010.1 - TuneUp Software) Hidden Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) VirtualDJ Home FREE (HKLM-x32\...\{19192A84-6172-4312-A661-D8F9A34585AB}) (Version: 7.0.4.1 - Atomix Productions) VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions) Web Companion (HKLM-x32\...\{d6e3fcc2-3043-4fa9-ac4a-5bd9145d1a9e}) (Version: 2.1.1265.2535 - Lavasoft) Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3004 - Acer Incorporated) Windows Live Anmelde-Assistent (HKLM-x32\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileCoAuth.exe (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {08798CFB-DDF9-4444-B732-299ECDA8A973} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08] (Sun Microsystems, Inc.) Task: {0A9D94A7-228F-4E54-ACFC-640C6FFD6008} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {19639003-C77D-4B18-A332-8DD151EC2CEE} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {1EF41258-2361-4435-B500-B774E7C9A65B} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {21AE865E-E468-4C66-867A-FF05FB272454} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {25E443D9-FDDD-4FF6-A6AD-851434DBDE77} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-08-14] (Overwolf LTD) Task: {271C0386-D54D-4A89-B34C-25C482A17FF9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-14] (Google Inc.) Task: {27EC5ADC-D1B8-4257-81FF-FB7B2866CD41} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {2A962F0F-2974-404E-A78F-4467E9EEB137} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {2C256425-F33F-4FFC-BBC1-55568D4C0405} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.) Task: {2C6CE008-C8D9-43A4-BE6E-1577ECF7BDEE} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {30E277BB-AD19-4955-AF85-60BD9730D343} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd) Task: {3510A4A3-A209-42AA-9D63-ED2A2BB7397A} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {3619DDEB-01D8-4AEF-BA75-2F893C3AB41D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {3B438481-7716-48C7-8F26-CDDCB32B72DB} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {4100373C-75FD-4D2B-BB49-7BF3EB34E54E} - System32\Tasks\{32D6F56B-7833-457F-9718-457689953BF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.1.0.179.367/de/abandoninstall?source=lightinstaller&page=tsOptions&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;notincluded Task: {57331538-E388-41D4-AEB2-0B9A6B2B9B01} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {5F20C597-0BD8-48E1-95E0-0871A15CA3E8} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {66411273-9DF4-47B4-9B75-944299189921} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {69B6444B-BFF6-4CA3-9D1A-400E43C66C05} - System32\Tasks\{F3EA1D55-FD45-431E-B847-554D475A3F6C} => Firefox.exe hxxp://ui.skype.com/ui/0/4.1.0.179.367/de/abandoninstall?source=lightinstaller&page=tsMain&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;notincluded Task: {6B03AB12-F40F-4417-A139-84B6A70EB610} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {73F9B103-3EE7-4B05-8D4E-40F0CCC962A9} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-08-17] (Microsoft Corporation) Task: {757B2DC7-58A5-4F77-A711-5C3493D90F88} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {7B07EB25-D90B-42A0-8AEC-82F95314ADA2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {82B45B36-6237-4F43-975D-C6ECC37A25CE} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-09-05] (filetypeadvisor.com ) Task: {868BFDBC-C5C8-4363-B770-658518AA278E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {8AD66453-92BC-475A-A5FB-2AE8237E961C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-08-10] (Microsoft Corporation) Task: {8F158D86-9AFB-455C-B00B-7E929DD83D81} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {9192218C-A91F-4FE3-874B-0F3A6EB8F85C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {921F0D5F-50B5-4D5F-81C5-FF2278365DC2} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {97696FC3-36DC-4F2D-B4EC-72E2A847B77D} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {9C26BBD8-C3A0-42F9-BB27-9BA1C4665722} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {9EBAFC53-E906-47E6-BDAC-F007A73F0184} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-14] (Google Inc.) Task: {A8CB5879-61D0-4488-936D-BE917FB72D36} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {B22B4BB8-C7B5-4905-96DE-FECC25B22D28} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Keine Datei <==== ACHTUNG Task: {B3143ED4-CA6B-42CB-BA0E-5808C049D0B3} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-09-04] (File Type Advisor) Task: {B3FC0613-3EB0-44A7-B33F-D2CF847E1726} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {B7BB9DB2-5AB7-4FC7-869F-07EA042B77FB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {BBC27A08-F6A9-4DEC-8CAB-19D9FEA5533D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {C5A4AAF9-FCA8-444B-B0D4-716823EA71DD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {CB45435D-F51C-461E-8BCC-59BADDF06F66} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {D3E12E90-512B-4A37-A984-24A94839BC0B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12] (Adobe Systems Incorporated) Task: {DA0A6D3E-E0BB-46D6-B33A-A2BAE3B5823B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {DD7DE760-6056-4A7D-8D5A-1BB224CB9308} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {DEB4E9AC-5C50-4B77-AA52-4EA4F3B5EA0B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {E59AE448-17AF-4A00-A1CF-965288D9856C} - System32\Tasks\{71547766-FA89-4004-9203-F3F410888270} => launchwinapp.exe hxxp://ui.skype.com/ui/0/7.18.85.112/de/abandoninstall?page=tsMain Task: {E5C357C7-9935-49C6-B5D1-5EAB992C1C2C} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {EAE8F0A1-96E1-41C2-9C75-DFD74D91AE69} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {EB87C302-8830-44E2-93D8-A80193AE26A6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {EC9FE113-BB82-47AC-84D1-8A6BB184763C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {ED3227B2-FB7B-44AF-8BCC-8D020B07C8A6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {F26141CE-E1E5-4FCB-AC75-5709BF949E68} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {F40D7047-305C-44D2-8853-4B75B1B5BBF9} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {FAD93FFC-0011-4077-BC6B-199970C92E59} - System32\Tasks\{46FDBF1B-2F00-4BEB-910C-C50DB49D1A4E} => pcalua.exe -a F:\install_flash_player.exe -d F:\ Task: {FAEA0EDC-C25E-4820-866B-01CBC081F2C1} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {FFA0B3AE-525E-48CE-BAAB-D4B166BB9631} - System32\Tasks\{067A521F-C03C-4F1A-A33C-E4B44A20E46A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=4.1.0.179.367&LastError=12007 (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\Online Help.lnk -> hxxp://www.virtualdj.com/wiki/ Shortcut: C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\www.virtualdj.com.lnk -> hxxp://www.virtualdj.com/ ShortcutWithArgument: C:\Users\MM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX ShortcutWithArgument: C:\Users\MM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-09-03 04:07 - 2015-12-16 16:54 - 00126256 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-01-19 20:43 - 2015-12-16 18:59 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-09-03 11:11 - 2016-09-03 11:11 - 01864384 _____ () C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll 2016-07-16 13:42 - 2016-07-16 13:42 - 00130048 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll 2016-07-16 13:42 - 2016-07-16 13:42 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-07-16 13:43 - 2016-07-16 13:43 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2012-11-27 00:54 - 2012-11-27 00:54 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-11-16 18:55 - 2015-11-16 18:55 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2016-07-16 13:43 - 2016-07-17 00:56 - 09761280 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-07-16 13:43 - 2016-07-17 00:56 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-07-16 13:43 - 2016-07-17 00:56 - 01033728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 02438144 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-09-03 04:56 - 2016-09-03 04:56 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-09-03 11:09 - 2016-09-03 11:11 - 01383616 _____ () C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\ClientTelemetry.dll 2016-09-03 11:14 - 2016-09-03 11:14 - 00118976 _____ () C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncViews.dll 2010-08-30 11:45 - 2009-05-20 08:02 - 00072200 _____ () C:\Program Files (x86)\Launch Manager\CdDirIo.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Temp:798A3728 [250] AlternateDataStreams: C:\ProgramData\Temp:93EB7685 [300] AlternateDataStreams: C:\ProgramData\Temp:CDFF58FE [288] AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D [129] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\localhost -> localhost ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2012-03-17 20:34 - 00000860 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 secure.tune-up.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupreg: mwlDaemon => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe MSCONFIG\startupreg: SuiteTray => "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" HKLM\...\StartupApproved\Run32: => "BlueStacks Agent" HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\StartupApproved\Run: => "Skype" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{6596FFDC-7FE7-4A88-99D7-CEDE81883B23}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{CF9A20C3-7AEE-4DD0-A679-8DB0365286BD}] => (Allow) C:\Program Files (x86)\Emergency 2016\bin\x64r\emergency5.exe FirewallRules: [{714C21CD-17FE-4CD8-9F59-FA025C9A809B}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{0A40B483-B8E3-4C58-A04B-5BD93A6EDDB9}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{1014C0D5-FA60-4922-B908-15D2DB542D74}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{CF8DAE82-421F-46D4-B713-864CACCA616F}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{667A5E1D-6809-4005-A7B9-254AA2922B95}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{807D104E-5101-4BC4-8AAB-23F2FFD958D1}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{7E0F7427-E995-4066-B266-6794AFBF1A57}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{721EAAC1-6054-45BC-BF64-03F36E43E75A}] => (Allow) LPort=5357 FirewallRules: [{62463BA9-2908-4B90-82F6-B9FA037E6713}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\DeviceSetup.exe FirewallRules: [{016D1AAD-3A92-48D8-A128-563CC3690F1F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe FirewallRules: [{CC2D7DF0-87FF-42E9-A6A7-ED4D5DF90B31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe FirewallRules: [{2BC12A8C-3FC2-4977-9078-0CD61E1CCCAD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{E572ABC1-5480-4244-AB96-229DA15AB318}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{942517F2-A473-45CE-A158-87548B98D89A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{7AF68B21-F7F0-4379-B953-6C9E0366243B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{78BC8548-9507-4383-8321-90EB37A206D2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{AEF1267F-DA14-4368-AB68-934EB232BB89}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{A1F13B90-8332-41A4-8476-D2BBB33AE57A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{884A71EA-1E95-4D62-8CA6-1570CB0DF30C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{2A7DBD6F-9195-4BA6-80C9-A6B57F5D92F7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{ED1FAC01-D73E-428E-AA2A-321DDC5385C7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{FA9D4E50-78A6-47E7-AC89-686D33D0B7EA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{07334558-0CE9-4375-8824-0E926CCEB3BB}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe FirewallRules: [{1C081AE0-33AF-4820-A52B-52E202294289}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [TCP Query User{E9B1FF08-3465-4876-954B-AED6B5619F4B}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe FirewallRules: [UDP Query User{24A8CEFF-1F6A-46B7-A191-2D18AE69EA24}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe FirewallRules: [{721C6183-1324-4A22-9B14-24E9B67EC4DE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{8F5C15AF-01C6-48F5-97FA-516117AFC5B4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{FD539E59-0CD6-4D10-8F96-76C71E22B8D7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{FF349834-7C8E-4C58-BFB4-A6223374B91A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{CD42AD52-6DA8-4B24-A34C-B42ACA41E6A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3.exe FirewallRules: [{86FE8263-C1BB-44A1-887D-8689D2C7AC9F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3.exe FirewallRules: [{46F9961A-9F91-4CC3-A653-E7DD525F2894}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3_Debug.exe FirewallRules: [{A1343DB2-FEC5-4987-8F7E-6002969D6F99}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3_Debug.exe FirewallRules: [TCP Query User{B5422021-7111-4D66-A230-53CD8289C8E8}C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe FirewallRules: [UDP Query User{5F4935CE-1088-4854-8DC1-3264984699D3}C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe FirewallRules: [{583A2132-6DF1-4C37-9DD2-9A020780ACEA}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{A5829E81-A004-4615-912C-B8A414B8D4C8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{C42C582A-1D60-4292-9596-43AA9BD33C17}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mm\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{98A86413-AA27-4E95-BE4F-EBFA14B73550}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mm\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{3D2328B1-B57E-41BC-BD92-90AEA5560A0D}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\mm\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{21A0030D-3525-4B99-ADB0-76614F31F258}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\mm\appdata\local\akamai\netsession_win.exe FirewallRules: [{BEBC9B44-5B9D-4E6A-83A9-F05173DB8BF8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{778EE8DB-9C04-48DD-86CB-B556CC39DC63}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{CDC6CDFB-9778-429B-8C24-C5DD0842BED6}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{E40CEEAB-906B-4F3D-BD4F-66F1952071E4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{0F5C6FFE-E656-4C7E-9848-8F20F1906F32}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{243B8960-0A22-41AB-9824-7A965547A55B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{923D60F3-37AA-496E-9837-1BAADA79D34F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [TCP Query User{0DFB7521-7449-4C58-A473-DAE8A9A216FF}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{AFCED6E2-75A3-4919-896E-725D07656E46}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{4298EABA-E23C-49E0-927A-14ACA0A9C35D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3Launcher.exe FirewallRules: [{43372A2D-1579-4702-98F8-ADA4732B70F3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3Launcher.exe FirewallRules: [{C6F3AAA2-C8BE-4A42-8E57-3F9A984A38B4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{43063579-5942-44A3-BD66-10203A6DB15F}] => (Allow) LPort=49187 FirewallRules: [{5A8031EF-62B5-413E-952C-BB32193AB3E5}] => (Allow) LPort=5000 FirewallRules: [{2191F477-D6BE-4DC0-8EA1-4DA0D3E8EF2F}] => (Block) C:\WINDOWS\systemapps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe ==================== Wiederherstellungspunkte ========================= 03-09-2016 07:10:17 Windows Update ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (09/04/2016 07:53:49 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (09/04/2016 07:53:49 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_74bc87d3d22d9abe.manifest. Error: (09/04/2016 07:50:53 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\messenger\wlcsdk.exe". Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (09/04/2016 07:49:03 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (09/04/2016 07:46:10 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\eset\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_74bc87d3d22d9abe.manifest. Error: (09/04/2016 04:09:13 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (09/04/2016 04:09:12 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_74bc87d3d22d9abe.manifest. Error: (09/04/2016 04:08:23 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\messenger\wlcsdk.exe". Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (09/04/2016 04:08:02 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (09/04/2016 04:05:52 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Systemfehler: ============= Error: (09/04/2016 02:03:50 AM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT) Description: Fehler "1053" in DCOM, als der Dienst "gupdate" mit den Argumenten "/comsvc" gestartet wurde, um den folgenden Server zu verwenden: {4EB61BAC-A3B6-4760-9581-655041EF4D69} Error: (09/04/2016 02:03:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (09/04/2016 02:03:50 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update-Dienst (gupdate) erreicht. Error: (09/03/2016 11:03:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (09/03/2016 11:03:58 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\MM\AppData\Local\Temp\ehdrv.sys Error: (09/03/2016 11:03:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (09/03/2016 11:03:57 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\MM\AppData\Local\Temp\ehdrv.sys Error: (09/03/2016 11:03:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (09/03/2016 11:03:57 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\MM\AppData\Local\Temp\ehdrv.sys Error: (09/03/2016 11:02:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. CodeIntegrity: =================================== Date: 2016-09-04 06:37:59.020 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:59.018 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:59.015 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:59.005 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:59.003 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:59.000 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:58.990 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:58.988 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:58.986 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-04 06:37:58.976 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3 CPU M 380 @ 2.53GHz Prozentuale Nutzung des RAM: 50% Installierter physikalischer RAM: 3766.7 MB Verfügbarer physikalischer RAM: 1867.48 MB Summe virtueller Speicher: 7606.7 MB Verfügbarer virtueller Speicher: 5356.28 MB ==================== Laufwerke ================================ Drive c: (Acer) (Fixed) (Total:452.22 GB) (Free:100.06 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 40731DA7) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=452.2 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=450 MB) - (Type=27) ==================== Ende von Addition.txt ============================ |
06.10.2016, 10:08 | #3 |
/// TB-Ausbilder /// Anleitungs-Guru | Laptop Windows 10 - ziemlich vollgemüllt!Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...
Hinweis: Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst. Los geht's: Schritt 1 Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ |
Themen zu Laptop Windows 10 - ziemlich vollgemüllt! |
adobe, akamai, avg, defender, explorer, fehler, firefox, flash player, google, home, homepage, infizierte, langsam, launch, malware, mozilla, mp3, prozesse, realtek, registry, revo uninstaller, rundll, services.exe, svchost.exe, teamspeak, trojaner, windows, windowsapps |