|
Log-Analyse und Auswertung: rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.12.2016, 05:07 | #1 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... hi, hab das gefühl, dass mal wieder irgendwas mit meinem laptop nicht stimmt. heißt meine maus bewegt sich teilweise nicht wie sie soll, vor allem wenn ich zocke, meine festplatte ist teilweise zu 100% ausgelastet, auch wenn ich absolut nichts mache, mein lüfter arbeitet durchgehend auf hochtouren einige programme funktionieren nicht richtig, u.a. frooty loops und ich habe einiege anwendungen die mir suspekt ercheinen. weiß allerdings nicht sicher, ob ich nicht mal wieder nur paranoia hab^^ mein antivirenprogramm findet nichts, aber ich hab FRST ausgeführt. hab schon öfter versucht damit meinen pc wieder auf vordermann zu bringen. selbst mit anleitung und vielen stunden zeitaufwand, hat beim letzten mal nur system komplett platt machen mit DBAN geholfen. da aber das kostenlose win 10 update nicht mehr verfügbar ist, muss dieses mal fast eine andere lösung her. Anhang 79427 Anhang 79428 Anhang 79428 |
02.12.2016, 09:43 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......+++ WICHTIGER HINWEIS +++ Während der Analyse und Bereinigung nimmst du KEINERLEI Änderungen auf eigene Faust vor, d.h. du installierst oder deinstallierst keine Software ohne Absprache. Auch veränderst du keine Systemeinstellungen, solange wir deinen Fall bearbeiten. Änderungen, Installationen oder Deinstallationen machst du AUSSCHLIESSLICH nur auf Anweisung! Es wird erforderlich sein, deinen Virenscanner zu deaktivieren und in bestimmten Fällen auch zu deinstallieren, damit vernünftig bereinigt werden kann. Dein System ist daher erst wenn wir hier fertig sind wieder für den alltäglichen Gebrauch wie surfen oder mailen von mir freigegeben. Gelesen und verstanden? Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
02.12.2016, 21:12 | #3 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... ok verstanden. danke für die schnelle antwort.
__________________ |
02.12.2016, 23:12 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... Gut. Poste bitte die Logs in CODE-Tags. Weil als Anhang ist das zu umständlich für uns. Danke.
__________________ Logfiles bitte immer in CODE-Tags posten |
17.12.2016, 18:55 | #5 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 17-12-2016 durchgeführt von Dragonfly (17-12-2016 18:50:23) Gestartet von C:\Users\Dragonfly\Desktop Windows 10 Home Version 1511 (X64) (2016-07-29 23:35:10) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-614321186-1851163967-905647231-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-614321186-1851163967-905647231-503 - Limited - Disabled) Dragonfly (S-1-5-21-614321186-1851163967-905647231-1000 - Administrator - Enabled) => C:\Users\Dragonfly Gast (S-1-5-21-614321186-1851163967-905647231-501 - Limited - Disabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov) Adblock Plus für IE (32-Bit- und 64-Bit) (HKLM\...\{588B7DD2-3480-4A89-A8F6-C6781CBFAD56}) (Version: 1.5 - Eyeo GmbH) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated) Ansel (Version: 376.33 - NVIDIA Corporation) Hidden ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.13 - Michael Tippach) Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.24.146 - Avira Operations GmbH & Co. KG) Avira Browser Safety (HKLM-x32\...\{9E10EA90-5E97-43B7-A246-FC7B4F5E9493}) (Version: 1.4.5.509 - Avira Operations GmbH & Co KG) Avira Connect (HKLM-x32\...\{707e8edf-9482-4417-ae39-c9b5fe605e87}) (Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Avira Connect (x32 Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Hidden CyberGhost 6 (HKLM\...\CyberGhost 6_is1) (Version: - CyberGhost S.R.L.) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel® PROSet/Wireless WiFi-Software (HKLM\...\{181BBF43-CA17-4E1A-A78D-81E67A57B8A4}) (Version: 15.02.0000.1258 - Intel Corporation) League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games) League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 3.15.0414.1 - Vimicro) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) NVIDIA GeForce Experience 3.2.0.96 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.2.0.96 - NVIDIA Corporation) NVIDIA Grafiktreiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.33 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.2.0.96 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.0.0.0 - NVIDIA Corporation) Hidden OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation) paint.net (HKLM\...\{A1D05314-DC32-4668-A97E-51060EC8BCCE}) (Version: 4.0.12 - dotPDN LLC) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.54.309.2012 - Realtek) SHIELD Streaming (Version: 7.1.0350 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.2.0.96 - NVIDIA Corporation) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.9.5 - Synaptics Incorporated) TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - ) Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows 10-Upgrade-Assistent (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17332 - Microsoft Corporation) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncApi64.dll => Keine (Der Dateneintrag hat 5 mehr Zeichen). ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {03E3805D-70CA-4B7A-88FE-B0A7ECB79FA0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {05E29CAC-D387-45CE-AE18-876241F8A74B} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {05FD0347-5C60-4CE5-8A7F-B13732DA5194} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {06DB1599-D4C7-4B21-AA32-2E8AFE0B60AA} - \Microsoft\Windows\Setup\gwx\rundetector -> Keine Datei <==== ACHTUNG Task: {07A62BCD-1B29-4E4E-910C-9C1FF254C0B6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-12-13] (NVIDIA Corporation) Task: {0848D22A-6161-4F11-A372-96D326C7D0BC} - System32\Tasks\Avira Browser Safety Updater Task => C:\Program Files (x86)\Avira\Browser Safety\AviraBrowserSafetyUpdater.exe [2015-03-11] (Avira Operations GmbH & Co. KG) Task: {1C2F7D9C-9FB4-4994-A225-EB858F74F810} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {1C60354A-D04E-4B4D-A8BE-2B2311FE4CBA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {217D3CCF-9F2D-4AD6-9EFF-6CEB68DE2301} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {248A8323-DA31-4222-96A2-5C6E6951F619} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {360EB739-EB12-49D4-BED1-E2021BDCA7C8} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {40EB871D-0140-44C8-9E7B-525645048C0D} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {40EF86BA-63C8-47D9-92DD-EB62496BCA26} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {41B5F213-92D6-4DFE-BECF-387CB2885869} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {4EB4A967-6105-45ED-B825-629CB423DE43} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {5A33D8D1-EC9E-41A2-BBB6-2420356CD89C} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {5B76CB83-A5F9-4E43-A63B-CBF8F67C41A5} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {62D21782-9F4C-4347-AAAF-5B1584328DBB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {6C2C580E-AB30-4A56-BDE3-4A963668C9F7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {6F0FA1DC-6A61-40FF-8E48-E2E6D9D1EC5B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {73EAD0A0-D4D3-42F2-AB00-158104EE5FD7} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {743B6204-186E-4EFE-B6D3-CBBAB15C84BE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {76A0339D-DA5E-4811-8264-0A64B9BD2138} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) Task: {80CC415F-3D85-42A5-85C4-DB80FCBBA889} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {8AE3FC4C-B5A2-47FE-B764-2FDC7CF41766} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {9029FA70-4FC2-41D9-869D-42A60F4662E4} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG Task: {97DFCF79-D4C3-48A8-AF2F-66F28E6A5A88} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {9E48F49C-D889-4CCC-9F07-C83816CEAB70} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A551C101-F597-4E55-BF05-A5B30B685C6D} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Keine Datei <==== ACHTUNG Task: {A9CB0F2A-7B83-4E5F-B717-2F669157731D} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {AAE922AD-510D-48AA-B0DD-3EF0C60C967D} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {B1146A5D-8566-4172-8D39-F826DA990E8D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-12-13] (NVIDIA Corporation) Task: {B4905C69-C0BC-47D8-BF0A-8CDFE0E01150} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BA55B185-6F05-44EC-B7C8-1EA0D065D486} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) Task: {BBF13E3A-451D-4AD4-8A81-DEB0933E1D5F} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {BDF6FE28-C910-4FDB-8906-5D062A256641} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C6B39C71-78D8-40D7-B9B0-36C543724A9A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {CA269936-C128-4BB7-A0E2-3D7E955C4A5F} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {CF619372-64D8-4ECB-9782-7FDE3D0F7FB6} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-12-13] (NVIDIA Corporation) Task: {DADC79E6-4947-4B1C-85F5-C40EC1D7560D} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {DD1D530A-1547-4E97-A2EC-C16E96BCC0D9} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {E454C27B-586C-4D8C-830C-459442B08B45} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {E9E6F3AA-93E4-4497-B237-0D4F75BC228E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {F4D8ABA4-EF6C-4378-A09F-5C0662B919E1} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F4F793B4-DA06-4683-BAA0-A6108BB1BFD7} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-10-07 14:20 - 2016-12-13 00:36 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-07 14:20 - 2016-12-13 00:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-11-09 01:24 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-09 01:24 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-04-27 06:17 - 2016-04-27 06:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-30 00:41 - 2016-07-30 00:41 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-11-09 01:25 - 2016-10-25 08:01 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll 2016-11-09 01:24 - 2016-10-25 05:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-09 01:24 - 2016-10-25 05:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-09 01:24 - 2016-10-25 05:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-09 01:24 - 2016-10-25 05:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-10-07 14:20 - 2016-12-13 00:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-07 14:20 - 2016-12-13 00:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-07 14:20 - 2016-12-13 00:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-07 14:20 - 2016-12-12 15:36 - 00525760 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-10-07 14:20 - 2016-12-12 15:36 - 00254008 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-10-07 14:20 - 2016-12-12 15:36 - 02808888 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-10-07 14:20 - 2016-12-12 15:36 - 00384568 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-10-07 14:20 - 2016-12-12 15:36 - 00447424 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node 2016-10-07 14:20 - 2016-12-12 15:36 - 00336832 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-10-07 14:20 - 2016-12-12 15:36 - 01003456 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node 2016-12-17 12:22 - 2016-12-12 15:36 - 00956472 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSDKAPINode.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-614321186-1851163967-905647231-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\Services: AMPPALR3 => 2 MSCONFIG\Services: Avira.ServiceHost => 2 MSCONFIG\Services: CG6Service => 2 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: EvtEng => 2 MSCONFIG\Services: Fax => 3 MSCONFIG\Services: IAStorDataMgrSvc => 2 MSCONFIG\Services: igfxCUIService1.0.0.0 => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: MyWiFiDHCPDNS => 3 MSCONFIG\Services: NvContainerLocalSystem => 2 MSCONFIG\Services: NvContainerNetworkService => 3 MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2 MSCONFIG\Services: NVIDIA Wireless Controller Service => 2 MSCONFIG\Services: RegSrvc => 2 MSCONFIG\Services: SynTPEnhService => 2 MSCONFIG\Services: TapiSrv => 3 MSCONFIG\Services: ZeroConfigService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Update Benachrichtigungsdienst.lnk => C:\Windows\pss\Update Benachrichtigungsdienst.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Preloader.lnk => C:\Windows\pss\WinZip Preloader.lnk.CommonStartup MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 6\CyberGhost.exe" /autostart /min MSCONFIG\startupreg: IntelPROSet => "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless HKLM\...\StartupApproved\StartupFolder: => "FAH.lnk" HKLM\...\StartupApproved\Run: => "SynLenovoGestureMgr" HKLM\...\StartupApproved\Run32: => "331BigDog" HKLM\...\StartupApproved\Run32: => "IAStorIcon" HKU\S-1-5-21-614321186-1851163967-905647231-1000\...\StartupApproved\Run: => "OneDrive" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [MSMQ-In-TCP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => LPort=808 FirewallRules: [{C42E09EE-544C-4058-B937-1E1C214C3179}] => C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{C13FCC8E-EA7C-4CF3-A00E-B34183437A33}] => C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{60B6505E-646C-49A7-AED9-61624970AD3A}] => C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{DDA3AE79-ADE7-4908-8334-C9DA3F39B5B1}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{9C9D448E-E0C6-4AB9-BDB5-B501BA9707ED}] => %systemroot%\system32\mqsvc.exe FirewallRules: [{3EB2F7F5-4D9C-4CC4-ABF8-4B5239F07BB4}] => %systemroot%\system32\mqsvc.exe FirewallRules: [{E07F3B24-CA0A-4C07-9E7B-AD478A9A1BCF}] => %systemroot%\system32\mqsvc.exe FirewallRules: [{66237BE3-1D77-47EA-AFD0-64530BFBE380}] => %systemroot%\system32\mqsvc.exe FirewallRules: [{EC4463D8-0CDF-4C6E-A8F3-ED1AECD22E7A}] => LPort=808 FirewallRules: [{AEB7ABE0-DE10-4AE4-8C08-394F31414C3A}] => C:\Fruity Loops Studio 8\FL_3GB.exe FirewallRules: [{A8A6276D-B39F-4DD2-9B64-5D280508E2D7}] => C:\Fruity Loops Studio 8\FL_3GB.exe FirewallRules: [{9A47A000-1124-4309-B74A-11D80A8C9F4D}] => C:\Fruity Loops Studio 8\FL_3GB.exe FirewallRules: [{20824275-6B98-4756-8CF8-4E37B4FABE0A}] => C:\Fruity Loops Studio 8\FL_3GB.exe FirewallRules: [{50977907-6F8B-483C-A95A-AC054B7F83B4}] => C:\Fruity Loops Studio 8\FL.exe FirewallRules: [{5439A04F-8DA4-4FBE-85AB-F1F50F10CE07}] => C:\Fruity Loops Studio 8\FL.exe FirewallRules: [{8043D186-EF79-453E-B207-B1C0304910A2}] => C:\Fruity Loops Studio 8\FL.exe FirewallRules: [{5133CF13-31A7-4A88-A181-89D2E1F3A29F}] => C:\Fruity Loops Studio 8\FL.exe FirewallRules: [{0921E149-3077-41B7-8F31-09C8F36CE06E}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{8C0DBFD5-D27C-4B56-BD72-D58BDC1C1516}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{CB643C00-DDAE-4619-9558-0BC84F1667E4}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{2B7A0D01-EA76-49D8-8281-243149DE9D24}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{B7A429B8-C176-4617-A67B-5D0F59DA53A3}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (12/17/2016 12:37:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00012f4b ID des fehlerhaften Prozesses: 0x1678 Startzeit der fehlerhaften Anwendung: 0x01d25859f3e47dad Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll Berichtskennung: a36d47d5-9f60-4e33-af47-ed7fcda8c113 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (12/17/2016 12:36:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00012f4b ID des fehlerhaften Prozesses: 0x1354 Startzeit der fehlerhaften Anwendung: 0x01d25859deef5288 Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll Berichtskennung: 0ea1f4ad-8817-4168-ae1f-fd70af18d25e Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (12/17/2016 12:16:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00012f4b ID des fehlerhaften Prozesses: 0x1448 Startzeit der fehlerhaften Anwendung: 0x01d2585700195c8d Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll Berichtskennung: 41d347ad-0001-488b-9852-9f2885c8213c Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (12/17/2016 12:14:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00012f4b ID des fehlerhaften Prozesses: 0x1728 Startzeit der fehlerhaften Anwendung: 0x01d25856ab785d8b Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll Berichtskennung: e309e262-cd45-4f67-9915-15b403e29093 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (12/16/2016 10:32:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC) Description: Bei der Aktivierung der App „Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/16/2016 10:32:22 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm LockApp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 13d8 Startzeit: 01d2573779f06a60 Beendigungszeit: 4294967295 Anwendungspfad: C:\WINDOWS\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe Berichts-ID: 7ff06158-c372-11e6-aef7-208984e59db3 Vollständiger Name des fehlerhaften Pakets: Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy Auf das fehlerhafte Paket bezogene Anwendungs-ID: WindowsDefaultLockScreen Error: (12/13/2016 12:03:39 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC) Description: Bei der Aktivierung der App „Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/11/2016 07:31:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: ShellExperienceHost.exe, Version: 10.0.10586.494, Zeitstempel: 0x5775e94c Name des fehlerhaften Moduls: twinapi.appcore.dll, Version: 10.0.10586.672, Zeitstempel: 0x580ef283 Ausnahmecode: 0xc000027b Fehleroffset: 0x000000000004b1c9 ID des fehlerhaften Prozesses: 0x318 Startzeit der fehlerhaften Anwendung: 0x01d253dc7a71494a Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Pfad des fehlerhaften Moduls: C:\Windows\System32\twinapi.appcore.dll Berichtskennung: 899a1405-ce81-403e-8920-787ca73c9839 Vollständiger Name des fehlerhaften Pakets: Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (12/11/2016 05:08:33 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm LockApp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1900 Startzeit: 01d2534b12d37acc Beendigungszeit: 4294967295 Anwendungspfad: C:\WINDOWS\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe Berichts-ID: 50dec74a-bf3e-11e6-aef5-208984e59db3 Vollständiger Name des fehlerhaften Pakets: Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy Auf das fehlerhafte Paket bezogene Anwendungs-ID: WindowsDefaultLockScreen Error: (12/07/2016 11:12:26 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Systemfehler: ============= Error: (12/17/2016 05:51:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Synchronisierungshost_3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/17/2016 12:34:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CG6Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (12/17/2016 12:34:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst CG6Service erreicht. Error: (12/17/2016 12:34:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira.ServiceHost erreicht. Error: (12/17/2016 12:34:11 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Error: (12/17/2016 12:33:00 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Benutzerdatenspeicher _3de5d erreicht. CodeIntegrity: =================================== Date: 2016-12-15 21:52:02.547 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-12-14 13:00:08.180 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-12-14 03:41:15.867 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-11 11:36:35.733 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-09 13:06:47.157 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-09 08:22:05.757 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-09 03:44:07.044 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-30 12:47:21.004 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-29 04:39:02.108 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-15 10:29:41.341 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz Prozentuale Nutzung des RAM: 23% Installierter physikalischer RAM: 8053.6 MB Verfügbarer physikalischer RAM: 6156.52 MB Summe virtueller Speicher: 16245.6 MB Verfügbarer virtueller Speicher: 14176.04 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:930.91 GB) (Free:847.2 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 9BCA118F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=930.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=511 MB) - (Type=27) ==================== Ende von Addition.txt =========================== Code:
ATTFilter Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 17-12-2016 durchgeführt von Dragonfly (17-12-2016 18:51:19) Gestartet von C:\Users\Dragonfly\Desktop Start-Modus: Normal ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\Dragonfly\Documents () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\Dragonfly\Downloads () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\Dragonfly\Music () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\Dragonfly\Pictures () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\Dragonfly\Videos () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk -> Microsoft.Windows.Homegroup Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk -> Microsoft.Windows.Network Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\Dragonfly () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk -> C:\WINDOWS\DevicesFlow\DevicesFlow.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk -> C:\WINDOWS\MiracastView\MiracastView.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (dotPDN LLC) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk -> C:\WINDOWS\PrintDialog\PrintDialog.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10-Upgrade-Assistent.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Uninstall Winamp.lnk -> C:\Program Files (x86)\Winamp\UninstWA.exe (Nullsoft, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\What's New.lnk -> C:\Program Files (x86)\Winamp\whatsnew.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel(R) Rapid Storage Technology.lnk -> C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUI.exe (Intel Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 6\CyberGhost 6 deinstallieren.lnk -> C:\Program Files\CyberGhost 6\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 6\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Avira Antivirus Hilfe.lnk -> C:\Program Files (x86)\Avira\Antivirus\57\avwin.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Avira Antivirus starten.lnk -> C:\Program Files (x86)\Avira\Antivirus\avcenter.exe (Avira Operations GmbH & Co. KG) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Avira im Internet.lnk -> C:\Program Files (x86)\Avira\Antivirus\weblink.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\WINDOWS\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\WINDOWS\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\WINDOWS\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\WINDOWS\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\WINDOWS\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\WINDOWS\SysWOW64\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\WINDOWS\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\WINDOWS\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\WINDOWS\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\WINDOWS\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\WINDOWS\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Bluetooth File Transfer Wizard.lnk -> C:\WINDOWS\System32\fsquirt.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\WINDOWS\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\WINDOWS\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\WINDOWS\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\WINDOWS\System32\psr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\WINDOWS\System32\StikyNot.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\WINDOWS\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\WINDOWS\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm () Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\WINDOWS\explorer.exe,-304 Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\WINDOWS\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\System32\diskmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\WINDOWS\explorer.exe,-304 Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\WINDOWS\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc () Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\System32\diskmgmt.msc () Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\Links\Desktop.lnk -> C:\Users\Dragonfly\Desktop () Shortcut: C:\Users\Dragonfly\Links\Downloads.lnk -> C:\Users\Dragonfly\Downloads () Shortcut: C:\Users\Dragonfly\Links\RecentPlaces.lnk -> L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ć ꀀz 匱卐뜥䟯ယ怂麌곫1 ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ Systemordner 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀ⴀ㐀㘀䄀ⴀ㤀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 Shortcut: C:\Users\Dragonfly\Desktop\ASIO4ALL v2 Anleitung.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Anleitung.pdf () Shortcut: C:\Users\Dragonfly\Desktop\-\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.) Shortcut: C:\Users\Dragonfly\Desktop\-\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) Shortcut: C:\Users\Dragonfly\Desktop\-\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe () Shortcut: C:\Users\Dragonfly\Desktop\-\McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\McUICnt.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\OpenOffice 4.1.2.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\Desktop\-\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (dotPDN LLC) Shortcut: C:\Users\Dragonfly\Desktop\-\Security Task Manager.lnk -> C:\Program Files (x86)\Security Task Manager\TaskMan.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\Dragonfly\Desktop\-\True Key.lnk -> C:\Program Files\Intel Security\True Key\application\truekey.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.) Shortcut: C:\Users\Dragonfly\Desktop\-\Windows 10-Upgrade-Assistent.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\Desktop\-\WinZip.lnk -> C:\Program Files\WinZip\WINZIP64.EXE (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Tor Browser\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\firefox (2).lnk -> C:\Users\Dragonfly\Desktop\firefox.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk -> C:\WINDOWS\System32\fodhelper.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\WINDOWS\explorer.exe,-304 Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\WINDOWS\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Base.lnk -> C:\Program Files (x86)\OpenOffice 4\program\sbase.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Calc.lnk -> C:\Program Files (x86)\OpenOffice 4\program\scalc.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Draw.lnk -> C:\Program Files (x86)\OpenOffice 4\program\sdraw.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Impress.lnk -> C:\Program Files (x86)\OpenOffice 4\program\simpress.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Math.lnk -> C:\Program Files (x86)\OpenOffice 4\program\smath.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Writer.lnk -> C:\Program Files (x86)\OpenOffice 4\program\swriter.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2\ASIO4ALL v2 Anleitung.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Anleitung.pdf () Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2\ASIO4ALL Web Site.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL Web Site.url () Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2\Uninstall.lnk -> C:\Program Files (x86)\ASIO4ALL v2\uninstall.exe () Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\WINDOWS\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth-Dateiübertragung.LNK -> C:\WINDOWS\System32\fsquirt.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc () Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\System32\diskmgmt.msc () Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\WINDOWS\System32\rundll32.exe (Microsoft Corporation) -> -sta {C90FB8CA-3295-4462-A721-2935E83694BA} ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Winamp (Safe Mode).lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.) -> /SAFE=1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /7 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Administrator-Toolkit.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\itFrmwrk.exe (Intel(R) Corporation) -> /af Administrator Tool /class IT Admin Class ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Ereignisanzeige für WiFi.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\imFrmwrk.exe (Intel(R) Corporation) -> /sf Wireless Event Viewer ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Erweiterte Statistik für WiFi.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\imFrmwrk.exe (Intel(R) Corporation) -> /sf Advanced Statistics ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Manuelles Diagnose-Tool für WiFi.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\imFrmwrk.exe (Intel(R) Corporation) -> /sf Wireless Diagnostics ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\WiFi Connection Utility.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation) -> /af Intel PROSet/Wireless ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Connect.lnk -> C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\WINDOWS\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\WINDOWS\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\WINDOWS\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation) -> /open ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\WINDOWS\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\Dragonfly\Desktop\-\Avira Launcher.lnk -> C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} InternetURL: C:\Users\Dragonfly\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\Dragonfly\Favorites\Teen Babysitter Sydney Cole Fucks for Job - Pornhub.com.url -> BASEURL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4 URL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=70742 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Ideas.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72700 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Mail.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72681 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Spaces.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72682 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Auto.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72680 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Fernsehen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72659 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Money.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72640 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Nachrichten.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72636 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Sport.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72635 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72630 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\IE-Site auf Microsoft.com.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72186 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Deutschland GmbH.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72520 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Store.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=140813 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Windows - Start.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72629 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft zu Hause.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72406 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft.com durchsuchen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72893 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Site für IE Add-Ons.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893 InternetURL: C:\Users\Dragonfly\Favorites\Links\Vorgeschlagene Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice InternetURL: C:\Users\Dragonfly\Favorites\Links\Web Slice-Katalog.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315 InternetURL: C:\Users\Dragonfly\AppData\Local\Microsoft\Internet Explorer\Pinned Sites\Family Guy (7) - Burning Series Serien online sehen.website -> URL: hxxps://bs.to/serie/Family-Guy/7 ==================== Ende von Shortcut.txt ============================= Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-12-2016 durchgeführt von Dragonfly (Administrator) auf DRAGONFLY-PC (17-12-2016 18:59:13) Gestartet von C:\Users\Dragonfly\Desktop Geladene Profile: Dragonfly (Verfügbare Profile: Dragonfly & DefaultAppPool) Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Microsoft Corporation) C:\WINDOWS\System32\InstallAgent.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SynLenovoGestureMgr] => %ProgramFiles%\Synaptics\SynTP\SynLenovoGestureMgr.exe HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61640 2016-11-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-13] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [571928 2015-09-03] (Vimicro) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-614321186-1851163967-905647231-1000\...\RunOnce: [Uninstall C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64" AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [172736 2016-12-12] (NVIDIA Corporation) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{532a19c3-72f7-44e7-9dd6-29ffc5f32635}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{710a9cfb-03be-40ab-86c0-bcc56c490da4}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{8db06c7b-14a1-4d88-b57a-c536e881adc4}: [DhcpNameServer] 194.187.251.67 185.93.180.131 38.132.106.139 Internet Explorer: ================== HKU\S-1-5-21-614321186-1851163967-905647231-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH) BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2015-10-30] (Microsoft Corporation) BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH) Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\Windows\system32\mscoree.dll [2015-10-30] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default [2016-12-17] FF Extension: (Avira Browser Safety) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default\Extensions\abs@avira.com.xpi [2016-11-21] FF Extension: (Video DownloadHelper) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-10-11] FF Extension: (Adblock Plus) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-22] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-22] () Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-13] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-13] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-13] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-13] (Avira Operations GmbH & Co. KG) S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [350528 2016-11-24] (Avira Operations GmbH & Co. KG) S2 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [76336 2016-11-28] (CyberGhost S.R.L) S4 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation) S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-06-25] () R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation) R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-13] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-13] (NVIDIA Corporation) S3 PrintNotify; C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll [3337728 2016-09-07] (Microsoft Corporation) [Datei ist nicht signiert] S4 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation) S4 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3325232 2012-06-25] (Intel® Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [151352 2016-12-13] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [153904 2016-12-13] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [35488 2016-07-30] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [78208 2016-07-30] (Avira Operations GmbH & Co. KG) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-13] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [422656 2016-03-09] (Realsil Semiconductor Corporation) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated) R3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [648872 2015-09-03] (Vimicro Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) S3 WUDFWpdComp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation) U3 idsvc; kein ImagePath U3 wpcsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-17 18:51 - 2016-12-17 18:59 - 00013144 _____ C:\Users\Dragonfly\Desktop\FRST.txt 2016-12-17 18:51 - 2016-12-17 18:51 - 00042436 _____ C:\Users\Dragonfly\Desktop\Shortcut.txt 2016-12-17 18:50 - 2016-12-17 18:51 - 00040991 _____ C:\Users\Dragonfly\Desktop\Addition.txt 2016-12-17 12:32 - 2016-09-09 19:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2016-12-17 12:32 - 2016-09-09 19:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll 2016-12-17 12:32 - 2016-09-09 19:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2016-12-17 12:32 - 2016-09-09 19:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe 2016-12-17 12:30 - 2016-12-12 22:27 - 00047032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys 2016-12-17 12:30 - 2016-12-12 04:03 - 40125496 _____ C:\WINDOWS\system32\nvcompiler.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 35222976 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 34710584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 28201408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 24389160 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 17586992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 14529624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 10912744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 10803880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 10353960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 09158616 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 08913328 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 08761560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 02950200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 02587704 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 01953336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437633.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437633.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 01038392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00974784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00942528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00894400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00802768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00683640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00643928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00572888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00470400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00438208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00394888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00388544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00327408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00153368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00150784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2016-12-17 12:30 - 2016-12-12 04:03 - 00131536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2016-12-17 12:22 - 2016-12-17 12:33 - 00005110 _____ C:\ProgramData\NvTelemetryContainer.log_backup1 2016-12-17 12:22 - 2016-12-17 12:22 - 00004418 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-17 12:22 - 2016-12-17 12:22 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Chromium 2016-12-17 12:22 - 2016-12-12 15:36 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat 2016-12-17 12:21 - 2016-12-17 12:31 - 00000000 ____D C:\WINDOWS\LastGood.Tmp 2016-12-17 12:21 - 2016-12-13 00:36 - 00156096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll 2016-12-17 12:21 - 2016-12-13 00:36 - 00123840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2016-12-14 00:46 - 2016-11-22 12:42 - 00384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2016-12-14 00:46 - 2016-11-22 11:43 - 03692040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-12-14 00:46 - 2016-11-22 11:38 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-12-14 00:46 - 2016-11-22 11:38 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-12-14 00:46 - 2016-11-22 11:36 - 00159640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll 2016-12-14 00:46 - 2016-11-22 11:35 - 00609056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-12-14 00:46 - 2016-11-22 11:35 - 00075448 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll 2016-12-14 00:46 - 2016-11-22 11:04 - 02549456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2016-12-14 00:46 - 2016-11-22 11:03 - 01777280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-12-14 00:46 - 2016-11-22 11:02 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2016-12-14 00:46 - 2016-11-22 11:02 - 01399216 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2016-12-14 00:46 - 2016-11-22 10:32 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2016-12-14 00:46 - 2016-11-22 10:24 - 02938408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-12-14 00:46 - 2016-11-22 10:21 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe 2016-12-14 00:46 - 2016-11-22 10:17 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll 2016-12-14 00:46 - 2016-11-22 10:16 - 00064072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll 2016-12-14 00:46 - 2016-11-22 10:13 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll 2016-12-14 00:46 - 2016-11-22 10:00 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe 2016-12-14 00:46 - 2016-11-22 09:59 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-12-14 00:46 - 2016-11-22 09:55 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-12-14 00:46 - 2016-11-22 09:54 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-12-14 00:46 - 2016-11-22 09:50 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2016-12-14 00:46 - 2016-11-22 09:49 - 02195640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2016-12-14 00:46 - 2016-11-22 09:48 - 01522672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-12-14 00:46 - 2016-11-22 09:47 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2016-12-14 00:46 - 2016-11-22 09:47 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2016-12-14 00:46 - 2016-11-22 09:35 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-12-14 00:46 - 2016-11-22 09:32 - 01386496 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-12-14 00:46 - 2016-11-22 09:27 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-12-14 00:46 - 2016-11-22 09:20 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-12-14 00:46 - 2016-11-22 09:12 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-12-14 00:46 - 2016-11-22 09:04 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-12-14 00:46 - 2016-11-22 08:57 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-12-14 00:46 - 2016-11-22 08:54 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-12-14 00:46 - 2016-11-22 08:53 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-12-14 00:46 - 2016-11-22 08:41 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-12-14 00:46 - 2016-11-22 08:38 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2016-12-14 00:46 - 2016-11-22 08:36 - 00766464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-12-14 00:46 - 2016-11-22 08:26 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-12-14 00:46 - 2016-11-22 08:26 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-12-14 00:46 - 2016-11-22 08:21 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-12-14 00:46 - 2016-11-22 08:15 - 22373376 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-12-14 00:46 - 2016-11-22 08:14 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-12-14 00:46 - 2016-11-22 08:02 - 24610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-12-14 00:46 - 2016-11-22 08:01 - 13392384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-12-14 00:46 - 2016-11-22 07:59 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-12-14 00:46 - 2016-11-22 07:55 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-12-14 00:46 - 2016-11-22 07:49 - 07839232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-12-14 00:46 - 2016-11-22 07:35 - 19350016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-12-14 00:46 - 2016-11-22 07:34 - 18670080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-12-14 00:46 - 2016-11-22 07:34 - 12134400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-12-14 00:46 - 2016-11-22 07:32 - 03663872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-12-14 00:46 - 2016-11-22 07:17 - 05658624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-12-04 00:53 - 2016-12-04 00:53 - 00213053 _____ C:\Users\Dragonfly\Desktop\frenchcore_9.flp 2016-12-04 00:38 - 2016-12-04 00:38 - 00212230 _____ C:\Users\Dragonfly\Desktop\frenchcore_8.flp 2016-12-03 21:44 - 2016-12-03 21:44 - 00211869 _____ C:\Users\Dragonfly\Desktop\frenchcore_7.flp 2016-12-03 21:18 - 2016-12-03 21:18 - 00207810 _____ C:\Users\Dragonfly\Desktop\frenchcore_6.flp 2016-12-03 18:51 - 2016-12-03 18:51 - 00202861 _____ C:\Users\Dragonfly\Desktop\frenchcore_5.flp 2016-12-03 18:38 - 2016-12-03 18:38 - 00156550 _____ C:\Users\Dragonfly\Desktop\frenchcore_4.flp 2016-12-03 18:25 - 2016-12-03 18:25 - 00156753 _____ C:\Users\Dragonfly\Desktop\frenchcore_3.flp 2016-12-03 17:34 - 2016-12-03 17:34 - 00145338 _____ C:\Users\Dragonfly\Desktop\frenchcore_2.flp 2016-12-02 21:51 - 2016-12-03 15:08 - 00145351 _____ C:\Users\Dragonfly\Desktop\frenchcore.flp 2016-12-02 08:21 - 2016-12-03 19:13 - 00000000 ____D C:\Users\Dragonfly\Desktop\speadhead 2016-12-02 03:47 - 2016-12-17 18:48 - 00000000 ____D C:\Users\Dragonfly\Desktop\FRST-OlderVersion 2016-12-01 16:37 - 2016-12-12 04:03 - 20748080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2016-12-01 16:37 - 2016-12-12 04:03 - 00572584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2016-12-01 16:37 - 2016-11-24 21:53 - 01951680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437609.dll 2016-12-01 16:37 - 2016-11-24 21:53 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437609.dll 2016-11-30 14:54 - 2016-11-30 14:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2016-11-30 14:54 - 2016-11-30 14:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_wpdcomp_01_11_00.Wdf 2016-11-22 03:16 - 2016-12-17 18:48 - 02420224 _____ (Farbar) C:\Users\Dragonfly\Desktop\FRST64.exe 2016-11-21 04:41 - 2016-11-17 03:06 - 01953336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437595.dll 2016-11-21 04:41 - 2016-11-17 03:06 - 01585088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437595.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 06384576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 02475968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 01764408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 00548408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 00145344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2016-11-21 04:33 - 2016-12-11 19:47 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2016-11-21 04:33 - 2016-12-09 09:52 - 07639617 _____ C:\WINDOWS\system32\nvcoproc.bin 2016-11-21 04:32 - 2016-12-11 19:47 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat 2016-11-19 21:55 - 2016-11-19 21:55 - 00106714 _____ C:\Users\Dragonfly\Desktop\hummel_gut.flp 2016-11-19 21:49 - 2016-11-19 21:49 - 00106714 _____ C:\Users\Dragonfly\Desktop\hummel_3.flp 2016-11-19 21:47 - 2016-11-19 21:47 - 00106716 _____ C:\Users\Dragonfly\Desktop\hummel_2.flp 2016-11-19 13:57 - 2016-11-19 21:52 - 00105720 _____ C:\Users\Dragonfly\Desktop\hummel.flp 2016-11-18 17:23 - 2016-12-17 18:50 - 00000000 ____D C:\Users\Dragonfly\AppData\LocalLow\Mozilla 2016-11-18 16:02 - 2016-12-17 14:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-11-18 14:17 - 2016-12-12 22:26 - 14200880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2016-11-18 14:17 - 2016-12-12 04:03 - 03934504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2016-11-18 14:17 - 2016-12-12 04:03 - 03474392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2016-11-18 14:17 - 2016-12-12 04:03 - 00172736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2016-11-18 14:17 - 2016-12-12 04:03 - 00042286 _____ C:\WINDOWS\system32\nvinfo.pb 2016-11-18 14:17 - 2016-11-11 00:51 - 01951680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437586.dll 2016-11-18 14:17 - 2016-11-11 00:51 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437586.dll 2016-11-18 14:17 - 2016-11-11 00:51 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json 2016-11-18 14:17 - 2016-11-11 00:51 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json 2016-11-18 14:11 - 2016-12-17 12:22 - 00001485 _____ C:\Users\Public\Desktop\GeForce Experience.lnk ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-17 18:59 - 2016-07-04 21:54 - 00000000 ____D C:\FRST 2016-12-17 17:54 - 2016-07-17 12:15 - 00007634 _____ C:\Users\Dragonfly\AppData\Local\Resmon.ResmonCfg 2016-12-17 17:05 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-12-17 17:05 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-12-17 17:00 - 2016-07-29 23:51 - 00000000 ____D C:\ProgramData\NVIDIA 2016-12-17 14:23 - 2016-09-30 00:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-12-17 12:37 - 2016-07-14 19:27 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\CrashDumps 2016-12-17 12:33 - 2016-04-27 06:48 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-12-17 12:33 - 2015-10-30 07:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-12-17 12:32 - 2016-07-13 22:03 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2016-12-17 12:31 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF 2016-12-17 12:22 - 2016-10-07 14:21 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-17 12:22 - 2016-10-07 14:20 - 00004004 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-17 12:22 - 2016-10-07 14:20 - 00003976 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-17 12:22 - 2016-10-07 14:20 - 00003968 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-17 12:22 - 2016-10-07 14:20 - 00003806 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-17 12:22 - 2016-10-07 14:20 - 00003764 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-17 12:22 - 2016-07-29 23:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-12-17 12:22 - 2016-07-29 23:50 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-17 12:22 - 2016-07-29 23:50 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-17 12:22 - 2016-07-13 22:08 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA Corporation 2016-12-17 12:21 - 2016-07-13 22:07 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA 2016-12-16 13:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache 2016-12-15 11:26 - 2016-07-29 23:53 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-12-15 11:26 - 2016-04-27 06:13 - 00889250 _____ C:\WINDOWS\system32\perfh007.dat 2016-12-15 11:26 - 2016-04-27 06:13 - 00197298 _____ C:\WINDOWS\system32\perfc007.dat 2016-12-14 12:58 - 2016-04-26 21:44 - 00224368 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-12-14 12:56 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-12-14 02:55 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-12-14 02:53 - 2016-07-17 12:16 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-12-14 02:51 - 2016-07-17 12:16 - 135632432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-12-13 01:30 - 2016-07-04 20:21 - 00000000 ____D C:\ProgramData\Package Cache 2016-12-13 01:30 - 2016-07-04 20:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2016-12-13 01:27 - 2016-10-11 10:32 - 00028272 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys 2016-12-13 01:27 - 2016-07-04 20:22 - 00153904 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2016-12-13 01:27 - 2016-07-04 20:22 - 00151352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2016-12-13 00:37 - 2016-10-07 14:21 - 01853376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2016-12-13 00:37 - 2016-10-07 14:21 - 01755072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2016-12-13 00:37 - 2016-10-07 14:21 - 01452480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2016-12-13 00:37 - 2016-10-07 14:21 - 01317312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2016-12-13 00:37 - 2016-10-07 14:21 - 00120256 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll 2016-12-13 00:36 - 2016-07-13 22:00 - 00046016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys 2016-12-12 15:27 - 2016-10-07 14:14 - 00000000 ____D C:\Users\Dragonfly\dwhelper 2016-12-12 00:03 - 2015-10-30 08:26 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-12-12 00:03 - 2015-10-30 08:26 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-12-02 22:53 - 2016-09-29 20:54 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\ElevatedDiagnostics 2016-12-02 07:14 - 2016-07-30 00:35 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Packages 2016-11-22 23:37 - 2016-08-11 00:43 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Adobe 2016-11-22 23:37 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-11-22 23:37 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-11-22 03:59 - 2016-07-25 18:44 - 00000000 __SHD C:\Users\Dragonfly\IntelGraphicsProfiles 2016-11-22 03:14 - 2016-07-17 23:35 - 01741824 _____ (Farbar) C:\Users\Dragonfly\Downloads\FRST.exe 2016-11-21 21:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration 2016-11-21 04:33 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Help 2016-11-21 04:00 - 2016-10-04 11:27 - 00000000 ___HD C:\$SysReset 2016-11-18 20:57 - 2016-07-29 23:50 - 00000000 ____D C:\Program Files\Intel 2016-11-18 20:56 - 2016-08-11 00:52 - 00000000 ____D C:\Program Files\Common Files\McAfee 2016-11-18 20:38 - 2016-08-11 00:43 - 00000000 ____D C:\ProgramData\McAfee ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-07-17 12:15 - 2016-12-17 17:54 - 0007634 _____ () C:\Users\Dragonfly\AppData\Local\Resmon.ResmonCfg 2016-12-17 12:22 - 2016-12-17 16:56 - 0003771 _____ () C:\ProgramData\NvTelemetryContainer.log 2016-12-17 12:22 - 2016-12-17 12:33 - 0005110 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1 Einige Dateien in TEMP: ==================== C:\Users\Dragonfly\AppData\Local\Temp\avgnt.exe C:\Users\Dragonfly\AppData\Local\Temp\NvTelemetry.dll C:\Users\Dragonfly\AppData\Local\Temp\NvTelemetryAPI32.dll C:\Users\Dragonfly\AppData\Local\Temp\NvTelemetryAPI64.dll ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-12-14 07:01 ==================== Ende von FRST.txt ============================ Geändert von izockdi (17.12.2016 um 19:17 Uhr) |
20.12.2016, 10:15 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... Bitte Avira deinstallieren. Das Teil empfehlen wir schon seit Jahren aus mehreren Gründen nicht mehr. Ein Grund ist ne rel. hohe Fehlalarmquote, der zweite Hauptgrund ist, dass die immer noch mit ASK zusammenarbeiten (Avira Suchfunktion geht über ASK). Auch andere Freewareanbieter wie AVG, Avast oder Panda sprangen auf diesen Zug auf; so was ist bei Sicherheitssoftware einfach inakzeptabel. Vgl. Antivirensoftware: Schutz Für Ihre Dateien, Aber Auf Kosten Ihrer Privatsphäre? | Emsisoft Blog Gib Bescheid wenn Avira weg ist; wenn wir hier durch sind, kannst du auf einen anderen Virenscanner umsteigen, Infos folgen dann im Abschlussposting. Bitte JETZT nix mehr ohne Absprache installieren!
__________________ --> rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... |
20.01.2017, 05:03 | #7 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... ok danke. der rest passt? |
20.01.2017, 10:20 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... Was soll das heißen, der Rest passt, lies mein Posting doch mal bis zum Ende - wir sind hier nämlich nicht fertig.
__________________ Logfiles bitte immer in CODE-Tags posten |
24.01.2017, 09:52 | #9 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... schade dass wir noch nicht fertig sind... sorry ich hatte wenig zeit die tage und muss gestehen mich auch nicht großartig mit dem thema auseinander gesetzt zu haben. leider häufen sich aber die probleme und dank gebrochenem arm hab ich auch gut zeit. ich hab emisoft installiert und danach noch mal frst asgeführt. hier die neuen berichte: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2017 durchgeführt von Dragonfly (Administrator) auf DRAGONFLY-PC (24-01-2017 09:38:53) Gestartet von C:\Users\Dragonfly\Desktop Geladene Profile: Dragonfly & (Verfügbare Profile: Dragonfly) Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Edge) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel Corporation) C:\Windows\syswow64\IntelCpHeciSvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe (Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2start.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Farbar) C:\Users\Dragonfly\Desktop\FRST64 (1).exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1812544 2016-09-12] (NVIDIA Corporation) HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [8140696 2016-12-29] (Emsisoft Ltd) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [571928 2015-09-03] (Vimicro) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Keine Datei ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== FireFox: ======== FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-23] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-23] (Google Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com CHR Profile: C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default [2017-01-24] CHR Extension: (Google Docs) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-24] CHR Extension: (Google Drive) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-24] CHR Extension: (YouTube) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-24] CHR Extension: (Google Docs Offline) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-24] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-23] CHR Extension: (Google Mail) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-24] CHR Extension: (Chrome Media Router) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-24] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [9461280 2016-12-29] (Emsisoft Ltd) R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2017-01-23] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2017-01-23] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 epp; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys [124552 2016-11-23] (Emsisoft Ltd) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [422656 2016-03-09] (Realsil Semiconductor Corporation) S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [42184 2015-06-03] (Synaptics Incorporated) R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated) S3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [648872 2015-09-03] (Vimicro Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-24 08:05 - 2017-01-24 08:05 - 00042168 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS 2017-01-24 07:50 - 2017-01-24 07:50 - 01932769 _____ C:\Users\Dragonfly\Downloads\processexplorer (1).zip 2017-01-24 06:32 - 2017-01-24 06:32 - 00036409 _____ C:\Users\Dragonfly\Desktop\Shortcut.txt 2017-01-24 06:32 - 2017-01-24 06:32 - 00023299 _____ C:\Users\Dragonfly\Desktop\Addition.txt 2017-01-24 06:31 - 2017-01-24 09:38 - 00007525 _____ C:\Users\Dragonfly\Desktop\FRST.txt 2017-01-24 06:31 - 2017-01-24 06:31 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Desktop\FRST64 (1).exe 2017-01-24 06:30 - 2017-01-24 06:30 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Desktop\FRST64.exe 2017-01-24 01:56 - 2017-01-24 03:41 - 00000000 ____D C:\ProgramData\Emsisoft 2017-01-24 01:55 - 2017-01-24 01:55 - 00000937 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2017-01-24 01:55 - 2017-01-24 01:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware 2017-01-24 01:54 - 2017-01-24 09:09 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware 2017-01-24 01:53 - 2017-01-24 01:54 - 241881560 _____ (Emsisoft Ltd. ) C:\Users\Dragonfly\Desktop\EmsisoftAntiMalwareSetup (1).exe 2017-01-24 01:52 - 2017-01-24 01:53 - 241881560 _____ (Emsisoft Ltd. ) C:\Users\Dragonfly\Desktop\EmsisoftAntiMalwareSetup.exe 2017-01-24 01:47 - 2017-01-24 01:47 - 00000000 ____D C:\EEK 2017-01-24 01:45 - 2017-01-24 01:46 - 283519832 _____ C:\Users\Dragonfly\Downloads\EmsisoftEmergencyKit.exe 2017-01-24 01:37 - 2017-01-24 01:37 - 00000000 ____D C:\Users\Dragonfly\Desktop\Neuer Ordner 2017-01-24 01:31 - 2016-10-28 02:22 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2017-01-24 01:16 - 2017-01-24 06:28 - 00007616 _____ C:\Users\Dragonfly\AppData\Local\resmon.resmoncfg 2017-01-24 00:46 - 2017-01-24 00:46 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Downloads\FRST64 (1).exe 2017-01-24 00:44 - 2017-01-24 00:45 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Downloads\FRST64.exe 2017-01-23 23:22 - 2017-01-23 23:22 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA 2017-01-23 23:17 - 2017-01-23 23:17 - 00000000 ____D C:\ProgramData\Package Cache 2017-01-23 23:17 - 2017-01-23 23:17 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-01-23 23:17 - 2016-05-04 03:23 - 00129824 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2017-01-23 23:17 - 2016-05-04 03:22 - 00130848 _____ C:\WINDOWS\system32\vulkan-1.dll 2017-01-23 23:17 - 2016-05-04 03:22 - 00045344 _____ C:\WINDOWS\system32\vulkaninfo.exe 2017-01-23 23:17 - 2016-05-04 03:22 - 00040224 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2017-01-23 22:19 - 2017-01-23 22:19 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Comms 2017-01-23 22:15 - 2017-01-23 22:15 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\LolClient 2017-01-23 22:12 - 2017-01-23 22:12 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk 2017-01-23 22:12 - 2017-01-23 22:12 - 00000000 ____D C:\ProgramData\Riot Games 2017-01-23 22:12 - 2017-01-23 22:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2017-01-23 22:12 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll 2017-01-23 22:12 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll 2017-01-23 22:12 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2017-01-23 22:12 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2017-01-23 22:12 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2017-01-23 22:09 - 2017-01-23 22:12 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\Riot Games 2017-01-23 21:57 - 2017-01-23 21:57 - 00000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2017-01-23 21:53 - 2017-01-23 22:09 - 31876824 _____ (Riot Games) C:\Users\Dragonfly\Downloads\LeagueofLegends_EUW_Installer_2016_11_10.exe 2017-01-23 21:53 - 2017-01-23 21:53 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\Macromedia 2017-01-23 21:48 - 2017-01-23 21:48 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-01-23 21:48 - 2017-01-23 21:48 - 00002324 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-01-23 21:39 - 2017-01-23 22:58 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-01-23 21:39 - 2017-01-23 22:58 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-01-23 21:39 - 2017-01-23 21:52 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgsnx.sys.148520484293701 2017-01-23 21:39 - 2017-01-23 21:48 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Google 2017-01-23 21:39 - 2017-01-23 21:48 - 00000000 ____D C:\Program Files (x86)\Google 2017-01-23 21:38 - 2017-01-23 21:38 - 00000000 ____D C:\WINDOWS\SysWOW64\sda 2017-01-23 21:38 - 2017-01-23 21:38 - 00000000 ____D C:\Program Files (x86)\USB Camera 2017-01-23 21:36 - 2017-01-23 21:36 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\CEF 2017-01-23 21:35 - 2017-01-24 02:53 - 00000000 ____D C:\ProgramData\Avg 2017-01-23 21:35 - 2017-01-24 02:09 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\AvgSetupLog 2017-01-23 21:35 - 2017-01-23 21:35 - 03449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Dragonfly\Downloads\AVG_Protection_Free_1606.exe 2017-01-23 21:35 - 2017-01-23 21:35 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Avg 2017-01-23 21:33 - 2017-01-23 21:33 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\MicrosoftEdge 2017-01-23 21:31 - 2017-01-23 21:31 - 00015664 _____ C:\Users\Dragonfly\Desktop\Entfernte Anwendungen.html 2017-01-23 21:31 - 2017-01-23 21:31 - 00002366 _____ C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-01-23 21:31 - 2017-01-23 21:31 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\ActiveSync 2017-01-23 21:31 - 2017-01-23 21:31 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2017-01-23 21:30 - 2017-01-24 01:40 - 01799166 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-01-23 21:29 - 2017-01-24 02:03 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Packages 2017-01-23 21:29 - 2017-01-23 21:29 - 00000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2017-01-23 21:29 - 2017-01-23 21:29 - 00000020 ___SH C:\Users\Dragonfly\ntuser.ini 2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\Adobe 2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\VirtualStore 2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\TileDataLayer 2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Publishers 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Vorlagen 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Startmenü 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\All Users 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Vorlagen 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Startmenü 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Favoriten 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Dokumente 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2017-01-23 21:23 - 2017-01-24 01:25 - 00000000 ____D C:\Users\Dragonfly 2017-01-23 21:23 - 2017-01-23 21:24 - 00000000 ____D C:\Users\DefaultAppPool 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Vorlagen 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Startmenü 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Netzwerkumgebung 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Lokale Einstellungen 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Eigene Dateien 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Druckumgebung 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Documents\Eigene Videos 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Documents\Eigene Musik 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Documents\Eigene Bilder 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\AppData\Local\Verlauf 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\AppData\Local\Anwendungsdaten 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Anwendungsdaten 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten 2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten 2017-01-23 21:17 - 2017-01-23 23:19 - 00000000 ____D C:\ProgramData\NVIDIA 2017-01-23 21:17 - 2017-01-23 23:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-01-23 21:17 - 2017-01-23 23:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-01-23 21:17 - 2017-01-23 21:17 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-01-23 21:17 - 2017-01-23 21:17 - 00000000 ____D C:\Program Files\Common Files\Atheros 2017-01-23 21:17 - 2016-08-01 13:54 - 06386744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 02466360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 01365048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2017-01-23 21:17 - 2016-08-01 13:54 - 00547896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 00139712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2017-01-23 21:17 - 2016-07-28 14:02 - 07242545 _____ C:\WINDOWS\system32\nvcoproc.bin 2017-01-23 21:17 - 2016-05-03 22:30 - 00081416 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL 2017-01-23 21:17 - 2016-05-03 22:30 - 00077832 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL 2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf 2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf 2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____D C:\ProgramData\USOShared 2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____D C:\Program Files\Intel 2017-01-23 21:15 - 2017-01-23 20:52 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2017-01-23 21:13 - 2017-01-24 01:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-01-23 21:13 - 2017-01-23 21:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2017-01-23 21:12 - 2017-01-23 21:21 - 00194272 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-01-23 21:11 - 2017-01-23 21:26 - 00000000 ___DC C:\WINDOWS\Panther 2017-01-23 21:11 - 2017-01-23 21:11 - 00000000 ____D C:\WINDOWS\InfusedApps 2017-01-23 21:10 - 2017-01-24 05:24 - 00000000 ____D C:\Windows.old 2017-01-23 21:10 - 2017-01-23 21:10 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2017-01-23 21:08 - 2017-01-23 21:08 - 00000000 ____D C:\Program Files\Synaptics 2017-01-23 21:07 - 2017-01-23 21:07 - 00000000 ____D C:\WINDOWS\Setup 2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\OCR 2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files\Reference Assemblies 2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files\MSBuild 2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files (x86)\MSBuild 2017-01-23 21:01 - 2017-01-24 01:40 - 00776766 _____ C:\WINDOWS\system32\perfh007.dat 2017-01-23 21:01 - 2017-01-24 01:40 - 00155544 _____ C:\WINDOWS\system32\perfc007.dat 2017-01-23 21:01 - 2017-01-23 21:00 - 00305634 _____ C:\WINDOWS\system32\perfi007.dat 2017-01-23 21:01 - 2017-01-23 21:00 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\de 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\0409 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\winrm 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\WCN 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\slmgr 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\de 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\0409 2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\DigitalLocker 2017-01-23 20:57 - 2017-01-23 20:52 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-01-23 20:57 - 2017-01-23 20:52 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-01-23 20:56 - 2017-01-23 20:53 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat 2017-01-23 20:56 - 2017-01-23 20:53 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2017-01-23 20:56 - 2017-01-23 20:53 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat 2017-01-23 20:56 - 2017-01-23 20:53 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat 2017-01-23 20:56 - 2017-01-23 20:53 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT 2017-01-23 20:55 - 2017-01-24 03:39 - 00000000 ____D C:\WINDOWS\appcompat 2017-01-23 20:55 - 2017-01-24 02:12 - 00000000 ___HD C:\Program Files\WindowsApps 2017-01-23 20:55 - 2017-01-24 02:12 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-01-23 20:55 - 2017-01-24 01:22 - 00000000 ____D C:\WINDOWS\Registration 2017-01-23 20:55 - 2017-01-23 21:46 - 00000000 ___RD C:\WINDOWS\DevicesFlow 2017-01-23 20:55 - 2017-01-23 21:38 - 00000000 ____D C:\WINDOWS\System 2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\PurchaseDialog 2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\PrintDialog 2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\MiracastView 2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-01-23 20:55 - 2017-01-23 21:27 - 00000000 ____D C:\WINDOWS\rescache 2017-01-23 20:55 - 2017-01-23 21:25 - 00000000 ____D C:\Program Files\Windows NT 2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 __RHD C:\Users\Public\Libraries 2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 ____D C:\WINDOWS\system32\spool 2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2017-01-23 20:55 - 2017-01-23 21:20 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2017-01-23 20:55 - 2017-01-23 21:17 - 00000000 ____D C:\WINDOWS\Help 2017-01-23 20:55 - 2017-01-23 21:11 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 __RSD C:\WINDOWS\Media 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\Provisioning 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\bcastdvr 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files\Windows Portable Devices 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2017-01-23 20:55 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2017-01-23 20:55 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\SystemApps 2017-01-23 20:55 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\system32\MUI 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\system32\dsc 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\setup 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\Com 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\setup 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\migwiz 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\Com 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\IME 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Windows Defender 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Common Files\System 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops 2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 __SHD C:\Program Files\Windows Sidebar 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\system32\Nui 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\system32\Configuration 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___RD C:\WINDOWS\Offline Web Pages 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___RD C:\WINDOWS\DesktopTileResources 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Web 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Vss 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\tracing 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\TAPI 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\ras 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SystemResources 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\WinMetadata 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\winevt 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\ras 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\ProximityToast 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\PointOfService 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\MsDtc 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\Ipmi 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\IME 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\icsxml 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\ias 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\downlevel 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\config\Journal 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\Bthprops 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\AppLocker 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SKB 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\security 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\schemas 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SchCache 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Resources 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\PLA 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Performance 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\ModemLogs 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\L2Schemas 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\InputMethod 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Globalization 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Cursors 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Branding 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\addins 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\ProgramData\USOPrivate 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\ProgramData\Comms 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\Program Files\Common Files\Services 2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\Program Files (x86)\Windows NT 2017-01-23 20:55 - 2017-01-23 20:53 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2017-01-23 20:55 - 2017-01-23 20:53 - 00215943 _____ C:\WINDOWS\system32\dssec.dat 2017-01-23 20:55 - 2017-01-23 20:53 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services 2017-01-23 20:55 - 2017-01-23 20:53 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2017-01-23 20:55 - 2017-01-23 20:53 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat 2017-01-23 20:55 - 2017-01-23 20:53 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam 2017-01-23 20:55 - 2017-01-23 20:53 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat 2017-01-23 20:55 - 2017-01-23 20:53 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol 2017-01-23 20:55 - 2017-01-23 20:53 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json 2017-01-23 20:55 - 2017-01-23 20:53 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT 2017-01-23 20:55 - 2017-01-23 20:53 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks 2017-01-23 20:55 - 2017-01-23 20:53 - 00000389 _____ C:\WINDOWS\system32\AutoWorkplace.exe.config 2017-01-23 20:55 - 2017-01-23 20:53 - 00000219 _____ C:\WINDOWS\system.ini 2017-01-23 20:55 - 2017-01-23 20:53 - 00000092 _____ C:\WINDOWS\win.ini 2017-01-23 20:54 - 2017-01-24 04:50 - 00000000 ____D C:\WINDOWS\INF 2017-01-23 20:43 - 2017-01-24 04:03 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-01-23 20:33 - 2017-01-24 01:32 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2017-01-23 20:33 - 2017-01-23 21:16 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2017-01-23 20:33 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\servicing 2017-01-23 20:33 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\SMI 2017-01-23 20:33 - 2015-10-30 07:33 - 00000164 _____ C:\WINDOWS\system32\config\FP 2017-01-22 16:50 - 2017-01-22 16:52 - 00000000 ____D C:\Users\Dragonfly\Desktop\Neuer Ordner (2) 2017-01-20 05:39 - 2017-01-20 05:39 - 00000000 ____D C:\Users\Dragonfly\AppData\Temp 2017-01-20 05:32 - 2017-01-23 20:32 - 00002362 _____ C:\bdlog.txt 2017-01-20 05:30 - 2017-01-20 05:30 - 00000684 ____H C:\bdr-cf01 2017-01-20 05:29 - 2017-01-20 05:30 - 00253404 ____H C:\bdr-ld01 2017-01-20 05:29 - 2017-01-20 05:30 - 00009216 ____H C:\bdr-ld01.mbr 2017-01-20 05:29 - 2016-10-18 11:51 - 49758588 ____H C:\bdr-im01.gz 2017-01-20 05:29 - 2013-08-13 13:38 - 03271472 ____H C:\bdr-bz01 2017-01-20 05:09 - 2017-01-20 05:11 - 11842672 _____ C:\Users\Dragonfly\Desktop\bitdefender_antivirus.exe 2017-01-15 00:00 - 2017-01-23 20:29 - 00000000 ____D C:\Users\Dragonfly\Documents\13 in one Session 2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\Sleepless & Destruction 2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\Projects3 2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\Projects in 2016 2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\2016 2017-01-15 00:00 - 2017-01-14 23:59 - 00000068 _____ C:\Users\Dragonfly\Desktop\pmp_usb.ini 2017-01-15 00:00 - 2017-01-14 14:01 - 00000110 ____H C:\Users\Dragonfly\Desktop\.~lock.TOM Bewerbung Krankenpfleger wbg.odt# 2017-01-15 00:00 - 2017-01-14 13:59 - 00017624 _____ C:\Users\Dragonfly\Desktop\TOM Lebenslauf.odt 2017-01-15 00:00 - 2017-01-05 11:32 - 00006869 _____ C:\Users\Dragonfly\Desktop\TOM Bewerbung Krankenpfleger wbg.odt 2017-01-15 00:00 - 2016-10-26 17:46 - 00020499 _____ C:\Users\Dragonfly\Desktop\TOM Bewerbung Krankenpfleger.odt 2017-01-15 00:00 - 2016-10-24 09:05 - 00082789 _____ C:\Users\Dragonfly\Desktop\winamp_metadata.dat 2017-01-15 00:00 - 2016-10-24 09:05 - 00004196 _____ C:\Users\Dragonfly\Desktop\winamp_metadata.idx 2017-01-15 00:00 - 2016-07-17 15:12 - 00185700 _____ C:\Users\Dragonfly\Documents\Daso_Version 2.flp 2017-01-15 00:00 - 2013-06-10 18:59 - 00015014 _____ C:\Users\Dragonfly\Desktop\TOM Bewerbung Lehre Wasserburg.odt 2017-01-15 00:00 - 2013-06-03 20:43 - 00014689 _____ C:\Users\Dragonfly\Desktop\TOM Bewerbung Lehre.odt 2017-01-15 00:00 - 2010-06-15 22:26 - 00102759 _____ C:\Users\Dragonfly\Documents\needspweed2.flp 2017-01-15 00:00 - 2010-06-10 16:09 - 00126729 _____ C:\Users\Dragonfly\Documents\wooly days neuer bass.flp 2017-01-15 00:00 - 2010-05-28 20:52 - 00100757 _____ C:\Users\Dragonfly\Documents\melodie.flp 2017-01-15 00:00 - 2010-02-10 19:58 - 00274250 _____ C:\Users\Dragonfly\Documents\Neustart4.flp 2017-01-14 23:59 - 2017-01-14 23:59 - 00000000 ____D C:\Users\Dragonfly\Documents\Acid Trumpet - becomming shroom 2017-01-14 23:59 - 2017-01-14 23:59 - 00000000 ____D C:\Users\Dragonfly\Desktop\Faithless 2017-01-14 14:09 - 2017-01-14 14:09 - 00018268 _____ C:\Users\Dragonfly\Documents\TOM Bewerbung Krankenpfleger wbg.odt 2016-12-30 23:49 - 2017-01-09 13:26 - 00000000 ____D C:\Users\Dragonfly\Documents\hummel 2016-12-28 14:50 - 2016-12-28 14:51 - 00311294 _____ C:\Users\Dragonfly\Documents\goa drogen4 blue.png ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-24 09:38 - 2016-07-04 21:54 - 00000000 ____D C:\FRST 2017-01-24 09:09 - 2016-11-18 07:18 - 01457312 _____ (Sysinternals - www.sysinternals.com) C:\Users\Dragonfly\Desktop\procexp64.exe 2017-01-24 09:08 - 2016-07-25 18:44 - 00000000 __SHD C:\Users\Dragonfly\IntelGraphicsProfiles 2017-01-24 07:51 - 2016-11-18 07:26 - 02720928 _____ (Sysinternals - www.sysinternals.com) C:\Users\Dragonfly\Desktop\procexp.exe 2017-01-24 07:50 - 2016-11-18 07:10 - 00072154 _____ C:\Users\Dragonfly\Desktop\procexp.chm 2017-01-24 07:50 - 2016-03-03 21:44 - 00007490 _____ C:\Users\Dragonfly\Desktop\Eula.txt 2017-01-24 05:24 - 2016-10-04 11:27 - 00000000 ___HD C:\$SysReset 2017-01-23 21:31 - 2016-07-30 00:38 - 00000000 ___RD C:\Users\Dragonfly\OneDrive 2017-01-23 21:29 - 2016-04-27 06:56 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-01-23 21:24 - 2010-11-21 08:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2017-01-23 21:06 - 2016-04-27 06:17 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2017-01-23 21:06 - 2016-04-27 06:17 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2017-01-23 21:06 - 2016-04-27 06:17 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2017-01-23 20:53 - 2016-04-27 06:17 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-01-23 20:53 - 2016-04-27 06:17 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2017-01-23 20:53 - 2016-04-27 06:17 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2017-01-23 20:53 - 2016-04-27 06:17 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-01-23 20:53 - 2016-04-27 06:17 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-01-23 20:53 - 2016-04-27 06:17 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2017-01-23 20:53 - 2016-04-27 06:17 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2017-01-23 20:53 - 2016-04-27 06:17 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2017-01-23 20:53 - 2016-04-27 06:17 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2017-01-23 20:53 - 2016-04-27 06:17 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2017-01-23 20:53 - 2015-10-30 08:19 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2017-01-23 20:53 - 2015-10-30 08:19 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr 2017-01-23 20:53 - 2015-10-30 08:19 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll 2017-01-23 20:53 - 2015-10-30 08:19 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll 2017-01-23 20:53 - 2015-10-30 08:19 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPDShServiceObj.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 01123328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00965120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00824832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comuid.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00451072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUXHost.exe 2017-01-23 20:53 - 2015-10-30 08:18 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoipRT.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUX.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msobjs.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2017-01-23 20:53 - 2015-10-30 08:18 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll 2017-01-23 20:53 - 2015-10-30 08:17 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll 2017-01-23 20:53 - 2015-10-30 08:17 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll 2017-01-23 20:53 - 2015-10-30 08:17 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys 2017-01-23 20:53 - 2015-10-30 08:17 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsvc.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-01-23 20:52 - 2016-04-27 06:17 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2017-01-23 20:52 - 2016-04-27 06:17 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2017-01-23 20:52 - 2016-04-27 06:17 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-01-23 20:52 - 2016-04-27 06:17 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2017-01-23 20:52 - 2016-04-27 06:17 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-01-23 20:52 - 2016-04-27 06:17 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2017-01-23 20:52 - 2016-04-27 06:17 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys 2017-01-23 20:52 - 2016-04-27 06:17 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2017-01-23 20:52 - 2016-04-27 06:17 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe 2017-01-23 20:52 - 2016-04-27 06:17 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2017-01-23 20:52 - 2016-04-27 06:17 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 28851224 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 01558528 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sbe.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartCardSimulator.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmsdk.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00495848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmdev.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dxpserver.exe 2017-01-23 20:52 - 2015-10-30 08:19 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiarpc.dll 2017-01-23 20:52 - 2015-10-30 08:19 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\vsstrace.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 04405248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 02771968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 02723840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 02519552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 02361856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 02102272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01987072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01187840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFramework.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01166848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Pimstore.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01085736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00885248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00835072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroles.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00759808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-01-23 20:52 - 2015-10-30 08:18 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl 2017-01-23 20:52 - 2015-10-30 08:18 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00707600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcsecproc_ssp.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00599040 _____ (Microsoft Corporation) C:\WINDOWS\system32\duser.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2017-01-23 20:52 - 2015-10-30 08:18 - 00504832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00442880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2017-01-23 20:52 - 2015-10-30 08:18 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00355680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00324448 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2017-01-23 20:52 - 2015-10-30 08:18 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2017-01-23 20:52 - 2015-10-30 08:18 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssphtb.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.ps.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe 2017-01-23 20:52 - 2015-10-30 08:18 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\spcompat.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\pngfilt.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2017-01-23 20:52 - 2015-10-30 08:18 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2017-01-23 20:52 - 2015-10-30 08:18 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\IconCodecService.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 04387680 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 03093504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 02573824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 02187408 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 02012672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmsipc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 01443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagperf.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 01424384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 01238584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcsecproc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 01113600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpedit.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00697344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00513024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00512512 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00511488 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00507904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcfile.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 00390656 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPSECSVC.DLL 2017-01-23 20:52 - 2015-10-30 08:17 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\polstore.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00317952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 00204048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys 2017-01-23 20:52 - 2015-10-30 08:17 - 00131424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufxsynopsys.sys 2017-01-23 20:52 - 2015-10-30 08:17 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapsvc.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecureTimeAggregator.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00080640 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpreference.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 00058208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwminit.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2017-01-23 20:52 - 2015-10-30 08:17 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe 2017-01-23 20:52 - 2015-10-30 08:17 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2017-01-23 20:51 - 2016-04-27 06:17 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2017-01-23 20:51 - 2016-04-27 06:17 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2017-01-23 20:51 - 2016-04-27 06:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2017-01-23 20:51 - 2016-04-27 06:17 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2017-01-23 20:51 - 2016-04-27 06:17 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2017-01-23 20:51 - 2016-04-27 06:17 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2017-01-23 20:51 - 2016-04-27 06:17 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2017-01-23 20:51 - 2016-04-27 06:17 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys 2017-01-23 20:51 - 2016-04-27 06:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2017-01-23 20:51 - 2016-04-27 06:17 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-01-23 20:51 - 2016-04-27 06:17 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2017-01-23 20:51 - 2016-04-27 06:17 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2017-01-23 20:51 - 2016-04-27 06:17 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 03415040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 02331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL 2017-01-23 20:51 - 2015-10-30 08:19 - 02217984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe 2017-01-23 20:51 - 2015-10-30 08:19 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00253080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2017-01-23 20:51 - 2015-10-30 08:19 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceConnectApi.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 06471168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-01-23 20:51 - 2015-10-30 08:18 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 04143104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 04078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 03577344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 02849792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 02632192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 02195128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 02106368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certmgr.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01676288 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01557504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01552104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01537024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pla.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01535024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01336832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01240064 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01228800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01194496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2017-01-23 20:51 - 2015-10-30 08:18 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00963072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-01-23 20:51 - 2015-10-30 08:18 - 00846080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00824832 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00726288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00638304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys 2017-01-23 20:51 - 2015-10-30 08:18 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00535088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00516608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00503600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00453464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DbgModel.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl 2017-01-23 20:51 - 2015-10-30 08:18 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2017-01-23 20:51 - 2015-10-30 08:18 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00322560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysdm.cpl 2017-01-23 20:51 - 2015-10-30 08:18 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WmpDui.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys 2017-01-23 20:51 - 2015-10-30 08:18 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2017-01-23 20:51 - 2015-10-30 08:18 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe 2017-01-23 20:51 - 2015-10-30 08:18 - 00256192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Maps.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe 2017-01-23 20:51 - 2015-10-30 08:18 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2017-01-23 20:51 - 2015-10-30 08:18 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10_1.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usbceip.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2017-01-23 20:51 - 2015-10-30 08:18 - 00116216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00097088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00064584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Clipc.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msobjs.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe 2017-01-23 20:51 - 2015-10-30 08:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll 2017-01-23 20:51 - 2015-10-30 08:18 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 03350528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 03079168 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 02745856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 02476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 02103296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01965568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01603224 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01568768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 01540216 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01447784 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01338368 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01337184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 01144320 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00897024 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppinst.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00742200 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00528736 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcbase.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskeng.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsExt.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmdskmgr.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00259840 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhengine.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00209760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cic.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00131248 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcshext.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoipRT.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvc.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00087904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdport.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\filecrypt.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 2017-01-23 20:51 - 2015-10-30 08:17 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2017-01-23 20:51 - 2015-10-30 08:17 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2017-01-23 20:51 - 2015-10-30 08:17 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe 2017-01-23 20:50 - 2016-04-27 06:17 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-01-23 20:50 - 2016-04-27 06:17 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll |
24.01.2017, 09:53 | #10 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......Code:
ATTFilter 2017-01-23 20:50 - 2016-04-27 06:17 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-01-23 20:50 - 2016-04-27 06:17 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2017-01-23 20:50 - 2016-04-27 06:17 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-01-23 20:50 - 2016-04-27 06:17 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe 2017-01-23 20:50 - 2016-04-27 06:17 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2017-01-23 20:50 - 2016-04-27 06:17 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-01-23 20:50 - 2016-04-27 06:17 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 2017-01-23 20:50 - 2016-04-27 06:17 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00235008 _____ C:\WINDOWS\system32\MTF.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2017-01-23 20:50 - 2016-04-27 06:17 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2017-01-23 20:50 - 2016-04-27 06:17 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll 2017-01-23 20:50 - 2016-04-27 06:17 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe 2017-01-23 20:50 - 2015-10-30 08:19 - 03573248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 03555840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2017-01-23 20:50 - 2015-10-30 08:19 - 03459584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 01570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe 2017-01-23 20:50 - 2015-10-30 08:19 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00992256 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00918016 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmsdk.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00588320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmdev.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-01-23 20:50 - 2015-10-30 08:19 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll 2017-01-23 20:50 - 2015-10-30 08:19 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 03065344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2017-01-23 20:50 - 2015-10-30 08:18 - 03046400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 02563584 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-01-23 20:50 - 2015-10-30 08:18 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01865584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01537024 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01276928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01162144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01094656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 01033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00952320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl 2017-01-23 20:50 - 2015-10-30 08:18 - 00716640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2017-01-23 20:50 - 2015-10-30 08:18 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmIndexer.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00620176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00559616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00512816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnfldr.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl 2017-01-23 20:50 - 2015-10-30 08:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WLanConn.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00405856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2017-01-23 20:50 - 2015-10-30 08:18 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WmpDui.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authfwcfg.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\syncutil.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00312160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00268040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp 2017-01-23 20:50 - 2015-10-30 08:18 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe 2017-01-23 20:50 - 2015-10-30 08:18 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GnssAdapter.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00175120 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00170848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.exe 2017-01-23 20:50 - 2015-10-30 08:18 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00129888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys 2017-01-23 20:50 - 2015-10-30 08:18 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00107408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FingerprintEnrollment.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevDispItemProvider.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SCardDlg.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00064072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00057912 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe 2017-01-23 20:50 - 2015-10-30 08:18 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwcfg.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll 2017-01-23 20:50 - 2015-10-30 08:18 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CheckNetIsolation.exe 2017-01-23 20:50 - 2015-10-30 08:18 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 02874880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 02445312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 01465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe 2017-01-23 20:50 - 2015-10-30 08:17 - 01434112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 01098640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00904704 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipsecsnp.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\comuid.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00775344 _____ C:\WINDOWS\SysWOW64\locale.nls 2017-01-23 20:50 - 2015-10-30 08:17 - 00757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcsecproc_ssp.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00619520 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00600064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00465248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00422752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe 2017-01-23 20:50 - 2015-10-30 08:17 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00290856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe 2017-01-23 20:50 - 2015-10-30 08:17 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrokerLib.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpclean.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00124248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00100752 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthmodem.sys 2017-01-23 20:50 - 2015-10-30 08:17 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll 2017-01-23 20:50 - 2015-10-30 08:17 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2017-01-23 20:49 - 2016-04-27 06:17 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-01-23 20:49 - 2016-04-27 06:17 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2017-01-23 20:49 - 2016-04-27 06:17 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2017-01-23 20:49 - 2016-04-27 06:17 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2017-01-23 20:49 - 2016-04-27 06:17 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2017-01-23 20:49 - 2016-04-27 06:17 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-01-23 20:49 - 2016-04-27 06:17 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-01-23 20:49 - 2016-04-27 06:17 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys 2017-01-23 20:49 - 2016-04-27 06:17 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2017-01-23 20:49 - 2016-04-27 06:17 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys 2017-01-23 20:49 - 2016-04-27 06:17 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-01-23 20:49 - 2016-04-27 06:17 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe 2017-01-23 20:49 - 2015-10-30 08:19 - 28083144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 09375232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL 2017-01-23 20:49 - 2015-10-30 08:19 - 04170240 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 02578432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 01976832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 01140224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00879616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00546816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr 2017-01-23 20:49 - 2015-10-30 08:19 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00305296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceConnectApi.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDShServiceObj.dll 2017-01-23 20:49 - 2015-10-30 08:19 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vsstrace.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 06675968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-01-23 20:49 - 2015-10-30 08:18 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 04170752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 03053568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 02902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 02679808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 02641928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL 2017-01-23 20:49 - 2015-10-30 08:18 - 02548432 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01582592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmsipc.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01297408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe 2017-01-23 20:49 - 2015-10-30 08:18 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01159168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpedit.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcsecproc.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2017-01-23 20:49 - 2015-10-30 08:18 - 00862720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00836208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2017-01-23 20:49 - 2015-10-30 08:18 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00753664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00706048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00686984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00629760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00523264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00486400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00482816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\duser.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00482816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe 2017-01-23 20:49 - 2015-10-30 08:18 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00430816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00405504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 2017-01-23 20:49 - 2015-10-30 08:18 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wbemcomn.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe 2017-01-23 20:49 - 2015-10-30 08:18 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcfile.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00328520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl 2017-01-23 20:49 - 2015-10-30 08:18 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\polstore.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00273752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00252064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2017-01-23 20:49 - 2015-10-30 08:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe 2017-01-23 20:49 - 2015-10-30 08:18 - 00183896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00129368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2017-01-23 20:49 - 2015-10-30 08:18 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00069224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys 2017-01-23 20:49 - 2015-10-30 08:18 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Cortana.ProxyStub.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FwRemoteSvr.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe 2017-01-23 20:49 - 2015-10-30 08:18 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2017-01-23 20:49 - 2015-10-30 08:18 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IconCodecService.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 04212736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMM.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 02881536 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01951848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01847520 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01783808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01743872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01526784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\pla.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01479168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00958464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00871776 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00707424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00638816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00619296 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxApplicabilityEngine.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00550656 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00439128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe 2017-01-23 20:49 - 2015-10-30 08:17 - 00414559 _____ C:\WINDOWS\system32\ApnDatabase.xml 2017-01-23 20:49 - 2015-10-30 08:17 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2017-01-23 20:49 - 2015-10-30 08:17 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00337328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00254816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe 2017-01-23 20:49 - 2015-10-30 08:17 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00216408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00110552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevDispItemProvider.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Clipc.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll 2017-01-23 20:49 - 2015-10-30 08:17 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe 2017-01-23 20:49 - 2015-10-30 08:17 - 00030048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\genericusbfn.sys 2017-01-23 20:49 - 2015-10-30 08:17 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2017-01-23 20:48 - 2016-04-27 06:17 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2017-01-23 20:48 - 2016-04-27 06:17 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2017-01-23 20:48 - 2016-04-27 06:17 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-01-23 20:48 - 2016-04-27 06:17 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2017-01-23 20:48 - 2016-04-27 06:17 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2017-01-23 20:48 - 2016-04-27 06:17 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2017-01-23 20:48 - 2015-10-30 08:19 - 09375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL 2017-01-23 20:48 - 2015-10-30 08:19 - 04646400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe 2017-01-23 20:48 - 2015-10-30 08:19 - 03549184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 03301376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncCenter.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 01211392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 01186816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll 2017-01-23 20:48 - 2015-10-30 08:19 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 04268360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 03294208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 02527232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 02177024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 02144512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01915392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01562112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 01554152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01522152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01355344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01349128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 01083136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 00854016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00785920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00730352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00589856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00569744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00507904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnfldr.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 00431296 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00385376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2017-01-23 20:48 - 2015-10-30 08:18 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanui.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00357216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00306840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00300032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcbase.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsExt.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskeng.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2017-01-23 20:48 - 2015-10-30 08:18 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmdskmgr.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingMonitor.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cic.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcshext.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll 2017-01-23 20:48 - 2015-10-30 08:18 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe 2017-01-23 20:48 - 2015-10-30 08:18 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 01671168 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 01051136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagCpl.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 01040792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00994816 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2017-01-23 20:48 - 2015-10-30 08:17 - 00904704 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmIndexer.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00775344 _____ C:\WINDOWS\system32\locale.nls 2017-01-23 20:48 - 2015-10-30 08:17 - 00764976 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00705584 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe 2017-01-23 20:48 - 2015-10-30 08:17 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\filemgmt.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00527872 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanConn.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\authfwcfg.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbemcomn.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00458240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroleui.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00435712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00414232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00341944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00330080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2017-01-23 20:48 - 2015-10-30 08:17 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp 2017-01-23 20:48 - 2015-10-30 08:17 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe 2017-01-23 20:48 - 2015-10-30 08:17 - 00159648 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsutil.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00106928 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe 2017-01-23 20:48 - 2015-10-30 08:17 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00075448 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwcfg.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll 2017-01-23 20:48 - 2015-10-30 08:17 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys 2017-01-23 20:48 - 2015-10-30 08:17 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys 2017-01-23 20:48 - 2015-10-30 08:17 - 00033472 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2017-01-23 20:48 - 2015-10-30 08:17 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CheckNetIsolation.exe 2017-01-23 20:48 - 2015-10-30 08:17 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe 2017-01-23 20:48 - 2015-10-30 08:17 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MTConfig.sys 2017-01-23 20:47 - 2016-04-27 06:17 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2017-01-23 20:47 - 2016-04-27 06:17 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll 2017-01-23 20:47 - 2015-10-30 08:19 - 02731008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2017-01-23 20:47 - 2015-10-30 08:18 - 03679232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2017-01-23 20:47 - 2015-10-30 08:18 - 00435200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll 2017-01-23 20:29 - 2016-08-09 18:42 - 00000000 ____D C:\Users\Dragonfly\Documents\Projects 2017-01-23 20:29 - 2016-07-30 23:04 - 00000000 ___RD C:\Users\Dragonfly\Desktop\- 2017-01-23 19:36 - 2016-11-18 17:23 - 00000000 ____D C:\Users\Dragonfly\AppData\LocalLow\Mozilla 2017-01-17 15:54 - 2016-10-07 14:14 - 00000000 ____D C:\Users\Dragonfly\dwhelper 2017-01-02 14:10 - 2016-07-14 15:21 - 10328598 _____ (Nullsoft, Inc.) C:\Users\Dragonfly\Downloads\winamp5666_full_en-us_redux.exe ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-01-24 01:16 - 2017-01-24 06:28 - 0007616 _____ () C:\Users\Dragonfly\AppData\Local\resmon.resmoncfg ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-01-23 21:42 ==================== Ende von FRST.txt ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 22-01-2017 durchgeführt von Dragonfly (24-01-2017 09:39:54) Gestartet von C:\Users\Dragonfly\Desktop Windows 10 Home Version 1511 (X64) (2017-01-23 20:26:00) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-614321186-1851163967-905647231-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-614321186-1851163967-905647231-503 - Limited - Disabled) Dragonfly (S-1-5-21-614321186-1851163967-905647231-1000 - Administrator - Enabled) => C:\Users\Dragonfly Gast (S-1-5-21-614321186-1851163967-905647231-501 - Limited - Disabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Emsisoft Anti-Malware (Enabled - Up to date) {701CB209-EBBC-AADC-11E6-DE73E7AF4C9D} AS: Emsisoft Anti-Malware (Enabled - Up to date) {CB7D53ED-CD86-A552-2B56-E5019C280620} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Emsisoft Anti-Malware (HKLM\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 12.2 - Emsisoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.123 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games) League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 3.15.0414.1 - Vimicro) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) NVIDIA Grafiktreiber 369.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 369.09 - NVIDIA Corporation) NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.9.5 - Synaptics Incorporated) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {50EB80B4-0793-4AD7-880B-13CF2D3CE57A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-23] (Google Inc.) Task: {FC35B7C5-F263-4BA7-B430-A22F1D73449E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-23] (Google Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 ____N () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-01-23 21:17 - 2016-08-01 13:54 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-04-27 06:17 - 2017-01-23 20:53 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2017-01-24 01:54 - 2017-01-24 01:55 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-04-27 06:17 - 2017-01-23 20:53 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-04-27 06:17 - 2016-04-27 06:17 - 00093696 ____N () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-04-27 06:17 - 2017-01-23 20:49 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-04-27 06:17 - 2017-01-23 20:52 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-04-27 06:17 - 2017-01-23 20:52 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-04-27 06:17 - 2017-01-23 20:52 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-04-27 06:17 - 2017-01-23 20:52 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-01-24 01:54 - 2017-01-24 01:55 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2017-01-24 01:54 - 2017-01-24 01:55 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2017-01-23 20:55 - 2017-01-23 20:53 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-614321186-1851163967-905647231-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper -> $(runtime.windows)\Web\Wallpaper\Windows\img0.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run32: => "331BigDog" HKU\S-1-5-21-614321186-1851163967-905647231-1000\...\StartupApproved\Run: => "OneDrive" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [{5F2A0CDB-43ED-4F23-87D2-5FCC23AB5538}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{BF250A34-5A24-49D6-8698-DF9993664B60}C:\windows\system32\mmc.exe] => C:\windows\system32\mmc.exe FirewallRules: [UDP Query User{978339B8-8D4A-4EF1-BE90-837538EA8ADE}C:\windows\system32\mmc.exe] => C:\windows\system32\mmc.exe ==================== Wiederherstellungspunkte ========================= 23-01-2017 22:09:56 Microsoft Visual C++ 2005 Redistributable (x64) wird installiert ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Lenovo EasyCamera Description: Lenovo EasyCamera Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Chicony Service: vm331avs Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Microsoft Device Association Root Enumerator Description: Generisches Softwaregerät Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2} Manufacturer: Microsoft Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Qualcomm Atheros AR3012 Bluetooth 4.0 Description: Qualcomm Atheros AR3012 Bluetooth 4.0 Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Qualcomm Atheros Communications Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Microsoft GS Wavetable Synthesizer Description: Generisches Softwaregerät Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2} Manufacturer: Microsoft Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/24/2017 09:08:57 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (01/24/2017 09:08:53 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: SearchUI.exe, Version: 10.0.10586.63, Zeitstempel: 0x568b1fdc Name des fehlerhaften Moduls: Windows.UI.Xaml.dll, Version: 10.0.10586.71, Zeitstempel: 0x5699d8e0 Ausnahmecode: 0xc000027b Fehleroffset: 0x00000000006fce8b ID des fehlerhaften Prozesses: 0xdac Startzeit der fehlerhaften Anwendung: 0x01d276191700dba4 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Pfad des fehlerhaften Moduls: C:\Windows\System32\Windows.UI.Xaml.dll Berichtskennung: beee5f28-69a6-4673-94dd-567d6955e075 Vollständiger Name des fehlerhaften Pakets: Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy Anwendungs-ID, die relativ zum fehlerhaften Paket ist: CortanaUI Error: (01/24/2017 05:34:46 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35 Name des fehlerhaften Moduls: edgehtml.dll, Version: 11.0.10586.162, Zeitstempel: 0x56cd3d95 Ausnahmecode: 0xc0000602 Fehleroffset: 0x00000000004a5851 ID des fehlerhaften Prozesses: 0x15ec Startzeit der fehlerhaften Anwendung: 0x01d275faf8b28cf1 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\edgehtml.dll Berichtskennung: 01245a2d-b6cb-4750-95f2-1b5fe855ca3f Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (01/24/2017 05:33:10 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35 Name des fehlerhaften Moduls: edgehtml.dll, Version: 11.0.10586.162, Zeitstempel: 0x56cd3d95 Ausnahmecode: 0xc0000602 Fehleroffset: 0x00000000004a5851 ID des fehlerhaften Prozesses: 0xcd4 Startzeit der fehlerhaften Anwendung: 0x01d275fac07488be Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\edgehtml.dll Berichtskennung: 569b9f98-4557-4687-b457-000e87aeeacc Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (01/24/2017 05:31:35 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35 Name des fehlerhaften Moduls: edgehtml.dll, Version: 11.0.10586.162, Zeitstempel: 0x56cd3d95 Ausnahmecode: 0xc0000602 Fehleroffset: 0x00000000004a5851 ID des fehlerhaften Prozesses: 0x15d8 Startzeit der fehlerhaften Anwendung: 0x01d275fa7ec9c3bc Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\edgehtml.dll Berichtskennung: 72017a3c-39b0-48d7-aa89-9c44bbad21d6 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (01/24/2017 01:56:28 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC) Description: Bei der Aktivierung der App „Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (01/24/2017 01:23:56 AM) (Source: MSDTC Client 2) (EventID: 4361) (User: ) Description: Fehler des Cluster-API-Aufrufs mit dem Fehlercode: 0x800706D9. Cluster-API-Funktion: OpenCluster, Argumente: lpszClusterName: (null) Error: (01/23/2017 11:43:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC) Description: Bei der Aktivierung der App „Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (01/23/2017 11:25:34 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: SystemSettings.exe, Version: 10.0.10586.11, Zeitstempel: 0x56457cb1 Name des fehlerhaften Moduls: Windows.UI.Xaml.dll, Version: 10.0.10586.71, Zeitstempel: 0x5699d8e0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000023c018 ID des fehlerhaften Prozesses: 0x1a54 Startzeit der fehlerhaften Anwendung: 0x01d275c768039362 Pfad der fehlerhaften Anwendung: C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe Pfad des fehlerhaften Moduls: C:\Windows\System32\Windows.UI.Xaml.dll Berichtskennung: 2b4653e2-a5e0-4b02-a640-7d38792bce4c Vollständiger Name des fehlerhaften Pakets: windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoft.windows.immersivecontrolpanel Error: (01/23/2017 10:39:12 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC) Description: Bei der Aktivierung der App „Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App“ ist folgender Fehler aufgetreten: -2147024770. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Systemfehler: ============= Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Synchronisierungshost_487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/24/2017 01:56:28 AM) (Source: DCOM) (EventID: 10001) (User: Dragonfly-PC) Description: Ein DCOM-Server konnte nicht gestartet werden: App.AppXck5aaxyarfx8gxrgfk6pvakmmxeqvepc.mca als Nicht verfügbar/Nicht verfügbar. Fehler: "15616" Aufgetreten beim Start dieses Befehls: "C:\Program Files\WindowsApps\Microsoft.Messaging_1.10.22012.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer Error: (01/24/2017 01:30:45 AM) (Source: DCOM) (EventID: 10029) (User: NT-AUTORITÄT) Description: Das Zeitlimit für die Aktivierung der CLSID "{752073A1-23F2-4396-85F0-8FDB879ED0ED}" wurde überschritten, während auf das Beenden von Dienst "TrustedInstaller" gewartet wurde. Error: (01/24/2017 01:25:54 AM) (Source: DCOM) (EventID: 10010) (User: Dragonfly-PC) Description: Der Server "{0002DF02-0000-0000-C000-000000000046}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/24/2017 01:25:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_3dca0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/24/2017 01:25:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _3dca0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/24/2017 01:25:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_3dca0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2017-01-24 01:56:04.124 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Store signing level requirements. Date: 2017-01-24 01:56:04.116 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Store signing level requirements. Date: 2017-01-24 01:56:04.109 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Store signing level requirements. Date: 2017-01-23 22:13:12.937 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2017-01-23 21:21:04.596 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system. Date: 2017-01-23 21:21:04.591 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system. Date: 2017-01-23 21:15:36.505 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz Prozentuale Nutzung des RAM: 25% Installierter physikalischer RAM: 8053.6 MB Verfügbarer physikalischer RAM: 6032.96 MB Summe virtueller Speicher: 9973.6 MB Verfügbarer virtueller Speicher: 7916.26 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:930.91 GB) (Free:862.76 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 9BCA118F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=930.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=511 MB) - (Type=27) ==================== Ende von Addition.txt ============================ |
24.01.2017, 09:54 | #11 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......Code:
ATTFilter Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 22-01-2017 durchgeführt von Dragonfly (24-01-2017 09:40:19) Gestartet von C:\Users\Dragonfly\Desktop Start-Modus: Normal ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\Dragonfly\Documents () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\Dragonfly\Downloads () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\Dragonfly\Music () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\Dragonfly\Pictures () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\Dragonfly\Videos () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk -> Microsoft.Windows.Homegroup Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk -> Microsoft.Windows.Network Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\Dragonfly () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk -> C:\Windows\DevicesFlow\DevicesFlow.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk -> C:\Windows\MiracastView\MiracastView.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk -> C:\Windows\PrintDialog\PrintDialog.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Deinstallieren.lnk -> C:\Program Files\Emsisoft Anti-Malware\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Emsisoft Anti-Malware.lnk -> C:\Program Files\Emsisoft Anti-Malware\a2start.exe (Emsisoft Ltd) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Emsisoft Homepage.lnk -> C:\Program Files\Emsisoft Anti-Malware\Emsisoft.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Hilfe.lnk -> C:\Program Files\Emsisoft Anti-Malware\de-de.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\syswow64\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\Links\Desktop.lnk -> C:\Users\Dragonfly\Desktop () Shortcut: C:\Users\Dragonfly\Links\Downloads.lnk -> C:\Users\Dragonfly\Downloads () Shortcut: C:\Users\Dragonfly\Links\RecentPlaces.lnk -> L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ć ꀀz 匱卐뜥䟯ယ怂麌곫1 ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ Systemordner 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀ⴀ㐀㘀䄀ⴀ㤀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 Shortcut: C:\Users\Dragonfly\Documents\Projects\fl stuff\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\ASIO4ALL v2 Anleitung.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Anleitung.pdf (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Avira Launcher.lnk -> C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe () Shortcut: C:\Users\Dragonfly\Desktop\-\McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\McUICnt.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\OpenOffice 4.1.2.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Security Task Manager.lnk -> C:\Program Files (x86)\Security Task Manager\TaskMan.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\Dragonfly\Desktop\-\True Key.lnk -> C:\Program Files\Intel Security\True Key\application\truekey.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Windows 10-Upgrade-Assistent.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\Desktop\-\WinZip.lnk -> C:\Program Files\WinZip\WINZIP64.EXE (Keine Datei) Shortcut: C:\Users\Dragonfly\Desktop\-\Tor Browser\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk -> C:\Program Files\Emsisoft Anti-Malware\a2start.exe (Emsisoft Ltd) Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Public\Desktop\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe () ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> -sta {C90FB8CA-3295-4462-A721-2935E83694BA} ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} InternetURL: C:\Users\Dragonfly\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\Dragonfly\Favorites\Teen Babysitter Sydney Cole Fucks for Job - Pornhub.com.url -> BASEURL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4 URL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=70742 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Ideas.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72700 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Mail.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72681 InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Spaces.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72682 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Auto.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72680 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Fernsehen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72659 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Money.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72640 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Nachrichten.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72636 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Sport.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72635 InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72630 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\IE-Site auf Microsoft.com.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72186 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Deutschland GmbH.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72520 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Store.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=140813 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Windows - Start.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72629 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft zu Hause.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72406 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft.com durchsuchen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72893 InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Site für IE Add-Ons.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893 InternetURL: C:\Users\Dragonfly\Favorites\Links\Vorgeschlagene Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice InternetURL: C:\Users\Dragonfly\Favorites\Links\Web Slice-Katalog.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315 InternetURL: C:\Users\Dragonfly\Documents\Projects\fl stuff\deep_house_drum_samples\soundpacks.com.url -> URL: hxxp://soundpacks.com/ InternetURL: C:\Users\Dragonfly\Desktop\Neuer Ordner (2)\soundpacks.com.url -> URL: hxxp://soundpacks.com/ InternetURL: C:\Users\Dragonfly\Desktop\Neuer Ordner (2)\hidden_gems_massive_presets\soundpacks.com.url -> URL: hxxp://soundpacks.com/ ==================== Ende von Shortcut.txt ============================= |
24.01.2017, 10:03 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... Bitte ab jetzt meine Instruktionen RICHTIG lesen und RICHTIG umsetzen. Du solltest 1. noch kein weiteres AV installieren und 2. waren neue FRST-Logs auch nicht gefordert. Aber egal. 1. Schritt: Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers 2. Schritt: Kaspersky TDSS-Killer Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ Logfiles bitte immer in CODE-Tags posten |
24.01.2017, 16:05 | #13 |
| rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... hab beides nach anleitung durchgeführt aber weder tdsskiller noch Malwarebytes haben was gefunden. hier report von tdss: Code:
ATTFilter 12:07:38.0579 0x1414 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01 12:07:41.0048 0x1414 ============================================================ 12:07:41.0048 0x1414 Current date / time: 2017/01/24 12:07:41.0048 12:07:41.0048 0x1414 SystemInfo: 12:07:41.0063 0x1414 12:07:41.0063 0x1414 OS Version: 10.0.10586 ServicePack: 0.0 12:07:41.0063 0x1414 Product type: Workstation 12:07:41.0063 0x1414 ComputerName: DRAGONFLY-PC 12:07:41.0063 0x1414 UserName: Dragonfly 12:07:41.0063 0x1414 Windows directory: C:\WINDOWS 12:07:41.0063 0x1414 System windows directory: C:\WINDOWS 12:07:41.0063 0x1414 Running under WOW64 12:07:41.0063 0x1414 Processor architecture: Intel x64 12:07:41.0063 0x1414 Number of processors: 4 12:07:41.0063 0x1414 Page size: 0x1000 12:07:41.0063 0x1414 Boot type: Normal boot 12:07:41.0063 0x1414 CodeIntegrityOptions = 0x00000001 12:07:41.0063 0x1414 ============================================================ 12:07:41.0407 0x1414 KLMD registered as C:\WINDOWS\system32\drivers\49387004.sys 12:07:41.0407 0x1414 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 10586.162, osProperties = 0x19 12:07:41.0657 0x1414 System UUID: {BA761053-A871-8A1A-3A0E-D0D9996800FB} 12:07:41.0985 0x1414 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 12:07:41.0985 0x1414 ============================================================ 12:07:41.0985 0x1414 \Device\Harddisk0\DR0: 12:07:41.0985 0x1414 MBR partitions: 12:07:41.0985 0x1414 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 12:07:41.0985 0x1414 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x745D3C39 12:07:41.0985 0x1414 ============================================================ 12:07:42.0017 0x1414 C: <-> \Device\Harddisk0\DR0\Partition2 12:07:42.0017 0x1414 ============================================================ 12:07:42.0017 0x1414 Initialize success 12:07:42.0017 0x1414 ============================================================ 12:07:47.0368 0x1830 ============================================================ 12:07:47.0368 0x1830 Scan started 12:07:47.0368 0x1830 Mode: Manual; SigCheck; TDLFS; 12:07:47.0368 0x1830 ============================================================ 12:07:47.0368 0x1830 KSN ping started 12:07:49.0741 0x1830 KSN ping finished: true 12:07:50.0386 0x1830 ================ Scan system memory ======================== 12:07:50.0386 0x1830 System memory - ok 12:07:50.0386 0x1830 ================ Scan services ============================= 12:07:50.0667 0x1830 [ DF1C3D7E6C7929AD83BE22852B5B08CB, 9ECF6211CCD30273A23247E87C31B3A2ACDA623133CEF6E9B3243463C0609C5F ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys 12:07:50.0723 0x1830 1394ohci - ok 12:07:50.0755 0x1830 [ 2C5B3035B86770ADD2FE9BFBAF5B35A4, 19E16F9144FE3E33B5FF248CF0040AB079ACAE22290B1369CC72AE4CB5FE3A90 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys 12:07:50.0755 0x1830 3ware - ok 12:07:51.0154 0x1830 [ D57CE14F8A32EECD2F0D76761ED0744E, 116F23D7CF035CE0E46A1EB294F983A59AAC051F9CD2BE415604F6C8535AB07B ] a2AntiMalware C:\Program Files\Emsisoft Anti-Malware\a2service.exe 12:07:51.0320 0x1830 a2AntiMalware - ok 12:07:51.0414 0x1830 [ 469441BAE3FF8A16826FC62C51EF5E18, E1204677B87F47222D05F670F8DF3DB65EA0881782A8DCFBE0103478ED71187C ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys 12:07:51.0447 0x1830 ACPI - ok 12:07:51.0476 0x1830 [ 7EADED8087C392876521F7EBCE846EF4, 99BF1BD948F97C1ECBC049C7F949B71D73D0B41FB505B2F75B208E655F7DC8A3 ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys 12:07:51.0489 0x1830 acpiex - ok 12:07:51.0523 0x1830 [ C498887123327CDFD73A05E7A2780920, B45392C46254FCB8D79B6C3A82C8D894063199E6167D8E5F7EA7D60C75CD16EA ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys 12:07:51.0535 0x1830 acpipagr - ok 12:07:51.0561 0x1830 [ C8DBE6EFFCF014CAA010B9BDDAC833EC, 96FC29340C62A6B0910DCCBF8945F32089FC300F45B451A540B8854D53734298 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys 12:07:51.0573 0x1830 AcpiPmi - ok 12:07:51.0591 0x1830 [ 17039DBEB3B7B9ADCDB4B4533AA9771F, A4D38B144639A20B8B31E4F35FB776A028DB502FAC849FC73EECEB3CCD91830B ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys 12:07:51.0603 0x1830 acpitime - ok 12:07:51.0659 0x1830 [ E13DE7CD2B62254DD4FF658B7798A37D, 9FCCC90DEF6BE83F8C41D4552D235A7BB5534954D2E7CB7B1C336A31FCCAB3AD ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys 12:07:51.0674 0x1830 ACPIVPC - ok 12:07:51.0740 0x1830 [ F7D0CD345D2DA42E7042ABCD73662403, 03183F90A994D69066F15C3DFC1D7D7514AEAF46A5AAC059B1FB327F8C30A35C ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS 12:07:51.0777 0x1830 ADP80XX - ok 12:07:51.0809 0x1830 [ 70148EFA9A562E7185B75BBE7D376BF7, 8200E3349A1AFA1040B3D956A17BAF3CDC784A1A3CA396125E7872B36C03D84A ] AFD C:\WINDOWS\system32\drivers\afd.sys 12:07:51.0824 0x1830 AFD - ok 12:07:51.0856 0x1830 [ 870F1A2C936F92B5D053DF7EC75B352F, D617524FD5886D6D3BC2EFBBB5EA310E906454CD7CA7257C3D7BDEA8C4F2DA71 ] agp440 C:\WINDOWS\system32\drivers\agp440.sys 12:07:51.0871 0x1830 agp440 - ok 12:07:51.0903 0x1830 [ 3DF7751D5DC6525E7DC6617FBB45054F, 8E6D4C809DB3B66E7558C4829E01F5C227EE614AC82F33FD99DCC629770D1BE3 ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys 12:07:51.0918 0x1830 ahcache - ok 12:07:51.0949 0x1830 [ 19707ECBCEA71080A85DB2336580DB39, A09AE69C9DE2F3765417F212453B6927C317A94801AE68FBA6A8E8A7CB16CED7 ] AJRouter C:\WINDOWS\System32\AJRouter.dll 12:07:51.0949 0x1830 AJRouter - ok 12:07:51.0981 0x1830 [ AA91A5E156D0364ABA7B01658C2EB014, F61055D581745023939C741CAB3370074D1416BB5A0BE0BD47642D5A75669E12 ] ALG C:\WINDOWS\System32\alg.exe 12:07:51.0996 0x1830 ALG - ok 12:07:52.0030 0x1830 [ B70F0F2F54B4A4DB6E9C830454752F5A, C882DEAC30812E5FA4479A8CB688603C6AF269EF08236688F4C5E7EBED1D4572 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys 12:07:52.0043 0x1830 AmdK8 - ok 12:07:52.0057 0x1830 [ 35E890482C9728DD5C552B85DA8A5AB2, 1E0EB7D902AB4C38E23CAFC0BEA250E7F6E180E8814385B4F29730BFC373A191 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys 12:07:52.0072 0x1830 AmdPPM - ok 12:07:52.0096 0x1830 [ 5B30BCFE6E02E45D3EE268FF001BC5E0, 9901DB728885CE36911F79998629B2DD42D56AF9633B5277834F498CC59B0346 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys 12:07:52.0107 0x1830 amdsata - ok 12:07:52.0139 0x1830 [ F20B30F35A5C7888441B4DCA001ECF8E, 695A5BC1F18B65992EB06A202AD3CBFA17228E76DDFD1AE6977FD315724F75C2 ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys 12:07:52.0170 0x1830 amdsbs - ok 12:07:52.0194 0x1830 [ AFE838D7576C581D6483529621AB10CC, 14476A04CC64E7A0F1BBFDACCBD7A87F384BE1877C27656DBB973AF3975D4AE2 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys 12:07:52.0203 0x1830 amdxata - ok 12:07:52.0242 0x1830 [ EDDB0D726DBECDFC1DBCC6DB464E5A13, 98D128D1E6FA270ED9ADBFE50078F68A794C00D4CBB86E28EC6161FFAD0CA8FF ] AppID C:\WINDOWS\system32\drivers\appid.sys 12:07:52.0259 0x1830 AppID - ok 12:07:52.0281 0x1830 [ 7A55F9237F726D1667073A47B0D1B90F, 7C2D9AA84F1D4CC6C1FAF6848DF9479A534E01029C4387E8C0647745F1E74603 ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll 12:07:52.0299 0x1830 AppIDSvc - ok 12:07:52.0326 0x1830 [ 56E219DF92BE16F62308F884739BE022, FE189EE8A52BC5A0E6B76C632021F84F60307A182F2A67C0C0C7CAA72DEFC723 ] Appinfo C:\WINDOWS\System32\appinfo.dll 12:07:52.0351 0x1830 Appinfo - ok 12:07:52.0381 0x1830 [ 610499A73DF3599608EBB6B3F9929052, A9CA49C4A39A825916AB3791090BCFC7044FDB6B2C3538E01F0CFBC2A9931152 ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll 12:07:52.0427 0x1830 AppReadiness - ok 12:07:52.0537 0x1830 [ 3DF25A56F18D2AB4CF58C1300C8CD323, 34A20004A93BC0F22BF99E56E6657CF0A68B64B375A66408FB1E26ADA7A72FC4 ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll 12:07:52.0599 0x1830 AppXSvc - ok 12:07:52.0615 0x1830 [ E3FE8F610B1CC12BC3B2E6BC43DC97E2, 0E18542CF2095A9ADA1759AB8F986E78B0A50A3C6B2AD4EACD80A23D832A2C6D ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys 12:07:52.0631 0x1830 arcsas - ok 12:07:52.0646 0x1830 [ 5E00748A1AD246CAECBBB7553BED36CC, DAD2C93F0894E7BB5E5D8D767D8286A909086B49172C504A01097C3A180998C6 ] AsyncMac C:\WINDOWS\System32\drivers\asyncmac.sys 12:07:52.0662 0x1830 AsyncMac - ok 12:07:52.0709 0x1830 [ 492B99D2E3D5D7BFD5F0AE1BE7BD37DD, A3F6BFC4FDC1933FBF3145019B118689A414108B04F43E2563946B2673C89324 ] atapi C:\WINDOWS\system32\drivers\atapi.sys 12:07:52.0709 0x1830 atapi - ok 12:07:52.0865 0x1830 [ 41DFF214D30294F18F64257167F1CCBA, 87BB8BC1AB5EC4F5DAD84CB0B16CDD4634F10DC687264E4C84E47EFEFF4310F6 ] athr C:\WINDOWS\System32\drivers\athw8x.sys 12:07:52.0990 0x1830 athr - ok 12:07:53.0052 0x1830 [ 42BF7FA295F453618104B5A50BEE105B, AB44BA2AD2FC5AF3B6BE4489C444C03FD1AB02C22109BF5F39BE459294C4CB18 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll 12:07:53.0084 0x1830 AudioEndpointBuilder - ok 12:07:53.0146 0x1830 [ 9610CE53A9ED0789C8B669A5F86008F7, 9EE4B3F8528B20682595DDBDB0FF9F98FD8B957EE4C335FDD4382AE30D3C2EA0 ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll 12:07:53.0187 0x1830 Audiosrv - ok 12:07:53.0234 0x1830 [ 7062CE507814D5306DCA5D6A15B7B6B6, 9D60506003A66C2E516B1FCB70CC5B26FB3A9948B95D97C828DD0328E76F2C91 ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll 12:07:53.0249 0x1830 AxInstSV - ok 12:07:53.0296 0x1830 [ 6447BA6FA709514B6C803D159B4C7D1E, 549DDCEAD93DF333F6BBD56A9258A867E4DA219741C00D48C68F8F230A87B11A ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys 12:07:53.0327 0x1830 b06bdrv - ok 12:07:53.0359 0x1830 [ B4AC08B1D04D0CE085435E5CD0E663C5, 61E641388E5692B2EB351E44BA1DB86B5305DD105EE56865D59072CA9407C8AC ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys 12:07:53.0374 0x1830 BasicDisplay - ok 12:07:53.0390 0x1830 [ 25B5BB369DEE2BAE4BF459C978FF9035, DBC2157B2AC0BC92B4011CE5E01F2DCDAAE71E37D9D21102503C6455FAAC4DCA ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys 12:07:53.0405 0x1830 BasicRender - ok 12:07:53.0437 0x1830 [ 3F5523DCEFE42B385659C5CB46A6B810, CA24A3DF002B19E7BDEDE9B5EB60623F299D0E78B2E4F58DCFC028D76DEFE52D ] bcmfn C:\WINDOWS\System32\drivers\bcmfn.sys 12:07:53.0452 0x1830 bcmfn - ok 12:07:53.0452 0x1830 [ 0B750A6A6D847E73CA48ADD7A0F5A393, 6A43020F23846EFB1AFA3C070465B0059E9DF60DEB16899E09559462DF30939F ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys 12:07:53.0468 0x1830 bcmfn2 - ok 12:07:53.0515 0x1830 [ F8F398A4AF7E0917320BC2B2CD812888, 02B9A6EA0AA750CA9B62AB09E99956C35E252A12B22C2CBFDC4E941ED5870591 ] BDESVC C:\WINDOWS\System32\bdesvc.dll 12:07:53.0562 0x1830 BDESVC - ok 12:07:53.0593 0x1830 [ 5A88834AEE15D97695FAE0837B73B3E4, 03035FB51DE218B8EDB15129A0376DDED0C7E7B6DA58DD95B12E4E5C8D852ED8 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 12:07:53.0609 0x1830 Beep - ok 12:07:53.0671 0x1830 [ 8EA08141590CB9331FA773FB430E91E4, 0507499EF423CC9EE9AC18C2B5CBF9965E69481C69DC96E361C2184C53C3F404 ] BFE C:\WINDOWS\System32\bfe.dll 12:07:53.0702 0x1830 BFE - ok 12:07:53.0749 0x1830 [ 64582C924C48175D52AED0D0E64AB413, 75DC6BC01D26A4BABEDB8013F0C106780F0991CA63075798C7C24B66022F58E3 ] BITS C:\WINDOWS\System32\qmgr.dll 12:07:53.0780 0x1830 BITS - ok 12:07:53.0827 0x1830 [ DA2C6F7ACE392193C424FEA975C5BFFB, 668F91F3E5F8EA170C10823D6959E0EDB32434C51FAA68BEA782EDDF5618690E ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys 12:07:53.0843 0x1830 bowser - ok 12:07:53.0890 0x1830 [ 9972A886D911234F833A265D5D641D30, E64199AB64CC60C75371D8421031DC02818C852427C4F66AD3DF7DCDF33952B1 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll 12:07:53.0905 0x1830 BrokerInfrastructure - ok 12:07:53.0952 0x1830 [ DA4C9335434E71D6CC86A3CA567769CC, 9FE5EE3CC91CADBF952446E0A9A79A8834B03C8D4C47D6E9257AF64B2C17F518 ] Browser C:\WINDOWS\System32\browser.dll 12:07:53.0968 0x1830 Browser - ok 12:07:54.0015 0x1830 [ C8BF11D79B29BB23A461B65B58BA8593, 35AFAD5ED40304976287E6C982085DF7A91FF48F0320DAC32370FA039AA03C69 ] BtFilter C:\WINDOWS\system32\DRIVERS\btfilter.sys 12:07:54.0046 0x1830 BtFilter - ok 12:07:54.0093 0x1830 [ CAEC7BC11AF69A181AF7932E636E09E4, 503C69045F1E025CBEE2405043BB71CC58478985ECAF6587F73FCB57860F5709 ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys 12:07:54.0109 0x1830 BthAvrcpTg - ok 12:07:54.0124 0x1830 [ 36417FC4F11C31C880CB428037DEDF3F, ACDB798A038E3D5CC350AC53A9EC8E14AD02E2C28AE4578EC0205E6DF537A8F9 ] BthEnum C:\WINDOWS\system32\DRIVERS\BthEnum.sys 12:07:54.0140 0x1830 BthEnum - ok 12:07:54.0171 0x1830 [ 5F2B4B32E986C058525D3BA2A475A16C, CEC5BB0B025DD9525CFBBEDF6EB6F63336534798495A4F95763CE112DF915088 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys 12:07:54.0187 0x1830 BthHFEnum - ok 12:07:54.0218 0x1830 [ 5406289E8AE2CB52FC408154E0A64BA7, 0A3795F2E6E2B51198452CF69A99159D8E11650E95F41DF0B575CB72F9C6C6B5 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys 12:07:54.0234 0x1830 bthhfhid - ok 12:07:54.0249 0x1830 [ BAB101E7826BE287F79C4BA721621989, E6DD25C89267FE87253B8226292F2894F5E702075D3B23B09339D3B28744C060 ] BthHFSrv C:\WINDOWS\System32\BthHFSrv.dll 12:07:54.0283 0x1830 BthHFSrv - ok 12:07:54.0315 0x1830 [ CC6C1393B423EBFF9F6696CB9CC4CBCB, AB1861727631EDDD5B8404C51E75A67CAA42FD640E067A6ECC07EF0FCC871840 ] BthLEEnum C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys 12:07:54.0333 0x1830 BthLEEnum - ok 12:07:54.0366 0x1830 [ A76F20CCCA31895A1DA78A875E50F946, ECD4B3670DA5984AA24F4354457B4E45983938A89FF6DB03B556A633B4B37E3C ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys 12:07:54.0379 0x1830 BTHMODEM - ok 12:07:54.0428 0x1830 [ 09C3DB1B137B269A822F941D867A6BB6, CC99FBD76DA19D951864D4967EA9F3C048811E9BB7BBB67B724FC82A50B14516 ] BthPan C:\WINDOWS\System32\drivers\bthpan.sys 12:07:54.0442 0x1830 BthPan - ok 12:07:54.0482 0x1830 [ CEFF59649E90987D263D96078724A54A, 3EB69F0BA282085682FB09F1469BF66A84229D8C7A044C6B98B78477716917EE ] BTHPORT C:\WINDOWS\system32\DRIVERS\BTHport.sys 12:07:54.0516 0x1830 BTHPORT - ok 12:07:54.0539 0x1830 [ 7A177E18AA6A6A6365E6351C2BF8EDAE, A35224A20014B1215A6824AE5E17B8869A775EA272EF7F25EAFFA18733F8D09D ] bthserv C:\WINDOWS\system32\bthserv.dll 12:07:54.0539 0x1830 bthserv - ok 12:07:54.0558 0x1830 [ 0D279373091AA1BBEEE958AAF02B5EDF, 79CEBC2D9345103958DC161C31AC4BE078626D6DC28F6F06C432917872A1E3B4 ] BTHUSB C:\WINDOWS\system32\DRIVERS\BTHUSB.sys 12:07:54.0570 0x1830 BTHUSB - ok 12:07:54.0630 0x1830 [ BF89BDBA5D3A0B4256D3F6FC8D31880D, 940F3BF55B88261C9E9A951A092331559FC5B24FE3BA0F1E1AB3450D2CA364C1 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys 12:07:54.0645 0x1830 buttonconverter - ok 12:07:54.0676 0x1830 [ C24C27FDF93B85A4EFCF25F830253AA2, 35C87518BB59663B57C2361A13AD4E57E37392598F1EB9F07F86CA5A6321AF5A ] CapImg C:\WINDOWS\System32\drivers\capimg.sys 12:07:54.0719 0x1830 CapImg - ok 12:07:54.0751 0x1830 [ 7F9C7226D743B232907ED2537B8A574F, 2211AFC30E8F8FA03020DB48EE14914CD31E50BB6A63FF20AC7C6FA481E72C18 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys 12:07:54.0766 0x1830 cdfs - ok 12:07:54.0797 0x1830 [ 0A92DC116CFC7F6BE8167DD25CB925CC, 50CAC7BE14FF69B10C029E049F7C441A5572540F027F95F940B185C76C689409 ] CDPSvc C:\WINDOWS\System32\CDPSvc.dll 12:07:54.0813 0x1830 CDPSvc - ok 12:07:54.0844 0x1830 [ 82D97776BF982AA143BDC7DFB5054EA8, 954F56728371E6B3514586DCEAF15C4727BAED6CAFBF788654C4E03BD702942C ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys 12:07:54.0860 0x1830 cdrom - ok 12:07:54.0891 0x1830 [ 4E9158CECF77A029AB98E8FBB43FCED5, AFF8BDB8F8F8DDF4FC0D65712E031DC360856CD3CE5C8A4C8FF960388F37462F ] CertPropSvc C:\WINDOWS\System32\certprop.dll 12:07:54.0907 0x1830 CertPropSvc - ok 12:07:54.0945 0x1830 [ 0505C1D991D0F9D47F3353BB98597C7E, 3B801CCF4980256327A4A9FBD98007DA1E3ACE9C94E5A4C23AB21303B46E8B5A ] circlass C:\WINDOWS\System32\drivers\circlass.sys 12:07:54.0956 0x1830 circlass - ok 12:07:54.0993 0x1830 [ 8B4B39C507ABA09AAFE8E3932D1B392C, 734700155A658BC08FC96E8F99A01DE7F7251D7DDEFA79D258B2EEB370BA7AA8 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys 12:07:55.0010 0x1830 CLFS - ok 12:07:55.0075 0x1830 [ F7526C133AC265F283012E9CD751F873, 6AABDD92FD880F49F63C1CC478C3D8291AF670802CEC58B32730E7675D858D88 ] ClipSVC C:\WINDOWS\System32\ClipSVC.dll 12:07:55.0097 0x1830 ClipSVC - ok 12:07:55.0131 0x1830 [ 95832B049E2833B9F5189823CDF946C7, 72773A42A89220B4A6AC72D1633B16F11191A44D876A44FAB5CEFB717CE3223D ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys 12:07:55.0142 0x1830 CmBatt - ok 12:07:55.0168 0x1830 [ A1105260EEEE3DBD8D38FD054B22BD00, CA943B0B03527B07690CAFFD53F8ABF14FB3974DAAA1036E54815BD0DAF803D8 ] CNG C:\WINDOWS\system32\Drivers\cng.sys 12:07:55.0189 0x1830 CNG - ok 12:07:55.0210 0x1830 [ 58D640BC2294C71BDE0953F12D4B432F, 0B3B7659FCB97791A2A1F895C8E6F9078F855C94C13EB47464492588C4B02B85 ] cnghwassist C:\WINDOWS\system32\DRIVERS\cnghwassist.sys 12:07:55.0210 0x1830 cnghwassist - ok 12:07:55.0391 0x1830 [ 14F9883588398A1BDE49C75098C75DE6, D9D82DE89FAFE60BC902683BC44C7555533A030150FD5E5A35A24542FACC5CAD ] CompositeBus C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_912dfdedc3d2f520\CompositeBus.sys 12:07:55.0422 0x1830 CompositeBus - ok 12:07:55.0422 0x1830 COMSysApp - ok 12:07:55.0437 0x1830 [ 02B8E49148DE5E0A2F6FDF28CE94A6AC, EEA405823F441CA604BEAA44EB71A1D20BC80E124FF7B27380D0201AAF2E0849 ] condrv C:\WINDOWS\system32\drivers\condrv.sys 12:07:55.0453 0x1830 condrv - ok 12:07:55.0531 0x1830 [ DE6DF2C34718EADCFF8776E597F2104D, 35D03E95853CEAC69F674FB09C819A4698EBEDFD8AC0474F0ADF02741492401E ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll 12:07:55.0562 0x1830 CoreMessagingRegistrar - ok 12:07:55.0719 0x1830 [ A28D6FA203CE094BDE7ED8CEC6079E42, 5DCA8BA21F5FD0D9F00620E7592949ABCF3BA202CF7AF3D84F93DF7C13E2D4C9 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe 12:07:55.0753 0x1830 cphs - ok 12:07:55.0806 0x1830 [ 2CE0D74AED86A372997E9D77AE10B9F5, 1AFAA22C68FD0B81F73CE0EB763AD77AB97E78916752843A5056E1352F0FEA82 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll 12:07:55.0830 0x1830 CryptSvc - ok 12:07:55.0862 0x1830 [ 2619DC483579DB9FE804044C1ADFFD1A, 23A5420288735A980917091532BE7BB36EB51660AA4555C615AF736357EB02EC ] dam C:\WINDOWS\system32\drivers\dam.sys 12:07:55.0876 0x1830 dam - ok 12:07:55.0935 0x1830 [ B339861C6A2A86FBCA67C2006B461473, 228ADC8A8603C0A4342C6CBC6F2CC919271D42391365061AF660E0D7151C66A4 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 12:07:55.0977 0x1830 DcomLaunch - ok 12:07:56.0018 0x1830 [ 620921E77351FB651632322AD2C195C4, 5A98971995D7A2B5AE6BEA69344FCC6687B582FEF74BDA206D32FB2E6CEB0478 ] DcpSvc C:\WINDOWS\system32\dcpsvc.dll 12:07:56.0038 0x1830 DcpSvc - ok 12:07:56.0081 0x1830 [ 6129EA4294C5C69E4665801E95B16AB2, CE419186CF0F57434426FF925A09F13BE87639679CBB5F2074B0E1A243349D27 ] defragsvc C:\WINDOWS\System32\defragsvc.dll 12:07:56.0110 0x1830 defragsvc - ok 12:07:56.0147 0x1830 [ D12B9B6A6C4885824876422AACC89954, 5853ED5CAF84B7AAFF3EDC5C71FE23EB121DB681D81267D77118424BA9AB6F88 ] DeviceAssociationService C:\WINDOWS\system32\das.dll 12:07:56.0166 0x1830 DeviceAssociationService - ok 12:07:56.0203 0x1830 [ 15BA68662CED4B0618010A54478E18E5, 1B913BFA7AA11F3A82D80E95FC4857B810D341F9E68545710F90EBE44DAC1DF8 ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll 12:07:56.0223 0x1830 DeviceInstall - ok 12:07:56.0265 0x1830 [ 5BF8BD9B19D665452494C8D56DF4B28D, E5FC649207EF42C04B6737D442FECD3383E82F8998B140319FF400773F1D0978 ] DevQueryBroker C:\WINDOWS\system32\DevQueryBroker.dll 12:07:56.0280 0x1830 DevQueryBroker - ok 12:07:56.0312 0x1830 [ C9478D7DB7BE5D7ACE65CB1167F07320, D5082D09EE62E34A195768040B741E22ACC9421CFF315423D77A63ABF8F5E39E ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys 12:07:56.0340 0x1830 Dfsc - ok 12:07:56.0365 0x1830 [ 5841A361D28069DFC82E1E98040FDC3F, 3A48DB7ADE90654242CB54DAD07F5FF0CD5CABF372C50D5B2C4D7AED068986E1 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll 12:07:56.0381 0x1830 Dhcp - ok 12:07:56.0475 0x1830 [ 9F5AC03F5A0000DD96FA29CD68A6605B, 6964E077635E65DA902CA6C69E704A9DCD5856D22BA75E1CF823E63E62266AF7 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe 12:07:56.0490 0x1830 diagnosticshub.standardcollector.service - ok 12:07:56.0553 0x1830 [ 15D174719872A30F2FDD6B5B1B8BA5D9, B0E6FF6FC47B731C204F110D4B768231906B144B31F602ECE8EAC24D70BA880D ] DiagTrack C:\WINDOWS\system32\diagtrack.dll 12:07:56.0584 0x1830 DiagTrack - ok 12:07:56.0615 0x1830 [ 4904B152E4942BF700F2D73228B4D477, 0E5646DCA05A24C71F057C9F9F64AE992D338DA72DF3126175C2FA178854C30F ] disk C:\WINDOWS\system32\drivers\disk.sys 12:07:56.0631 0x1830 disk - ok 12:07:56.0678 0x1830 [ 49F069E2D22F33955A69D44DFD1B5179, 739C52C7B961BA683E8C7CCDB0E95423C17561B2F1F506BAE923DC53DB96B067 ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll 12:07:56.0694 0x1830 DmEnrollmentSvc - ok 12:07:56.0709 0x1830 [ 0197AE4B9790A4E73751CACFAA480126, 86BBB398F1A93754B2C329271F13A88FD2F285F30225C38F068F565CCA14EB9F ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys 12:07:56.0725 0x1830 dmvsc - ok 12:07:56.0772 0x1830 [ 5EF8EC71A7A91F3DF7798BEFE6786B0E, A3A56B43C72926881C66B7A17C9EAA35C2D9603C8D3849438838536BCD3F4633 ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll 12:07:56.0787 0x1830 dmwappushservice - ok 12:07:56.0819 0x1830 [ 570BB222E3AFC4407636B53F6EABFA70, D0194A128370BB0A337B61402F9EEDD6F7942ADB19BF672D0F92DA2DA563D0DD ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 12:07:56.0850 0x1830 Dnscache - ok 12:07:56.0881 0x1830 [ 1B15297A3A2CAB6BD586676154F389D8, 623D5F5FC8622B7D9AEEEB1787E6846C1570F0EEF94341239440B616D09D672A ] dot3svc C:\WINDOWS\System32\dot3svc.dll 12:07:56.0897 0x1830 dot3svc - ok 12:07:56.0928 0x1830 [ 316C2D8B8E3C0727969F1C3790EF7193, 631F8578FDB26578C8436E4B9C4DF21E1F58FCFE6DA66E5769AAC3739005D465 ] DPS C:\WINDOWS\system32\dps.dll 12:07:56.0944 0x1830 DPS - ok 12:07:56.0990 0x1830 [ 25FA06D3B49D6ADF8E874FFCDCD76B50, 9AF09B96ED79D94EA36581ABE6CC73313A72891779774B15860D018BEA2BBA0F ] drmkaud C:\WINDOWS\system32\DRIVERS\drmkaud.sys 12:07:57.0022 0x1830 drmkaud - ok 12:07:57.0053 0x1830 [ 16EE6701115BECF8C657D9D6E123F6A1, 16E115B5245C3C988F8B58B90D30F183021C7C7792D3D1C74BEC606E49672B2A ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll 12:07:57.0069 0x1830 DsmSvc - ok 12:07:57.0115 0x1830 [ FBC8C56814642A7CA88ACBCA8DD1121F, 108690704A359991C3D6577477E232F5F2F46B36DF6B4B0738A893EF05D7D4EB ] DsSvc C:\WINDOWS\System32\DsSvc.dll 12:07:57.0147 0x1830 DsSvc - ok 12:07:57.0225 0x1830 [ F45665E77D11F3C1552EDBEAD1559DC8, C7C4B493CB36A1A35B8CA33C044BA0ED273CDA80E36F48BFF7CE3A0356246838 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys 12:07:57.0272 0x1830 DXGKrnl - ok 12:07:57.0303 0x1830 [ 0CDF6B61D7F7FFCD195AF0113B9B2C16, 828D3FA31742B54075EAED2E67BBB5166D2EF4F84B791077E96DC0BD5557F11E ] Eaphost C:\WINDOWS\System32\eapsvc.dll 12:07:57.0319 0x1830 Eaphost - ok 12:07:57.0444 0x1830 [ 491275B864B704B54EC08168344E0F38, B4849400C3F819CF7809A2001EA2ECB527022483F7DFE31C3930F951EAFE50CE ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys 12:07:57.0537 0x1830 ebdrv - ok 12:07:57.0553 0x1830 [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] EFS C:\WINDOWS\System32\lsass.exe 12:07:57.0569 0x1830 EFS - ok 12:07:57.0600 0x1830 [ CEF108FCE06892CFA5F1B49527D4BF49, FA337584024B6E6EE4AF519F57FFA4C0FCA19EDC148FF309336C4CCA8F9C9CE8 ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys 12:07:57.0600 0x1830 EhStorClass - ok 12:07:57.0666 0x1830 [ 5B1EAAE3001A7A320C106FC3859F4111, 700BA2C7D4DFAFFEB78D3804B310A4EE5B4295C84600442665693FF661673951 ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys 12:07:57.0677 0x1830 EhStorTcgDrv - ok 12:07:57.0710 0x1830 [ E34DEFC09F2843C2C24C2248F1ABE6D8, 1FD67EB5820A1D2F4402DE9D95DE288DB69D421A8473074FF23491D7CA8B5ACE ] embeddedmode C:\WINDOWS\System32\embeddedmodesvc.dll 12:07:57.0725 0x1830 embeddedmode - ok 12:07:57.0758 0x1830 [ 062152DD5B225518A991DFCD8536770C, 5C8EF4E0C7DE3B24387FF239A8D0CDA39C2376826F16EAFF09739A6C7EDA01E0 ] EntAppSvc C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 12:07:57.0778 0x1830 EntAppSvc - ok 12:07:57.0896 0x1830 [ 0E840AA66CAB02CBA9730C772BBE305B, 8862583E653D13D1D10A1A4A33704E4F70576E80370943AAFD1EAED6657A0104 ] epp C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys 12:07:57.0905 0x1830 epp - ok 12:07:57.0936 0x1830 [ 7A2705148A4BB3CA255F81624338B461, 68AC8F8D2DD8AA4E8F2224A0054DE2AF67EA199217E87CD3C7299B021048F14F ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys 12:07:57.0947 0x1830 ErrDev - ok 12:07:57.0990 0x1830 [ 17BE4A35829B37C742084DC02D48E5F0, 7FDA62B56DF585C3F2C6FFB10AC7C0D8F70FA921C4DEA47B2789745CFE2618CE ] EventSystem C:\WINDOWS\system32\es.dll 12:07:58.0006 0x1830 EventSystem - ok 12:07:58.0037 0x1830 [ DFE8A33FBCF6F38182631A4D6097B92D, F9D06780830E74FD5309E6DC5C3EEDB9334A8AE284F381FA91EF2729297F8632 ] exfat C:\WINDOWS\system32\drivers\exfat.sys 12:07:58.0053 0x1830 exfat - ok 12:07:58.0084 0x1830 [ 03DE0EC072C5EBD5B018CAD83F1E522A, 9D0B30A2870FBA20B95017CE3A4205F2DD53FE169A0D16715E962D83DE040FB3 ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys 12:07:58.0099 0x1830 fastfat - ok 12:07:58.0146 0x1830 [ 952F10D2116B91BA433842D07879AE7A, 9E1EC0C719877EF198AA4DDBE896E9DDEAD360AAC1FC6DF305E7C5C73C7A761D ] Fax C:\WINDOWS\system32\fxssvc.exe 12:07:58.0178 0x1830 Fax - ok 12:07:58.0209 0x1830 [ 2C003DA244EDF9BC3FD058DCB3422798, 78F2A4143E1A0273DF4F778AE9E1C3CEC1F91501114367EE91DADB2D9A7CDC0D ] fcvsc C:\WINDOWS\System32\drivers\fcvsc.sys 12:07:58.0209 0x1830 fcvsc - ok 12:07:58.0224 0x1830 [ 9D299AE86D671488926126A84DF77BFD, C076EEDD0524B7D88BC56C97089E0A836CC1AD725E1A544CC4F8DDBB6670C366 ] fdc C:\WINDOWS\System32\drivers\fdc.sys 12:07:58.0240 0x1830 fdc - ok 12:07:58.0256 0x1830 [ 47D09B8C312658ACE433E46DDF51C3A5, E76948DA0F51C7DC6D69B7E36D63CE6E98FDE619FA30E91637F75B5084107D22 ] fdPHost C:\WINDOWS\system32\fdPHost.dll 12:07:58.0271 0x1830 fdPHost - ok 12:07:58.0287 0x1830 [ 177AC945B20C81400A1525ED7B49A425, FD215A2E718EA38A95D985F53AB3DD44B50C2549AA67F44BA98C4709E492051F ] FDResPub C:\WINDOWS\system32\fdrespub.dll 12:07:58.0303 0x1830 FDResPub - ok 12:07:58.0318 0x1830 [ 3E78BEC276DA5A062E4D55F3291B3463, 62983457F506C70D1F89F527AB61C1C0F4D1B002631256A2708F9AF092A8C95E ] fhsvc C:\WINDOWS\system32\fhsvc.dll 12:07:58.0350 0x1830 fhsvc - ok 12:07:58.0365 0x1830 [ 8F12AB59336143B680F71B217B495AD2, A28F62F065C68CC1A7EEF0CA52F83C3284B001565D8E154BF8568DE4A525104E ] FileCrypt C:\WINDOWS\system32\drivers\filecrypt.sys 12:07:58.0381 0x1830 FileCrypt - ok 12:07:58.0396 0x1830 [ 92ECCFA58C8195B8EA33ED942469D4E6, 8DB12E8CF80ECA22182F9A1F4CA922336A430297F1F596F204ECF4D9D19F30D9 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys 12:07:58.0412 0x1830 FileInfo - ok 12:07:58.0444 0x1830 [ 87C51FDD50C17882BA93E28BBABB9847, 8987D80FB77D1D3F9E89B491B1287B027DA26FFC4E4BA7B01E07D4D4FC69E236 ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys 12:07:58.0464 0x1830 Filetrace - ok 12:07:58.0487 0x1830 [ E99261DD76D1C9E05AF575939CAE5AC5, A789724FD2E22AFB2F921836F5C19A21D17F4BBD604771E2908C2651BD31989C ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys 12:07:58.0500 0x1830 flpydisk - ok 12:07:58.0511 0x1830 [ 25D7A58625E1453E40D36825DE74E4F1, 74119803D35E3C3CC349B44C6CD9EDF6B797F88584B847F0BF9EED542719B86B ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 12:07:58.0527 0x1830 FltMgr - ok 12:07:58.0605 0x1830 [ 4387DE200BF8DD0E2EE828E655434B9A, 9148D65E54663EEC139E754091F47ABF439A637BEA83F600D30736522DAA845D ] FontCache C:\WINDOWS\system32\FntCache.dll 12:07:58.0652 0x1830 FontCache - ok 12:07:58.0745 0x1830 [ E79DAC43A5E191FC4DDB04197A704BFA, 2FA6C8B5B2DFE66C05828E3F55DFD6268A8210E9BD083F2D09367AD59AF1C6C1 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 12:07:58.0761 0x1830 FontCache3.0.0.0 - ok 12:07:58.0777 0x1830 [ B4175E8BE60B099686FF55CA7D692316, 3158FC5B4D1A2F1FC1346754392AE24AE58999B9061B1CE78A65E785BFFADD52 ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys 12:07:58.0792 0x1830 FsDepends - ok 12:07:58.0808 0x1830 [ CC71372CEB811A72F1DC99089C5CBF53, BB9DDE74D60E534A6F8A51B63DDBB441245F06A00A0AFD37DBBE86255690946D ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 12:07:58.0808 0x1830 Fs_Rec - ok 12:07:58.0839 0x1830 [ 421497634C86EF4B8F86D0EBC076728F, E0D1449555D8849364E00AA747DBC820EF914A9F5B796E35070072FCBC532ADE ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys 12:07:58.0870 0x1830 fvevol - ok 12:07:58.0886 0x1830 [ B9981A4CB9F728B3312A3885BFAA7204, 12FB2EB2E5D2A912769823DD9C1B33DB358CD0B7FBFC788529EF83DD584334F8 ] gagp30kx C:\WINDOWS\system32\drivers\gagp30kx.sys 12:07:58.0902 0x1830 gagp30kx - ok 12:07:58.0961 0x1830 [ 77555B11B264991DDC26872FFCF1AB97, D5F230EEF74EB869F771F8A4AB19C1E6C845BB0EF4A1234882EBDA4FDC431E44 ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys 12:07:58.0976 0x1830 gencounter - ok 12:07:59.0008 0x1830 [ F3AC9652D88BF87BA6596CBEA28CE10F, 115F3C0A5B9903B17ADEA80E1825FE927B7361F5BDDF80CE3685EF2D327EDF4F ] genericusbfn C:\WINDOWS\System32\drivers\genericusbfn.sys 12:07:59.0023 0x1830 genericusbfn - ok 12:07:59.0055 0x1830 [ F802FBABF0C4DF1BAA733187B2E476F5, E2533284CEBBB872196B013DD1FBBCA794DB1CAAA37D64849BD9264ECDD2CEE6 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys 12:07:59.0070 0x1830 GPIOClx0101 - ok 12:07:59.0117 0x1830 [ B55458A83395A2CFD4E745E9EC4AB5F2, EAB06B089D8A7DBC9AE2A1C919B489911690D341013A5F8F906819C68431CA85 ] gpsvc C:\WINDOWS\System32\gpsvc.dll 12:07:59.0164 0x1830 gpsvc - ok 12:07:59.0211 0x1830 [ D011B0ADB15F4815310CE1BF4780B33E, 3860630917F83A89FE7A6407CC544505FA4BD754619CF273DD630ABFBAAE42EE ] GpuEnergyDrv C:\WINDOWS\system32\drivers\gpuenergydrv.sys 12:07:59.0226 0x1830 GpuEnergyDrv - ok 12:07:59.0320 0x1830 [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 12:07:59.0336 0x1830 gupdate - ok 12:07:59.0336 0x1830 [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 12:07:59.0351 0x1830 gupdatem - ok 12:07:59.0383 0x1830 [ 0F93EBE9071A6BB1548BF0F816EEA24B, 79A99544C00F59996980D299BFACA0463D86158BFA51C8045CE4FF4951779A44 ] HdAudAddService C:\WINDOWS\system32\DRIVERS\HdAudio.sys 12:07:59.0398 0x1830 HdAudAddService - ok 12:07:59.0430 0x1830 [ 84BC034B6BB763733C1949B7B9BAF976, 18C2C0F15BAFA46197F0BB629C4F585D893C2A78324CA198F88A04527D524F23 ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys 12:07:59.0445 0x1830 HDAudBus - ok 12:07:59.0475 0x1830 [ 6B8CB114B8E64C0636EB49F7B914D1FC, 1AD7A43CC5CD99DCEF60C61242B6843D4AD925CE93BA5D75CD8395C7125EF5A7 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys 12:07:59.0491 0x1830 HidBatt - ok 12:07:59.0507 0x1830 [ D1AD197CCDAAC0CB4819DA1D6EB17BAE, C370F974D0A1F7B60F47EAFF57B6CCABE82913187F8BFEE169B8237AE91247B1 ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys 12:07:59.0522 0x1830 HidBth - ok 12:07:59.0538 0x1830 [ 64909DECCFCC6FB5D9A5BAFDCCB31FEE, E19C91FD8D5102A8C4F6C6FF70CA058BB272FEC1B6E9CBA3A473C49948E6AC7E ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys 12:07:59.0554 0x1830 hidi2c - ok 12:07:59.0598 0x1830 [ F510F7B7BF61DEAAC04E65C3B65E8D59, 11566086B06FB08B6A179E3068E022DA381C762DC8962D1E1D63DC646DD4D301 ] hidinterrupt C:\WINDOWS\System32\drivers\hidinterrupt.sys 12:07:59.0613 0x1830 hidinterrupt - ok 12:07:59.0629 0x1830 [ 90F3ED42D423C942BA5EA54E2FFE7AC7, BF7DE0C8141CD20A6235657BA897A019ABEFF6A01AA3FB202C73C33433CDEAF8 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys 12:07:59.0645 0x1830 HidIr - ok 12:07:59.0688 0x1830 [ 46DE2EF6382DD9613CB506760648F262, 419555220794380134A64E1956B83B2FD1D1B6E403C5FC729A9107E14A12E968 ] hidserv C:\WINDOWS\system32\hidserv.dll 12:07:59.0704 0x1830 hidserv - ok 12:07:59.0743 0x1830 [ 128DEDDD61915DBA4D451D91D21F0513, 961A0DDA02B0879989300C15E4FF9022882A4CD895D65335C263AC0DD1918314 ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys 12:07:59.0759 0x1830 HidUsb - ok 12:07:59.0790 0x1830 [ 2FEF4D90C0CAED258C93CFF72A8FFD71, 56473D90E9FE52849067D080FD88B29C0BBE76E5266657E2ABD6366B7A4E9474 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll 12:07:59.0806 0x1830 HomeGroupListener - ok 12:07:59.0837 0x1830 [ E2145534FB853921788F52701BED0CAB, DF71F842772FAC21DD8994C97F578A78AC43D06C5F26F752FB69B47DFE3BB112 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll 12:07:59.0868 0x1830 HomeGroupProvider - ok 12:07:59.0884 0x1830 [ FF442DCDCE1F6E9FAA9C8AD0CD1D199B, A239414E97B310C9545995B0E723B5E792B08D71F651450EB006AD4D1765E4F7 ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys 12:07:59.0884 0x1830 HpSAMD - ok 12:07:59.0940 0x1830 [ 318E816717431D3C23DC82779900C744, 363702CC8A5B5FBF5E8CE2DA5C48D52CBD6244C9398B164EFDF1A4B0FAF592E6 ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys 12:07:59.0971 0x1830 HTTP - ok 12:07:59.0987 0x1830 [ CBA5E88A0F0475B7F49653BB72150BEF, 0F03560D9C30E069D117A555AEE729C81E6BCAE443FA25172D0E9E6903695C67 ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys 12:08:00.0002 0x1830 hwpolicy - ok 12:08:00.0033 0x1830 [ D668FAB4B0397B426EE3D41683B9A1C0, 66F3E3B2ABC3C9B25A0DADBF09818547ED301230374AC5302B4794629A95DDF8 ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys 12:08:00.0065 0x1830 hyperkbd - ok 12:08:00.0080 0x1830 [ 53FDD9E69189E546DE4740F8C4D8AB2F, 45ED5B229ED5FD0CEE8BF52EFF88FD8B1889BF348ED7187926F290B3AD48A76D ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys 12:08:00.0096 0x1830 i8042prt - ok 12:08:00.0112 0x1830 [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c C:\WINDOWS\System32\drivers\iai2c.sys 12:08:00.0127 0x1830 iai2c - ok 12:08:00.0174 0x1830 [ 59A20F5AD9F4AE54098154359519408E, E27B7389C9D123CDDA4EC9CBDB06C4AA5000012391F940EE1492419B593608FE ] iaLPSS2i_I2C C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys 12:08:00.0190 0x1830 iaLPSS2i_I2C - ok 12:08:00.0205 0x1830 [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys 12:08:00.0221 0x1830 iaLPSSi_GPIO - ok 12:08:00.0252 0x1830 [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys 12:08:00.0268 0x1830 iaLPSSi_I2C - ok 12:08:00.0330 0x1830 [ C224331A54571C8C9162F7714400BBBD, C2CA4881ACD46071E67435BE5E3DB133D0743B026FD20D6D6E26B2FE7A03FCAA ] iaStor C:\WINDOWS\system32\drivers\iaStor.sys 12:08:00.0346 0x1830 iaStor - ok 12:08:00.0393 0x1830 [ 6B0029A0253098CCE28EACCFDB9E7208, E33AD69644E1683A971DA1169B704FBCFD9F715E9550816058E420BB5DE4D946 ] iaStorAV C:\WINDOWS\system32\drivers\iaStorAV.sys 12:08:00.0424 0x1830 iaStorAV - ok 12:08:00.0455 0x1830 [ 9652E1E35A92D8C75710C17A63B15796, 72F8C4A49B874226DEE9B7C9704F0E0A98DAA2DF4EAE2F2258E8324ACBD242E4 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys 12:08:00.0471 0x1830 iaStorV - ok 12:08:00.0502 0x1830 [ FFADF691F7BF727AF5C863454A372723, FCF5A5595E8C9C937BE9F1C3AB5D9BD0EFE82DE1298D12085E0CCD84A186D2F2 ] ibbus C:\WINDOWS\System32\drivers\ibbus.sys 12:08:00.0518 0x1830 ibbus - ok 12:08:00.0565 0x1830 [ 80BF2990E01E774D64F6E13F30661942, ADFEA2280D29F2C7B0A556C61709301D6327C288064FF5A4D29358403DF41DCE ] icssvc C:\WINDOWS\System32\tetheringservice.dll 12:08:00.0580 0x1830 icssvc - ok 12:08:00.0580 0x1830 IEEtwCollectorService - ok 12:08:00.0752 0x1830 [ 9CE4D3A79D3180AC5A141E2F7E7137F4, 1D717D2156B78632895281779D2646AB066619EA1DB293A9505BF7C174F53271 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys 12:08:00.0830 0x1830 igfx - ok 12:08:00.0846 0x1830 [ 6A9C613D0F5F9676D128F39B63ACE45B, 027B9568C740E336C7CBBE952309E2719E8FFA14E7DFC2B85B49E0C0CE7D2149 ] igfxCUIService1.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe 12:08:00.0862 0x1830 igfxCUIService1.0.0.0 - ok 12:08:00.0924 0x1830 [ 12F8D27ED8623DDDC09A549EDADCBAC9, D3A3F0588D9CAF1027D8BC14601E2A6AB7E5924A2C23C90D38A9E14538DB02A9 ] IKEEXT C:\WINDOWS\System32\ikeext.dll 12:08:00.0971 0x1830 IKEEXT - ok 12:08:01.0033 0x1830 [ 87871AB7AC797F922A6F3D4C874CED96, 2BCD89911E42827CD294DD7D1486A7845D1F98019E51958E0F488384401B2944 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys 12:08:01.0049 0x1830 IntcDAud - ok 12:08:01.0080 0x1830 [ ECDB27420D3A98424666904525A8562A, BDA98C3C95F2AD79945EF8213D5C65064052C09C82DD36F0D6724E1D21DCC30A ] intelide C:\WINDOWS\system32\drivers\intelide.sys 12:08:01.0096 0x1830 intelide - ok 12:08:01.0127 0x1830 [ 8FF1978643EFD219C5BA49690191D701, 6FD78A8490107C80090D7125644B8C910855374BE1373D1D6B199307C79680BA ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys 12:08:01.0127 0x1830 intelpep - ok 12:08:01.0159 0x1830 [ B61B60F36E1C8022FA8166ABF0F66B07, 23161F1DA51D44D936329E62DF4C2DAEE3DDD4B3D62CC501A888C0E149788968 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys 12:08:01.0174 0x1830 intelppm - ok 12:08:01.0190 0x1830 [ CA0D42029AFFC4514D295E1EF823D02D, F2A05CB2B2E8C843FD02DC37E86F23CF928A4B2F9044424A60DE4E82B87DF5C3 ] IoQos C:\WINDOWS\system32\drivers\ioqos.sys 12:08:01.0205 0x1830 IoQos - ok 12:08:01.0237 0x1830 [ 6E3F9D95235DFC9417384080A216F310, 6F13D72661038A91CFABB360621F4B169D78955C3EAD64956A7C825ABAEC5121 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 12:08:01.0252 0x1830 IpFilterDriver - ok 12:08:01.0299 0x1830 [ 6E75B731A8A7EFED0821327B08DAB46D, A77B746447824BD3C68B82D7329B82D62098B2409F8AEE4738FA23CB1561E629 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll 12:08:01.0346 0x1830 iphlpsvc - ok 12:08:01.0362 0x1830 [ 4F527ECB5EAB47D8EAF34A469666C469, 8FFBEEF42515B6A7758BE579ED69E3911856CBF7710D9785011332C5E3DFE495 ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys 12:08:01.0377 0x1830 IPMIDRV - ok 12:08:01.0393 0x1830 [ 9E5E8F2A1996F23B7E9687846AA81B01, 29E59384A4F92B3B4F2974942C91A12380113C13D3800900B5F44E2355D05455 ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys 12:08:01.0424 0x1830 IPNAT - ok 12:08:01.0440 0x1830 [ C317EB660138BC9CBFE37CCDE56351AE, F3AF6C573419D7F65C96A4841D4F056CA281CD5AFACDC7A5F586A390DC6E615B ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys 12:08:01.0455 0x1830 IRENUM - ok 12:08:01.0471 0x1830 [ 531994A6D9399D9B74BE12B5BB58A81E, 6D5CF540C777F4828E1D4C5FE58EE41E6C2F5F399C554DC85F19D1E52229B094 ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys 12:08:01.0487 0x1830 isapnp - ok 12:08:01.0534 0x1830 [ 68D5354A4A9692EEC24664C60F47D4A2, 92124E98B6E286B6127DC6D0BFACC9C6D293D58EAE2B47B45532714CE6A6D0CD ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys 12:08:01.0549 0x1830 iScsiPrt - ok 12:08:01.0580 0x1830 [ 48B904D31F2369D7B0122617038D3F5B, 8A43CB37667929CCCC37B6E79E82509BBCA6C8884B44059DC87BCA7C21BE7FE1 ] iwdbus C:\WINDOWS\System32\drivers\iwdbus.sys 12:08:01.0580 0x1830 iwdbus - ok 12:08:01.0612 0x1830 [ 701D7DB13B0815E7076EF4CB4CE981F8, 02585661656C0069AC318B82DE83DAC660451A0B970FDBCA0F7A8B4CBF7D93A9 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys 12:08:01.0643 0x1830 kbdclass - ok 12:08:01.0659 0x1830 [ 884EBBDDBF5968003B40185BD96FF0E6, E3934D0FF0BEDDF5526AF529F7D15BA8BE479383894975B1AF1A1818C394A6E3 ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys 12:08:01.0674 0x1830 kbdhid - ok 12:08:01.0721 0x1830 [ 6B3A0C7902811E6372643447E41F7048, 30667B56A306CFD5D15BC46F8E7D9E167612E71B6C8F554406E706A6330F5B94 ] kdnic C:\WINDOWS\System32\drivers\kdnic.sys 12:08:01.0721 0x1830 kdnic - ok 12:08:01.0737 0x1830 [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] KeyIso C:\WINDOWS\system32\lsass.exe 12:08:01.0752 0x1830 KeyIso - ok 12:08:01.0768 0x1830 [ 982C795DE20CED7AEDD2E7899B5D9BC1, 9F4E7536DB253CD83AA2AB89E9F3311714CD70F13AFD16F9B4D4CD86A70FC164 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys 12:08:01.0784 0x1830 KSecDD - ok 12:08:01.0815 0x1830 [ 7D8B9214692C4D0F1646215D9984E19A, DC73503A8CA67F4E167DEA69AADDEA5F2D756E1C1F4FF42B6ECEA7E637BB80AB ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys 12:08:01.0830 0x1830 KSecPkg - ok 12:08:01.0846 0x1830 [ E9BB0023D730701BB5D9839B44F5E6B5, 19D4BAC09424D331922472CFD2D0E32BEFA9188A6AF194C8D1F93FD77CE36691 ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys 12:08:01.0877 0x1830 ksthunk - ok 12:08:01.0909 0x1830 [ 71DE1AD9B23661EEC4F2A6EAA5A7D33D, 3219AEF3D6AE5933AE669FD2ED9ED95A8780612E39F31DB3DB9ED6B6244C5F7B ] KtmRm C:\WINDOWS\system32\msdtckrm.dll 12:08:01.0944 0x1830 KtmRm - ok 12:08:01.0975 0x1830 [ 8BBB2B4429AF340481520C20C17FC5B6, 9E32815349195FC4B1BE213600FD407F2EAEEC8368289EB3E6B769125A739C08 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll 12:08:02.0007 0x1830 LanmanServer - ok 12:08:02.0038 0x1830 [ 1F5D48B1DA1B812BD2411CA44D75DD32, D1BDB8142CB13E8C6DD6F42E07C9D19BBBF6410D5122A04C01B34B95B442DD95 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll 12:08:02.0069 0x1830 LanmanWorkstation - ok 12:08:02.0085 0x1830 [ 02C54C5C7EBE371EC0C59795ED22213F, 712AFE0EDF40436124F3FD55ED9B5A3A33A8761A58F4D482BB65229741B1C270 ] lfsvc C:\WINDOWS\System32\lfsvc.dll 12:08:02.0085 0x1830 lfsvc - ok 12:08:02.0132 0x1830 [ 01BF128CC327A2E53898F732AF52B3DB, D62ACDA69D9942F9CEF400874DBB6EAF9811D9657CBFEF89174F88D76BB8D8EA ] LicenseManager C:\WINDOWS\system32\LicenseManagerSvc.dll 12:08:02.0147 0x1830 LicenseManager - ok 12:08:02.0194 0x1830 [ EC34EED89C34B27C292166B725AC7A7B, 58F1BA0CB7743314AC012A82F8CE4072CBDD05D9570C52BC18DC551882F5B1BA ] lltdio C:\WINDOWS\system32\drivers\lltdio.sys 12:08:02.0225 0x1830 lltdio - ok 12:08:02.0257 0x1830 [ 2C23283A0815B048C06D8C0ED76AAD95, 4335546939C1A98CFE9A4403CC82D79CC713439E4DFD1F4760FDD867305151E0 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll 12:08:02.0288 0x1830 lltdsvc - ok 12:08:02.0319 0x1830 [ CB6365E995F4DB856866500EDD8F61C1, 717ED387F245CAC68217B0F393D7B8AB3805721AB2C4D2D43430FE6E740F0856 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll 12:08:02.0350 0x1830 lmhosts - ok 12:08:02.0382 0x1830 [ 961F28D879D345BFA50AF51285C90F2E, F9931A436651F695B746BC0C07E833D9C9F64126746DF976E691E6CAE26DAC9B ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys 12:08:02.0382 0x1830 LSI_SAS - ok 12:08:02.0429 0x1830 [ 6BFB8D1B3407518BE06B6F81F92FA0F5, DE0818DCC0D8D1D30A29AB167C65461A78100ABE2368637CEB9D0ED2B4E88D8E ] LSI_SAS2i C:\WINDOWS\system32\drivers\lsi_sas2i.sys 12:08:02.0429 0x1830 LSI_SAS2i - ok 12:08:02.0460 0x1830 [ BE0E47988D78F731DEC2C0CB03E765CB, CA0015E87A3962611DBF714253FA618A6568346BAE640884432C1D44DE4C8684 ] LSI_SAS3i C:\WINDOWS\system32\drivers\lsi_sas3i.sys 12:08:02.0460 0x1830 LSI_SAS3i - ok 12:08:02.0491 0x1830 [ F99BF02BE9219986817BF094981EEB18, 4303C772366065885C5D937B2E9AC0BF80C84BFB2737716055AD57BF6AADD673 ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys 12:08:02.0491 0x1830 LSI_SSS - ok 12:08:02.0522 0x1830 [ FFAA37FBBDD161E8C200C83B40F7872E, 0637B3119FC220CB8E23EE6694A9F1F25CF8D61008B14F6E30FDC17DCF9E077E ] LSM C:\WINDOWS\System32\lsm.dll 12:08:02.0554 0x1830 LSM - ok 12:08:02.0554 0x1830 [ 2FCF837196082864F66CFD9CAB256275, 8BE01C3BCBC1E6E5D1FD7F49E936482E61ACB805F397AB81B8D39C2F0F1083BD ] luafv C:\WINDOWS\system32\drivers\luafv.sys 12:08:02.0585 0x1830 luafv - ok 12:08:02.0616 0x1830 [ 88B38A7435DFA9B7E8F94F5D5FE999D2, FF4EBB6CE013D0EA62FEDA5FBBD1205D9A6F684E701F40039A95A4EF4145DC16 ] MapsBroker C:\WINDOWS\System32\moshost.dll 12:08:02.0616 0x1830 MapsBroker - ok 12:08:02.0647 0x1830 [ 2ED29B635F35E31A1C0D3DDB7DD2AD03, F70CC20B98C2DBCD13B0D509D92B3BC3828D1B88F3ACD60C860E163064844181 ] megasas C:\WINDOWS\system32\drivers\megasas.sys 12:08:02.0663 0x1830 megasas - ok 12:08:02.0694 0x1830 [ 22E3CB85870879CBAE13C5095A8B12E3, 5FA5A8EFBA117089CFDBE09743A16BC3A7CC2042C96ABA1F57901747493106BF ] megasr C:\WINDOWS\system32\drivers\megasr.sys 12:08:02.0710 0x1830 megasr - ok 12:08:02.0741 0x1830 [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys 12:08:02.0757 0x1830 MEIx64 - ok 12:08:02.0788 0x1830 [ F2C23E25636BCA3543E6AD7858E861B7, 0CAB0A037471B4858CE9477E49BF50A5E3E6685E05F8A4BD2D9238551D5073A6 ] MessagingService C:\WINDOWS\System32\MessagingService.dll 12:08:02.0804 0x1830 MessagingService - ok 12:08:02.0929 0x1830 [ D41920FBFFF2BBCBBC69A5B383AD022E, E66218A8303422EA10C19BA12343740B9A1A70B11B39E185E805B4F74CD2B75E ] mlx4_bus C:\WINDOWS\System32\drivers\mlx4_bus.sys 12:08:02.0944 0x1830 mlx4_bus - ok 12:08:02.0960 0x1830 [ 64BD0C87064EA20C2D3DC4199F9C239C, ED69706277A58ED2C5F2B1B4E9A4A9C7C20173D46EB57FB31D8B63340BA23193 ] MMCSS C:\WINDOWS\system32\drivers\mmcss.sys 12:08:02.0975 0x1830 MMCSS - ok 12:08:03.0007 0x1830 [ 8D4B46FA84A3A3702EDADD37FAC6EDBA, E3B9E12BD324FE637C365FDC5E490C41889047004D4FC8F7D78339484F2F717B ] Modem C:\WINDOWS\system32\drivers\modem.sys 12:08:03.0022 0x1830 Modem - ok 12:08:03.0038 0x1830 [ 78FEC1BDB168370F131BFBFEA0A04E9D, E07B1BC429C2CFBD6162F89A6502C67A4BAD904ADC05D3505D87A0B2BCE1061B ] monitor C:\WINDOWS\System32\drivers\monitor.sys 12:08:03.0063 0x1830 monitor - ok 12:08:03.0073 0x1830 [ D1CC0833CFBC4222A95CAA5D0C8C78FF, 54F04374C6D3EFF5C1B794C069870458F10757E5773AEE911957089EAF51EC8D ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys 12:08:03.0084 0x1830 mouclass - ok 12:08:03.0093 0x1830 [ C2E05EC6B80BCF5AE362DA873E1BCE64, 4ABE5CA2005A54E92259EDB52205A5C59BDB83026FC0CD7CBB1E3A003C2B535B ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys 12:08:03.0106 0x1830 mouhid - ok 12:08:03.0126 0x1830 [ D5B7668A8F6C67C51FA5C6C513396D6C, 35985AD89344A8464BD78B8DA6A772E4E60A2EB93072AC23673A86EFD0B2270A ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys 12:08:03.0138 0x1830 mountmgr - ok 12:08:03.0157 0x1830 [ 5FBCB85D127BE21E3A9DAF11A13C00EA, D00AB99CC813E26B0BD2D39161D4138AB89A06B3E3A28712F2D5BCA60905BEC4 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys 12:08:03.0171 0x1830 mpsdrv - ok 12:08:03.0248 0x1830 [ 553F19DC6F3F73545CB17FCD7A8AE37B, 49ABB625EB9C2981254EEA1FE7858DF630BA2D65653CC91CD4FEEACF69C5392F ] MpsSvc C:\WINDOWS\system32\mpssvc.dll 12:08:03.0301 0x1830 MpsSvc - ok 12:08:03.0332 0x1830 [ BF6CA7EA5ECD6CF72D3D76652A9B8280, 8EC031D0D8E75CB583B129CBA518701097697498621307108388FA05FBF604BB ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys 12:08:03.0364 0x1830 MRxDAV - ok 12:08:03.0379 0x1830 [ 0B3B0C1D86050355676640488FA897D3, DBED9D6F7AAFB11F4C00C1F69DB7A887A3058E5FA66615A1640242439822B60C ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 12:08:03.0395 0x1830 mrxsmb - ok 12:08:03.0442 0x1830 [ 1A490555FD330CA2764D89191177C867, 1004AE2F80BEA9A6DBA3E6B5D2DDFA44FBA253F7137D60B000B094699DE1CB12 ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys 12:08:03.0457 0x1830 mrxsmb10 - ok 12:08:03.0489 0x1830 [ 0F47A6C09F0A7FB5513D322A2B9BE4EC, 00A17CB55D232E11F3D24D0B43FE4FA9E55F7EF5E5607B26ED84C13108AAC4FA ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys 12:08:03.0520 0x1830 mrxsmb20 - ok 12:08:03.0535 0x1830 [ A4411C522D41707D5BCA817A5BB9E30B, EF7505BE475ECAB2B5E66A7419EDAF42A7E7A65BAD3BBE346A8CEE5DD69782CC ] MsBridge C:\WINDOWS\system32\drivers\bridge.sys 12:08:03.0535 0x1830 MsBridge - ok 12:08:03.0567 0x1830 [ 807A6636828E5F43C10A01474B8907EE, F275645F4F0D0A796C33C03EA7FA563A0B890AB3A93E5F99C5EA166F91D249B1 ] MSDTC C:\WINDOWS\System32\msdtc.exe 12:08:03.0582 0x1830 MSDTC - ok 12:08:03.0598 0x1830 [ D123343DDB02E372B02BF2C4293F835F, 8E02D9F7E5DA717B64538444B3FE1C55AA4B0F26F51DA20947E971D27EA09D12 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 12:08:03.0614 0x1830 Msfs - ok 12:08:03.0645 0x1830 [ B3358F380BA3F29F56BE0F7734C24D5F, 229D9E72C429AC51BF6E7C8306218620CB1AA50FE39BA6C11ED0F643E7AF90E5 ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys 12:08:03.0675 0x1830 msgpiowin32 - ok 12:08:03.0693 0x1830 [ B2044D5D125F249680508EC0B2AAEFAC, 9631FF42DA5A7CEE1F2607AA8972EF0A67616F0EEEBC95F97B1C8F5A577ED5C4 ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys 12:08:03.0709 0x1830 mshidkmdf - ok 12:08:03.0721 0x1830 [ 36ABE7FC80BED4FE44754AE5CFB51432, FB89DF3A50C52B69D4E831A370157D1901810093A0D7D7120A120FC5C6E14BF5 ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys 12:08:03.0736 0x1830 mshidumdf - ok 12:08:03.0749 0x1830 [ 59307FEAFC9E72EEEC56B7FD7D294F4C, 56576635870FC68980977FFA0E7F8E8D69A7981DECF5B52D0B2A82E3BA6685EA ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys 12:08:03.0760 0x1830 msisadrv - ok 12:08:03.0805 0x1830 [ 236A38F5CB0A23BF0ACCD70ED0BD7F70, 8106B528458E6C8E4437D9064D58F10FF195E67CD308AEBBD5F860AD2D59DCC4 ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll 12:08:03.0821 0x1830 MSiSCSI - ok 12:08:03.0825 0x1830 msiserver - ok 12:08:03.0835 0x1830 [ E9457EDFEBC774199F907395C6D09CA2, C3655CE83F4AD1258382722E9A99C33FDD3AA40B62CFEB8DFDD141E254E6DCE2 ] MSKSSRV C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys 12:08:03.0846 0x1830 MSKSSRV - ok 12:08:03.0860 0x1830 [ C85D79735641D27C5821C35ECDDC2334, C1BAFD98122B04665870171C143EC119181351D10777A83680A63BF305703FF3 ] MsLldp C:\WINDOWS\system32\drivers\mslldp.sys 12:08:03.0875 0x1830 MsLldp - ok 12:08:03.0891 0x1830 [ EF75184B64356850D0F04D049C253526, 325476F53372BD70201347F044C8EFEC0DB939E1926454B6DCC0CF7864969650 ] MSPCLOCK C:\WINDOWS\system32\DRIVERS\MSPCLOCK.sys 12:08:03.0902 0x1830 MSPCLOCK - ok 12:08:03.0920 0x1830 [ 543933D166C618E7588EA77707EC1683, 84A65D277E28FDD7CE2345188891093AC88B577E4C528AD39AB629E341199688 ] MSPQM C:\WINDOWS\system32\DRIVERS\MSPQM.sys 12:08:03.0920 0x1830 MSPQM - ok 12:08:03.0959 0x1830 [ 182711E9DDF70121A20EBB61B2DFB9E8, 70606503F6280EA3175B9AEC8370A8F461575755DA86EF6E9C9D04EAD61481FA ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys 12:08:03.0971 0x1830 MsRPC - ok 12:08:04.0002 0x1830 [ E887FFDD6734C496407E9219225CB6FF, 0EC9A79224BCE5D0A782E62CC38E3494E8FB65DFC07C66D25C5A1A351121C27D ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys 12:08:04.0017 0x1830 mssmbios - ok 12:08:04.0033 0x1830 [ 83A2AB75951000D681FABDB80C07AEFC, 3B2F582F097E3F934C4587B27CB05525350F36924B74CA6BCD364878FA8EC273 ] MSTEE C:\WINDOWS\system32\DRIVERS\MSTEE.sys 12:08:04.0049 0x1830 MSTEE - ok 12:08:04.0071 0x1830 [ 4FA0483896FC16583851EFB733FCB083, BB59243ABE32FBE92EC1B04D24239BE2DF7C2354A407C2EFF97623F07DCBDA35 ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys 12:08:04.0086 0x1830 MTConfig - ok 12:08:04.0118 0x1830 [ 60F88248608315E13391C2F1C3B4473F, 99E8B74118A01FC281A1C6B323EFD1A8EA1997B81A013442205066F55327D555 ] Mup C:\WINDOWS\system32\Drivers\mup.sys 12:08:04.0149 0x1830 Mup - ok 12:08:04.0180 0x1830 [ 218705233D02776AE4D19CC37D985C1B, 3D92925867B6B8FFAF78E4080139DCB3D45E1E6E1D0AFB6A4FE248B002BD8471 ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys 12:08:04.0180 0x1830 mvumis - ok 12:08:04.0227 0x1830 [ 536A0806CE2061A2157E65D4D8ABF30C, F9893F66505E3F748365CD4625B34357531804BDFE33E57285C0106C03F7916C ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys 12:08:04.0258 0x1830 NativeWifiP - ok 12:08:04.0274 0x1830 [ A340A4B27CC7DEDDF953B7E2C9699747, 4C5AB23BD0C69B17E9BD29CAFEDC100A6EFC78BAB645B007FCAE4318C459D345 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll 12:08:04.0290 0x1830 NcaSvc - ok 12:08:04.0321 0x1830 [ 7467BD76D6ED5981E6C3DBFEB50F0F4D, 237E1C2E15D5F3BAC49B09E1CD0EAE56A6998AE1FF560A4F7A7EFFEB46884798 ] NcbService C:\WINDOWS\System32\ncbservice.dll 12:08:04.0368 0x1830 NcbService - ok 12:08:04.0399 0x1830 [ 476466DC3AB2327E2DBFAEC11798E2EE, 9ACD74720664CF3F239601DF0BE80AC443AF0FBF666CBB8509169364FB22B95D ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll 12:08:04.0415 0x1830 NcdAutoSetup - ok 12:08:04.0430 0x1830 [ B57CE307DA101C739885B7CC0678077F, F7F45DB6D306060F0FE0E59F39C3B95F6A9B6173930F22C5C41B2003895D6642 ] ndfltr C:\WINDOWS\System32\drivers\ndfltr.sys 12:08:04.0446 0x1830 ndfltr - ok 12:08:04.0493 0x1830 [ AFAECF904F1C343EBD50F91BC8D0DBE8, FABAE70F62895708415B8E176A880D2D20D46D9A14C3D41D371B905CE4D64BA0 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys 12:08:04.0524 0x1830 NDIS - ok 12:08:04.0555 0x1830 [ 202260E7CDD731A32AF62ABD1ABEE008, 0E019FAE09B2659CC3267756DB962CCD69172BA67E3288B491F7B455287A5392 ] NdisCap C:\WINDOWS\system32\drivers\ndiscap.sys 12:08:04.0571 0x1830 NdisCap - ok 12:08:04.0586 0x1830 [ A1D473D0CF10561F29B58EA7C5412A92, 3DBFC1D769E03E30C87FF4F30A9B523A69A7E0CD4EB87F8A9ECE190FEB84C569 ] NdisImPlatform C:\WINDOWS\system32\drivers\NdisImPlatform.sys 12:08:04.0602 0x1830 NdisImPlatform - ok 12:08:04.0633 0x1830 [ 1A0AE283B8DE6BB76412A0F8213D45AC, 91AFFDC7A9277EB59CD54021049BEA715078F90470B8A12F3E9F1386DF068D2D ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12:08:04.0649 0x1830 NdisTapi - ok 12:08:04.0665 0x1830 [ A74EE2D2C0BFF5EC3A6185791868C4CA, A346320DEBEAE890575B4C6594FB3A3A9890A0E86881ADD8376E442282C88D38 ] Ndisuio C:\WINDOWS\system32\drivers\ndisuio.sys 12:08:04.0680 0x1830 Ndisuio - ok 12:08:04.0696 0x1830 [ 32A9BD1342640D48AD85C8B3E812B984, B702B05A0180472139B35B105DD3B6B6F75AEDC9DD1EE342FB576259076455AE ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys 12:08:04.0711 0x1830 NdisVirtualBus - ok 12:08:04.0774 0x1830 [ 6A6A8CF5EE61801375A38EBB871D4057, AE8EFF18D82BBE83101B380189A6889822891A993EB865E2E81C1D2F60B77C4C ] NdisWan C:\WINDOWS\System32\drivers\ndiswan.sys 12:08:04.0805 0x1830 NdisWan - ok 12:08:04.0805 0x1830 [ 6A6A8CF5EE61801375A38EBB871D4057, AE8EFF18D82BBE83101B380189A6889822891A993EB865E2E81C1D2F60B77C4C ] ndiswanlegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys 12:08:04.0821 0x1830 ndiswanlegacy - ok 12:08:04.0852 0x1830 [ 50AEF8EF0064A91ABB08D858D039C9DE, 16F1CBE1EC3778D157CC054261068C8D7F8A72D85853CB70178F8DF81D238C8F ] ndproxy C:\WINDOWS\system32\DRIVERS\NDProxy.sys 12:08:04.0868 0x1830 ndproxy - ok 12:08:04.0915 0x1830 [ D358DF634F52247CB43F0781218F4D6E, D375E9E681551467FC5F7AB2AC053C9F22AAC541C0BCBA57090211F45009342C ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys 12:08:04.0930 0x1830 Ndu - ok 12:08:04.0946 0x1830 [ 026618ECF6C4BEBDCB7885D42EC0DBE4, 8E7E13361DCF8748FA3AD518B3DE0A3DCE932316EE32E5529E75785BC5395AD1 ] NetBIOS C:\WINDOWS\system32\drivers\netbios.sys 12:08:04.0961 0x1830 NetBIOS - ok 12:08:05.0008 0x1830 [ F51C02D992A8D6BC5EC4D990F227D4C7, DBBDA422BFA82219403689637BE8D6B0D0A893895143E807FA5A007C166454CB ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 12:08:05.0040 0x1830 NetBT - ok 12:08:05.0055 0x1830 [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] Netlogon C:\WINDOWS\system32\lsass.exe 12:08:05.0071 0x1830 Netlogon - ok 12:08:05.0087 0x1830 [ 7FD4C3D32DAE890608F44074A3437CD8, 5B7D9E9AEE26896B818F3C5DBE4C96A33D43CE2CF7716B95AAB7203611C03BFE ] Netman C:\WINDOWS\System32\netman.dll 12:08:05.0121 0x1830 Netman - ok 12:08:05.0168 0x1830 [ A059F75402710535A90A8D043674A514, E98536DF74A2B75FDBA6B866DC1909544292DFE5E14F984941470FBA6E8D810C ] netprofm C:\WINDOWS\System32\netprofmsvc.dll 12:08:05.0199 0x1830 netprofm - ok 12:08:05.0235 0x1830 [ 3D58D04A9269CE21B61960544A05573D, 250DB1266EE37BAAA9F9E51434879DB4564A8550FCAB28BAB3308772882850CF ] NetSetupSvc C:\WINDOWS\System32\NetSetupSvc.dll 12:08:05.0252 0x1830 NetSetupSvc - ok 12:08:05.0354 0x1830 [ 9E9BEB22644CE1DA521A1D7821BF891F, 5480D52AE1942205B513F916DBCBF5B5F2FFF92D927F4E598FBA618E75BBC2E9 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 12:08:05.0380 0x1830 NetTcpPortSharing - ok 12:08:05.0428 0x1830 [ 91B32D7036700BEED5343E1F6A7122CC, 8123CA398A79F0E69126F962AA29C2464FAB50182E961CB6A6ADB6CEA09A6732 ] NgcCtnrSvc C:\WINDOWS\System32\NgcCtnrSvc.dll 12:08:05.0444 0x1830 NgcCtnrSvc - ok 12:08:05.0475 0x1830 [ C64B693DF26EB7BFF25F9BAD8B54D571, 12363E81B329D048E0148739AA542958F7CAF6FF3404BB001AF51850EF84338D ] NgcSvc C:\WINDOWS\system32\ngcsvc.dll 12:08:05.0506 0x1830 NgcSvc - ok 12:08:05.0537 0x1830 [ 1B8F07B59F7DAE02264FB8A16088C467, 1795DA9F72C34A9F47D9AAF5E95D40C3296948EB89D9600679AB4660671A5C65 ] NlaSvc C:\WINDOWS\System32\nlasvc.dll 12:08:05.0569 0x1830 NlaSvc - ok 12:08:05.0600 0x1830 [ 465DC580170CD844206D7E3EF1DBF2A1, 5A14001029BE154C708CCA34449B280905DB79978FC7F0BE0CF20B20E47752CF ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 12:08:05.0600 0x1830 Npfs - ok 12:08:05.0647 0x1830 [ 29395C214D2CD4C81F73166AB988A797, 3631EB2EA17E455ECD151C0BC9A3DF6EC87C75B15DC9B607CFB68D7C463E04B7 ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys 12:08:05.0662 0x1830 npsvctrig - ok 12:08:05.0678 0x1830 [ AF8B7848E102A83AAECCD24B181CEBE5, B2AAE3567EE3A7975CDFCB3FE41D33C74D4486BFF35FF56E0516A01C744BA52B ] nsi C:\WINDOWS\system32\nsisvc.dll 12:08:05.0694 0x1830 nsi - ok 12:08:05.0709 0x1830 [ 2871225495F832A8C8A7DD1A17EDB3DC, 2F6664C7F5FB2341B2AAF3C5A258FA0D7AEEE447562D7F39FD5A4EE905C18C6D ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys 12:08:05.0725 0x1830 nsiproxy - ok 12:08:05.0803 0x1830 [ 58BFFEF692A47FCE3FAAEDBC8F3DCBBB, 4F55CDF153306B17EDEA6F621939990667735676CBA460CC3078789C2766EF68 ] NTFS C:\WINDOWS\system32\drivers\NTFS.sys 12:08:05.0850 0x1830 NTFS - ok 12:08:05.0865 0x1830 [ 6DBD703320484C37CEA9E4E2D266A8CE, 85D6F73C0E3FDE16829C9BC0D13DD89E64183EAE02F84607F6B8440CB7F366E6 ] Null C:\WINDOWS\system32\drivers\Null.sys 12:08:05.0865 0x1830 Null - ok 12:08:06.0225 0x1830 [ 60328FA27CB565D708CACAC8206037FB, 6D3A4B1B593428CA9F6EB2607C3F5A60DFEB92F4F437956FD916DF6B3B8E27FD ] nvlddmkm C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys 12:08:06.0459 0x1830 nvlddmkm - ok 12:08:06.0522 0x1830 [ 019557823197E07EE33C8E363AE648BB, B9D9E9A013FDEF0F37CD37D5C92F4B1CFE0ADC08FD4ED86966E9A02FF9D80183 ] nvpciflt C:\WINDOWS\system32\DRIVERS\nvpciflt.sys 12:08:06.0553 0x1830 nvpciflt - ok 12:08:06.0569 0x1830 [ 604D27CC38CC23493F218D0BB834B3FF, EF5E5759CCF16DD97271C82DAF47FB2086EBCA5DE7D05177B70CA1197B95F41E ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys 12:08:06.0584 0x1830 nvraid - ok 12:08:06.0600 0x1830 [ 8B50D897657AB4A15FD9E251BBF7D107, 36036130DD46D9BF105AC7176E219F3BE7D1168A660A0F8DFF76F61FBFA4B417 ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys 12:08:06.0615 0x1830 nvstor - ok 12:08:06.0647 0x1830 [ 4398DCC9BA21E1BE911A13BD18C63481, 251DF1EF6101AC071100665686811915C3B306055C3901BDA96F99612FD001B2 ] NvStUSB C:\WINDOWS\System32\drivers\nvstusb.sys 12:08:06.0662 0x1830 NvStUSB - ok 12:08:06.0772 0x1830 [ 85397430F424516BF8300FAAEF929366, 2EDF41407C7483AC8E4703BC0A13F764563E4B00D6923FD4678E6E361AC14D6B ] nvsvc C:\WINDOWS\system32\nvvsvc.exe 12:08:06.0803 0x1830 nvsvc - ok 12:08:06.0834 0x1830 [ 31F990B2B6B91E9D7A667405CE12FCB1, 907E095D1E83CDAFF34BE789FC41CDD7BB4DEE23261E1D03C1CF0D4D030534AC ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys 12:08:06.0834 0x1830 nv_agp - ok 12:08:06.0881 0x1830 [ 7F3A0D052B8E00E730316210B1DD092F, 14BD026EA759F6C81ED6B4DBB04E0584B7F6456725503FC73CD4347B7743005F ] OneSyncSvc C:\WINDOWS\System32\APHostService.dll 12:08:06.0912 0x1830 OneSyncSvc - ok 12:08:06.0991 0x1830 [ 334131C162B118EF49930D41B0E17825, 10EF08870B6E118AED2E0E3F45E06BA8A485439823BE98F44E34E7D2B65AA2EF ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll 12:08:07.0006 0x1830 p2pimsvc - ok 12:08:07.0053 0x1830 [ 4A5634915AF62C983E08425905D0C04C, 09BC3F7AD9F79C5FF59520933D06FE155AC21CD0ABAFE66B81C9F87D83A2339F ] p2psvc C:\WINDOWS\system32\p2psvc.dll 12:08:07.0084 0x1830 p2psvc - ok 12:08:07.0116 0x1830 [ 7D0FC96264C0F8F2C1321E33E8EB646C, 82A06437B9B096BCCF5CE31BDF3539696E2E41DFA9870C358566EEE2F7D3B447 ] Parport C:\WINDOWS\System32\drivers\parport.sys 12:08:07.0131 0x1830 Parport - ok 12:08:07.0169 0x1830 [ 24AC0FD10325FBC2303B29A5F237AEB0, D94B26A36EBE4EFE8EA270FA6600811206830480BE953809F74FAB80628DF879 ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys 12:08:07.0171 0x1830 partmgr - ok 12:08:07.0218 0x1830 [ 0ECA2ADD5FBCE73183A68935C71B40B7, 08CC5F2F10D1DD1A1396CC29196314003491D3AF3DE59CADB281F252577F1860 ] PcaSvc C:\WINDOWS\System32\pcasvc.dll 12:08:07.0233 0x1830 PcaSvc - ok 12:08:07.0265 0x1830 [ 1D4E995955BDAE781C46CB97AE1CFB58, FF7475F19782CA253AA839DDB86E5AC20C5785D5CC1DD57D9FECBE4F5A5C0BFB ] pci C:\WINDOWS\system32\drivers\pci.sys 12:08:07.0280 0x1830 pci - ok 12:08:07.0327 0x1830 [ 2B4D98DF0CA57FB9536DBC80D2449D1F, AB34FA8585A20854369C0FAEB18BF5C7734D7E3C791F644B0576E40D609FCD09 ] pciide C:\WINDOWS\system32\drivers\pciide.sys 12:08:07.0343 0x1830 pciide - ok 12:08:07.0358 0x1830 [ F4D5793BF2E58AF15C6CF2FEEF9E73EB, 9B5A40AF8838063F8F0A2B1480B39A2711AAE78BD972CDA60CCA0EB2BA211A87 ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys 12:08:07.0374 0x1830 pcmcia - ok 12:08:07.0390 0x1830 [ 22A53744CEEADFFFD33BA010FAD95229, 30B775EC9795105B8BF785BD63115C160955E7EFF74B995D3EC288138D1825A3 ] pcw C:\WINDOWS\system32\drivers\pcw.sys 12:08:07.0405 0x1830 pcw - ok 12:08:07.0436 0x1830 [ 48F3A3222CF340FE31535CB6D49C6D6F, 5F8904871219FA6C1BD74747583855B0FBCE42F340A3BE10270D8D3F02766E9D ] pdc C:\WINDOWS\system32\drivers\pdc.sys 12:08:07.0452 0x1830 pdc - ok 12:08:07.0483 0x1830 [ E2F8376F9731D12A009C522036C6073A, 5B8B68D3C013AAA8ED368C97042984C35E8D023542DBA404E7A03E89F2357E66 ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys 12:08:07.0515 0x1830 PEAUTH - ok 12:08:07.0530 0x1830 [ 1398A85E59698067CBBE1D66A9C13ADF, E3609F183068BFAED756B2F9237181D60A6F6D78691248B8BF5B0AEB6A367E3D ] percsas2i C:\WINDOWS\system32\drivers\percsas2i.sys 12:08:07.0546 0x1830 percsas2i - ok 12:08:07.0577 0x1830 [ 35F7C7AD709D909D618D9EDF987FC3ED, EE713E33688E74C5A2546CC58EBD8EA8F8116F25E42DCF8DA21DCBC7C7590E0E ] percsas3i C:\WINDOWS\system32\drivers\percsas3i.sys 12:08:07.0593 0x1830 percsas3i - ok 12:08:07.0768 0x1830 [ 0DAF7B7D85F7AF38E29161460899C63F, F2609F2BD02C714857F5D5E6EF580643429C54E175AA72D38467F8F3A4E7F59F ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe 12:08:07.0799 0x1830 PerfHost - ok 12:08:07.0893 0x1830 [ 57606281E23B0F53347527691E947B2B, 7030182E706CEBE6BD52BDC71CA8F2230AD445AE6554188E76F09A5E2612BD2E ] PhoneSvc C:\WINDOWS\System32\PhoneService.dll 12:08:07.0924 0x1830 PhoneSvc - ok 12:08:07.0971 0x1830 [ 04F7878E7017105AB782353231561749, FB2811D98216720D4FDF0AC0EDF16C6CD33D7224B4CAFA752B4D2A839E6DD88A ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll 12:08:07.0987 0x1830 PimIndexMaintenanceSvc - ok 12:08:08.0049 0x1830 [ A546F72EFFE5CBBC98003A0CA19DA0F8, 89AE396676A37D851F46427E421E8E8ED5B4BADC33023F1E215CC352A4110F44 ] pla C:\WINDOWS\system32\pla.dll 12:08:08.0112 0x1830 pla - ok 12:08:08.0158 0x1830 [ 15BA68662CED4B0618010A54478E18E5, 1B913BFA7AA11F3A82D80E95FC4857B810D341F9E68545710F90EBE44DAC1DF8 ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll 12:08:08.0174 0x1830 PlugPlay - ok 12:08:08.0205 0x1830 [ 6BF7093B27EA90FD9222845D19C1BE5F, CF8A6764BB6B369258F21FD303E4CAE08632195620A0BD66B62F62F5D7B762B8 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll 12:08:08.0221 0x1830 PNRPAutoReg - ok 12:08:08.0252 0x1830 [ 334131C162B118EF49930D41B0E17825, 10EF08870B6E118AED2E0E3F45E06BA8A485439823BE98F44E34E7D2B65AA2EF ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll 12:08:08.0268 0x1830 PNRPsvc - ok 12:08:08.0315 0x1830 [ 5A91C28F99043215121499257468C4BD, 816D2AEBA29B8A050747E01CE11EB12A05C1CDDF91835C44BBB6A7B9D348B15A ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll 12:08:08.0346 0x1830 PolicyAgent - ok 12:08:08.0377 0x1830 [ AE3B1056FC1795F18D990C4908A6ECBF, 1C41F7714EBF54DF358D9B19D6AFE7281D3EABE20038B568A12031B76E1D50D9 ] Power C:\WINDOWS\system32\umpo.dll 12:08:08.0393 0x1830 Power - ok 12:08:08.0440 0x1830 [ 5BA6B9AD03B81546BA64E488C4EF9D17, C43442577685FA1A7C32094B2F14FC92BA6B511FD9FDBA6FD82473A1B165FC61 ] PptpMiniport C:\WINDOWS\System32\drivers\raspptp.sys 12:08:08.0455 0x1830 PptpMiniport - ok 12:08:08.0643 0x1830 [ 959F94AD1255BC749884EDDD14EC29C4, 2CD6DA9778EA36FA0B4080F6DB1C634712238E014E47546403CD3CDB35A1DCA8 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll 12:08:08.0737 0x1830 PrintNotify - ok 12:08:08.0783 0x1830 [ 21AECFF3EB5748CBE12538A2500EFDE5, A1679F21363E99E3698B9C6F7E7E3BB2877D47089BC381AF0C51B1DD8B24325B ] Processor C:\WINDOWS\System32\drivers\processr.sys 12:08:08.0815 0x1830 Processor - ok 12:08:08.0846 0x1830 [ A08AAC62EF7A1E291B3E895B5864BB86, 340E6648F9A5F4B7543FDEC5BDAFBDA3DE319B8F998FF2EF60D02EE5EF3D56CB ] ProfSvc C:\WINDOWS\system32\profsvc.dll 12:08:08.0862 0x1830 ProfSvc - ok 12:08:08.0893 0x1830 [ 596FB6C5A72F34B7566930985E543806, 870B43783DB4CF845FA72BC5E40CE76BE6DFC66FE9E9B4B0A52D6B7FE7EA65FC ] Psched C:\WINDOWS\system32\drivers\pacer.sys 12:08:08.0908 0x1830 Psched - ok 12:08:08.0940 0x1830 [ E84F66BA185934C166F8DF0FA8F88455, 2E0380E98DA29B3F43FB3FE0E1ECA52B3C9AEF54CE982D5514F70FAE81758449 ] QWAVE C:\WINDOWS\system32\qwave.dll 12:08:08.0955 0x1830 QWAVE - ok 12:08:08.0971 0x1830 [ CFBA9C976CBF6796E5DC39EF59984021, A1C956AD828FC70ED92D702516E0F88A4BDAF8C93C571D7CA20F1695FD8E70C2 ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys 12:08:08.0987 0x1830 QWAVEdrv - ok 12:08:09.0018 0x1830 [ 7B2AD8C55217B514C14281AB97B4E21D, A1E295897B864B9C0177FF1C502EB060084A1783C0E7E53636291F901C2E2AA8 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 12:08:09.0018 0x1830 RasAcd - ok 12:08:09.0065 0x1830 [ E15A9CE1E2E7D1C8DF97A4FC1FFE6289, 44B53418D6BC51ACC567CF6917A0981889B44AE420489C9C03F5A30418B37267 ] RasAgileVpn C:\WINDOWS\System32\drivers\AgileVpn.sys 12:08:09.0096 0x1830 RasAgileVpn - ok 12:08:09.0127 0x1830 [ D60BA4C76D194472D6602FF3D2D51ADE, 01272663897685C75FFBC3F1C0CFDB8D0E1A58182049E0B607D634536A8F6400 ] RasAuto C:\WINDOWS\System32\rasauto.dll 12:08:09.0143 0x1830 RasAuto - ok 12:08:09.0174 0x1830 [ E3C82823B22463BC38AA4F8ADA852624, FF601B117F4003E2CC65B6143C2A270331EB257EE82B3BC020247D1AB1CD625F ] Rasl2tp C:\WINDOWS\System32\drivers\rasl2tp.sys 12:08:09.0174 0x1830 Rasl2tp - ok 12:08:09.0205 0x1830 [ 3655D86C5E2982B131FC0935DE24F98F, 0386B31FECDDED77450609A807097B2307361CB59B236DEC41037BDC95897463 ] RasMan C:\WINDOWS\System32\rasmans.dll 12:08:09.0237 0x1830 RasMan - ok 12:08:09.0281 0x1830 [ 3369023EB5790A75BA7DABA14B75D922, 36B63D5B74FDC932AAF1A876514024602D2F3EAF2CA33D1247CBA1E52FDB0418 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 12:08:09.0299 0x1830 RasPppoe - ok 12:08:09.0321 0x1830 [ 1E32A8CD65C4AD0A827CFEB13034DA29, 5D9A92E13020D994CCD39F701BACAFE2177A40A9CC89649441B91E3F3DECD911 ] RasSstp C:\WINDOWS\System32\drivers\rassstp.sys 12:08:09.0337 0x1830 RasSstp - ok 12:08:09.0366 0x1830 [ 2B648363E4C5E34B469C58596F377DD9, 30F82770468BBA562CEA0E9E39B24ACEFBE022343D0180C82E2ACE8957B73E44 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 12:08:09.0385 0x1830 rdbss - ok 12:08:09.0408 0x1830 [ D0221C13960E274CC539D72D5A842ED0, A5A961506B9D7429D97D0635FD69E74736C0E8405487E1D22BB5CD978A60044C ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys 12:08:09.0420 0x1830 rdpbus - ok 12:08:09.0441 0x1830 [ 1DC2CC74B51E4DC4CD5A20C1021E4010, 46B7D17EE27439F2191504D1C6F6C70B2540BD4F2261DBB1F4BE783BEA99B04C ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys 12:08:09.0456 0x1830 RDPDR - ok 12:08:09.0506 0x1830 [ 177DF954D0DEC0465A380C75F6E7F65F, 6B30C78223029BD5DBA586BF961968F85762209BA55CD031460A215B20F93AB2 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys 12:08:09.0515 0x1830 RdpVideoMiniport - ok 12:08:09.0531 0x1830 [ 5D1680871054D2B0B8A971BC8AB3B837, 9CAB0B2E3857829D34A82A78B120D07E292D4D5060168D964295EB23339B7DE7 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys 12:08:09.0562 0x1830 rdyboost - ok 12:08:09.0609 0x1830 [ 341E6830DA70F65730300DAB4CB0B490, 341EC8DB5E39963EF89E726F08730AFB2356C3BAD71CCE9EECCAB4D9B31C4863 ] ReFSv1 C:\WINDOWS\system32\drivers\ReFSv1.sys 12:08:09.0640 0x1830 ReFSv1 - ok 12:08:09.0703 0x1830 [ 8355BCA85B0928382DFCDD02FCD1681A, F306F038DA09C8D2095C311818E2F991B55BCD96B40B95D2A53A60EA6AC37014 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 12:08:09.0734 0x1830 RemoteAccess - ok 12:08:09.0781 0x1830 [ 2C82F4DCABAB389CEBB1C9E86C715C9C, 70354621D3D467616A419A818C54D2C89EA013C5050BA9944E3A7A4F25CAD6BA ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 12:08:09.0796 0x1830 RemoteRegistry - ok 12:08:09.0859 0x1830 [ AD43141CE6D5074DA1D28B5BCD4E4507, C1A9AA856DD4FEE00BBA329C150E0CBCD1CE13ED0BB7B4AC9B152321CD854212 ] RetailDemo C:\WINDOWS\system32\RDXService.dll 12:08:09.0906 0x1830 RetailDemo - ok 12:08:09.0937 0x1830 [ 74727B8BF0227820660A79450F2D94EF, 86BC249322A3C63CBC3B532AD86BFDCB5A46A24A767137D02C944B94A899C521 ] RFCOMM C:\WINDOWS\System32\drivers\rfcomm.sys 12:08:09.0953 0x1830 RFCOMM - ok 12:08:09.0984 0x1830 [ 176D8470B15CD9080861594F9A33FA01, CFB66D7FEB9465985C2866D64EA03B7E7BE830DCF6C02B3FE2244D7F7E5343E2 ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll 12:08:10.0000 0x1830 RpcEptMapper - ok 12:08:10.0031 0x1830 [ 1A563653DAEDFE4CA81936E0D2FD8B56, 308B0DFEBA63333D407093C449A08ABFECE118C9274100809356BDAF7FA32EB6 ] RpcLocator C:\WINDOWS\system32\locator.exe 12:08:10.0031 0x1830 RpcLocator - ok 12:08:10.0078 0x1830 [ B339861C6A2A86FBCA67C2006B461473, 228ADC8A8603C0A4342C6CBC6F2CC919271D42391365061AF660E0D7151C66A4 ] RpcSs C:\WINDOWS\system32\rpcss.dll 12:08:10.0109 0x1830 RpcSs - ok 12:08:10.0140 0x1830 [ 0AC5FCDC29ED97ECDEF1276425EE2059, 8A12D1732D4AA18A9ED8416F4D4A49B81CE7C4C86ABCEE8FF28A16EA61993CFE ] rspndr C:\WINDOWS\system32\drivers\rspndr.sys 12:08:10.0156 0x1830 rspndr - ok 12:08:10.0218 0x1830 [ FBEFF38DE03450E03E6CD9E8E37A8C74, C1C0876785DB4366D67792A3AFA219FC933FC1894AF93D07B0016BBCC81A5886 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys 12:08:10.0234 0x1830 rt640x64 - ok 12:08:10.0312 0x1830 [ 4DBBD2B451A2C45536F14FA972DD3E83, 22B47D79452593E57640B70F3A2EAA9D448046BD1BACBFD2851366DD6FC6DCAE ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys 12:08:10.0328 0x1830 RTSUER - ok 12:08:10.0375 0x1830 [ 044890BB0D6CF1E23C1087234D320509, FA6C79D24BE4ACCFAC617D2850B922BFAA7C2766AE625C725F3ACF43C934EFAF ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys 12:08:10.0375 0x1830 s3cap - ok 12:08:10.0409 0x1830 [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] SamSs C:\WINDOWS\system32\lsass.exe 12:08:10.0414 0x1830 SamSs - ok 12:08:10.0461 0x1830 [ 530F797129776AA7E81994783A97E2AD, F131EF036702C6E741E5A6851AE07E81043CE8BAEED0768838C0F31CE14FEC1A ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys 12:08:10.0477 0x1830 sbp2port - ok 12:08:10.0515 0x1830 [ 0C12493B333B96797AFC5F3C7831C051, BEE786D7ED14221B1A9450060597393AC44116D776B913E045B5F6066D720F74 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll 12:08:10.0541 0x1830 SCardSvr - ok 12:08:10.0585 0x1830 [ 40110802D217FE1CB581D9A70B1FD16F, CCB920593CCC6663676039F3F731536DFEF535C3F715F6DB6F34D0D733BEF89B ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll 12:08:10.0605 0x1830 ScDeviceEnum - ok 12:08:10.0618 0x1830 [ 9B6B1D4DB35A3D9BEAF023BC95E1F49D, CA44124CA3E9958FB77A891CD234A993B63E8AC6632AE801CDEC6666267E7C7E ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys 12:08:10.0634 0x1830 scfilter - ok 12:08:10.0676 0x1830 [ EA195B8BC11C1CDB313CFD456EFFA0E9, EEDF349C59ED0645B04040707906BB4496527243858C2A6BE46BE7029B4A7F37 ] Schedule C:\WINDOWS\system32\schedsvc.dll 12:08:10.0713 0x1830 Schedule - ok 12:08:10.0733 0x1830 [ 4E9158CECF77A029AB98E8FBB43FCED5, AFF8BDB8F8F8DDF4FC0D65712E031DC360856CD3CE5C8A4C8FF960388F37462F ] SCPolicySvc C:\WINDOWS\System32\certprop.dll 12:08:10.0737 0x1830 SCPolicySvc - ok 12:08:10.0769 0x1830 [ 70165A0A2653FB8AFDE3D85000727F29, BAC35D7B0296CAC78EAC4266FC96E292174827E0B24ECAF085228B26A5052911 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys 12:08:10.0784 0x1830 sdbus - ok 12:08:10.0815 0x1830 [ 811EC0B1221402FCED0BA37E112BF627, 366EB8AF04C603BED6CF53652CC937099B247D5DD8C58D699D0D8DA22F8FDD51 ] SDRSVC C:\WINDOWS\System32\SDRSVC.dll 12:08:10.0831 0x1830 SDRSVC - ok 12:08:10.0862 0x1830 [ DE6D7DC78D956928F59F7415A0F41E13, C0F8EEED29BF63A0D8FB5A0286C1C768BFEF598EC52715D910B5BB1A76231805 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys 12:08:10.0878 0x1830 sdstor - ok 12:08:10.0894 0x1830 [ EBD07BD20B5E0E92A398566EF8720F79, 8A88C861D4113B9938C32CBD28FD3D7F1C3133E700E23E17F5DFD7B26CCDA04A ] seclogon C:\WINDOWS\system32\seclogon.dll 12:08:10.0909 0x1830 seclogon - ok 12:08:10.0925 0x1830 [ B7B9EEBCB7466338403A75D15AC120D7, B8F79DA71F8CD0F30983F7D92B625A431C212DD543DE2B3DC03EC5A68C41B00D ] SENS C:\WINDOWS\System32\sens.dll 12:08:10.0940 0x1830 SENS - ok 12:08:11.0019 0x1830 [ D14DD7D766664F880FECF44CE6017966, ECF966E3ACF4EBD5A3259468A076619A539E35F1B97AB6A98FBD7882F1FBBBAB ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe 12:08:11.0081 0x1830 SensorDataService - ok 12:08:11.0128 0x1830 [ A74C62AE99A015CD6275F0D8D8843886, DF08E0BB1160E054C6B000BC5F62DEF77C6D9E4B5679AD013C313BA14207B589 ] SensorService C:\WINDOWS\system32\SensorService.dll 12:08:11.0159 0x1830 SensorService - ok 12:08:11.0190 0x1830 [ 7363A65C738F5A5292D7BDBE55D8C3C2, C53C10A0AE58613DFCC91E62E004D9B188E4793C2A19B4BE871A705EEE77048E ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll 12:08:11.0237 0x1830 SensrSvc - ok 12:08:11.0253 0x1830 [ 67585C295FF2D221679E376B68893B35, 4B5E9A8DA8C6F7B1F7129F80A0603503D467E5650306FB4C309977D74037E46B ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys 12:08:11.0269 0x1830 SerCx - ok 12:08:11.0284 0x1830 [ B8C4852CBCAAC1374C08EC7445443824, DDE577A81B3E11B5B56096317BC47AA6E286573042407B96A9D29BE981F3FA4D ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys 12:08:11.0300 0x1830 SerCx2 - ok 12:08:11.0347 0x1830 [ D3A103944A8FCD78FD48B2B19092790C, 252DB8395DA8639E748658D3BE7863C1700E27AA5C41BB700CFCE193FE3F04E9 ] Serenum C:\WINDOWS\System32\drivers\serenum.sys 12:08:11.0362 0x1830 Serenum - ok 12:08:11.0378 0x1830 [ 88D58E1DAA6C5062DD3A26273106961F, D1E2FF37C888245BD0BABCD7C6B76AD5A87415B68FEFE37B5FA29AE3342AE50B ] Serial C:\WINDOWS\System32\drivers\serial.sys 12:08:11.0404 0x1830 Serial - ok 12:08:11.0433 0x1830 [ 0F5B43074AE731D2C6F061241C9D84A6, 05CFEB30A4FC11441552D37687608C8C2FD6DC2F2266AE9D6526753E26283DE6 ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys 12:08:11.0433 0x1830 sermouse - ok 12:08:11.0464 0x1830 [ CD90E445F6458512A5BA884D561EFCF1, E792FAB8AFF4126C1977024060842D788A06475139782896AFD7B39C85FCDF3F ] SessionEnv C:\WINDOWS\system32\sessenv.dll 12:08:11.0479 0x1830 SessionEnv - ok 12:08:11.0511 0x1830 [ D9FE59276BD56A9643C32D5FACE2F251, 591862D868A545F468496DE97DEE42C9DB3AFBFC0881CBA79EB6641A254AF033 ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys 12:08:11.0511 0x1830 sfloppy - ok 12:08:11.0558 0x1830 [ F8083C536BEDE61AFB4069D8A8C16DA7, 13AADAD7B5582911B8ABBE0CF7132CC517F7413A361CCF8ED502F803D061FFA3 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 12:08:11.0573 0x1830 SharedAccess - ok 12:08:11.0620 0x1830 [ AE6E4D3172FBF45B944668CB3998B8A8, E7D7F98CB464C236A17069987F7B678D7688D9D577334151EF09DF5C6F22AFFC ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 12:08:11.0651 0x1830 ShellHWDetection - ok 12:08:11.0683 0x1830 [ ABBE803FE0BDAE0E5BE74DDEFBE62F23, 5009F489F7A6D66628C23A0FA3D7632399D0AD72BD11A1B70D7E768ED507377D ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys 12:08:11.0698 0x1830 SiSRaid2 - ok 12:08:11.0714 0x1830 [ 6043DF55CFE3C7ACF477645FA64DEA98, 0E18EF8EC589841BC319C17FBABA7383FD247C9441ABF64A0D830976F3E611AE ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys 12:08:11.0729 0x1830 SiSRaid4 - ok 12:08:11.0761 0x1830 [ C584D941C2F915B27FAEE9B407744641, 539CF92D713F502FB4C60E0ED4239ED993D94985B03067A9007343AFA5D8E497 ] SmbDrv C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys 12:08:11.0761 0x1830 SmbDrv - ok 12:08:11.0808 0x1830 [ 8A6571231D93C08434A56E19E33A35CB, 78A12B58D129D5B2017C9A94734656B9F1ED41345DF1D01F82702D4D95C1BE3F ] SmbDrvI C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys 12:08:11.0823 0x1830 SmbDrvI - ok 12:08:11.0854 0x1830 [ B922D32039A3B5991E64429EC4EE52A9, 5EB7EB1F6D2C25F06044D8CA9F3BA0471FB40C8C96432BDC2C80CC36DC49BA0B ] smphost C:\WINDOWS\System32\smphost.dll 12:08:11.0886 0x1830 smphost - ok 12:08:11.0933 0x1830 [ F07301C282AA222C33F8C28B4F545275, 2938943A3A62B33C8296DF3B57897D32293F5395A5E2A01C76B0160A98C12520 ] SmsRouter C:\WINDOWS\system32\SmsRouterSvc.dll 12:08:11.0964 0x1830 SmsRouter - ok 12:08:11.0995 0x1830 [ 0B6BECB2651EF947249CDC3715E8B9CC, EB7281AF3529DE16FE8CD0C0C0C8877641865A5864D58628DBAB865B510B0D0B ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe 12:08:12.0011 0x1830 SNMPTRAP - ok 12:08:12.0058 0x1830 [ 1A6CB30F0EFC1632E6F1B852CA892583, 0E6BDCEE837AEC3D02C437478143C75550C94A50E36895DDB095F54A2FA18E2A ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys 12:08:12.0073 0x1830 spaceport - ok 12:08:12.0089 0x1830 [ E1C158F6C00359278727A2CEE5D2ED71, 1591F942C6DD99D3BA7FD4D72D957864117B2263F205468A15F1D1417C6F799D ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys 12:08:12.0104 0x1830 SpbCx - ok 12:08:12.0136 0x1830 [ D1241DFC397FA8CCFB4BB4B63AAD31AC, F8C57C2F7CA8B6D8FEE1505A143A3FECF502C8DCFFC375F9C8848A87D9714C9E ] Spooler C:\WINDOWS\System32\spoolsv.exe 12:08:12.0167 0x1830 Spooler - ok 12:08:12.0323 0x1830 [ 7C58AFEC26E9F7730A8AA7FD40225937, 546EAD8889F2A1BB6DCCB7781976B975F34DA1C9047F95FEAA52CF38EC60C6DD ] sppsvc C:\WINDOWS\system32\sppsvc.exe 12:08:12.0480 0x1830 sppsvc - ok 12:08:12.0512 0x1830 [ ACC1709EC7FE6EB8999DBC91C50C2B34, 83ABF51751A264291C53A32B86239A607361E56CB045CD2CBE6E41DBB8A01F54 ] srv C:\WINDOWS\system32\DRIVERS\srv.sys 12:08:12.0543 0x1830 srv - ok 12:08:12.0590 0x1830 [ AFBCFC946FAE7483E27BD316D03F94A5, CC9478EA717E85C38304957E923997821DFE2A995D7C8DF98C15267D952BEFBE ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys 12:08:12.0621 0x1830 srv2 - ok 12:08:12.0668 0x1830 [ 107C1EBE79710E4A759449BD6604245A, 963D693F4E61EDC7B3AA9006CC274D56E577CE0035A61DDB2A6DE72116D5C52B ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys 12:08:12.0699 0x1830 srvnet - ok 12:08:12.0715 0x1830 [ 8C1786C073A496B8C0C8A5450A4FFD5B, 13BF3B42A63CE6C461259D4CE767FB0DE1F10433512A11D2B2C033E36E652542 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 12:08:12.0746 0x1830 SSDPSRV - ok 12:08:12.0777 0x1830 [ 217A982201052EFC8C3C0C88D229791C, 11509E3446ED7B75C9A05CDC4A7AF18926CB463E0D98BAE1CD5DB43E88F94F90 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll 12:08:12.0793 0x1830 SstpSvc - ok 12:08:12.0902 0x1830 [ 58863C57E4598C4F9DA967C5C36CFA5D, BB34FBC324E84E05128258CE3755241ECB63F7F2AE7F96716AC373931FAF92A8 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll 12:08:12.0980 0x1830 StateRepository - ok 12:08:13.0012 0x1830 [ CCDA497C880AD16D87EDFAEFCFB2EDF5, 622599AA35ACFF0375DA252210BE42E7E90F30EDFEFF2F62FDB14AE6E45B5F88 ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys 12:08:13.0027 0x1830 stexstor - ok 12:08:13.0059 0x1830 [ 75476CAA8FA0A4E573948CDE8C7F0304, 68C4405CACA77AEED71761875A9AF60BCFBDD39E356BEA1BA8226E099BAA5FA4 ] stisvc C:\WINDOWS\System32\wiaservc.dll 12:08:13.0090 0x1830 stisvc - ok 12:08:13.0137 0x1830 [ BF8EA6FC3358C2F69678E3E94F764F84, D274DAD7B5756DD49CA44277C73497F1EC465C8E365CC730CD194932C3825920 ] storahci C:\WINDOWS\system32\drivers\storahci.sys 12:08:13.0152 0x1830 storahci - ok 12:08:13.0199 0x1830 [ 32FF460DA8C1F370F5C08B7654899B73, 0C9D5D38D033109BA672ABAFEF0F0CD295E9FFA108ACFCA9044429D9B2CA9057 ] storflt C:\WINDOWS\system32\drivers\vmstorfl.sys 12:08:13.0215 0x1830 storflt - ok 12:08:13.0230 0x1830 [ CC21DB3EF619B9480FE31A4EFE92CBEB, 256EFCA2F231F41D34250E1460BF88894D943EAE83A0B153FCADE700AB4DE11E ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys 12:08:13.0246 0x1830 stornvme - ok 12:08:13.0262 0x1830 [ 390B8A75768E2689586539C224520895, D72F52E6D7AC5DC318FF9C1DF1F4E8A435D65B6BB59D7F1642222EC026BC54DB ] storqosflt C:\WINDOWS\system32\drivers\storqosflt.sys 12:08:13.0287 0x1830 storqosflt - ok 12:08:13.0321 0x1830 [ 9953FA89A4E3BC33296DAFB1ACFDC62F, D2F2698834691FF7915BDFFB82DB549354311A5DD7D37BF767F95D407AC4019F ] StorSvc C:\WINDOWS\system32\storsvc.dll 12:08:13.0352 0x1830 StorSvc - ok 12:08:13.0367 0x1830 [ 770A92D9D3A0BF61C97C3AFCB36847D9, 21A8CC3F8E63B971C4FF8DDED5C7032E093A7B0F16E2128A9BD2E890BA76A1D9 ] storufs C:\WINDOWS\system32\drivers\storufs.sys 12:08:13.0383 0x1830 storufs - ok 12:08:13.0399 0x1830 [ 736A2418E3E7F3DB3CF6EB0A55D1D581, 2D3BBC4E0C7B51EDE7479A978E4BCD5F47A7257745179F01D2D9ECFD83CCCC82 ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys 12:08:13.0414 0x1830 storvsc - ok 12:08:13.0446 0x1830 [ FA8F6E3AD3F92B35D2673CC9FD20429C, 62F81CBACF7E16FEF9DE3BE95FA5C9BDB51BAE4667AE5AE71399864A390FF6D5 ] svsvc C:\WINDOWS\system32\svsvc.dll 12:08:13.0461 0x1830 svsvc - ok 12:08:13.0477 0x1830 [ BD98B0225BCD49E8A62F4F8EE1D1F613, CDAD11969B2DA417079547724BECC3DB4FC4711B3C01590EB0D02774B69B6D90 ] swenum C:\WINDOWS\System32\drivers\swenum.sys 12:08:13.0477 0x1830 swenum - ok 12:08:13.0524 0x1830 [ 22E539A9B96C66A713583EC017562616, 210DA61DFC7AA9AD23277D9CC0239B781F4EABD322D0803AEC9434D68B81FABD ] swprv C:\WINDOWS\System32\swprv.dll 12:08:13.0555 0x1830 swprv - ok 12:08:13.0586 0x1830 [ CAE4B27B469C583131EA5AAE622F5D76, 3979006EB22489D1AAD2EC2E9F32C286EEDCDB83B37B97E58BA831263EC33B84 ] Synth3dVsc C:\WINDOWS\System32\drivers\Synth3dVsc.sys 12:08:13.0602 0x1830 Synth3dVsc - ok 12:08:13.0633 0x1830 [ 7DC2B34FB6F1798F2D13453E0321D025, 60EF12A8824384DD88D9C5D188E8FB137F0F85A63C06AAF720CB2D616EB847F4 ] SynTP C:\WINDOWS\System32\drivers\SynTP.sys 12:08:13.0649 0x1830 SynTP - ok 12:08:13.0789 0x1830 [ 6FBDBC24B1642868E041463795CBFA44, E9FA0DB094E7B2129ABD325BC91A48D6646380D6AA97BE6233C220E0C98637AF ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe 12:08:13.0805 0x1830 SynTPEnhService - ok 12:08:13.0883 0x1830 [ 34A3EB84B2A830E6F450B8F885AE4E6E, E61AC6D17B815CB71F26D71CA3CCAFD9E66A170E3ED2E64A4F20D097A0C683B5 ] SysMain C:\WINDOWS\system32\sysmain.dll 12:08:13.0930 0x1830 SysMain - ok 12:08:13.0961 0x1830 [ AF2C8D7C1D4DCFD5C31501F009DF42B7, 3DDF9353F014EE99B031BBC969620CA07647FBB8D78EB4697C8D633021B46B11 ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll 12:08:13.0977 0x1830 SystemEventsBroker - ok 12:08:14.0008 0x1830 [ 6979A147C0D5C5CAB621ADC394D32B80, C30B8E3D271A1591D965559EA4A11A1BE63A34D832ED53B26CE91799C888DF77 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll 12:08:14.0024 0x1830 TabletInputService - ok 12:08:14.0055 0x1830 [ 86B62FC8CB89946446F9B24FE49A66FD, 7B095310D1C78B82E5ACAC4713E101DD1323A3CF6FB39218C2E78ABE2B0385B5 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 12:08:14.0071 0x1830 TapiSrv - ok 12:08:14.0164 0x1830 [ 892F30506DCCF230C5A57019C1D8D31B, 52C83A963E2D05770B6A281E8E559C8203E102D6B4C9C37801B1F58CB4B92D2F ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys 12:08:14.0227 0x1830 Tcpip - ok 12:08:14.0274 0x1830 [ 892F30506DCCF230C5A57019C1D8D31B, 52C83A963E2D05770B6A281E8E559C8203E102D6B4C9C37801B1F58CB4B92D2F ] Tcpip6 C:\WINDOWS\system32\drivers\tcpip.sys 12:08:14.0321 0x1830 Tcpip6 - ok 12:08:14.0367 0x1830 [ 17F37EC9042D84561C550620643D9A85, B01620BA319A1383D403E6E50C7724879520F3267654556D975CAFFF91A82C78 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys 12:08:14.0383 0x1830 tcpipreg - ok 12:08:14.0414 0x1830 [ 91D3F2A6253EF83EFBD7903028F58C4D, C15768CCCF734093B0F8A5E76882B35927B716E4F14D91ACEE897E1C078D43D1 ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys 12:08:14.0430 0x1830 tdx - ok 12:08:14.0461 0x1830 [ E730D0EB1B84EBC98423FC8D285EDBC0, 442DD433F9D22304E64EC7ACFC4E04892D4D92D8AC545A3530FC932A2EEC4767 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys 12:08:14.0461 0x1830 terminpt - ok 12:08:14.0518 0x1830 [ 14307D4801C8CEF0A615907C09E886B3, C7F34C294D70DE689F673E0B5E9253B27EFEBBE6FA38B68B3B0B0374A896407E ] TermService C:\WINDOWS\System32\termsrv.dll 12:08:14.0580 0x1830 TermService - ok 12:08:14.0627 0x1830 [ D009D1BC14FD5F2AC93D1878735F6C39, D8BCE505B66E05BC00075E46B38359CA4D0FA484EB7981A74221885E8A1FFB87 ] Themes C:\WINDOWS\system32\themeservice.dll 12:08:14.0659 0x1830 Themes - ok 12:08:14.0690 0x1830 [ 5F27DE2082E16D4C1D6C627C8ECBD341, 08DA3EB3EF2B2006B6F9F2C8C149DF55DE6738975D556206A814096CAB5C1411 ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe 12:08:14.0705 0x1830 TieringEngineService - ok 12:08:14.0752 0x1830 [ FC971E1D1B5900C231591A7720FCD8B8, DF58C350977019E4A8F381FB35702E9BEA89F6A8C6BF36C56376D36BC8FE630F ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll 12:08:14.0768 0x1830 tiledatamodelsvc - ok 12:08:14.0799 0x1830 [ 7E81E3E0D7F83BFE3C3975020B6C7F12, 316F9415646CC7A4E9A5F1E07310D433457E623B3E589543E4A6C73C4F77712C ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll 12:08:14.0815 0x1830 TimeBroker - ok 12:08:14.0846 0x1830 [ 169B0A246067457FEF8A18EED7EED9D5, BF5AC0CB29E1E456253B881CD0608B578D7343E9DFE1738A14598D1DFFE1AB66 ] TPM C:\WINDOWS\System32\drivers\tpm.sys 12:08:14.0846 0x1830 TPM - ok 12:08:14.0877 0x1830 [ AA84AF93CE5AF1F05838B51D20295419, 85B3EE773C691EEDFA080CD9C59D31CB58A5BC577AEE91A929F5DFBE1368AB6D ] TrkWks C:\WINDOWS\System32\trkwks.dll 12:08:14.0893 0x1830 TrkWks - ok 12:08:14.0940 0x1830 [ E50DD57F496CED8873FA3E7D38BCCD42, 36B95F6F2CF48078C6B19FB452C87BB07E95C8804A5C6B526D349AC6227CAB26 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe 12:08:14.0955 0x1830 TrustedInstaller - ok 12:08:14.0987 0x1830 [ 48E828C66AB016E48F2CB4DD585315FD, 063809B610F6B177B65D62D12605FB94F108DB26A9FD3067E6D6C51F0D92E774 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys 12:08:15.0002 0x1830 TsUsbFlt - ok 12:08:15.0034 0x1830 [ 267C76EE60736EA5A1811A53FA02AABE, 28D4C4CB972534204B8336D0403B70E4EFE4F8369ABDE7401FFCCF7D4E3EA165 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys 12:08:15.0049 0x1830 TsUsbGD - ok 12:08:15.0080 0x1830 [ 8CE72F094B822AD5EE9C3A3AFC0C16B6, 827CCD849544E1DA364B03DBC82A848D2F93AD32BA14ED52709C609BC70CE5CA ] tunnel C:\WINDOWS\System32\drivers\tunnel.sys 12:08:15.0096 0x1830 tunnel - ok 12:08:15.0112 0x1830 [ 1A9A77ACDAC29C39F50D2A492FD0DB16, E21F2E2BA6EABE0F6B5A1930DDB2CE5A921389A58C08A2D3F66D245E8698E6B4 ] tzautoupdate C:\WINDOWS\system32\tzautoupdate.dll 12:08:15.0127 0x1830 tzautoupdate - ok 12:08:15.0159 0x1830 [ 42C546414F80BD6C0137FC3A106F8A69, 067FFCAF0059935851888BD984E848E4E1A6CC1941A8F4534067CCF0B2A3B2E6 ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys 12:08:15.0174 0x1830 uagp35 - ok 12:08:15.0190 0x1830 [ 1686DBC81748B096232B15F16C302985, 63D72D1838C42A95599AF3C0B19A069E310ADB091208011D7D6FBAC968D1A59A ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys 12:08:15.0205 0x1830 UASPStor - ok 12:08:15.0237 0x1830 [ 3995CC3DEDED258768B8EBC2F4C0DC73, 130E99EF13EB494B8BB6A8E037DD8D59C195190EA3C27CA9E3A695AF4349DC7C ] UcmCx0101 C:\WINDOWS\system32\Drivers\UcmCx.sys 12:08:15.0252 0x1830 UcmCx0101 - ok 12:08:15.0268 0x1830 [ 1C95F7CE37D9EFB90EBE987A9712356C, B9EE7743ADA50276F05D735C5C29E44039D630A7DC93766A0EAF400DA037E4AF ] UcmUcsi C:\WINDOWS\System32\drivers\UcmUcsi.sys 12:08:15.0284 0x1830 UcmUcsi - ok 12:08:15.0299 0x1830 [ AED081772091C98173905E2DF28C223B, 08541CF3354EBB634BD590E0019128F70A6FCA9075B7E785A9E9BD82EC234DD3 ] Ucx01000 C:\WINDOWS\system32\drivers\ucx01000.sys 12:08:15.0315 0x1830 Ucx01000 - ok 12:08:15.0330 0x1830 [ DCA34A111C29E4578DF2B8CEA3C7CDBD, 86BCE4C8EC228724D5896067A85A4768B6069D10A482ECC51A8F828DBD3880C9 ] UdeCx C:\WINDOWS\system32\drivers\udecx.sys 12:08:15.0346 0x1830 UdeCx - ok 12:08:15.0362 0x1830 [ 718A956AE00CE086F381044AB66CC29C, E4EED1600C72CECE1D4507827C329A93D356BBA027470FCF6C4B5C1651DED643 ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys 12:08:15.0393 0x1830 udfs - ok 12:08:15.0409 0x1830 [ BA760F8E66428BA9FF1E8BFBC6248136, BE7DCBB293B12672CB3653E640C46F669BD738D320F34F4FA4A26F6B248561F0 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys 12:08:15.0409 0x1830 UEFI - ok 12:08:15.0440 0x1830 [ 5F0D997E6FC5A418D7673148CEF72887, 6C142CB8F06E5958045451253C9188CE876A84D08266FFD7F64AAE09964D8431 ] Ufx01000 C:\WINDOWS\system32\drivers\ufx01000.sys 12:08:15.0455 0x1830 Ufx01000 - ok 12:08:15.0487 0x1830 [ 2B1DABA97DDF5365FC66EE7DEDD86A13, 2FF3355862938B37EE63FCA149415CE5032BF54747B07517BB21460733B65AD8 ] UfxChipidea C:\WINDOWS\System32\drivers\UfxChipidea.sys 12:08:15.0502 0x1830 UfxChipidea - ok 12:08:15.0541 0x1830 [ DB630FC660443D63EBAB2C830C298EFE, 7698772FF9C988DF752DF3FAF1B154E923EBA425B92F288ABB6EF0805ABD3296 ] ufxsynopsys C:\WINDOWS\System32\drivers\ufxsynopsys.sys 12:08:15.0568 0x1830 ufxsynopsys - ok 12:08:15.0605 0x1830 [ 63451BD694651307254B8DD37A3D79C7, C781E2D876AF42D5972CCDCF86B7A59F6AF8AF0C6350647F3FA1B209119B5EF9 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe 12:08:15.0627 0x1830 UI0Detect - ok 12:08:15.0641 0x1830 [ 6DE78C04BF32ECA7AF3064F53687C9A5, 164D3BB24EBA3EAF613799928063FE75220A4E583D985F53A895017782C18600 ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys 12:08:15.0652 0x1830 uliagpkx - ok 12:08:15.0672 0x1830 [ 67D1E0E6E4D5D33AF0AEF0E33B4DA0F4, BA2E6F16B6B3B54C943F1E7B9F79A6D1332A7ED228D754CC5AE70E3CD78B1F37 ] umbus C:\WINDOWS\System32\drivers\umbus.sys 12:08:15.0685 0x1830 umbus - ok 12:08:15.0707 0x1830 [ 11680607944A719EF20E0E740785712A, 1567C2B3AAD702DCC2DC9C6B7B92EE5B681C06701A39DAC3AA7E2BE9E1E04F47 ] UmPass C:\WINDOWS\System32\drivers\umpass.sys 12:08:15.0718 0x1830 UmPass - ok 12:08:15.0742 0x1830 [ FD949725D9EB52C0B87435CDE1134668, 96E2B3D3379E9AE225E5A4C5251207F1E7DA573901F4F026758EDE9FAEF4F2C5 ] UmRdpService C:\WINDOWS\System32\umrdp.dll 12:08:15.0774 0x1830 UmRdpService - ok 12:08:15.0813 0x1830 [ CB902A15DD21B363FECA5DCCF34F5C57, 6A0836A12A410EBD5C667982852B58CA9E9EDB11EA666C413CC0F811E01A549D ] UnistoreSvc C:\WINDOWS\System32\unistore.dll 12:08:15.0859 0x1830 UnistoreSvc - ok 12:08:15.0911 0x1830 [ B85A8CF2BE74DFF1E80097AC94584112, B1DBACC33A4143FEE2CF54E567590A69580312AD7A053BCC85B487C4D451FBDA ] upnphost C:\WINDOWS\System32\upnphost.dll 12:08:15.0942 0x1830 upnphost - ok 12:08:15.0958 0x1830 [ 2410A0C20D21A25E6C01979FA886BE90, DD3F92D8CF110D47B9E36BA0EB10EB34C0FDD28FE0D57E4B60F9326703388F75 ] UrsChipidea C:\WINDOWS\System32\drivers\urschipidea.sys 12:08:15.0973 0x1830 UrsChipidea - ok 12:08:16.0005 0x1830 [ 6E59CE43B6BA5AA1ADCF36A4DBBB92BB, 647D66775A90F67D803043DE8C8AE8BC2F7A042A8DCF9C95BF5458C79609481B ] UrsCx01000 C:\WINDOWS\system32\drivers\urscx01000.sys 12:08:16.0020 0x1830 UrsCx01000 - ok 12:08:16.0036 0x1830 [ E8A59FA109A22FC07E44BDFCC9727DBD, 0DC5928C0FF7E5B38917660D6EFECCC22172DB0BB9B23216F33E750790529C16 ] UrsSynopsys C:\WINDOWS\System32\drivers\urssynopsys.sys 12:08:16.0051 0x1830 UrsSynopsys - ok 12:08:16.0083 0x1830 [ D8A44550ECE102B6443F5D54DCE7DAB3, 97F5AE7B17DAC4A4F3186C77116BC8E49874FB0018C99D8E2CDA29D89E8B0912 ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys 12:08:16.0083 0x1830 usbccgp - ok 12:08:16.0098 0x1830 [ 66B3D22DAB5312FF238ABF5C6D9F8FAB, 4A644AFC1C27D692D352BEB8801398A00EA5B4055476063AF905A0A46DDBF8BB ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys 12:08:16.0114 0x1830 usbcir - ok 12:08:16.0161 0x1830 [ 3E4F20DB902D2E2914F3FF3DB9772200, F3D32BE06A26164B5F6E8DB67160D1DBBDC6D14666EEF84EA43C78CB7706E31C ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys 12:08:16.0161 0x1830 usbehci - ok 12:08:16.0176 0x1830 [ 41F7F00D76904416EF1F9EFA1A4C37A2, 7A4250EB2E2E0037B3AE1480C13B229ECFF5C575E68E4F934EE011DB1833B46A ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys 12:08:16.0208 0x1830 usbhub - ok 12:08:16.0255 0x1830 [ B7E1CAA9429E4C3E7E01CB35B97E1536, 11A6431C27821F247202AC9F18441FEA26544630461522C129F1671257C527BA ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys 12:08:16.0270 0x1830 USBHUB3 - ok 12:08:16.0301 0x1830 [ DAB35CCA86F5FBE77D870A40089BC4A1, 4A47D59D882D0F2B93F2EE7F10995E7D68B58009434E2CBD04C659E0D1F059D8 ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys 12:08:16.0317 0x1830 usbohci - ok 12:08:16.0333 0x1830 [ 21162F65C7756AAECAEBED9E67D0A5FE, DE3B43964171DB5B0464DA5E7A674A5D200A8695E6EF1AE2030681066ABA2688 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys 12:08:16.0348 0x1830 usbprint - ok 12:08:16.0395 0x1830 [ F259A45D6B555B14CC8365AA6BC8DC20, 28A588656449307F6E9C999BE5D73E34A2542A5771F4B504D9D36B9F93F32303 ] usbser C:\WINDOWS\System32\drivers\usbser.sys 12:08:16.0411 0x1830 usbser - ok 12:08:16.0442 0x1830 [ 8949F77132A4F8F3BA17C6727099F002, 86AD4A2263B34983335180FDAE775D1744E042D2A11300D27DF546F15F285A25 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS 12:08:16.0442 0x1830 USBSTOR - ok 12:08:16.0458 0x1830 [ 8B3E458A8851F9A3B2109B1680EE1159, 753AC8F82F65564F00EA2F60B43E4B815FEAABE0DA35B6356210A5F4B1CA3EFC ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys 12:08:16.0489 0x1830 usbuhci - ok 12:08:16.0520 0x1830 [ 4B13B61CBB9CC3CB373C60B930D648F5, C79D10A1BF2B6BF141DD37A90BCCA0E1F2AF31B5028BB21537A8EE6EED630F5B ] usbvideo C:\WINDOWS\System32\Drivers\usbvideo.sys 12:08:16.0551 0x1830 usbvideo - ok 12:08:16.0598 0x1830 [ 325727F01F03C504CF788618A13DC266, 9F685113F714ADBC6DCD423CCD205F71E00D1AA9B5DD045B95E61E53B0F8E9AF ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS 12:08:16.0614 0x1830 USBXHCI - ok 12:08:16.0694 0x1830 [ 2771EBB565F5C121E66060B173991D4D, 1EB34A6262A18E47ADCA392FDB2D58E8428A1CA43EB4196D76A897F74A03CA7F ] UserDataSvc C:\WINDOWS\System32\userdataservice.dll 12:08:16.0732 0x1830 UserDataSvc - ok 12:08:16.0795 0x1830 [ 36EC82F0E399F36BD25F593D63DC144A, 2A9E916A098ACD5A5074A5FD053ECAB027A0932A348C728F20CD63EF16289533 ] UserManager C:\WINDOWS\System32\usermgr.dll 12:08:16.0857 0x1830 UserManager - ok 12:08:16.0888 0x1830 [ 05F4CB5991D897E4253BF61FA5E828F8, 25B5B6751B4455491E9A050DF5C12F788B5677F70FB4844E0BF851090AC1F74C ] UsoSvc C:\WINDOWS\system32\usocore.dll 12:08:16.0904 0x1830 UsoSvc - ok 12:08:16.0920 0x1830 [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] VaultSvc C:\WINDOWS\system32\lsass.exe 12:08:16.0935 0x1830 VaultSvc - ok 12:08:16.0966 0x1830 [ E1BE37312785A71862516F66B3FD24CE, D248C513DBEACB192653C6E46809209F341771B146544BBF43B86369280B4F8B ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys 12:08:16.0982 0x1830 vdrvroot - ok 12:08:17.0013 0x1830 [ 67A6E949395A09914AD8B38FE14B8D15, 593F2FAA880B2E0468F98BD58B5214A170E5890907B25294D7A47C66505A3D45 ] vds C:\WINDOWS\System32\vds.exe 12:08:17.0060 0x1830 vds - ok 12:08:17.0076 0x1830 [ E42C0F2850735FF9D908B9DB581E6314, E2204A56BF37FC57CD2ED96E3F908882D72B4BFF1BFB97C5172C851F1E4F9650 ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys 12:08:17.0091 0x1830 VerifierExt - ok 12:08:17.0138 0x1830 [ EC15FD6A28757793E2DA394CD94ABD52, DC758BBEE9C6952D7B3F7171EF67B037B4068E88189A2C4A894122D1D1209468 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys 12:08:17.0154 0x1830 vhdmp - ok 12:08:17.0185 0x1830 [ D0C9632C350F46786643A069251BC249, CF65BA0D3F3D2B821C10E2D4F53F5B6BF6236CA9767419392A561CFA79254C3B ] vhf C:\WINDOWS\System32\drivers\vhf.sys 12:08:17.0185 0x1830 vhf - ok 12:08:17.0263 0x1830 [ FF9E47752DE943B35D00E5BC96BDC714, 953A14637E310E27BDBD46B3A711875DBE0963AF185A523BC7E002427EA0E710 ] vm331avs C:\WINDOWS\System32\Drivers\vm331avs.sys 12:08:17.0295 0x1830 vm331avs - ok 12:08:17.0326 0x1830 [ E886CB75DA2B6EB35469EF10135624C7, 3AFC59A0709B984F517A918D5BBEBEB1C80001BEC87C133447DCEAEDE00E516D ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys 12:08:17.0326 0x1830 vmbus - ok 12:08:17.0341 0x1830 [ 46D2EC27820EC0F798F85821E53C2942, D298A7D6AC16F76A069F843C8DD323ECB340D361733CB9B076BCDE8FC5F1FEFC ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys 12:08:17.0357 0x1830 VMBusHID - ok 12:08:17.0404 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll 12:08:17.0420 0x1830 vmicguestinterface - ok 12:08:17.0435 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicheartbeat C:\WINDOWS\System32\ICSvc.dll 12:08:17.0451 0x1830 vmicheartbeat - ok 12:08:17.0466 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll 12:08:17.0482 0x1830 vmickvpexchange - ok 12:08:17.0498 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicrdv C:\WINDOWS\System32\ICSvc.dll 12:08:17.0529 0x1830 vmicrdv - ok 12:08:17.0529 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicshutdown C:\WINDOWS\System32\ICSvc.dll 12:08:17.0560 0x1830 vmicshutdown - ok 12:08:17.0576 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmictimesync C:\WINDOWS\System32\ICSvc.dll 12:08:17.0591 0x1830 vmictimesync - ok 12:08:17.0607 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicvmsession C:\WINDOWS\System32\ICSvc.dll 12:08:17.0623 0x1830 vmicvmsession - ok 12:08:17.0638 0x1830 [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicvss C:\WINDOWS\System32\ICSvc.dll 12:08:17.0670 0x1830 vmicvss - ok 12:08:17.0701 0x1830 [ B9265F47E7A354BAAA0AF5CBA3F8F7CE, F836E7BEDC7CAB1C01225164D171A0210D8F909F52992E4C0BF3C92B365BCD52 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys 12:08:17.0711 0x1830 volmgr - ok 12:08:17.0722 0x1830 [ BEE9C8B72AB752B794F69C2B9B3678AA, 49A5093C26F3CDCD60577F7F2D7F936C7B2BD010B27F2C49A7B6AA41E42DF98D ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys 12:08:17.0738 0x1830 volmgrx - ok 12:08:17.0785 0x1830 [ E1F91A727A04C9F8199D04FF3BBBF63C, 076CAEE621DBF7DE24ED92BA239C440879FDB674CF3213DF3E35AEC03D0D2031 ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys 12:08:17.0800 0x1830 volsnap - ok 12:08:17.0816 0x1830 [ F7B1B1101271E31F43CC76E890704F51, 2282D82B220C3D13FF980ED8E40443C83816D3DA9557EACEA137873F92BB9CF4 ] vpci C:\WINDOWS\System32\drivers\vpci.sys 12:08:17.0832 0x1830 vpci - ok 12:08:17.0847 0x1830 [ D48ED0A08BD2FD25A833E6AC99623091, 6CA7580878D3893E14B4938023A00CDFC9BE215A0CE4ED59A94F95DFD9FDF4D8 ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys 12:08:17.0863 0x1830 vsmraid - ok 12:08:17.0925 0x1830 [ 4CF5A1E0C4FCA956ACD6C654E2A8610E, 57F3C7200C25E8717AF92AF2ED7615C6605179D3514B432220FA6EA94CAB4F2E ] VSS C:\WINDOWS\system32\vssvc.exe 12:08:17.0972 0x1830 VSS - ok 12:08:18.0035 0x1830 [ 6990D4AFDF545669D4E6C232F26DE1FB, 9B8F99A035188FD96BA79E935E8EF387BEA2223ECA0B74CF64AB993DABAA5722 ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys 12:08:18.0066 0x1830 VSTXRAID - ok 12:08:18.0082 0x1830 [ 1EE11F0508C58EF081F4176E66D6970B, 9069B3FC8850C7CF617909C6DBFC3753FEB59A9E708379CC57190F4097FB374E ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys 12:08:18.0097 0x1830 vwifibus - ok 12:08:18.0113 0x1830 [ 938E4EF58E42D252B742B0E243011B90, AC0C21FBAF15924CB271CA43ACB7A86287936C78B4852BCFC59EC7EC703E036C ] vwififlt C:\WINDOWS\system32\drivers\vwififlt.sys 12:08:18.0128 0x1830 vwififlt - ok 12:08:18.0144 0x1830 [ 3BE5AAC930447FD18D4A8255A2FEC95C, A517357188FE4A5BD98A3CDB2165ACCE96CCE4BE2B90DDBEAF70B6DDF393F506 ] vwifimp C:\WINDOWS\System32\drivers\vwifimp.sys 12:08:18.0160 0x1830 vwifimp - ok 12:08:18.0207 0x1830 [ 48C1A256591297C43ECFC4E30D144EAA, 8E66833ED2CEB6D7E499EB2E4282B4F9DFA28B6D21757BB88EC52FD069D7FACE ] W32Time C:\WINDOWS\system32\w32time.dll 12:08:18.0238 0x1830 W32Time - ok 12:08:18.0253 0x1830 [ 00C27B64C758C111E5D78A70DE6CA2B6, C99761B9B671B3A1FF1C52796CCA3F4F825BF50D9657D13B551E849CDD82055D ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys 12:08:18.0253 0x1830 WacomPen - ok 12:08:18.0316 0x1830 [ D76D1AC4F2C642D09A68227D129A4726, D14D6C4D94E9660848C74B220359683D91A4A3D70750E781A20B6D86D46794CE ] WalletService C:\WINDOWS\system32\WalletService.dll 12:08:18.0347 0x1830 WalletService - ok 12:08:18.0394 0x1830 [ 8CB53620B2C2F0641DD7563EA0FDF491, D62FE75C908409A54949F0E3C39558DC7A8F11AF7496ED7B0872D80D08CB67A7 ] wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 12:08:18.0425 0x1830 wanarp - ok 12:08:18.0425 0x1830 [ 8CB53620B2C2F0641DD7563EA0FDF491, D62FE75C908409A54949F0E3C39558DC7A8F11AF7496ED7B0872D80D08CB67A7 ] wanarpv6 C:\WINDOWS\system32\DRIVERS\wanarp.sys 12:08:18.0441 0x1830 wanarpv6 - ok 12:08:18.0535 0x1830 [ 2598BBF11C9E7D0885DCA52E7FD5BCBD, 46B1FB080A2CD88C89A0EB8BA2594A1FA2C341ED77A6C6835CBFFE42907FAC55 ] wbengine C:\WINDOWS\system32\wbengine.exe 12:08:18.0582 0x1830 wbengine - ok 12:08:18.0628 0x1830 [ 642EFABF900374FA85639D83B5533AFD, 292692D6AAC2A785D237ADFBC7CA3D379E8FC79FA366A8CE7D06F5CA5CE6866B ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll 12:08:18.0675 0x1830 WbioSrvc - ok 12:08:18.0724 0x1830 [ E9A0D466F6D8EC349DB526146618BCB6, CFD6F3F979E4366A68FBEC3BE90A42BF3D65403A987E80741A720C0622871F32 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll 12:08:18.0767 0x1830 Wcmsvc - ok 12:08:18.0813 0x1830 [ 53A036CED1270F2459E708A05922FD49, 2F281A72E4B0408DE6C8153F5988C9AA38591FB1E72558767D389637D0666A85 ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll 12:08:18.0860 0x1830 wcncsvc - ok 12:08:18.0907 0x1830 [ 965B6197A659782B6A0F68411A180AAD, 5541AB78B71E4FA655BCBF2D80D574B2A3B4AA8871F65D26620BDE549FA5459A ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll 12:08:18.0923 0x1830 WcsPlugInService - ok 12:08:18.0923 0x1830 [ 069D3D6E20AD753B34FCE856F0436869, CF8C12295DDAA56E7350019AADBA533D7857CFB3F20DEE14E557963645A9331B ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys 12:08:18.0938 0x1830 WdBoot - ok 12:08:18.0970 0x1830 [ 6CC727E94CD84E9720FDCDA8089CABCC, BCF66056B06DED6BC2D329E910FCD3E685D627BAD3B5D7F4B0E970B45CD9CEF4 ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys 12:08:18.0985 0x1830 Wdf01000 - ok 12:08:19.0032 0x1830 [ E3E97151A1D1E87BB2D5371F66C5F169, 0ED0B9852FE0533816F5EE2F06045B3964A00FD749A7011DB3C663AB6FA369E2 ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys 12:08:19.0048 0x1830 WdFilter - ok 12:08:19.0048 0x1830 [ 75DC67553051103547B693898CB32D08, 4FCF2C3DBBE85461364B1F3A3F3629B52C8664487D30142D15937A4C96EF6A8F ] WdiServiceHost C:\WINDOWS\system32\wdi.dll 12:08:19.0079 0x1830 WdiServiceHost - ok 12:08:19.0079 0x1830 [ 75DC67553051103547B693898CB32D08, 4FCF2C3DBBE85461364B1F3A3F3629B52C8664487D30142D15937A4C96EF6A8F ] WdiSystemHost C:\WINDOWS\system32\wdi.dll 12:08:19.0095 0x1830 WdiSystemHost - ok 12:08:19.0142 0x1830 [ E70DDD8E2245CC67547B0861983912D8, 64C73B1496FFF1F6BB3D877CB5BE54DE35C303AE234B11FC90038DC4F73241D9 ] wdiwifi C:\WINDOWS\system32\DRIVERS\wdiwifi.sys 12:08:19.0173 0x1830 wdiwifi - ok 12:08:19.0204 0x1830 [ 07B043160399AF4009054E2EA3464BF4, 8D652D7CD75F8FB2B5414155355F0C970015914E1AC6522DBB8387BB8662F542 ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys 12:08:19.0204 0x1830 WdNisDrv - ok 12:08:19.0267 0x1830 WdNisSvc - ok 12:08:19.0282 0x1830 [ 9972D395DBD05D91DA5EDADEB9325680, 9382D846793F285721A1A0FED42F914035A53D856B902FADB0B7144C471BDA91 ] WebClient C:\WINDOWS\System32\webclnt.dll 12:08:19.0298 0x1830 WebClient - ok 12:08:19.0329 0x1830 [ B6BF579761489720BCE787F723F596E5, 879B17F6A4F23F5E85A09126B7B407955DDCEB1BA4A8FFC0A418B7F47311C056 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll 12:08:19.0360 0x1830 Wecsvc - ok 12:08:19.0360 0x1830 [ 10C9CF8771A2A87F575F9FB56821474E, 15E3DFFE9CF6777F67E426ECF797D2DF743EA152DEE336DCC9C2F92A0E6EB9A3 ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll 12:08:19.0376 0x1830 WEPHOSTSVC - ok 12:08:19.0423 0x1830 [ 357C083FE35D030D991D163AAF622A06, F301852D49DBDEF0D28F56CD74CBDC71CA003EBD07D3F46EA5C870DC1BD07896 ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll 12:08:19.0438 0x1830 wercplsupport - ok 12:08:19.0454 0x1830 [ 2235AF716D15D9DFE4C59DC2AC0C440C, 2DCFCEBEA77E7E40CEF9A785BE1A794B390B36E40FBCF49B494F9CEA3F6A28C4 ] WerSvc C:\WINDOWS\System32\WerSvc.dll 12:08:19.0470 0x1830 WerSvc - ok 12:08:19.0485 0x1830 [ C11272713719922DE5711094333BD166, 61D4F07E02AECF04964FF51EEA31069A2B0EAA549AD2B29B5FD3E1E6BB543593 ] WFPLWFS C:\WINDOWS\system32\drivers\wfplwfs.sys 12:08:19.0501 0x1830 WFPLWFS - ok 12:08:19.0517 0x1830 [ 205A1FAE910F5C493D236245850BB62A, DBA4D1D734BAA3CDEB8A7F9C81A8DAA88CEA55AF5C4C5908E76FB8E522C5EC8A ] WiaRpc C:\WINDOWS\System32\wiarpc.dll 12:08:19.0532 0x1830 WiaRpc - ok 12:08:19.0563 0x1830 [ EF536C54AB9281FDC4E83B07279FCFC4, 22E4F133170682EE14413CA8FDC2DBE73AB31960D6ACB728A6B398229FDDFD3B ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys 12:08:19.0591 0x1830 WIMMount - ok 12:08:19.0594 0x1830 WinDefend - ok 12:08:19.0621 0x1830 [ D8966A76408107224C6013993135DD78, 6159F69BC26FF817078E68C70E6DFC9075FEBF9EF9F4F046C7A65BC377544AE6 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys 12:08:19.0638 0x1830 WindowsTrustedRT - ok 12:08:19.0657 0x1830 [ 8B102A7B6CE326FD4208CC7C2D183343, E47C1D76CBFD2A382C3A7BB048D752FB6DD4616FADDEB1C3ADD5DDAE149742AF ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys 12:08:19.0671 0x1830 WindowsTrustedRTProxy - ok 12:08:19.0707 0x1830 [ FFD04E8263FC9CDB89BAD8C27C337223, 7021161D354F1536DA261D001524B92301466631DCFA161A7C6355AAC86BBE40 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll 12:08:19.0741 0x1830 WinHttpAutoProxySvc - ok 12:08:19.0765 0x1830 [ 4A53441C1C4D2878BEF27E381138BB2D, C221E74491E6FD2AF472B53876B46788D5CF62F4E645457F3B3816FD0ED2BAA1 ] WinMad C:\WINDOWS\System32\drivers\winmad.sys 12:08:19.0775 0x1830 WinMad - ok 12:08:19.0898 0x1830 [ 1033C37122C7404C3B926ADF84874832, 163B3A7112F13AE7BB2655A28C6B19AF9B263F2AD2FF1B75314BE3E2B9118903 ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 12:08:19.0929 0x1830 Winmgmt - ok 12:08:20.0023 0x1830 [ 703D0F62C5AA4D08EE8756516C0D125D, 02015A5E62490C11EC968160C528C2AFD1D7194AACA27F407B06EB462657511F ] WinRM C:\WINDOWS\system32\WsmSvc.dll 12:08:20.0101 0x1830 WinRM - ok 12:08:20.0132 0x1830 [ 260907CE034FE327AC99BDA4153AB22F, B96501F43248713C2E153B9D22B78D51412A3C6989A2FB5F53A406C6CDC98D30 ] WINUSB C:\WINDOWS\System32\drivers\WinUSB.SYS 12:08:20.0132 0x1830 WINUSB - ok 12:08:20.0163 0x1830 [ 40A3E8D729F458B2C9A8BD9380FF83D5, CD42FFC138969EF8C9588FD113F0B9A98FBA282D46A5B6BCFA765F55ED6E97A1 ] WinVerbs C:\WINDOWS\System32\drivers\winverbs.sys 12:08:20.0195 0x1830 WinVerbs - ok 12:08:20.0257 0x1830 [ 453740989239803FE363FF8B40EA2E08, 25499705627C38D3431B3C336E0CF3BF55ABB0C461B88DA6D3767CAAE1E2B893 ] WlanSvc C:\WINDOWS\System32\wlansvc.dll 12:08:20.0335 0x1830 WlanSvc - ok 12:08:20.0413 0x1830 [ E48BBF1363F843E030757EC190DD33E6, B37199495115ED423BA99B7317377CE865BB482D4E847861E871480AC49D4A84 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll 12:08:20.0476 0x1830 wlidsvc - ok 12:08:20.0523 0x1830 [ 8F010BF65238F3F822D22BA12831796E, 2CA830F259B742D2F5CDD0437960BF512D40FB4A4C2342E3BABB38D468F79694 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys 12:08:20.0555 0x1830 WmiAcpi - ok 12:08:20.0594 0x1830 [ 74ACA5A7880C1F0BB9D60E32E1705A70, A89817BCCBFF94D7394614DA81D1C6C4F53AF47A539E674EEF6DC3FC496BF702 ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe 12:08:20.0621 0x1830 wmiApSrv - ok 12:08:20.0634 0x1830 WMPNetworkSvc - ok 12:08:20.0654 0x1830 [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof C:\WINDOWS\system32\drivers\Wof.sys 12:08:20.0667 0x1830 Wof - ok 12:08:20.0737 0x1830 [ 4090C6738AA92B428220857B4D44F638, 4A3EE47494051E5BA8393F2AC8226EF434DA3AA1895CF4BADC9BC1BC378647C6 ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll 12:08:20.0799 0x1830 workfolderssvc - ok 12:08:20.0832 0x1830 [ 22C52D7EE7C7D0E02C8EFD8CAE8E3A71, 126605A12CEC9CC07DE3050F12E43CECABEAF0D00DF12300AF70F34700F7FE8E ] wpcfltr C:\WINDOWS\system32\DRIVERS\wpcfltr.sys 12:08:20.0843 0x1830 wpcfltr - ok 12:08:20.0859 0x1830 [ D282ECA35ADAC7A93D6B4943E775010B, A76A9698A95646FA63AC18DFFA02B744D7C6043934CBF6C37832ED2E6B21F570 ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll 12:08:20.0874 0x1830 WPDBusEnum - ok 12:08:20.0890 0x1830 [ 1C08E424CBDD5065BB7266F8C048C1B1, 0452C85EDA6CBAB75C2617886C5D8117ED25D91F1BE0F8377B08D55B6629B028 ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys 12:08:20.0906 0x1830 WpdUpFltr - ok 12:08:20.0921 0x1830 [ 2C6EEFFBB7FB1C51CCD3737C77AB9109, 8C2ED309FAF4312512E7BCCBBC51B1353603A3499077A1DE21991F0692AF1620 ] WpnService C:\WINDOWS\system32\WpnService.dll 12:08:20.0937 0x1830 WpnService - ok 12:08:20.0953 0x1830 [ 638B43D39A3D0B47024555CF1095E6F1, C7EA0A6ED227A5256EB02CA76FEC538DF196B8DC38DA2A567757D2B221C9473E ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys 12:08:20.0968 0x1830 ws2ifsl - ok 12:08:21.0015 0x1830 [ 9C17CF2D05F8DA5AC66880B6BEE64E7D, 8930079A1AFA97657BE567038EE57C988D3DE9A6C24EA46160E2974837082535 ] wscsvc C:\WINDOWS\System32\wscsvc.dll 12:08:21.0031 0x1830 wscsvc - ok 12:08:21.0031 0x1830 WSearch - ok 12:08:21.0140 0x1830 [ 6E04BBE242E2889B37300C4DF5CE1126, FBDAEAC62C48A4FC5EF412AE47FF10590AE83E8871412F76F6F9BAE910542DFA ] WSService C:\WINDOWS\System32\WSService.dll 12:08:21.0234 0x1830 WSService - ok 12:08:21.0296 0x1830 [ 722FA682ED9EA8B85FA843A5C8F39E61, 47B09984582E55C22450A851FAF00EBEC76CD46149B19B199916255D553C6BF8 ] wuauserv C:\WINDOWS\system32\wuaueng.dll 12:08:21.0375 0x1830 wuauserv - ok 12:08:21.0421 0x1830 [ A928F25CB62232F413EE655352856E10, 1D2B278A24DDDE8792ADE7649FF90A98E186B79F13AA296C30E4180293BE906A ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys 12:08:21.0437 0x1830 WudfPf - ok 12:08:21.0468 0x1830 [ A932391623D5CEC4EF4A2A17D3CEBFCD, 54AA17F385347DED262BDA84F2D99106DC5D9BF8765D647BD76265356193BDFA ] WUDFRd C:\WINDOWS\system32\drivers\WudfRd.sys 12:08:21.0484 0x1830 WUDFRd - ok 12:08:21.0562 0x1830 [ 1336DA39FE006EAB2733CA4DE5B3560C, F0D6C71ADCB66D4D14EC6D09FD43F5521A3A8CA53F248DFD01696FB4F033BE77 ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll 12:08:21.0578 0x1830 wudfsvc - ok 12:08:21.0656 0x1830 [ 417D1526811D9646A7E8779209F11361, 220FE28801474AB26579F2A37D792975D9AAD2384B420BCE52215B1389E08F91 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll 12:08:21.0703 0x1830 WwanSvc - ok 12:08:21.0750 0x1830 [ 405A419F4CDAC3C18F91FEDBD146C0A8, 92A6539AE6FC1B140366A0F733FDB784CAFB2359C4E0E2DF80629FEEA2CBFC98 ] XblAuthManager C:\WINDOWS\System32\XblAuthManager.dll 12:08:21.0781 0x1830 XblAuthManager - ok 12:08:21.0875 0x1830 [ 7118498F6E48758A2EF5A7D1982E2B62, 1FF75AE64CB6DB263E8B35515E092B325AA71A6B2210F8F2B0AD087B3BA33345 ] XblGameSave C:\WINDOWS\System32\XblGameSave.dll 12:08:21.0906 0x1830 XblGameSave - ok 12:08:21.0937 0x1830 [ F279536122B83FD0D8E158AA753E1B7C, 6A542F28E24B30DBDC2EEE24DA33C2F4ADB3596AEDDD71DC1495DD40577CE4BB ] xboxgip C:\WINDOWS\System32\drivers\xboxgip.sys 12:08:21.0953 0x1830 xboxgip - ok 12:08:22.0000 0x1830 [ 69E727F94BEA64E66C284F3C482F33E6, B3E0F287E7A251E0FC17C41089C45737027E54F0213BDE847356AC882B4D3700 ] XboxNetApiSvc C:\WINDOWS\system32\XboxNetApiSvc.dll 12:08:22.0047 0x1830 XboxNetApiSvc - ok 12:08:22.0070 0x1830 [ DBACD4E4FE191D0CE7C624ACA389535E, A706DA0A284398E80AEB6FBE1B5F6C3192C3F4D1C1B7533528D689D163374DDF ] xinputhid C:\WINDOWS\System32\drivers\xinputhid.sys 12:08:22.0082 0x1830 xinputhid - ok 12:08:22.0083 0x1830 ================ Scan global =============================== 12:08:22.0118 0x1830 [ D923EC03E24F7633DED3F2D46AD59A28, C635DB4483E24BE0188583E63B06D0F37BDE7AD944E4D0246A7D19CBC3EA3A6B ] C:\WINDOWS\system32\basesrv.dll 12:08:22.0143 0x1830 [ E2899695BD30B5F93EC626EBBEF2CB69, B190D2903A109D2C146D881F90769060A0E971942F4AA61AEAD81861032D89C3 ] C:\WINDOWS\system32\winsrv.dll 12:08:22.0174 0x1830 [ 09E92888FFF86F3334E59778724DCA6F, 2344763B52395EF565A9DE5F55BEDCA026AD2E8072FFD06F826BF366B3BA2AB4 ] C:\WINDOWS\system32\sxssrv.dll 12:08:22.0215 0x1830 [ 6FF8248F3A9D69A095C7F3F42BC29CB2, 9077B1AA0AFB8DB329FDED0E51085DE1C51B22A986162F29037FCA404A80D512 ] C:\WINDOWS\system32\services.exe 12:08:22.0223 0x1830 [ Global ] - ok 12:08:22.0223 0x1830 ================ Scan MBR ================================== 12:08:22.0236 0x1830 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 12:08:22.0513 0x1830 \Device\Harddisk0\DR0 - ok 12:08:22.0528 0x1830 ================ Scan VBR ================================== 12:08:22.0528 0x1830 [ 42125037B6005A1EC6B8538B6EA7EBE5 ] \Device\Harddisk0\DR0\Partition1 12:08:22.0528 0x1830 \Device\Harddisk0\DR0\Partition1 - ok 12:08:22.0528 0x1830 [ CF84383B7833112A93E1F4F09734CA55 ] \Device\Harddisk0\DR0\Partition2 12:08:22.0528 0x1830 \Device\Harddisk0\DR0\Partition2 - ok 12:08:22.0528 0x1830 ================ Scan generic autorun ====================== 12:08:22.0528 0x1830 SynTPEnh - ok 12:08:22.0638 0x1830 [ 6FDE88ED6A92F34EFAFA6C20E849D694, 9FA9ACD9B67F75E9E6FF6D682C1C957E6845756D059792814F4EA938DF03FDBA ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe 12:08:22.0685 0x1830 NvBackend - ok 12:08:22.0981 0x1830 [ 7FCDC7D1591DCB3036ECE8DFC0342E50, 44C2D67425D35784F3A857FF4238A344FAA15EBBB56C58AF83D942353A698C60 ] c:\program files\emsisoft anti-malware\a2guard.exe 12:08:23.0122 0x1830 emsisoft anti-malware - ok 12:08:23.0205 0x1830 [ 279175F66914D5BE0D3A3DD9F85FD5B3, 24FC4EF12209BBACD523570E66182D9470A3499BB74FD50E890298281F422097 ] C:\Program Files (x86)\USB Camera\VM331STI.EXE 12:08:23.0229 0x1830 331BigDog - ok 12:08:23.0626 0x1830 [ 88F8A731DEA7F49D92F84A0A77C5CC67, 030458922DA43AAF6C95EC430860A73032616851E03E58170F71E918720717CB ] C:\Windows\SysWOW64\OneDriveSetup.exe 12:08:23.0774 0x1830 OneDriveSetup - ok 12:08:23.0918 0x1830 [ 88F8A731DEA7F49D92F84A0A77C5CC67, 030458922DA43AAF6C95EC430860A73032616851E03E58170F71E918720717CB ] C:\Windows\SysWOW64\OneDriveSetup.exe 12:08:24.0043 0x1830 OneDriveSetup - ok 12:08:24.0214 0x1830 [ 91DD4AD85BB341CC8CF5187EA06FD171, 68330A5EBDA7E4A51926EC2085D71C11BD2857A6EB1D4749DEE7A6D1D5679B98 ] C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\OneDrive.exe 12:08:24.0214 0x1830 OneDrive - ok 12:08:24.0386 0x1830 [ 88F8A731DEA7F49D92F84A0A77C5CC67, 030458922DA43AAF6C95EC430860A73032616851E03E58170F71E918720717CB ] C:\Windows\SysWOW64\OneDriveSetup.exe 12:08:24.0523 0x1830 OneDriveSetup - ok 12:08:24.0523 0x1830 Waiting for KSN requests completion. In queue: 162 12:08:25.0540 0x1830 Waiting for KSN requests completion. In queue: 162 12:08:26.0541 0x1830 Waiting for KSN requests completion. In queue: 162 12:08:27.0562 0x1830 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.0 ), 0x60100 ( disabled : updated ) 12:08:27.0562 0x1830 AV detected via SS2: Emsisoft Anti-Malware, C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2start.exe ( 12.2.0.7060 ), 0x41000 ( enabled : updated ) 12:08:27.0578 0x1830 Win FW state via NFP2: enabled ( trusted ) 12:08:29.0926 0x1830 ============================================================ 12:08:29.0926 0x1830 Scan finished 12:08:29.0926 0x1830 ============================================================ 12:08:29.0946 0x1db8 Detected object count: 0 12:08:29.0946 0x1db8 Actual detected object count: 0 Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2017.01.24.02 rootkit: v2016.11.20.01 Windows 10 x64 NTFS Internet Explorer 11.162.10586.0 Dragonfly :: DRAGONFLY-PC [administrator] 24.01.2017 11:36:43 mbar-log-2017-01-24 (11-36-43).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 315303 Time elapsed: 17 minute(s), 32 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
24.01.2017, 16:12 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ Logfiles bitte immer in CODE-Tags posten |
24.01.2017, 16:12 | #15 |
/// Winkelfunktion /// TB-Süch-Tiger™ | rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... |
100%, anleitung, antivirenprogramm, anwendungen, arbeitet, ausgelastet, festplatte, frst scan habe ich angehängt., funktionieren, komplett, kostenlose, laptop, lüfter, lösung, mal-ware, maus, nicht mehr, nichts, platte, programme, rootkit, system, update, verfügbar, viren befall ???, virus, virus?, win, win 10 update |