|
Log-Analyse und Auswertung: wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichtsWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.12.2016, 14:57 | #1 |
| wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichts Hallo liebe Helfende, zuerst möchte ich einmal klarstellen, dass ich ein totaler Computerlaie bin und keine Ahnung von all dem dem habe. Auf meinem rechener läuft Windows10 und seit einiger zeit habe ich darauf wajam. Ich weiß nicht wie wajam auf meinen PC gekommen ist aber es ist schon mehrere Monate drauf und lässt sich nicht auf dem herkömmlichen weg deinstallieren. Als Vierenschutz habe ich nichts anderes als windowsdefender aber bei dem werden keine gefundenen vieren angezeigt. Ich habs auch schon mit Bullguard versucht aber da hat es bei jeweils 2 Versuchen nicht geklappt fertig zu laden. Der Computer sit wegen der Fehlermeldung IRQL NOT LESS OR EQUAL abgestürtzt. Das Problem hatte ich vorher auch schon mal, da hab ich den PC resettet. Wenn möglich würde ich das vermeiden aber im allernötigsten Fall nehme ich das selbstverständlich auf mich. ich sollte noch erwähnen, dass bei mir auf dem Rechner regelmäßig Nachrichten von gefundener Malware aufpoppen. Ich glaube, das Programm von wo es kommt heißt Byte Fence Anti-Malware aber ich bin mir nicht sicher. Falls mir jemand helfen kann wäre ich sehr dankbar. Ich mache mir Sorgen, was mit meinen Daten passiert, vor allen Dingen weil ich mich nach dem Herunterfahren des PC´s öfter mal wieder mit allen Programmen anmelden musste. Das ist nicht immer der Fall aber bisher kam das etwa 3 oder 4 mal schon vor, obwohl ich mich nirgendswo abgemeldet hatte. Außerdem kam es bis jetzt 2 mal vor, dass anstatt die Gewünschte Internetseite irgendwelche Werbung aufgegangen ist. Noch einmal danke für jegliche Hilfe die kommen mag. Liebe Grüße Molp |
10.12.2016, 15:32 | #2 |
/// Malwareteam | wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichtsMein Name ist Rafael und ich werde dir bei der Bereinigung helfen. Damit ich dir optimal helfen kann, halte dich bitte an folgende Regeln:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
10.12.2016, 22:17 | #3 |
| Danke für die Hilfe Hi,
__________________Vielen Dank erstmal, dass du mir hellfen willst. Und ich habe eine kleine Frage zu dem FRST-Programm. Da steht für welche Windowsversionen es geeignet ist. Windows 10 gehört nicht dazu. Soll ich es trotzdem runterladen oder lieber nicht? |
11.12.2016, 01:34 | #4 |
/// Malwareteam | wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichts Hi, die Beschreibung ist nicht richtig. Ja bitte herunterladen und ausführen wie beschrieben
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
11.12.2016, 01:54 | #5 |
| Ich hoffe, das dass das richtige ist. FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016 durchgeführt von Moritz (11-12-2016 01:51:23) Gestartet von C:\Users\Moritz\Downloads Windows 10 Home Version 1607 (X64) (2016-08-30 13:33:30) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1352620464-1759978224-1981204074-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1352620464-1759978224-1981204074-503 - Limited - Disabled) Gast (S-1-5-21-1352620464-1759978224-1981204074-501 - Limited - Disabled) Moritz (S-1-5-21-1352620464-1759978224-1981204074-1001 - Administrator - Enabled) => C:\Users\Moritz ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.3.183.90 - Adobe Systems Incorporated) Amazon 1Button App (HKLM-x32\...\{4E501F9C-337A-4BBA-A3CD-624D7ADF05CB}) (Version: 2.3.6 - Amazon) <==== ACHTUNG Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Blacklight: Retribution (HKLM\...\Steam App 209870) (Version: - Hardsuit Labs) Brawlhalla (HKLM\...\Steam App 291550) (Version: - Blue Mammoth Games) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{6DBD132B-7F42-4594-BBE7-0BB677EB2926}) (Version: 4.4.2 - SEIKO EPSON CORPORATION) EPSON WF-2540 Series Printer Uninstall (HKLM\...\EPSON WF-2540 Series) (Version: - SEIKO EPSON Corporation) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HiPatch (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}) (Version: 5.0.6.4 - Hi-Rez Studios) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games) League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden Logitech Gaming Software 8.87 (HKLM\...\Logitech Gaming Software) (Version: 8.87.116 - Logitech Inc.) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.91 - NVIDIA Corporation) NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation) NVIDIA Grafiktreiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.91 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) OpenOffice 4.1.3 (HKLM-x32\...\{8D5FCC56-BB9F-4122-923C-71753F50F6F5}) (Version: 4.13.9783 - Apache Software Foundation) Orcs Must Die! Unchained (HKLM\...\Steam App 427270) (Version: - Robot Entertainment) Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.100.9.0 - Overwolf Ltd.) Paladins (HKLM\...\Steam App 444090) (Version: - Hi-Rez Studios) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Remote Mouse version 3.000 (HKLM-x32\...\{01E4BC6D-3ACC-45E1-8928-C2FF626F63F3}_is1) (Version: 3.000 - Remote Mouse) Shakes and Fidget (HKLM\...\Steam App 438040) (Version: - Playa Games GmbH) SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.) SMITE (HKLM-x32\...\Steam App 386360) (Version: - Hi-Rez Studios) Spotify (HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Spotify) (Version: 1.0.44.100.ga60c0ce1 - Spotify AB) STAR WARS™ Battlefront™ (HKLM-x32\...\{E402D891-4E45-4ce9-B41F-DD35864EF170}) (Version: 1.0.7.36460 - Electronic Arts) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) Teeworlds (HKLM\...\Steam App 380840) (Version: - Teeworlds Team) Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Wajam (HKLM-x32\...\260f93d6175ed025fd9a3880a4ba7646) (Version: 1.71.12.2 - Wajam) <==== ACHTUNG Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes) WinRAR 5.31 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {25B783C7-77FC-4693-83BD-D956AA8C830B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {26149F4E-DC4B-4588-8D07-F7C17210003F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {3A0F445C-6D63-4C05-B4CA-20A7ABF9B97F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {6DC3ABB3-D7D4-422D-B48B-1EE597905C66} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-11-23] (Overwolf LTD) Task: {71112587-2E61-4271-BEDD-358C33D3B436} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {798FE0A8-AF38-4A03-9042-5A3A814677D4} - System32\Tasks\{C957B167-54F3-473A-ABC0-BB93E1A35F4B} => pcalua.exe -a C:\WINDOWS\a956be449a292952e1127356ecac2673.exe Task: {AEE8E303-B56E-4C79-A68E-7E06D07312A1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {D27E911F-1BB6-4487-BD05-FCB65ABC007D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-11-10] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-08-30 14:09 - 2016-02-09 06:29 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-06-14 19:49 - 2016-05-17 22:15 - 00018432 _____ () C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe 2016-05-27 10:08 - 2016-05-28 12:32 - 00076888 _____ () C:\WINDOWS\SysWoW64\PnkBstrA.exe 2016-02-22 21:22 - 2016-02-17 07:56 - 00299392 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2016-02-22 21:22 - 2016-02-17 07:56 - 01416064 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll 2016-02-22 21:22 - 2016-02-17 07:56 - 03613056 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll 2016-04-01 15:06 - 2016-05-02 06:55 - 02667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll 2016-04-01 15:06 - 2016-05-02 06:55 - 01990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll 2016-04-01 15:06 - 2016-05-02 06:55 - 01842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll 2016-02-22 21:22 - 2016-02-17 07:57 - 00210816 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-08-31 13:06 - 2016-08-31 13:06 - 01864384 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll 2016-09-17 23:18 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-11-17 14:11 - 2016-11-17 14:11 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-11-17 14:11 - 2016-11-17 14:11 - 00178688 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-11-17 14:11 - 2016-11-17 14:11 - 41609728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-08-30 01:17 - 2016-08-30 01:17 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-08-30 01:17 - 2016-08-30 01:17 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 00022024 _____ () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe 2016-03-19 22:32 - 2016-10-28 14:12 - 00145920 _____ () C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe 2016-11-23 15:16 - 2016-11-23 15:16 - 00019456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-11-23 15:16 - 2016-11-23 15:16 - 20433408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-06-03 17:09 - 2016-06-03 17:10 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2016-11-23 15:16 - 2016-11-23 15:16 - 01046528 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll 2016-11-23 15:16 - 2016-11-23 15:16 - 00353792 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Photos.Inking.dll 2016-11-10 17:21 - 2016-11-02 11:21 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-10 17:21 - 2016-11-02 11:15 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-10 17:21 - 2016-11-02 11:14 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-11-10 17:21 - 2016-11-02 11:15 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-11-10 17:21 - 2016-11-02 11:16 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-10 17:21 - 2016-11-02 11:17 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2016-06-14 19:49 - 2015-05-26 18:54 - 00152576 _____ () C:\Program Files (x86)\Remote Mouse\FileS.dll 2016-02-22 21:22 - 2016-02-17 08:02 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-08-31 13:05 - 2016-08-31 13:06 - 01383616 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\ClientTelemetry.dll 2016-08-31 13:06 - 2016-08-31 13:06 - 00118976 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncViews.dll 2016-02-22 15:57 - 2016-09-08 04:14 - 00784672 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 02321696 _____ () C:\Program Files (x86)\Steam\video.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 00836896 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2016-03-12 16:04 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 00012288 _____ () C:\Program Files (x86)\Origin\libEGL.DLL 2016-02-22 17:39 - 2016-06-11 09:25 - 00266240 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll 2016-02-25 18:20 - 2016-12-09 14:10 - 51777648 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\libcef.dll 2016-10-28 17:26 - 2016-12-09 14:10 - 00110192 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWinRT.dll 2016-10-14 15:18 - 2016-08-04 21:56 - 49825056 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.winxp\libcef.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 00380704 _____ () C:\Program Files (x86)\Steam\steam.dll 2016-02-25 18:20 - 2016-12-09 14:10 - 01803888 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\libglesv2.dll 2016-02-25 18:20 - 2016-12-09 14:10 - 00086128 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\libegl.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\.DEFAULT\...\amazon.de -> hxxps://amazon.de IE trusted site: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\amazon.de -> hxxps://amazon.de ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2016-02-21 16:47 - 2016-12-10 12:59 - 00002024 ____A C:\WINDOWS\system32\Drivers\etc\hosts 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com 0.0.0.0 media.opencandy.com 0.0.0.0 cdn.opencandy.com 0.0.0.0 tracking.opencandy.com 0.0.0.0 api.opencandy.com 0.0.0.0 api.recommendedsw.com 0.0.0.0 installer.betterinstaller.com 0.0.0.0 installer.filebulldog.com 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net 0.0.0.0 inno.bisrv.com 0.0.0.0 nsis.bisrv.com 0.0.0.0 cdn.file2desktop.com 0.0.0.0 cdn.goateastcach.us 0.0.0.0 cdn.guttastatdk.us 0.0.0.0 cdn.inskinmedia.com 0.0.0.0 cdn.insta.oibundles2.com 0.0.0.0 cdn.insta.playbryte.com 0.0.0.0 cdn.llogetfastcach.us 0.0.0.0 cdn.montiera.com 0.0.0.0 cdn.msdwnld.com 0.0.0.0 cdn.mypcbackup.com 0.0.0.0 cdn.ppdownload.com 0.0.0.0 cdn.riceateastcach.us 0.0.0.0 cdn.shyapotato.us 0.0.0.0 cdn.solimba.com 0.0.0.0 cdn.tuto4pc.com 0.0.0.0 cdn.appround.biz 0.0.0.0 cdn.bigspeedpro.com 0.0.0.0 cdn.bispd.com Da befinden sich 4 zusätzliche Einträge. ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Moritz\Pictures\league-of-legends-fan-art.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [UDP Query User{171B2627-DEFC-41AA-B3C9-287E47EC6BBA}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [TCP Query User{749023EB-D8FD-4420-9AC7-E4E2230DAE73}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{98AF7DC9-0EF2-4532-B489-A4115A2708A9}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [TCP Query User{59F600E4-2200-4891-88DE-517505BF8757}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [{4D24FBC9-55D8-4B79-9ADB-04369415B741}] => C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe FirewallRules: [{E7808F84-D012-4EA7-87FE-8E3C370DAC15}] => C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe FirewallRules: [{87D8D5FC-7CF6-4C97-B326-0D1EB719A5B8}] => C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe FirewallRules: [{3B1A788A-A056-4B28-8576-C94B0A918614}] => C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe FirewallRules: [{08DDDF30-6604-498E-86A5-94783B392A1C}] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [{00403A52-43F9-4F6A-BBD6-D92751A20E50}] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [{9915B4E2-FDB5-4B54-8F27-8BDD9B798392}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\teeworlds.exe FirewallRules: [{5BC6397F-C273-4ABE-BD16-0711CAB6413A}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\teeworlds.exe FirewallRules: [UDP Query User{6303235C-A172-4FE9-BA7E-E1826F97589D}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{4291F196-3B7C-4AEF-A99E-C9958ACF6C7E}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{5ABB841B-A52E-4318-8005-4BE953951A94}] => C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{300ED332-6ABF-4B0E-BF07-D1D3D36A99E9}] => C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{C4889F50-917F-41A9-9F71-7BCD93B9B456}] => C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{B87C0EE9-6F0F-4113-BBE8-80C887005D97}] => C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{E8AD663F-43A5-44F3-854B-2CB30C5C0CFA}] => C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [{204CC8CE-6B0D-4735-B5DA-1352BF537E4C}] => C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [UDP Query User{A3A16CD8-074A-46D7-B7F7-FB03119C0C79}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe] => C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe FirewallRules: [TCP Query User{E2B2F661-5DE8-4AFF-8FE2-D265B6BEC8E4}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe] => C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe FirewallRules: [{EC67536D-BCB8-4CB0-A339-004C85A8DA10}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Binaries\Win32\FoxGame-win32-Shipping.exe FirewallRules: [{A2B487E7-F928-4B8B-82C3-8A00A4BC05D6}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Binaries\Win32\FoxGame-win32-Shipping.exe FirewallRules: [{1811FF59-D55E-4F62-AC77-48B8DACD52CD}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Blacklight Retribution.exe FirewallRules: [{F1EB0788-FEFC-463D-AE09-A26AAE6964F8}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Blacklight Retribution.exe FirewallRules: [UDP Query User{90BCB480-9F75-4D62-BF93-6886F634BEF2}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{FAE64EC6-55C3-4205-997F-5B61ABAB4FF7}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{ADEA7124-1035-40D8-B4F8-1362C2A859A2}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [UDP Query User{F0CC8E85-FFE5-458D-B4B9-5418324B320F}C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe] => C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{0F2CA579-7B22-47BE-8709-005FA88A56FF}C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe] => C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{82465579-118B-4D56-BC78-0624CFEA80EC}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{DDA6F10F-71B5-4694-9C1B-C002DEEF3BED}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [{464D4A29-7E85-4763-ACFE-59AFD75FFC94}] => C:\Program Files (x86)\Steam\steamapps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe FirewallRules: [{98BE2BB8-A4F4-45DC-9077-173B13FC89F1}] => C:\Program Files (x86)\Steam\steamapps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe FirewallRules: [UDP Query User{C7F328C5-3448-4E3B-8923-745F18B6B69D}C:\program files\java\jre1.8.0_77\bin\javaw.exe] => C:\program files\java\jre1.8.0_77\bin\javaw.exe FirewallRules: [TCP Query User{7B9E4ED8-B00E-4B6C-AD29-6D59094BC041}C:\program files\java\jre1.8.0_77\bin\javaw.exe] => C:\program files\java\jre1.8.0_77\bin\javaw.exe FirewallRules: [UDP Query User{3683ABD1-BC68-4613-9248-DAB35856F894}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [TCP Query User{4584F67A-7676-442A-8DFE-7786F2E6422F}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [{6CE777BD-F20F-495A-B551-91ECDB0A2B73}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{BF10500B-7853-4C35-9A4D-8BA2A1D76A8B}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{C0C18B0D-8D00-4AF6-BB0E-73A7768CD092}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{10139860-2EB1-45D7-89C5-D68DDB3974F9}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{6A20F085-40ED-4F64-A008-F40C99A6399A}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{782C462A-0BF5-4549-9D98-623647C71E54}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{41682100-C0DC-4C38-8168-F54C65A31801}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{21C35BA2-02D4-4151-BB19-635617D0568E}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{C3EAFBB4-815A-4983-87F5-06A0FED02851}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{585C2009-6DD4-4CF9-88E9-3064555B8202}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{F00BF74C-F4D0-4581-A49F-1DF81B19B1BA}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{8C1A674C-3E46-40CD-B3CA-E22B5D8236BF}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{FD61E35D-3DC2-4A77-98B4-8ACC077D6011}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{6B1F40FB-A095-43E7-9ADD-8C14ADBBDD0D}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [UDP Query User{6DA33C40-3A41-4E03-BB49-B35B54C7167C}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [TCP Query User{83C9BC60-7DF4-4BCA-ADF3-C6150DB744C8}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{7358A27E-138E-4010-8E38-4FC515D76BB6}] => C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe FirewallRules: [{335B9884-E9BE-4BCF-9B0F-269CA40E0C7A}] => C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe FirewallRules: [UDP Query User{EB46B116-E7A9-4D33-B690-D2DB686FC6DE}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{25921E86-572F-4994-9C7C-3980BFE43D08}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{D5FC44E7-B5CC-40F9-AFAD-080B59F5EC66}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{A155E99F-64CB-4D38-9F73-23E607304839}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{D5F55766-8EDC-4B27-B5DC-8036A86BEA58}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{BE0690AF-EC4A-4327-AE4C-112C86A23A26}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{D107C374-1551-40C4-AC0F-256F7DFF0D42}C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{1FDAAFEC-507D-4409-9134-E0C2C27393EA}C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{A0B0DCCF-8216-46FC-A565-7BB7157044AF}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{CDFFADA9-4E90-41E4-A78A-F7323A2F1862}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [{F966CE5A-21BB-4D85-8E70-5486993429B0}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{B3F90A16-384F-4FD7-911B-6893AE3705E1}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [UDP Query User{7A5B186C-42F8-4A6C-A004-BEF58410831D}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [TCP Query User{76C38497-D952-4C31-829E-24F515DC48F3}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{B3EFC0CB-D60F-4A2C-978E-A7ED96F593AA}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{01D94F18-D1F6-462B-9665-9ED85762D28E}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0A7572F5-F406-467C-818D-6377BD0BABF3}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{7EBEC089-B19F-4BF1-8EB2-43E8C0B9040D}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{702BC7BD-5D0C-4D79-A410-ED88619871AE}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{CB550C66-A6F9-44AF-BEB1-5CEA66134640}] => C:\Program Files (x86)\Steam\steamapps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{3E31854E-0C16-4180-BEAD-3FD58B0FE854}] => C:\Program Files (x86)\Steam\steamapps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{AA95820B-D85B-4D30-97CF-8D4CA424CA37}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{280EDB2E-0E0D-4FBF-9106-C5E119691307}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{FCD9861F-DA32-499F-8B21-3B043D56AE26}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{49B3847A-833D-4400-B6B7-DBD7B22C98D4}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D738736C-DC9E-4B28-83A6-A3720EEDC79A}] => C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{126FA278-51A6-4ACE-BABC-A6336844C571}] => C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{BB3B13F8-0DA7-4649-8072-BD4BCDA38CAD}] => C:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{61FF8878-D5AC-4109-B189-568AC4D1EE50}] => C:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [TCP Query User{7C1DE088-EA81-4EE5-AD2C-AC18A5D516FA}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{16B7420E-25A3-4586-A99D-FE0FB0388B17}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [{B354E948-19B1-4508-8F39-7880B00E9535}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [{8E35D1DC-0DA9-46C3-834E-0D4DE55DBE93}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [TCP Query User{C0052537-C009-4AF4-8BFE-AE488884B62E}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{08FF909C-48FD-42A2-BFC9-BD19D747E47E}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{F929E1A5-48A6-4DF2-8214-D9910E425982}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [UDP Query User{CB57CC95-700D-456C-B147-3F13FB86368B}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [{B1E04A7D-2190-42B0-BF88-A4F4D1868580}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe FirewallRules: [{8FCCBCCA-7344-497C-A379-C3C1AFC1C5BA}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe FirewallRules: [{FA2AE04F-9F73-448C-8091-0A2F53EDE480}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{7D4FACC6-D66D-41E7-9B1B-831F7376E15B}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe ==================== Wiederherstellungspunkte ========================= 02-12-2016 20:14:58 Geplanter Prüfpunkt 07-12-2016 20:27:33 Removed WinZip 21.0 09-12-2016 16:31:31 OpenOffice 4.1.3 wird entfernt ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (12/10/2016 03:07:19 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Users\Moritz\AppData\Local\chromium\Application\chrome.exe". Die abhängige Assemblierung "51.0.2683.0,language="*",type="win32",version="51.0.2683.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/10/2016 01:06:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-ERBVLM6) Description: Bei der Aktivierung der App „Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/10/2016 01:04:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-ERBVLM6) Description: Bei der Aktivierung der App „Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/10/2016 01:04:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-ERBVLM6) Description: Bei der Aktivierung der App „Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/10/2016 01:02:19 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Users\Moritz\AppData\Local\chromium\Application\chrome.exe". Die abhängige Assemblierung "51.0.2683.0,language="*",type="win32",version="51.0.2683.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/09/2016 07:07:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: edgehtml.dll, Version: 11.0.14393.447, Zeitstempel: 0x5819c228 Ausnahmecode: 0x8000ffff Fehleroffset: 0x0000000000407552 ID des fehlerhaften Prozesses: 0x2288 Startzeit der fehlerhaften Anwendung: 0x01d25245fb93df17 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\edgehtml.dll Berichtskennung: 7f88cab8-da7d-4c42-8b9b-008ebf278e5c Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/09/2016 04:31:59 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (12/09/2016 04:29:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-ERBVLM6) Description: Bei der Aktivierung der App „Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/09/2016 04:27:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-ERBVLM6) Description: Bei der Aktivierung der App „Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/09/2016 04:27:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-ERBVLM6) Description: Bei der Aktivierung der App „Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Systemfehler: ============= Error: (12/10/2016 11:06:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 10:37:33 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 07:34:35 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 07:04:31 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 06:52:47 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 05:43:33 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 05:30:55 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 05:28:59 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 03:24:39 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/10/2016 03:06:23 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} und der APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. CodeIntegrity: =================================== Date: 2016-12-07 21:23:20.954 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:19.180 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:19.161 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:15.030 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:15.008 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:47:02.958 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:47:02.940 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:40:33.287 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:40:01.810 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:39:59.630 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: AMD FX(tm)-4300 Quad-Core Processor Prozentuale Nutzung des RAM: 41% Installierter physikalischer RAM: 8140.34 MB Verfügbarer physikalischer RAM: 4790.96 MB Summe virtueller Speicher: 9548.34 MB Verfügbarer virtueller Speicher: 5123.94 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:1862.46 GB) (Free:1616.42 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ==================== Ende von Addition.txt ============================ |
11.12.2016, 01:55 | #6 |
| wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichtsFRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016 durchgeführt von Moritz (Administrator) auf DESKTOP-ERBVLM6 (11-12-2016 01:49:23) Gestartet von C:\Users\Moritz\Downloads Geladene Profile: Moritz (Verfügbare Profile: Moritz) Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Edge) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe (© 2015 Microsoft Corporation) C:\Users\Moritz\AppData\Local\Microsoft\BingSvc\BingSvc.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyCrashService.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe (Valve Corporation) C:\Program Files (x86)\Steam\GameOverlayUI.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [16286840 2016-08-30] (Logitech Inc.) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2860832 2016-10-13] (Valve Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3044848 2016-12-06] (Electronic Arts) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Spotify Web Helper] => C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-09] (Spotify Ltd) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Spotify] => C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe [7095408 2016-12-09] (Spotify Ltd) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [BingSvc] => C:\Users\Moritz\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27219928 2016-11-15] (Skype Technologies S.A.) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Chromium] => c:\users\moritz\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [~Resuming Profile - Vollständiger Scan] => "C:\Program Files\BullGuard Ltd\BullGuard\BgScan.exe" "profilepath: C:\Users\Moritz\AppData\Roaming\BullGuard\Antivirus\Profiles\~Resuming Profile - Vollständiger Scan.xml" HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION) GroupPolicy: Beschränkung - Chrome <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{17ee23ff-c454-4ac7-aafe-24a47b714173}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{2c9c1031-1c58-4a0c-a510-c4b9546a53b7}: [DhcpNameServer] 172.17.2.1 Tcpip\..\Interfaces\{beb9c673-971c-479c-96ad-efdd872d05fa}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Start Page = HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-12-08] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-08] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-12-08] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-08] (Oracle Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-08] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32.dll [2016-02-22] () FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [245544 2016-07-12] (EasyAntiCheat Ltd) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation) U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-10-10] (Hi-Rez Studios) [Datei ist nicht signiert] R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-08-30] (Logitech Inc.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-12-06] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2016-12-06] (Electronic Arts) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1316080 2016-11-23] (Overwolf LTD) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-05-28] () R2 RemoteMouseService; C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe [18432 2016-05-17] () [Datei ist nicht signiert] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 Ke2200; C:\WINDOWS\System32\drivers\e22w7x64.sys [129200 2014-03-27] (Qualcomm Atheros, Inc.) S3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [45208 2016-08-30] (Logitech Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) S3 LGJoyHidFilter; C:\WINDOWS\system32\drivers\LGJoyHidFilter.sys [58144 2015-06-11] (Logitech Inc.) S3 LGJoyHidLo; C:\WINDOWS\system32\drivers\LGJoyHidLo.sys [47656 2015-06-11] (Logitech Inc.) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-08-30] (Logitech Inc.) S3 LGSHidFilt; C:\WINDOWS\System32\drivers\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation) R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5195776 2016-07-16] (Realtek Semiconductor Corporation ) S3 VUSB3HUB; C:\WINDOWS\System32\drivers\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.) S3 VUSBSTOR; C:\WINDOWS\System32\Drivers\vusbstor.sys [86064 2013-01-18] (VIA Technologies, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) S3 xhcdrv; C:\WINDOWS\System32\drivers\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 01:49 - 2016-12-11 01:50 - 00015617 _____ C:\Users\Moritz\Downloads\FRST.txt 2016-12-11 01:47 - 2016-12-11 01:49 - 00000000 ____D C:\FRST 2016-12-11 01:46 - 2016-12-11 01:46 - 02420224 _____ (Farbar) C:\Users\Moritz\Downloads\FRST64.exe 2016-12-11 01:45 - 2016-12-11 01:47 - 01761792 _____ (Farbar) C:\Users\Moritz\Downloads\FRST.exe 2016-12-10 15:01 - 2016-12-10 15:04 - 00000000 ____D C:\AdwCleaner 2016-12-10 15:01 - 2016-12-10 15:01 - 03968464 _____ C:\Users\Moritz\Downloads\adwcleaner_6.040.exe 2016-12-10 13:03 - 2016-12-10 13:03 - 00000000 ___HD C:\OneDriveTemp 2016-12-09 17:05 - 2016-11-11 11:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-12-09 17:05 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2016-12-09 17:05 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-12-09 17:05 - 2016-11-11 10:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2016-12-09 17:05 - 2016-11-11 10:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-12-09 17:05 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-12-09 17:05 - 2016-11-11 10:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-12-09 17:05 - 2016-11-11 10:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-12-09 17:05 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2016-12-09 17:05 - 2016-11-11 10:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-12-09 17:05 - 2016-11-11 10:17 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-12-09 17:05 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2016-12-09 17:05 - 2016-11-11 10:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-12-09 17:05 - 2016-11-11 10:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-12-09 17:05 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-12-09 17:05 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2016-12-09 17:05 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-12-09 17:05 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-12-09 17:05 - 2016-11-11 10:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-12-09 17:05 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-12-09 17:05 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-12-09 17:04 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2016-12-09 17:04 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2016-12-09 17:04 - 2016-11-11 11:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2016-12-09 17:04 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2016-12-09 17:04 - 2016-11-11 11:13 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-12-09 17:04 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-12-09 17:04 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2016-12-09 17:04 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-12-09 17:04 - 2016-11-11 11:09 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-12-09 17:04 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-12-09 17:04 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-12-09 17:04 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-12-09 17:04 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-12-09 17:04 - 2016-11-11 11:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-12-09 17:04 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2016-12-09 17:04 - 2016-11-11 10:59 - 02913136 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-12-09 17:04 - 2016-11-11 10:59 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 08170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-12-09 17:04 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-12-09 17:04 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2016-12-09 17:04 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-12-09 17:04 - 2016-11-11 10:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-12-09 17:04 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2016-12-09 17:04 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-12-09 17:04 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2016-12-09 17:04 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll 2016-12-09 17:04 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys 2016-12-09 17:04 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2016-12-09 17:04 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll 2016-12-09 17:04 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2016-12-09 17:04 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-12-09 17:04 - 2016-11-11 10:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-12-09 17:04 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2016-12-09 17:04 - 2016-11-11 10:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2016-12-09 17:04 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-12-09 17:04 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-12-09 17:04 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll 2016-12-09 17:04 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll 2016-12-09 17:04 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-12-09 17:04 - 2016-11-11 10:10 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-12-09 17:04 - 2016-11-11 10:09 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2016-12-09 17:04 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-12-09 17:04 - 2016-11-11 10:08 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-12-09 17:04 - 2016-11-11 10:06 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-12-09 17:04 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2016-12-09 17:04 - 2016-11-11 10:04 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-12-09 17:04 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-12-09 17:04 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-12-09 17:04 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-12-09 17:04 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-12-09 17:04 - 2016-11-11 10:01 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-12-09 17:04 - 2016-11-11 09:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-12-09 17:04 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-12-09 17:04 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-12-09 17:04 - 2016-11-11 08:56 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-12-09 17:04 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-12-09 17:04 - 2016-11-11 08:45 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-12-09 17:04 - 2016-11-11 08:45 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 06668032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll 2016-12-09 17:04 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-12-09 17:04 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe 2016-12-09 17:04 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-12-09 17:04 - 2016-11-11 08:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-12-09 17:04 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-12-09 17:04 - 2016-11-11 08:26 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-12-09 17:04 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-12-09 17:04 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-12-09 17:04 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-12-09 17:04 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-12-09 17:04 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-12-09 17:04 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2016-12-09 17:04 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-12-09 17:04 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-12-09 17:04 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2016-12-09 17:04 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2016-12-09 17:04 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2016-12-09 17:04 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2016-12-09 17:04 - 2016-11-11 08:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-12-09 17:04 - 2016-11-11 08:13 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-12-09 17:04 - 2016-11-11 08:11 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll 2016-12-09 17:04 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-12-09 17:04 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-12-09 17:04 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-12-09 17:04 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll 2016-12-09 17:04 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-12-09 17:04 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2016-12-09 17:04 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-12-09 17:04 - 2016-11-11 08:01 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-12-09 17:04 - 2016-11-11 07:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-12-09 17:03 - 2016-11-11 11:01 - 02189152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-12-09 17:03 - 2016-11-11 11:01 - 01738048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-12-09 17:03 - 2016-11-11 11:01 - 00658264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-12-09 17:03 - 2016-11-11 11:01 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-12-09 17:03 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-12-09 17:03 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-12-09 17:03 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-12-09 17:03 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe 2016-12-09 17:03 - 2016-11-11 10:51 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2016-12-09 17:03 - 2016-11-11 10:31 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-12-09 17:03 - 2016-11-11 10:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-12-09 17:03 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll 2016-12-09 17:03 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-12-09 17:03 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe 2016-12-09 17:03 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-12-09 17:03 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-12-09 17:03 - 2016-11-11 10:24 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-12-09 17:03 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-12-09 17:03 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-12-09 17:03 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2016-12-09 17:03 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-12-09 17:03 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2016-12-09 17:03 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2016-12-09 17:03 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2016-12-09 17:03 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-12-09 17:03 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2016-12-09 17:03 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-12-09 17:03 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll 2016-12-09 17:03 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-12-09 17:03 - 2016-11-11 10:11 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-12-09 17:03 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll 2016-12-09 17:03 - 2016-11-11 10:10 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-12-09 17:03 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2016-12-09 17:03 - 2016-11-11 10:08 - 08127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2016-12-09 17:03 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-12-09 17:03 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-12-09 17:03 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-12-09 17:03 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-12-09 17:03 - 2016-11-11 10:04 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-12-09 17:03 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2016-12-09 17:03 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-12-09 17:03 - 2016-11-11 10:02 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2016-12-09 17:03 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll 2016-12-09 17:03 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-12-09 17:03 - 2016-11-11 08:47 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2016-12-09 17:03 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe 2016-12-09 17:03 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe 2016-12-09 17:03 - 2016-11-11 08:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-12-09 17:03 - 2016-11-11 08:20 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-12-09 17:03 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-12-09 17:03 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2016-12-09 17:03 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2016-12-09 17:03 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2016-12-09 17:03 - 2016-11-11 08:17 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-12-09 17:03 - 2016-11-11 08:14 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-12-09 17:03 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll 2016-12-09 17:03 - 2016-11-11 08:09 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2016-12-09 17:03 - 2016-11-11 08:06 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-12-09 17:03 - 2016-11-11 08:06 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2016-12-09 17:03 - 2016-11-11 08:05 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-12-09 17:03 - 2016-11-11 08:04 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2016-12-09 17:03 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-12-09 17:03 - 2016-11-11 08:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-12-09 16:34 - 2016-12-09 16:34 - 00003256 _____ C:\WINDOWS\System32\Tasks\{C957B167-54F3-473A-ABC0-BB93E1A35F4B} 2016-12-09 15:45 - 2016-12-09 15:47 - 00543244 _____ C:\WINDOWS\Minidump\120916-49953-01.dmp 2016-12-09 14:07 - 2016-12-09 15:45 - 804615481 _____ C:\WINDOWS\MEMORY.DMP 2016-12-09 14:07 - 2016-12-09 14:09 - 00543348 _____ C:\WINDOWS\Minidump\120916-75234-01.dmp 2016-12-08 23:05 - 2016-12-08 23:04 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll 2016-12-08 22:27 - 2016-12-08 22:27 - 00001454 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2016-12-08 22:25 - 2016-02-17 07:40 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll 2016-12-08 22:25 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll 2016-12-08 22:25 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2016-12-08 18:52 - 2016-12-08 18:52 - 00592057 _____ C:\Users\Moritz\Documents\open office flüchtlinge presentation.odp 2016-12-08 18:52 - 2016-12-08 18:52 - 00000125 ____H C:\Users\Moritz\Documents\.~lock.open office flüchtlinge presentation.odp# 2016-12-08 16:33 - 2016-12-08 16:33 - 00000000 ___SD C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3 2016-12-08 16:33 - 2016-12-08 16:33 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\OpenOffice 2016-12-08 16:32 - 2016-12-08 16:32 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2016-12-08 16:29 - 2016-12-08 16:31 - 171330228 _____ C:\Users\Moritz\Documents\Apache_OpenOffice_4.1.3_Win_x86_install_de.exe 2016-12-07 21:01 - 2016-12-09 15:45 - 00000000 ____D C:\WINDOWS\Minidump 2016-12-07 20:56 - 2016-12-09 16:12 - 00000356 _____ C:\WINDOWS\system32\config\afw_hm.conf 2016-12-07 20:56 - 2016-12-09 16:12 - 00000004 _____ C:\WINDOWS\system32\config\afw_db.conf 2016-12-07 20:54 - 2016-12-07 21:15 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\BullGuard 2016-12-07 20:51 - 2016-12-07 20:51 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\QuickScan 2016-12-07 20:50 - 2016-12-09 16:12 - 00000000 ____D C:\ProgramData\BullGuard 2016-12-07 20:13 - 2016-12-07 20:13 - 00000000 ____D C:\ProgramData\UniqueId 2016-12-07 20:12 - 2016-12-07 20:28 - 00000000 ____D C:\ProgramData\WinZip 2016-12-07 20:12 - 2016-12-07 20:12 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinZip 21.0 2016-12-07 20:11 - 2016-12-07 20:31 - 00000000 ____D C:\Users\Moritz\AppData\Local\chromium 2016-12-07 20:09 - 2016-12-07 20:54 - 00000306 __RSH C:\ProgramData\ntuser.pol 2016-11-24 11:04 - 2016-11-24 11:04 - 00001496 _____ C:\Users\Moritz\Desktop\Von Microsoft.lnk 2016-11-19 17:49 - 2016-11-19 17:49 - 00000000 ____D C:\Users\Moritz\Documents\League of Legends 2016-11-17 10:59 - 2016-11-17 10:59 - 00000992 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk 2016-11-17 10:59 - 2016-11-17 10:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm 2016-11-17 10:27 - 2016-12-10 22:07 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 01:48 - 2016-02-22 17:39 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Origin 2016-12-11 01:39 - 2016-04-17 19:15 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Skype 2016-12-11 01:36 - 2016-04-07 23:01 - 00000000 ____D C:\Users\Moritz\AppData\Local\Battle.net 2016-12-11 00:56 - 2016-04-07 22:49 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-12-11 00:55 - 2016-08-30 14:07 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-12-10 22:52 - 2016-02-25 18:20 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Spotify 2016-12-10 15:24 - 2016-02-22 15:55 - 00000000 ____D C:\Program Files (x86)\Steam 2016-12-10 15:10 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-12-10 15:08 - 2016-02-22 17:37 - 00000000 ____D C:\ProgramData\Origin 2016-12-10 15:07 - 2016-02-25 18:20 - 00000000 ____D C:\Users\Moritz\AppData\Local\Spotify 2016-12-10 15:07 - 2016-02-21 21:05 - 00000000 ___RD C:\Users\Moritz\OneDrive 2016-12-10 15:06 - 2016-08-30 14:13 - 00000000 ____D C:\Users\Moritz 2016-12-10 15:06 - 2016-02-22 21:30 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2016-12-10 15:05 - 2016-08-30 14:24 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-12-10 15:05 - 2016-08-30 14:09 - 00000000 ____D C:\ProgramData\NVIDIA 2016-12-10 15:04 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2016-12-10 15:03 - 2016-02-26 20:15 - 00000000 ____D C:\Program Files (x86)\Amazon 2016-12-10 13:07 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2016-12-10 13:06 - 2016-07-16 23:51 - 01280698 _____ C:\WINDOWS\system32\perfh007.dat 2016-12-10 13:06 - 2016-07-16 23:51 - 00314160 _____ C:\WINDOWS\system32\perfc007.dat 2016-12-10 13:06 - 2016-02-21 21:05 - 02926944 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-12-10 12:59 - 2016-08-30 14:06 - 00223720 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-12-10 12:59 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing 2016-12-09 19:07 - 2016-02-26 20:24 - 00000000 ____D C:\Users\Moritz\AppData\Local\CrashDumps 2016-12-09 18:37 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-12-09 16:18 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-12-09 16:11 - 2016-05-18 22:22 - 00000000 ____D C:\Program Files\e2dd5c3297ced70539992c1daa0a22bf 2016-12-09 07:22 - 2016-02-26 20:14 - 00000000 ____D C:\ProgramData\Oracle 2016-12-08 23:05 - 2016-04-02 14:34 - 00000000 ____D C:\Program Files\Java 2016-12-08 23:05 - 2016-02-26 20:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-12-08 23:05 - 2016-02-26 20:14 - 00000000 ____D C:\Program Files (x86)\Java 2016-12-08 23:04 - 2016-04-02 14:34 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2016-12-08 23:04 - 2016-02-26 20:14 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-12-08 22:27 - 2016-02-22 21:22 - 00000000 ____D C:\Users\Moritz\AppData\Local\NVIDIA 2016-12-08 22:26 - 2016-08-30 14:08 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-12-08 22:25 - 2016-08-30 14:08 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-08 22:25 - 2016-08-30 14:08 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-08 22:25 - 2016-02-22 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2016-12-08 22:24 - 2016-08-30 15:05 - 00000000 ___DC C:\WINDOWS\Panther 2016-12-08 11:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-12-08 11:55 - 2016-02-22 21:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\NVIDIA Corporation 2016-12-07 22:20 - 2016-02-22 19:58 - 00001389 _____ C:\Users\Public\Desktop\STAR WARS Battlefront.lnk 2016-12-07 21:39 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2016-12-07 20:50 - 2016-02-21 16:37 - 00000000 ____D C:\Users\Default.migrated 2016-12-07 20:09 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2016-12-07 20:09 - 2016-02-21 16:47 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy 2016-12-06 14:04 - 2016-02-22 17:37 - 00000000 ____D C:\Program Files (x86)\Origin 2016-12-06 14:03 - 2016-04-17 19:15 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-12-06 14:03 - 2016-04-17 19:15 - 00000000 ____D C:\ProgramData\Skype 2016-12-05 20:43 - 2016-08-04 18:29 - 00000000 ____D C:\Program Files (x86)\Overwatch 2016-12-05 15:53 - 2016-03-01 22:26 - 00000000 ____D C:\Users\Moritz\AppData\Local\ElevatedDiagnostics 2016-12-03 11:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-12-02 21:01 - 2016-09-09 19:54 - 00000000 ____D C:\Program Files (x86)\Overwolf 2016-12-02 20:52 - 2016-02-21 21:02 - 00000000 ____D C:\Users\Moritz\AppData\Local\Packages 2016-12-02 20:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache 2016-11-28 22:43 - 2016-04-02 14:29 - 00000000 ____D C:\ftb 2016-11-23 20:34 - 2016-03-24 22:24 - 00000000 ____D C:\Users\Moritz\Desktop\game 2016-11-22 17:30 - 2016-05-16 18:20 - 00001749 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-11-21 16:53 - 2016-06-11 09:00 - 00000000 ____D C:\Program Files\4319cafc0373b1ce231caf7b853b1dc0 2016-11-20 18:05 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2016-11-20 14:19 - 2016-03-21 22:14 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\TS3Client 2016-11-14 21:19 - 2016-02-22 22:29 - 00000000 ____D C:\Users\Moritz\Documents\My Games 2016-11-13 09:53 - 2016-04-02 14:29 - 00000000 ____D C:\Users\Moritz\AppData\Local\ftblauncher 2016-11-12 19:28 - 2016-02-26 20:08 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\.minecraft 2016-11-12 19:16 - 2016-02-21 21:02 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-11-12 18:51 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\migwiz Einige Dateien in TEMP: ==================== C:\Users\Moritz\AppData\Local\Temp\jre-8u111-windows-au.exe C:\Users\Moritz\AppData\Local\Temp\libeay32.dll C:\Users\Moritz\AppData\Local\Temp\msvcr120.dll C:\Users\Moritz\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-12-04 16:53 ==================== Ende von FRST.txt ============================ |
11.12.2016, 02:26 | #7 |
/// Malwareteam | wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichts Schritt 0 Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Hinweis: Falls bei der Deinstallation zu Beginn ein Fehler auftritt oder du den aufgerufenen Uninstaller nicht bedienen kannst, breche dieses Setup einfach ab und fahre mit der Entfernung durch Revo wie oben beschrieben fort. Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Lade dir folgendes Programm herunter und installiere es: Malwarebytes Anti-Malware
Schritt 3 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen. Bitte poste in deiner nächsten Antwort also:
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
11.12.2016, 15:42 | #8 |
| Zu Schritt 1: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v6.040 - Bericht erstellt am 11/12/2016 um 11:36:38 # Aktualisiert am 02/12/2016 von Malwarebytes # Datenbank : 2016-12-11.2 [Server] # Betriebssystem : Windows 10 Home (X64) # Benutzername : Moritz - DESKTOP-ERBVLM6 # Gestartet von : C:\Users\Moritz\Downloads\AdwCleaner_6.040 (1).exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** ***** [ Dateien ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: "Prefetch" Dateien gelöscht :: Proxy Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [10593 Bytes] - [10/12/2016 15:04:07] C:\AdwCleaner\AdwCleaner[C2].txt - [1048 Bytes] - [11/12/2016 11:36:38] C:\AdwCleaner\AdwCleaner[S0].txt - [9911 Bytes] - [10/12/2016 15:03:18] C:\AdwCleaner\AdwCleaner[S1].txt - [1501 Bytes] - [11/12/2016 11:36:13] ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1267 Bytes] ########## Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 11.12.16 Scan-Zeit: 11:47 Protokolldatei: mbam textdatei.txt Administrator: Ja -Softwaredaten- Version: 3.0.4.1269 Komponentenversion: 1.0.39 Version des Aktualisierungspakets: 1.0.693 Lizenz: Testversion -Systemdaten- Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: DESKTOP-ERBVLM6\Moritz -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Ergebnis: Abgeschlossen Gescannte Objekte: 389518 Abgelaufene Zeit: 5 Min., 11 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 2 PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\TRACING\winwb_RASAPI32, In Quarantäne, [3937], [262291],1.0.693 PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\TRACING\winwb_RASMANCS, In Quarantäne, [3937], [262291],1.0.693 Registrierungswert: 0 (keine bösartigen Elemente erkannt) Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 1 PUP.Optional.WebBar, C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\WEBBAR, In Quarantäne, [3937], [244762],1.0.693 Datei: 4 PUP.Optional.InstallCore, C:\USERS\MORITZ\DOWNLOADS\FLASHPLAYERPRO.EXE, In Quarantäne, [8], [16597],1.0.693 PUP.Optional.InstallCore, C:\USERS\MORITZ\DOWNLOADS\FLASHPLAYERPRO (1).EXE.129Y5GX.PARTIAL, In Quarantäne, [8], [114281],1.0.693 PUP.Optional.WebBar, C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\WEBBAR\WB.LOG, In Quarantäne, [3937], [244762],1.0.693 Trojan.FakeNSI.ED, C:\WINDOWS\A956BE449A292952E1127356ECAC2673.EXE, In Quarantäne, [2484], [67606],1.0.693 Physischer Sektor: 0 (keine bösartigen Elemente erkannt) (end) FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016 durchgeführt von Moritz (11-12-2016 12:11:21) Gestartet von C:\Users\Moritz\Downloads Windows 10 Home Version 1607 (X64) (2016-08-30 13:33:30) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1352620464-1759978224-1981204074-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1352620464-1759978224-1981204074-503 - Limited - Disabled) Gast (S-1-5-21-1352620464-1759978224-1981204074-501 - Limited - Disabled) Moritz (S-1-5-21-1352620464-1759978224-1981204074-1001 - Administrator - Enabled) => C:\Users\Moritz ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.3.183.90 - Adobe Systems Incorporated) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Blacklight: Retribution (HKLM\...\Steam App 209870) (Version: - Hardsuit Labs) Brawlhalla (HKLM\...\Steam App 291550) (Version: - Blue Mammoth Games) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{6DBD132B-7F42-4594-BBE7-0BB677EB2926}) (Version: 4.4.2 - SEIKO EPSON CORPORATION) EPSON WF-2540 Series Printer Uninstall (HKLM\...\EPSON WF-2540 Series) (Version: - SEIKO EPSON Corporation) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HiPatch (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}) (Version: 5.0.6.4 - Hi-Rez Studios) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games) League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden Logitech Gaming Software 8.87 (HKLM\...\Logitech Gaming Software) (Version: 8.87.116 - Logitech Inc.) Malwarebytes Version 3.0.4.1269 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.4.1269 - Malwarebytes) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.91 - NVIDIA Corporation) NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation) NVIDIA Grafiktreiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.91 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) OpenOffice 4.1.3 (HKLM-x32\...\{8D5FCC56-BB9F-4122-923C-71753F50F6F5}) (Version: 4.13.9783 - Apache Software Foundation) Orcs Must Die! Unchained (HKLM\...\Steam App 427270) (Version: - Robot Entertainment) Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.100.9.0 - Overwolf Ltd.) Paladins (HKLM\...\Steam App 444090) (Version: - Hi-Rez Studios) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Remote Mouse version 3.000 (HKLM-x32\...\{01E4BC6D-3ACC-45E1-8928-C2FF626F63F3}_is1) (Version: 3.000 - Remote Mouse) Shakes and Fidget (HKLM\...\Steam App 438040) (Version: - Playa Games GmbH) SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.) SMITE (HKLM-x32\...\Steam App 386360) (Version: - Hi-Rez Studios) Spotify (HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Spotify) (Version: 1.0.44.100.ga60c0ce1 - Spotify AB) STAR WARS™ Battlefront™ (HKLM-x32\...\{E402D891-4E45-4ce9-B41F-DD35864EF170}) (Version: 1.0.7.36460 - Electronic Arts) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) Teeworlds (HKLM\...\Steam App 380840) (Version: - Teeworlds Team) Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes) WinRAR 5.31 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {25B783C7-77FC-4693-83BD-D956AA8C830B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {26149F4E-DC4B-4588-8D07-F7C17210003F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {3A0F445C-6D63-4C05-B4CA-20A7ABF9B97F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {6DC3ABB3-D7D4-422D-B48B-1EE597905C66} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-11-23] (Overwolf LTD) Task: {71112587-2E61-4271-BEDD-358C33D3B436} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {798FE0A8-AF38-4A03-9042-5A3A814677D4} - System32\Tasks\{C957B167-54F3-473A-ABC0-BB93E1A35F4B} => pcalua.exe -a C:\WINDOWS\a956be449a292952e1127356ecac2673.exe Task: {AEE8E303-B56E-4C79-A68E-7E06D07312A1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {D27E911F-1BB6-4487-BD05-FCB65ABC007D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-11-10] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-08-30 14:09 - 2016-02-09 06:29 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-06-14 19:49 - 2016-05-17 22:15 - 00018432 _____ () C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe 2016-05-27 10:08 - 2016-05-28 12:32 - 00076888 _____ () C:\WINDOWS\SysWoW64\PnkBstrA.exe 2016-12-11 11:47 - 2016-11-29 06:27 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2016-12-11 11:47 - 2016-11-29 06:27 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2016-12-11 11:47 - 2016-11-29 06:27 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-08-31 13:06 - 2016-08-31 13:06 - 01864384 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll 2016-09-17 23:18 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-11-10 17:21 - 2016-11-02 11:21 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-10 17:21 - 2016-11-02 11:15 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-10 17:21 - 2016-11-02 11:14 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-11-10 17:21 - 2016-11-02 11:15 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-11-10 17:21 - 2016-11-02 11:16 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-10 17:21 - 2016-11-02 11:17 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-11-17 14:11 - 2016-11-17 14:11 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-11-17 14:11 - 2016-11-17 14:11 - 00178688 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-11-17 14:11 - 2016-11-17 14:11 - 41609728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-08-30 01:17 - 2016-08-30 01:17 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-08-30 01:17 - 2016-08-30 01:17 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 00022024 _____ () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe 2016-03-19 22:32 - 2016-10-28 14:12 - 00145920 _____ () C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe 2016-11-10 17:21 - 2016-11-02 11:13 - 00114176 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Dss.BackgroundTask.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2016-06-14 19:49 - 2015-05-26 18:54 - 00152576 _____ () C:\Program Files (x86)\Remote Mouse\FileS.dll 2016-02-22 21:22 - 2016-02-17 08:02 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-08-31 13:05 - 2016-08-31 13:06 - 01383616 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\ClientTelemetry.dll 2016-08-31 13:06 - 2016-08-31 13:06 - 00118976 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncViews.dll 2016-02-22 15:57 - 2016-09-08 04:14 - 00784672 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 02321696 _____ () C:\Program Files (x86)\Steam\video.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 00836896 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2016-03-12 16:04 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 00012288 _____ () C:\Program Files (x86)\Origin\libEGL.DLL 2016-02-22 17:39 - 2016-06-11 09:25 - 00266240 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll 2016-02-25 18:20 - 2016-12-09 14:10 - 51777648 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\libcef.dll 2016-10-28 17:26 - 2016-12-09 14:10 - 00110192 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWinRT.dll 2016-10-14 15:18 - 2016-08-04 21:56 - 49825056 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.winxp\libcef.dll 2016-02-25 18:20 - 2016-12-09 14:10 - 01803888 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\libglesv2.dll 2016-02-25 18:20 - 2016-12-09 14:10 - 00086128 _____ () C:\Users\Moritz\AppData\Roaming\Spotify\libegl.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 00380704 _____ () C:\Program Files (x86)\Steam\steam.dll 2016-12-11 11:46 - 2016-11-08 09:46 - 00693248 _____ () C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\.DEFAULT\...\amazon.de -> hxxps://amazon.de IE trusted site: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\amazon.de -> hxxps://amazon.de ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2016-02-21 16:47 - 2016-12-10 12:59 - 00002024 ____A C:\WINDOWS\system32\Drivers\etc\hosts 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com 0.0.0.0 media.opencandy.com 0.0.0.0 cdn.opencandy.com 0.0.0.0 tracking.opencandy.com 0.0.0.0 api.opencandy.com 0.0.0.0 api.recommendedsw.com 0.0.0.0 installer.betterinstaller.com 0.0.0.0 installer.filebulldog.com 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net 0.0.0.0 inno.bisrv.com 0.0.0.0 nsis.bisrv.com 0.0.0.0 cdn.file2desktop.com 0.0.0.0 cdn.goateastcach.us 0.0.0.0 cdn.guttastatdk.us 0.0.0.0 cdn.inskinmedia.com 0.0.0.0 cdn.insta.oibundles2.com 0.0.0.0 cdn.insta.playbryte.com 0.0.0.0 cdn.llogetfastcach.us 0.0.0.0 cdn.montiera.com 0.0.0.0 cdn.msdwnld.com 0.0.0.0 cdn.mypcbackup.com 0.0.0.0 cdn.ppdownload.com 0.0.0.0 cdn.riceateastcach.us 0.0.0.0 cdn.shyapotato.us 0.0.0.0 cdn.solimba.com 0.0.0.0 cdn.tuto4pc.com 0.0.0.0 cdn.appround.biz 0.0.0.0 cdn.bigspeedpro.com 0.0.0.0 cdn.bispd.com Da befinden sich 4 zusätzliche Einträge. ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Moritz\Pictures\league-of-legends-fan-art.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [UDP Query User{171B2627-DEFC-41AA-B3C9-287E47EC6BBA}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [TCP Query User{749023EB-D8FD-4420-9AC7-E4E2230DAE73}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{98AF7DC9-0EF2-4532-B489-A4115A2708A9}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [TCP Query User{59F600E4-2200-4891-88DE-517505BF8757}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [{4D24FBC9-55D8-4B79-9ADB-04369415B741}] => C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe FirewallRules: [{E7808F84-D012-4EA7-87FE-8E3C370DAC15}] => C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe FirewallRules: [{87D8D5FC-7CF6-4C97-B326-0D1EB719A5B8}] => C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe FirewallRules: [{3B1A788A-A056-4B28-8576-C94B0A918614}] => C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe FirewallRules: [{08DDDF30-6604-498E-86A5-94783B392A1C}] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [{00403A52-43F9-4F6A-BBD6-D92751A20E50}] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [{9915B4E2-FDB5-4B54-8F27-8BDD9B798392}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\teeworlds.exe FirewallRules: [{5BC6397F-C273-4ABE-BD16-0711CAB6413A}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\teeworlds.exe FirewallRules: [UDP Query User{6303235C-A172-4FE9-BA7E-E1826F97589D}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{4291F196-3B7C-4AEF-A99E-C9958ACF6C7E}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{5ABB841B-A52E-4318-8005-4BE953951A94}] => C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{300ED332-6ABF-4B0E-BF07-D1D3D36A99E9}] => C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{C4889F50-917F-41A9-9F71-7BCD93B9B456}] => C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{B87C0EE9-6F0F-4113-BBE8-80C887005D97}] => C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{E8AD663F-43A5-44F3-854B-2CB30C5C0CFA}] => C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [{204CC8CE-6B0D-4735-B5DA-1352BF537E4C}] => C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [UDP Query User{A3A16CD8-074A-46D7-B7F7-FB03119C0C79}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe] => C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe FirewallRules: [TCP Query User{E2B2F661-5DE8-4AFF-8FE2-D265B6BEC8E4}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe] => C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe FirewallRules: [{EC67536D-BCB8-4CB0-A339-004C85A8DA10}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Binaries\Win32\FoxGame-win32-Shipping.exe FirewallRules: [{A2B487E7-F928-4B8B-82C3-8A00A4BC05D6}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Binaries\Win32\FoxGame-win32-Shipping.exe FirewallRules: [{1811FF59-D55E-4F62-AC77-48B8DACD52CD}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Blacklight Retribution.exe FirewallRules: [{F1EB0788-FEFC-463D-AE09-A26AAE6964F8}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Blacklight Retribution.exe FirewallRules: [UDP Query User{90BCB480-9F75-4D62-BF93-6886F634BEF2}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{FAE64EC6-55C3-4205-997F-5B61ABAB4FF7}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{ADEA7124-1035-40D8-B4F8-1362C2A859A2}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [UDP Query User{F0CC8E85-FFE5-458D-B4B9-5418324B320F}C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe] => C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{0F2CA579-7B22-47BE-8709-005FA88A56FF}C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe] => C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{82465579-118B-4D56-BC78-0624CFEA80EC}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{DDA6F10F-71B5-4694-9C1B-C002DEEF3BED}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [{464D4A29-7E85-4763-ACFE-59AFD75FFC94}] => C:\Program Files (x86)\Steam\steamapps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe FirewallRules: [{98BE2BB8-A4F4-45DC-9077-173B13FC89F1}] => C:\Program Files (x86)\Steam\steamapps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe FirewallRules: [UDP Query User{C7F328C5-3448-4E3B-8923-745F18B6B69D}C:\program files\java\jre1.8.0_77\bin\javaw.exe] => C:\program files\java\jre1.8.0_77\bin\javaw.exe FirewallRules: [TCP Query User{7B9E4ED8-B00E-4B6C-AD29-6D59094BC041}C:\program files\java\jre1.8.0_77\bin\javaw.exe] => C:\program files\java\jre1.8.0_77\bin\javaw.exe FirewallRules: [UDP Query User{3683ABD1-BC68-4613-9248-DAB35856F894}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [TCP Query User{4584F67A-7676-442A-8DFE-7786F2E6422F}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [{6CE777BD-F20F-495A-B551-91ECDB0A2B73}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{BF10500B-7853-4C35-9A4D-8BA2A1D76A8B}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{C0C18B0D-8D00-4AF6-BB0E-73A7768CD092}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{10139860-2EB1-45D7-89C5-D68DDB3974F9}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{6A20F085-40ED-4F64-A008-F40C99A6399A}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{782C462A-0BF5-4549-9D98-623647C71E54}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{41682100-C0DC-4C38-8168-F54C65A31801}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{21C35BA2-02D4-4151-BB19-635617D0568E}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{C3EAFBB4-815A-4983-87F5-06A0FED02851}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{585C2009-6DD4-4CF9-88E9-3064555B8202}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{F00BF74C-F4D0-4581-A49F-1DF81B19B1BA}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{8C1A674C-3E46-40CD-B3CA-E22B5D8236BF}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{FD61E35D-3DC2-4A77-98B4-8ACC077D6011}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{6B1F40FB-A095-43E7-9ADD-8C14ADBBDD0D}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [UDP Query User{6DA33C40-3A41-4E03-BB49-B35B54C7167C}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [TCP Query User{83C9BC60-7DF4-4BCA-ADF3-C6150DB744C8}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{7358A27E-138E-4010-8E38-4FC515D76BB6}] => C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe FirewallRules: [{335B9884-E9BE-4BCF-9B0F-269CA40E0C7A}] => C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe FirewallRules: [UDP Query User{EB46B116-E7A9-4D33-B690-D2DB686FC6DE}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{25921E86-572F-4994-9C7C-3980BFE43D08}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{D5FC44E7-B5CC-40F9-AFAD-080B59F5EC66}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{A155E99F-64CB-4D38-9F73-23E607304839}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{D5F55766-8EDC-4B27-B5DC-8036A86BEA58}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{BE0690AF-EC4A-4327-AE4C-112C86A23A26}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{D107C374-1551-40C4-AC0F-256F7DFF0D42}C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{1FDAAFEC-507D-4409-9134-E0C2C27393EA}C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{A0B0DCCF-8216-46FC-A565-7BB7157044AF}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{CDFFADA9-4E90-41E4-A78A-F7323A2F1862}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [{F966CE5A-21BB-4D85-8E70-5486993429B0}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{B3F90A16-384F-4FD7-911B-6893AE3705E1}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [UDP Query User{7A5B186C-42F8-4A6C-A004-BEF58410831D}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [TCP Query User{76C38497-D952-4C31-829E-24F515DC48F3}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{B3EFC0CB-D60F-4A2C-978E-A7ED96F593AA}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{01D94F18-D1F6-462B-9665-9ED85762D28E}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0A7572F5-F406-467C-818D-6377BD0BABF3}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{7EBEC089-B19F-4BF1-8EB2-43E8C0B9040D}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{702BC7BD-5D0C-4D79-A410-ED88619871AE}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{CB550C66-A6F9-44AF-BEB1-5CEA66134640}] => C:\Program Files (x86)\Steam\steamapps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{3E31854E-0C16-4180-BEAD-3FD58B0FE854}] => C:\Program Files (x86)\Steam\steamapps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{AA95820B-D85B-4D30-97CF-8D4CA424CA37}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{280EDB2E-0E0D-4FBF-9106-C5E119691307}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{FCD9861F-DA32-499F-8B21-3B043D56AE26}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{49B3847A-833D-4400-B6B7-DBD7B22C98D4}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D738736C-DC9E-4B28-83A6-A3720EEDC79A}] => C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{126FA278-51A6-4ACE-BABC-A6336844C571}] => C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{BB3B13F8-0DA7-4649-8072-BD4BCDA38CAD}] => C:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{61FF8878-D5AC-4109-B189-568AC4D1EE50}] => C:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [TCP Query User{7C1DE088-EA81-4EE5-AD2C-AC18A5D516FA}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{16B7420E-25A3-4586-A99D-FE0FB0388B17}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [{B354E948-19B1-4508-8F39-7880B00E9535}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [{8E35D1DC-0DA9-46C3-834E-0D4DE55DBE93}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [TCP Query User{C0052537-C009-4AF4-8BFE-AE488884B62E}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{08FF909C-48FD-42A2-BFC9-BD19D747E47E}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{F929E1A5-48A6-4DF2-8214-D9910E425982}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [UDP Query User{CB57CC95-700D-456C-B147-3F13FB86368B}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [{B1E04A7D-2190-42B0-BF88-A4F4D1868580}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe FirewallRules: [{8FCCBCCA-7344-497C-A379-C3C1AFC1C5BA}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe FirewallRules: [{FA2AE04F-9F73-448C-8091-0A2F53EDE480}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{7D4FACC6-D66D-41E7-9B1B-831F7376E15B}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe ==================== Wiederherstellungspunkte ========================= 02-12-2016 20:14:58 Geplanter Prüfpunkt 07-12-2016 20:27:33 Removed WinZip 21.0 09-12-2016 16:31:31 OpenOffice 4.1.3 wird entfernt 11-12-2016 11:10:43 Removed Amazon 1Button App ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (12/11/2016 12:07:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 2c8d909e-e930-4c5e-bcd6-b403cba76dc8 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: dcdda769-d282-472d-9f2f-22c339fa9dee Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 1e7061ac-3294-4a39-9447-9d37f18e6cc8 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: cc1918dd-0775-4910-adfd-ddd6cfff3d43 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: fedcb111-379f-4cf8-8422-aee3e6cabe79 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: b7c67f8e-f291-4683-8878-7a63f0a9c360 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 7f56f9b3-1734-4ff2-aa2d-5b80b2937c5d Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:22 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 48df7519-8219-480e-ac39-238fb296c2a4 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: c4206ad9-e7d3-46a9-99fc-67d051007c44 Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Error: (12/11/2016 12:04:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.14393.82, Zeitstempel: 0x57a55786 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000604 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x24c4 Startzeit der fehlerhaften Anwendung: 0x01d2539e4eacd391 Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 513e6ef1-a94a-45a4-8160-264503021aed Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge Systemfehler: ============= Error: (12/11/2016 12:02:18 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/11/2016 11:57:52 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} und der APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/11/2016 11:55:31 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ERBVLM6) Description: Der Server "{0002DF02-0000-0000-C000-000000000046}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (12/11/2016 11:45:01 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} und der APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/11/2016 11:41:43 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-ERBVLM6) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "DESKTOP-ERBVLM6\Moritz" (SID: S-1-5-21-1352620464-1759978224-1981204074-1001) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {9E175B6D-F52A-11D8-B9A5-505054503030} und der APPID {9E175B9C-F52A-11D8-B9A5-505054503030} im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/11/2016 11:36:51 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: Es wird bereits eine Instanz des Dienstes ausgeführt. Error: (12/11/2016 11:36:23 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (12/11/2016 11:36:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/11/2016 11:36:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "NVIDIA Streamer Network Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (12/11/2016 11:36:20 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Epson Scanner Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. CodeIntegrity: =================================== Date: 2016-12-11 11:47:36.891 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2016-12-11 11:47:36.891 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:23:20.954 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:19.180 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:19.161 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:15.030 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:15.008 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:47:02.958 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:47:02.940 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:40:33.287 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: AMD FX(tm)-4300 Quad-Core Processor Prozentuale Nutzung des RAM: 50% Installierter physikalischer RAM: 8140.34 MB Verfügbarer physikalischer RAM: 4023.82 MB Summe virtueller Speicher: 9548.34 MB Verfügbarer virtueller Speicher: 4835.68 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:1862.46 GB) (Free:1615.74 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ==================== Ende von Addition.txt ============================ War das alles was du brauchst? Bin mir nicht ganz sicher ob das alles war... |
11.12.2016, 16:20 | #9 |
/// Malwareteam | wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichts das normale FRST Log fehlt noch bitte
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
11.12.2016, 16:43 | #10 |
| Das sollte richtig sein oder? das ist die 1. Hälfte... Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016 durchgeführt von Moritz (Administrator) auf DESKTOP-ERBVLM6 (11-12-2016 12:09:29) Gestartet von C:\Users\Moritz\Downloads Geladene Profile: Moritz (Verfügbare Profile: Moritz) Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Edge) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Alle) ========================= (Microsoft Corporation) C:\Windows\System32\smss.exe (Microsoft Corporation) C:\Windows\System32\csrss.exe (Microsoft Corporation) C:\Windows\System32\wininit.exe (Microsoft Corporation) C:\Windows\System32\csrss.exe (Microsoft Corporation) C:\Windows\System32\services.exe (Microsoft Corporation) C:\Windows\System32\lsass.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\winlogon.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\dwm.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\spoolsv.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe () C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\sihost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\taskhostw.exe (Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe (Microsoft Corporation) C:\Windows\explorer.exe (Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe (© 2015 Microsoft Corporation) C:\Users\Moritz\AppData\Local\Microsoft\BingSvc\BingSvc.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\fontdrvhost.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe () C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe (Microsoft Corporation) C:\Windows\System32\ApplicationFrameHost.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Valve Corporation) C:\Program Files (x86)\Steam\GameOverlayUI.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe (Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe (Microsoft Corporation) C:\Windows\System32\wbem\WmiPrvSE.exe (Farbar) C:\Users\Moritz\Downloads\FRST64.exe ==================== Registry (Alle) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [16286840 2016-08-30] (Logitech Inc.) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2786768 2016-11-29] (Malwarebytes) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKLM\...\Winlogon: [Userinit] C:\WINDOWS\system32\userinit.exe, [33280 2016-07-16] (Microsoft Corporation) HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [27648 2016-07-16] (Microsoft Corporation) HKLM\...\Winlogon: [Shell] explorer.exe [4673304 2016-11-11] (Microsoft Corporation) HKLM-x32\...\Winlogon: [Shell] explorer.exe [4311736 2016-11-11] (Microsoft Corporation) HKLM\...\Policies\Explorer: [ForceActiveDesktopOn] 0 HKLM\...\Policies\Explorer: [NoActiveDesktop] 1 HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1 HKLM\...\Policies\Explorer: [NoRecentDocsHistory] 0 HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [8886976 2016-07-16] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [8886976 2016-07-16] (Microsoft Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [OneDrive] => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\OneDrive.exe [633024 2016-08-31] (Microsoft Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2860832 2016-10-13] (Valve Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3044848 2016-12-06] (Electronic Arts) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Spotify Web Helper] => C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-09] (Spotify Ltd) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Spotify] => C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe [7095408 2016-12-09] (Spotify Ltd) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [BingSvc] => C:\Users\Moritz\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27219928 2016-11-15] (Skype Technologies S.A.) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Chromium] => c:\users\moritz\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [~Resuming Profile - Vollständiger Scan] => "C:\Program Files\BullGuard Ltd\BullGuard\BgScan.exe" "profilepath: C:\Users\Moritz\AppData\Roaming\BullGuard\Antivirus\Profiles\~Resuming Profile - Vollständiger Scan.xml" HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION) HKLM\...\Providers\Internet Print Provider: C:\WINDOWS\system32\inetpp.dll [174592 2016-07-16] (Microsoft Corporation) HKLM\...\Providers\LanMan Print Services: C:\WINDOWS\system32\win32spl.dll [833024 2016-10-05] (Microsoft Corporation) Lsa: [Authentication Packages] msv1_0 Lsa: [Notification Packages] scecli SecurityProviders: credssp.dll SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - Keine Datei SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - Keine Datei ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\FileSyncShell64.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\FileSyncShell64.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\FileSyncShell64.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\FileSyncShell64.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\FileSyncShell64.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers: [EnhancedStorageShell] -> {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} => C:\Windows\System32\EhStorShell.dll [2016-07-16] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncShell.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncShell.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncShell.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncShell.dll [2016-08-31] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncShell.dll [2016-08-31] (Microsoft Corporation) BootExecute: autocheck autochk * AlternateShell: cmd.exe ==================== Internet (Alle) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2016-07-16] (Microsoft Corporation) Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2016-07-16] (Microsoft Corporation) Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2016-07-16] (Microsoft Corporation) Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2016-07-16] (Microsoft Corporation) Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [24064 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 11 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog9 12 C:\WINDOWS\SysWOW64\mswsock.dll [306016 2016-07-16] (Microsoft Corporation) Winsock: Catalog5-x64 01 C:\Windows\system32\napinsp.dll [67584 2016-07-16] (Microsoft Corporation) Winsock: Catalog5-x64 02 C:\Windows\system32\pnrpnsp.dll [86016 2016-07-16] (Microsoft Corporation) Winsock: Catalog5-x64 03 C:\Windows\system32\pnrpnsp.dll [86016 2016-07-16] (Microsoft Corporation) Winsock: Catalog5-x64 04 C:\Windows\system32\NLAapi.dll [80896 2016-07-16] (Microsoft Corporation) Winsock: Catalog5-x64 05 C:\Windows\System32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog5-x64 06 C:\Windows\System32\winrnr.dll [31744 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 01 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 02 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 03 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 04 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 05 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 06 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 07 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 08 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 09 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 10 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 11 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Winsock: Catalog9-x64 12 C:\Windows\system32\mswsock.dll [357216 2016-07-16] (Microsoft Corporation) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{17ee23ff-c454-4ac7-aafe-24a47b714173}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{2c9c1031-1c58-4a0c-a510-c4b9546a53b7}: [DhcpNameServer] 172.17.2.1 Tcpip\..\Interfaces\{beb9c673-971c-479c-96ad-efdd872d05fa}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Start Page = HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp URLSearchHook: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation) URLSearchHook: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC SearchScopes: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 SearchScopes: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 SearchScopes: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-12-08] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-08] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-12-08] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-08] (Oracle Corporation) Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler-x32: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler-x32: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll [2016-11-02] (Microsoft Corporation) Handler-x32: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll [2016-11-02] (Microsoft Corporation) Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler-x32: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler-x32: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler-x32: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler-x32: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2016-07-16] (Microsoft Corporation) Handler-x32: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll [2016-07-16] (Microsoft Corporation) Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler-x32: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler-x32: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler-x32: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll [2016-11-02] (Microsoft Corporation) Handler-x32: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll [2016-11-02] (Microsoft Corporation) Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler-x32: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2016-11-11] (Microsoft Corporation) Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2016-07-16] (Microsoft Corporation) Handler-x32: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll [2016-07-16] (Microsoft Corporation) Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler-x32: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2016-07-16] (Microsoft Corporation) Handler-x32: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2016-07-16] (Microsoft Corporation) Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll [2016-11-02] (Microsoft Corporation) Handler-x32: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll [2016-11-02] (Microsoft Corporation) Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler-x32: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2016-11-11] (Microsoft Corporation) Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2016-07-16] (Microsoft Corporation) Handler-x32: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2016-07-16] (Microsoft Corporation) Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll [2016-07-16] (Microsoft Corporation) Filter-x32: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\SysWOW64\mscoree.dll [2016-07-16] (Microsoft Corporation) Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll [2016-07-16] (Microsoft Corporation) Filter-x32: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\SysWOW64\mscoree.dll [2016-07-16] (Microsoft Corporation) Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll [2016-07-16] (Microsoft Corporation) Filter-x32: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\SysWOW64\mscoree.dll [2016-07-16] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-08] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32.dll [2016-02-22] () FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Alle) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AJRouter; C:\WINDOWS\System32\AJRouter.dll [24576 2016-07-16] (Microsoft Corporation) S3 ALG; C:\WINDOWS\System32\alg.exe [95744 2016-07-16] (Microsoft Corporation) S3 AppIDSvc; C:\WINDOWS\System32\appidsvc.dll [124416 2016-07-16] (Microsoft Corporation) R3 Appinfo; C:\WINDOWS\System32\appinfo.dll [125952 2016-09-15] (Microsoft Corporation) S3 AppReadiness; C:\WINDOWS\system32\AppReadiness.dll [560128 2016-11-11] (Microsoft Corporation) S3 AppXSvc; C:\WINDOWS\system32\appxdeploymentserver.dll [2275840 2016-11-11] (Microsoft Corporation) R2 AudioEndpointBuilder; C:\WINDOWS\System32\AudioEndpointBuilder.dll [337920 2016-11-11] (Microsoft Corporation) R2 Audiosrv; C:\WINDOWS\System32\Audiosrv.dll [942080 2016-11-11] (Microsoft Corporation) S3 AxInstSV; C:\WINDOWS\System32\AxInstSV.dll [113664 2016-07-16] (Microsoft Corporation) S3 BDESVC; C:\WINDOWS\System32\bdesvc.dll [361472 2016-09-15] (Microsoft Corporation) R2 BFE; C:\WINDOWS\System32\bfe.dll [795648 2016-07-16] (Microsoft Corporation) S2 BITS; C:\WINDOWS\System32\qmgr.dll [1054208 2016-10-15] (Microsoft Corporation) R2 BrokerInfrastructure; C:\WINDOWS\System32\bisrv.dll [770560 2016-11-02] (Microsoft Corporation) S3 Browser; C:\WINDOWS\System32\browser.dll [134656 2016-07-16] (Microsoft Corporation) S3 BthHFSrv; C:\WINDOWS\System32\BthHFSrv.dll [321536 2016-07-16] (Microsoft Corporation) S3 bthserv; C:\WINDOWS\system32\bthserv.dll [157184 2016-07-16] (Microsoft Corporation) R2 CDPSvc; C:\WINDOWS\System32\CDPSvc.dll [411648 2016-11-11] (Microsoft Corporation) S2 CDPUserSvc; C:\WINDOWS\System32\CDPUserSvc.dll [339456 2016-11-11] (Microsoft Corporation) R2 CDPUserSvc_584bd; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation) R2 CDPUserSvc_584bd; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation) S3 CertPropSvc; C:\WINDOWS\System32\certprop.dll [193536 2016-07-16] (Microsoft Corporation) S3 ClipSVC; C:\WINDOWS\System32\ClipSVC.dll [729328 2016-07-16] (Microsoft Corporation) R2 CoreMessagingRegistrar; C:\WINDOWS\system32\coremessaging.dll [764392 2016-11-11] (Microsoft Corporation) R2 CoreMessagingRegistrar; C:\WINDOWS\SysWOW64\coremessaging.dll [483840 2016-11-11] (Microsoft Corporation) R2 CryptSvc; C:\WINDOWS\system32\cryptsvc.dll [81920 2016-07-16] (Microsoft Corporation) R2 DcomLaunch; C:\WINDOWS\system32\rpcss.dll [888320 2016-07-16] (Microsoft Corporation) S3 DcpSvc; C:\WINDOWS\system32\dcpsvc.dll [183808 2016-07-16] (Microsoft Corporation) S3 defragsvc; C:\WINDOWS\System32\defragsvc.dll [511488 2016-07-16] (Microsoft Corporation) R2 DeviceAssociationService; C:\WINDOWS\system32\das.dll [447488 2016-08-06] (Microsoft Corporation) S3 DeviceInstall; C:\WINDOWS\system32\umpnpmgr.dll [111104 2016-07-16] (Microsoft Corporation) S3 DevQueryBroker; C:\WINDOWS\system32\DevQueryBroker.dll [34304 2016-07-16] (Microsoft Corporation) R2 Dhcp; C:\WINDOWS\system32\dhcpcore.dll [360960 2016-07-16] (Microsoft Corporation) R2 Dhcp; C:\WINDOWS\SysWOW64\dhcpcore.dll [292864 2016-07-16] (Microsoft Corporation) S3 diagnosticshub.standardcollector.service; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [93184 2016-07-16] (Microsoft Corporation) R2 DiagTrack; C:\WINDOWS\system32\diagtrack.dll [1980416 2016-10-15] (Microsoft Corporation) S3 DmEnrollmentSvc; C:\WINDOWS\system32\Windows.Internal.Management.dll [407552 2016-11-11] (Microsoft Corporation) S3 DmEnrollmentSvc; C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll [298496 2016-11-11] (Microsoft Corporation) S3 dmwappushservice; C:\WINDOWS\system32\dmwappushsvc.dll [57344 2016-07-16] (Microsoft Corporation) R2 Dnscache; C:\WINDOWS\System32\dnsrslvr.dll [264192 2016-07-16] (Microsoft Corporation) R2 DoSvc; C:\WINDOWS\system32\dosvc.dll [1232384 2016-11-11] (Microsoft Corporation) S3 dot3svc; C:\WINDOWS\System32\dot3svc.dll [262144 2016-07-16] (Microsoft Corporation) R2 DPS; C:\WINDOWS\system32\dps.dll [172032 2016-07-16] (Microsoft Corporation) S3 DsmSvc; C:\WINDOWS\System32\DeviceSetupManager.dll [197632 2016-07-16] (Microsoft Corporation) S3 DsSvc; C:\WINDOWS\System32\DsSvc.dll [152576 2016-07-16] (Microsoft Corporation) S3 EapHost; C:\WINDOWS\System32\eapsvc.dll [112128 2016-07-16] (Microsoft Corporation) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [245544 2016-07-12] (EasyAntiCheat Ltd) S3 EFS; C:\WINDOWS\system32\efssvc.dll [55296 2016-07-16] (Microsoft Corporation) S3 embeddedmode; C:\WINDOWS\System32\embeddedmodesvc.dll [140800 2016-07-16] (Microsoft Corporation) S3 EntAppSvc; C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll [285696 2016-11-11] (Microsoft Corporation) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 EventLog; C:\WINDOWS\System32\wevtsvc.dll [1709056 2016-09-15] (Microsoft Corporation) R2 EventSystem; C:\WINDOWS\system32\es.dll [453632 2016-07-16] (Microsoft Corporation) R2 EventSystem; C:\WINDOWS\SysWOW64\es.dll [347136 2016-07-16] (Microsoft Corporation) S3 Fax; C:\WINDOWS\system32\fxssvc.exe [644608 2016-07-16] (Microsoft Corporation) R3 fdPHost; C:\WINDOWS\system32\fdPHost.dll [20992 2016-07-16] (Microsoft Corporation) R3 FDResPub; C:\WINDOWS\system32\fdrespub.dll [35328 2016-07-16] (Microsoft Corporation) S3 fhsvc; C:\WINDOWS\system32\fhsvc.dll [122368 2016-07-16] (Microsoft Corporation) R2 FontCache; C:\WINDOWS\system32\FntCache.dll [1840640 2016-10-15] (Microsoft Corporation) S3 FontCache3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [43696 2016-05-25] (Microsoft Corporation) S3 FrameServer; C:\WINDOWS\system32\FrameServer.dll [805888 2016-11-02] (Microsoft Corporation) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation) S2 gpsvc; C:\WINDOWS\System32\gpsvc.dll [1227264 2016-09-15] (Microsoft Corporation) R3 hidserv; C:\WINDOWS\system32\hidserv.dll [36864 2016-07-16] (Microsoft Corporation) R3 hidserv; C:\WINDOWS\SysWOW64\hidserv.dll [32256 2016-07-16] (Microsoft Corporation) U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-10-10] (Hi-Rez Studios) [Datei ist nicht signiert] S3 HomeGroupListener; C:\WINDOWS\system32\ListSvc.dll [274432 2016-11-02] (Microsoft Corporation) R3 HomeGroupProvider; C:\WINDOWS\system32\provsvc.dll [447488 2016-07-16] (Microsoft Corporation) R3 HomeGroupProvider; C:\WINDOWS\SysWOW64\provsvc.dll [385536 2016-07-16] (Microsoft Corporation) S3 HvHost; C:\WINDOWS\System32\hvhostsvc.dll [67584 2016-07-16] (Microsoft Corporation) S3 icssvc; C:\WINDOWS\System32\tetheringservice.dll [202240 2016-07-16] (Microsoft Corporation) S3 IKEEXT; C:\WINDOWS\System32\ikeext.dll [932352 2016-07-16] (Microsoft Corporation) R2 iphlpsvc; C:\WINDOWS\System32\iphlpsvc.dll [945664 2016-10-15] (Microsoft Corporation) S3 irmon; C:\WINDOWS\System32\irmon.dll [25088 2016-07-16] (Microsoft Corporation) R3 KeyIso; C:\WINDOWS\system32\keyiso.dll [96768 2016-07-16] (Microsoft Corporation) R3 KeyIso; C:\WINDOWS\SysWOW64\keyiso.dll [70656 2016-07-16] (Microsoft Corporation) S3 KtmRm; C:\WINDOWS\system32\msdtckrm.dll [376320 2016-07-16] (Microsoft Corporation) R2 LanmanServer; C:\WINDOWS\system32\srvsvc.dll [305152 2016-07-16] (Microsoft Corporation) R2 LanmanWorkstation; C:\WINDOWS\System32\wkssvc.dll [283648 2016-11-11] (Microsoft Corporation) R3 lfsvc; C:\WINDOWS\System32\lfsvc.dll [37376 2016-07-16] (Microsoft Corporation) R3 LicenseManager; C:\WINDOWS\system32\LicenseManagerSvc.dll [26112 2016-08-20] (Microsoft Corporation) S3 lltdsvc; C:\WINDOWS\System32\lltdsvc.dll [275456 2016-07-16] (Microsoft Corporation) R3 lmhosts; C:\WINDOWS\System32\lmhsvc.dll [27136 2016-07-16] (Microsoft Corporation) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-08-30] (Logitech Inc.) R2 LSM; C:\WINDOWS\System32\lsm.dll [691712 2016-11-11] (Microsoft Corporation) S2 MapsBroker; C:\WINDOWS\System32\moshost.dll [82944 2016-11-11] (Microsoft Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-11-29] (Malwarebytes) S3 MessagingService; C:\WINDOWS\System32\MessagingService.dll [52224 2016-07-16] (Microsoft Corporation) S3 MessagingService_584bd; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation) S3 MessagingService_584bd; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation) R2 MpsSvc; C:\WINDOWS\system32\mpssvc.dll [893952 2016-07-16] (Microsoft Corporation) S3 MSDTC; C:\WINDOWS\System32\msdtc.exe [147456 2016-07-16] (Microsoft Corporation) S3 MSiSCSI; C:\WINDOWS\system32\iscsiexe.dll [151552 2016-07-16] (Microsoft Corporation) S3 msiserver; C:\WINDOWS\System32\msiexec.exe [65024 2016-07-16] (Microsoft Corporation) S3 msiserver; C:\WINDOWS\SysWOW64\msiexec.exe [58368 2016-07-16] (Microsoft Corporation) S3 NcaSvc; C:\WINDOWS\System32\ncasvc.dll [167936 2016-07-16] (Microsoft Corporation) R3 NcbService; C:\WINDOWS\System32\ncbservice.dll [339968 2016-07-16] (Microsoft Corporation) R3 NcdAutoSetup; C:\WINDOWS\System32\NcdAutoSetup.dll [88576 2016-07-16] (Microsoft Corporation) S3 Netlogon; C:\WINDOWS\system32\netlogon.dll [827392 2016-07-16] (Microsoft Corporation) S3 Netlogon; C:\WINDOWS\SysWOW64\netlogon.dll [670720 2016-07-16] (Microsoft Corporation) S3 Netman; C:\WINDOWS\System32\netman.dll [259072 2016-07-16] (Microsoft Corporation) R3 netprofm; C:\WINDOWS\System32\netprofmsvc.dll [519168 2016-07-16] (Microsoft Corporation) S3 NetSetupSvc; C:\WINDOWS\System32\NetSetupSvc.dll [265728 2016-11-02] (Microsoft Corporation) S4 NetTcpPortSharing; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [136360 2016-07-16] (Microsoft Corporation) S3 NgcCtnrSvc; C:\WINDOWS\System32\NgcCtnrSvc.dll [326656 2016-07-16] (Microsoft Corporation) S3 NgcSvc; C:\WINDOWS\system32\ngcsvc.dll [983040 2016-10-05] (Microsoft Corporation) R2 NlaSvc; C:\WINDOWS\System32\nlasvc.dll [368640 2016-10-05] (Microsoft Corporation) R2 nsi; C:\WINDOWS\system32\nsisvc.dll [30720 2016-07-16] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation) S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation) R2 nvsvc; C:\WINDOWS\system32\nvvsvc.exe [1263040 2016-02-09] (NVIDIA Corporation) S2 OneSyncSvc; C:\WINDOWS\System32\APHostService.dll [366592 2016-07-16] (Microsoft Corporation) R2 OneSyncSvc_584bd; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation) R2 OneSyncSvc_584bd; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-12-06] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2016-12-06] (Electronic Arts) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1316080 2016-11-23] (Overwolf LTD) S3 p2pimsvc; C:\WINDOWS\system32\pnrpsvc.dll [345088 2016-07-16] (Microsoft Corporation) S3 p2psvc; C:\WINDOWS\system32\p2psvc.dll [425472 2016-07-16] (Microsoft Corporation) R2 PcaSvc; C:\WINDOWS\System32\pcasvc.dll [500064 2016-10-15] (Microsoft Corporation) S3 PerfHost; C:\WINDOWS\SysWow64\perfhost.exe [21504 2016-07-16] (Microsoft Corporation) S3 PhoneSvc; C:\WINDOWS\System32\PhoneService.dll [781824 2016-09-07] (Microsoft Corporation) S3 PimIndexMaintenanceSvc; C:\WINDOWS\System32\PimIndexMaintenance.dll [203776 2016-09-15] (Microsoft Corporation) R3 PimIndexMaintenanceSvc_584bd; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation) R3 PimIndexMaintenanceSvc_584bd; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation) S3 pla; C:\WINDOWS\system32\pla.dll [1457152 2016-07-16] (Microsoft Corporation) S3 pla; C:\WINDOWS\SysWOW64\pla.dll [1536512 2016-07-16] (Microsoft Corporation) R3 PlugPlay; C:\WINDOWS\system32\umpnpmgr.dll [111104 2016-07-16] (Microsoft Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-05-28] () S3 PNRPAutoReg; C:\WINDOWS\system32\pnrpauto.dll [27648 2016-07-16] (Microsoft Corporation) S3 PNRPsvc; C:\WINDOWS\system32\pnrpsvc.dll [345088 2016-07-16] (Microsoft Corporation) S3 PolicyAgent; C:\WINDOWS\System32\ipsecsvc.dll [391168 2016-07-16] (Microsoft Corporation) R2 Power; C:\WINDOWS\system32\umpo.dll [123904 2016-07-16] (Microsoft Corporation) S3 PrintNotify; C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll [3318272 2016-07-16] (Microsoft Corporation) R2 ProfSvc; C:\WINDOWS\system32\profsvc.dll [358400 2016-09-15] (Microsoft Corporation) S3 QWAVE; C:\WINDOWS\system32\qwave.dll [275456 2016-07-16] (Microsoft Corporation) S3 QWAVE; C:\WINDOWS\SysWOW64\qwave.dll [234496 2016-07-16] (Microsoft Corporation) S3 RasAuto; C:\WINDOWS\System32\rasauto.dll [105472 2016-07-16] (Microsoft Corporation) S3 RasMan; C:\WINDOWS\System32\rasmans.dll [657920 2016-11-11] (Microsoft Corporation) S4 RemoteAccess; C:\WINDOWS\System32\mprdim.dll [496128 2016-09-15] (Microsoft Corporation) S4 RemoteAccess; C:\WINDOWS\SysWOW64\mprdim.dll [431104 2016-09-15] (Microsoft Corporation) R2 RemoteMouseService; C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe [18432 2016-05-17] () [Datei ist nicht signiert] S4 RemoteRegistry; C:\WINDOWS\system32\regsvc.dll [155648 2016-07-16] (Microsoft Corporation) S3 RetailDemo; C:\WINDOWS\system32\RDXService.dll [650752 2016-11-11] (Microsoft Corporation) S3 RmSvc; C:\WINDOWS\System32\RMapi.dll [140800 2016-09-15] (Microsoft Corporation) R2 RpcEptMapper; C:\WINDOWS\System32\RpcEpMap.dll [79360 2016-07-16] (Microsoft Corporation) S3 RpcLocator; C:\WINDOWS\system32\locator.exe [11264 2016-07-16] (Microsoft Corporation) R2 RpcSs; C:\WINDOWS\system32\rpcss.dll [888320 2016-07-16] (Microsoft Corporation) R2 SamSs; C:\WINDOWS\system32\lsass.exe [57400 2016-09-07] (Microsoft Corporation) S4 SCardSvr; C:\WINDOWS\System32\SCardSvr.dll [250880 2016-07-16] (Microsoft Corporation) S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [201728 2016-07-16] (Microsoft Corporation) R2 Schedule; C:\WINDOWS\system32\schedsvc.dll [948224 2016-07-16] (Microsoft Corporation) S3 SCPolicySvc; C:\WINDOWS\System32\certprop.dll [193536 2016-07-16] (Microsoft Corporation) S3 SDRSVC; C:\WINDOWS\System32\SDRSVC.dll [147968 2016-07-16] (Microsoft Corporation) S3 seclogon; C:\WINDOWS\system32\seclogon.dll [31232 2016-07-16] (Microsoft Corporation) R2 SENS; C:\WINDOWS\System32\sens.dll [70656 2016-09-15] (Microsoft Corporation) S3 SensorDataService; C:\WINDOWS\System32\SensorDataService.exe [1312768 2016-09-07] (Microsoft Corporation) S3 SensorService; C:\WINDOWS\system32\SensorService.dll [417792 2016-09-15] (Microsoft Corporation) S3 SensrSvc; C:\WINDOWS\system32\sensrsvc.dll [179200 2016-07-16] (Microsoft Corporation) S3 SessionEnv; C:\WINDOWS\system32\sessenv.dll [387072 2016-09-15] (Microsoft Corporation) S3 SessionEnv; C:\WINDOWS\SysWOW64\sessenv.dll [331776 2016-09-15] (Microsoft Corporation) S3 SharedAccess; C:\WINDOWS\System32\ipnathlp.dll [541696 2016-11-02] (Microsoft Corporation) R2 ShellHWDetection; C:\WINDOWS\System32\shsvcs.dll [617472 2016-07-16] (Microsoft Corporation) R2 ShellHWDetection; C:\WINDOWS\SysWOW64\shsvcs.dll [566784 2016-07-16] (Microsoft Corporation) S4 shpamsvc; C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll [161792 2016-07-16] (Microsoft Corporation) S2 SkypeUpdate; C:\Program Files (x86)\Skype\Updater\Updater.exe [324224 2016-09-20] (Skype Technologies) S3 smphost; C:\WINDOWS\System32\smphost.dll [23552 2016-08-06] (Microsoft Corporation) S3 smphost; C:\WINDOWS\SysWOW64\smphost.dll [20992 2016-08-06] (Microsoft Corporation) S3 SmsRouter; C:\WINDOWS\system32\SmsRouterSvc.dll [590848 2016-07-16] (Microsoft Corporation) S3 SNMPTRAP; C:\WINDOWS\System32\snmptrap.exe [15872 2016-07-16] (Microsoft Corporation) R2 Spooler; C:\WINDOWS\System32\spoolsv.exe [792064 2016-10-15] (Microsoft Corporation) S2 sppsvc; C:\WINDOWS\system32\sppsvc.exe [5622088 2016-10-15] (Microsoft Corporation) R3 SSDPSRV; C:\WINDOWS\System32\ssdpsrv.dll [236544 2016-07-16] (Microsoft Corporation) S3 SstpSvc; C:\WINDOWS\system32\sstpsvc.dll [209920 2016-07-16] (Microsoft Corporation) R3 StateRepository; C:\WINDOWS\system32\windows.staterepository.dll [4136448 2016-11-11] (Microsoft Corporation) R3 StateRepository; C:\WINDOWS\SysWOW64\windows.staterepository.dll [3370496 2016-11-11] (Microsoft Corporation) R3 Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [1459488 2016-10-13] (Valve Corporation) R2 Stereo Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [426040 2016-02-09] (NVIDIA Corporation) R2 stisvc; C:\WINDOWS\System32\wiaservc.dll [646656 2016-07-16] (Microsoft Corporation) R3 StorSvc; C:\WINDOWS\system32\storsvc.dll [396800 2016-11-11] (Microsoft Corporation) S3 svsvc; C:\WINDOWS\system32\svsvc.dll [13824 2016-07-16] (Microsoft Corporation) S3 swprv; C:\WINDOWS\System32\swprv.dll [467456 2016-07-16] (Microsoft Corporation) R2 SysMain; C:\WINDOWS\system32\sysmain.dll [944128 2016-07-16] (Microsoft Corporation) R2 SystemEventsBroker; C:\WINDOWS\System32\SystemEventsBrokerServer.dll [387072 2016-07-16] (Microsoft Corporation) S3 TabletInputService; C:\WINDOWS\System32\TabSvc.dll [148992 2016-07-16] (Microsoft Corporation) S3 TapiSrv; C:\WINDOWS\System32\tapisrv.dll [309248 2016-07-16] (Microsoft Corporation) S3 TapiSrv; C:\WINDOWS\SysWOW64\tapisrv.dll [254976 2016-07-16] (Microsoft Corporation) S3 TermService; C:\WINDOWS\System32\termsrv.dll [987648 2016-07-16] (Microsoft Corporation) R2 Themes; C:\WINDOWS\system32\themeservice.dll [70656 2016-07-16] (Microsoft Corporation) S3 TieringEngineService; C:\WINDOWS\system32\TieringEngineService.exe [287744 2016-07-16] (Microsoft Corporation) R2 tiledatamodelsvc; C:\WINDOWS\system32\tileobjserver.dll [574976 2016-07-16] (Microsoft Corporation) R3 TimeBrokerSvc; C:\WINDOWS\System32\TimeBrokerServer.dll [177664 2016-07-16] (Microsoft Corporation) R2 TrkWks; C:\WINDOWS\System32\trkwks.dll [116736 2016-07-16] (Microsoft Corporation) S3 TrustedInstaller; C:\WINDOWS\servicing\TrustedInstaller.exe [122880 2016-11-11] (Microsoft Corporation) S4 tzautoupdate; C:\WINDOWS\system32\tzautoupdate.dll [95232 2016-09-07] (Microsoft Corporation) S3 UI0Detect; C:\WINDOWS\system32\UI0Detect.exe [42496 2016-07-16] (Microsoft Corporation) S3 UmRdpService; C:\WINDOWS\System32\umrdp.dll [273408 2016-07-16] (Microsoft Corporation) S3 UnistoreSvc; C:\WINDOWS\System32\unistore.dll [1184256 2016-07-16] (Microsoft Corporation) S3 UnistoreSvc; C:\WINDOWS\SysWOW64\unistore.dll [968704 2016-07-16] (Microsoft Corporation) R3 UnistoreSvc_584bd; C:\WINDOWS\System32\svchost.exe [44496 2016-07-16] (Microsoft Corporation) R3 UnistoreSvc_584bd; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation) S3 upnphost; C:\WINDOWS\System32\upnphost.dll [440832 2016-07-16] (Microsoft Corporation) S3 upnphost; C:\WINDOWS\SysWOW64\upnphost.dll [328192 2016-07-16] (Microsoft Corporation) S3 UserDataSvc; C:\WINDOWS\System32\userdataservice.dll [1512448 2016-07-16] (Microsoft Corporation) R3 UserDataSvc_584bd; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation) R3 UserDataSvc_584bd; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation) R2 UserManager; C:\WINDOWS\System32\usermgr.dll [1020928 2016-09-15] (Microsoft Corporation) R3 UsoSvc; C:\WINDOWS\system32\usocore.dll [539136 2016-10-15] (Microsoft Corporation) R3 VaultSvc; C:\Windows\System32\vaultsvc.dll [358912 2016-07-16] (Microsoft Corporation) S3 vds; C:\WINDOWS\System32\vds.exe [649216 2016-07-16] (Microsoft Corporation) S3 vmicguestinterface; C:\WINDOWS\System32\icsvc.dll [305152 2016-09-15] (Microsoft Corporation) S3 vmicheartbeat; C:\WINDOWS\System32\icsvc.dll [305152 2016-09-15] (Microsoft Corporation) S3 vmickvpexchange; C:\WINDOWS\System32\icsvc.dll [305152 2016-09-15] (Microsoft Corporation) S3 vmicrdv; C:\WINDOWS\System32\icsvcext.dll [349696 2016-09-15] (Microsoft Corporation) S3 vmicshutdown; C:\WINDOWS\System32\icsvc.dll [305152 2016-09-15] (Microsoft Corporation) S3 vmictimesync; C:\WINDOWS\System32\icsvc.dll [305152 2016-09-15] (Microsoft Corporation) S3 vmicvmsession; C:\WINDOWS\System32\icsvc.dll [305152 2016-09-15] (Microsoft Corporation) S3 vmicvss; C:\WINDOWS\System32\icsvcext.dll [349696 2016-09-15] (Microsoft Corporation) S3 VSS; C:\WINDOWS\system32\vssvc.exe [1443328 2016-07-16] (Microsoft Corporation) S3 W32Time; C:\WINDOWS\system32\w32time.dll [520192 2016-08-06] (Microsoft Corporation) S3 WalletService; C:\WINDOWS\system32\WalletService.dll [436224 2016-07-16] (Microsoft Corporation) S3 wbengine; C:\WINDOWS\system32\wbengine.exe [1547264 2016-07-16] (Microsoft Corporation) S2 WbioSrvc; C:\WINDOWS\System32\wbiosrvc.dll [837632 2016-10-05] (Microsoft Corporation) R2 Wcmsvc; C:\WINDOWS\System32\wcmsvc.dll [718848 2016-07-16] (Microsoft Corporation) S3 wcncsvc; C:\WINDOWS\System32\wcncsvc.dll [468992 2016-07-16] (Microsoft Corporation) R3 WdiServiceHost; C:\WINDOWS\system32\wdi.dll [97792 2016-07-16] (Microsoft Corporation) R3 WdiServiceHost; C:\WINDOWS\SysWOW64\wdi.dll [89088 2016-07-16] (Microsoft Corporation) R3 WdiSystemHost; C:\WINDOWS\system32\wdi.dll [97792 2016-07-16] (Microsoft Corporation) R3 WdiSystemHost; C:\WINDOWS\SysWOW64\wdi.dll [89088 2016-07-16] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WebClient; C:\WINDOWS\System32\webclnt.dll [227328 2016-07-16] (Microsoft Corporation) S3 WebClient; C:\WINDOWS\SysWOW64\webclnt.dll [198656 2016-07-16] (Microsoft Corporation) S3 Wecsvc; C:\WINDOWS\system32\wecsvc.dll [206848 2016-07-16] (Microsoft Corporation) S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [27648 2016-07-16] (Microsoft Corporation) S3 wercplsupport; C:\WINDOWS\System32\wercplsupport.dll [94208 2016-07-16] (Microsoft Corporation) S3 WerSvc; C:\WINDOWS\System32\WerSvc.dll [156672 2016-07-16] (Microsoft Corporation) S3 WiaRpc; C:\WINDOWS\System32\wiarpc.dll [82944 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) R3 WinHttpAutoProxySvc; C:\WINDOWS\system32\winhttp.dll [817664 2016-10-15] (Microsoft Corporation) R3 WinHttpAutoProxySvc; C:\WINDOWS\SysWOW64\winhttp.dll [636928 2016-10-15] (Microsoft Corporation) R2 Winmgmt; C:\WINDOWS\system32\wbem\WMIsvc.dll [222720 2016-07-16] (Microsoft Corporation) S3 WinRM; C:\WINDOWS\system32\WsmSvc.dll [2716672 2016-11-11] (Microsoft Corporation) S3 WinRM; C:\WINDOWS\SysWOW64\WsmSvc.dll [2333184 2016-11-11] (Microsoft Corporation) S3 wisvc; C:\WINDOWS\system32\flightsettings.dll [635904 2016-11-02] (Microsoft Corporation) R2 WlanSvc; C:\WINDOWS\System32\wlansvc.dll [2370048 2016-09-07] (Microsoft Corporation) S3 wlidsvc; C:\WINDOWS\system32\wlidsvc.dll [2104320 2016-11-11] (Microsoft Corporation) S3 wmiApSrv; C:\WINDOWS\system32\wbem\WmiApSrv.exe [203264 2016-07-16] (Microsoft Corporation) S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1184256 2016-09-07] (Microsoft Corporation) S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1836032 2016-07-16] (Microsoft Corporation) S3 WPDBusEnum; C:\WINDOWS\system32\wpdbusenum.dll [88064 2016-07-16] (Microsoft Corporation) R2 WpnService; C:\WINDOWS\system32\WpnService.dll [234496 2016-07-16] (Microsoft Corporation) S3 WpnUserService; C:\WINDOWS\System32\WpnUserService.dll [74240 2016-07-16] (Microsoft Corporation) S3 WpnUserService_584bd; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation) S3 WpnUserService_584bd; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation) R2 wscsvc; C:\WINDOWS\System32\wscsvc.dll [184832 2016-11-11] (Microsoft Corporation) R2 WSearch; C:\WINDOWS\system32\SearchIndexer.exe [903680 2016-09-15] (Microsoft Corporation) R2 WSearch; C:\WINDOWS\SysWOW64\SearchIndexer.exe [773120 2016-09-15] (Microsoft Corporation) R3 wuauserv; C:\WINDOWS\system32\wuaueng.dll [2317312 2016-11-11] (Microsoft Corporation) R3 wudfsvc; C:\WINDOWS\System32\WUDFSvc.dll [99840 2016-07-16] (Microsoft Corporation) S3 WwanSvc; C:\WINDOWS\System32\wwansvc.dll [1282048 2016-11-02] (Microsoft Corporation) S3 XblAuthManager; C:\WINDOWS\System32\XblAuthManager.dll [1013248 2016-09-15] (Microsoft Corporation) S3 XblGameSave; C:\WINDOWS\System32\XblGameSave.dll [1159680 2016-07-16] (Microsoft Corporation) S3 XboxNetApiSvc; C:\WINDOWS\system32\XboxNetApiSvc.dll [1025536 2016-07-16] (Microsoft Corporation) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Treiber (Alle) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 1394ohci; C:\WINDOWS\System32\drivers\1394ohci.sys [235520 2016-07-16] (Microsoft Corporation) S0 3ware; C:\WINDOWS\System32\drivers\3ware.sys [107360 2016-07-16] (LSI) R0 ACPI; C:\WINDOWS\System32\drivers\ACPI.sys [705888 2016-07-16] (Microsoft Corporation) S3 AcpiDev; C:\WINDOWS\System32\drivers\AcpiDev.sys [18432 2016-07-16] (Microsoft Corporation) R0 acpiex; C:\WINDOWS\System32\Drivers\acpiex.sys [126816 2016-07-16] (Microsoft Corporation) S3 acpipagr; C:\WINDOWS\System32\drivers\acpipagr.sys [12288 2016-07-16] (Microsoft Corporation) S3 AcpiPmi; C:\WINDOWS\System32\drivers\acpipmi.sys [14336 2016-07-16] (Microsoft Corporation) S3 acpitime; C:\WINDOWS\System32\drivers\acpitime.sys [13312 2016-07-16] (Microsoft Corporation) S0 ADP80XX; C:\WINDOWS\System32\drivers\ADP80XX.SYS [1135456 2016-07-16] (PMC-Sierra) R1 AFD; C:\WINDOWS\system32\drivers\afd.sys [584032 2016-10-15] (Microsoft Corporation) R1 ahcache; C:\WINDOWS\System32\DRIVERS\ahcache.sys [227328 2016-10-15] (Microsoft Corporation) S3 AmdK8; C:\WINDOWS\System32\drivers\amdk8.sys [123392 2016-07-16] (Microsoft Corporation) R3 AmdPPM; C:\WINDOWS\System32\drivers\amdppm.sys [120832 2016-07-16] (Microsoft Corporation) S0 amdsata; C:\WINDOWS\System32\drivers\amdsata.sys [83296 2016-07-16] (Advanced Micro Devices) S0 amdsbs; C:\WINDOWS\System32\drivers\amdsbs.sys [259424 2016-07-16] (AMD Technologies Inc.) S0 amdxata; C:\WINDOWS\System32\drivers\amdxata.sys [26976 2016-07-16] (Advanced Micro Devices) S3 AppID; C:\WINDOWS\System32\drivers\appid.sys [172896 2016-07-16] (Microsoft Corporation) S3 applockerfltr; C:\WINDOWS\System32\drivers\applockerfltr.sys [15360 2016-07-16] (Microsoft Corporation) S0 arcsas; C:\WINDOWS\System32\drivers\arcsas.sys [131936 2016-07-16] (PMC-Sierra, Inc.) S3 AsyncMac; C:\WINDOWS\System32\drivers\asyncmac.sys [28160 2016-07-16] (Microsoft Corporation) S0 atapi; C:\WINDOWS\System32\drivers\atapi.sys [28512 2016-07-16] (Microsoft Corporation) S0 b06bdrv; C:\WINDOWS\System32\drivers\bxvbda.sys [533856 2016-07-16] (QLogic Corporation) R1 BasicDisplay; C:\WINDOWS\System32\drivers\BasicDisplay.sys [56320 2016-07-16] (Microsoft Corporation) R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [41472 2016-07-16] (Microsoft Corporation) U5 BattC; C:\Windows\System32\Drivers\BattC.sys [36192 2016-07-16] (Microsoft Corporation) S3 bcmfn; C:\WINDOWS\System32\drivers\bcmfn.sys [9728 2016-07-16] (Windows (R) Win 7 DDK provider) S3 bcmfn2; C:\WINDOWS\System32\drivers\bcmfn2.sys [9728 2016-07-16] (Windows (R) Win 7 DDK provider) R1 Beep; C:\Windows\System32\Drivers\Beep.sys [9728 2016-07-16] (Microsoft Corporation) R3 bowser; C:\WINDOWS\System32\DRIVERS\bowser.sys [101888 2016-11-02] (Microsoft Corporation) S3 BthAvrcpTg; C:\WINDOWS\System32\drivers\BthAvrcpTg.sys [43008 2016-07-16] (Microsoft Corporation) S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [65536 2016-07-16] (Microsoft Corporation) S3 bthhfhid; C:\WINDOWS\System32\drivers\BthHFHid.sys [31232 2016-07-16] (Microsoft Corporation) S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [66048 2016-07-16] (Microsoft Corporation) S3 buttonconverter; C:\WINDOWS\System32\drivers\buttonconverter.sys [38912 2016-07-16] (Microsoft Corporation) S3 CapImg; C:\WINDOWS\System32\drivers\capimg.sys [118272 2016-09-10] (Microsoft Corporation) S4 cdfs; C:\WINDOWS\System32\DRIVERS\cdfs.sys [92160 2016-07-16] (Microsoft Corporation) R1 cdrom; C:\WINDOWS\System32\drivers\cdrom.sys [173056 2016-07-16] (Microsoft Corporation) S3 cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [346976 2016-07-16] (Chelsio Communications) S3 cht4vbd; C:\WINDOWS\System32\drivers\cht4vx64.sys [2104160 2016-07-16] (Chelsio Communications) S3 circlass; C:\WINDOWS\System32\drivers\circlass.sys [48640 2016-07-16] (Microsoft Corporation) R0 CLFS; C:\WINDOWS\System32\drivers\CLFS.sys [376672 2016-11-02] (Microsoft Corporation) R2 clreg; C:\WINDOWS\System32\drivers\registry.sys [70144 2016-07-16] (Microsoft Corporation) S3 CmBatt; C:\WINDOWS\System32\drivers\CmBatt.sys [29696 2016-07-16] (Microsoft Corporation) R0 CNG; C:\WINDOWS\System32\Drivers\cng.sys [619368 2016-08-06] (Microsoft Corporation) S4 cnghwassist; C:\WINDOWS\System32\DRIVERS\cnghwassist.sys [38752 2016-07-16] (Microsoft Corporation) R3 CompositeBus; C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys [39936 2016-07-16] (Microsoft Corporation) R3 condrv; C:\WINDOWS\System32\drivers\condrv.sys [53088 2016-07-16] (Microsoft Corporation) S1 dam; C:\WINDOWS\System32\drivers\dam.sys [63328 2016-10-15] (Microsoft Corporation) R1 Dfsc; C:\WINDOWS\System32\Drivers\dfsc.sys [144896 2016-10-05] (Microsoft Corporation) R0 disk; C:\WINDOWS\System32\drivers\disk.sys [101720 2016-07-16] (Microsoft Corporation) S3 dmvsc; C:\WINDOWS\System32\drivers\dmvsc.sys [35840 2016-07-16] (Microsoft Corporation) S3 drmkaud; C:\WINDOWS\system32\DRIVERS\drmkaud.sys [16168 2016-07-16] (Microsoft Corporation) R3 DXGKrnl; C:\WINDOWS\System32\drivers\dxgkrnl.sys [2189152 2016-11-11] (Microsoft Corporation) S0 ebdrv; C:\WINDOWS\System32\drivers\evbda.sys [3418976 2016-07-16] (QLogic Corporation) R0 EhStorClass; C:\WINDOWS\System32\drivers\EhStorClass.sys [88416 2016-07-16] (Microsoft Corporation) S0 EhStorTcgDrv; C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys [118112 2016-09-07] (Microsoft Corporation) S3 ErrDev; C:\WINDOWS\System32\drivers\errdev.sys [13312 2016-07-16] (Microsoft Corporation) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77408 2016-11-29] () S3 exfat; C:\Windows\System32\Drivers\exfat.sys [334848 2016-07-16] (Microsoft Corporation) R3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [352096 2016-11-11] (Microsoft Corporation) S3 fdc; C:\WINDOWS\System32\drivers\fdc.sys [32256 2016-07-16] (Microsoft Corporation) R1 FileCrypt; C:\WINDOWS\System32\drivers\filecrypt.sys [88576 2016-07-16] (Microsoft Corporation) R0 FileInfo; C:\WINDOWS\System32\drivers\fileinfo.sys [85344 2016-07-16] (Microsoft Corporation) S3 Filetrace; C:\WINDOWS\System32\drivers\filetrace.sys [35840 2016-07-16] (Microsoft Corporation) S3 flpydisk; C:\WINDOWS\System32\drivers\flpydisk.sys [26112 2016-07-16] (Microsoft Corporation) R0 FltMgr; C:\WINDOWS\System32\drivers\fltmgr.sys [377696 2016-07-16] (Microsoft Corporation) S3 FsDepends; C:\WINDOWS\System32\drivers\FsDepends.sys [62816 2016-07-16] (Microsoft Corporation) U0 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [31584 2016-07-16] (Microsoft Corporation) R0 fvevol; C:\WINDOWS\System32\DRIVERS\fvevol.sys [649568 2016-09-15] (Microsoft Corporation) S3 gencounter; C:\WINDOWS\System32\drivers\vmgencounter.sys [13312 2016-07-16] (Microsoft Corporation) S3 genericusbfn; C:\WINDOWS\System32\drivers\genericusbfn.sys [20480 2016-07-16] (Microsoft Corporation) S3 GPIOClx0101; C:\WINDOWS\System32\Drivers\msgpioclx.sys [168800 2016-07-16] (Microsoft Corporation) R1 GpuEnergyDrv; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [8192 2016-07-16] (Microsoft Corporation) R3 HdAudAddService; C:\WINDOWS\system32\DRIVERS\HdAudio.sys [410624 2016-07-16] (Microsoft Corporation) R3 HDAudBus; C:\WINDOWS\System32\drivers\HDAudBus.sys [83456 2016-07-16] (Microsoft Corporation) S3 HidBatt; C:\WINDOWS\System32\drivers\HidBatt.sys [36704 2016-07-16] (Microsoft Corporation) S3 HidBth; C:\WINDOWS\System32\drivers\hidbth.sys [108032 2016-07-16] (Microsoft Corporation) S3 hidi2c; C:\WINDOWS\System32\drivers\hidi2c.sys [51200 2016-07-16] (Microsoft Corporation) S3 hidinterrupt; C:\WINDOWS\System32\drivers\hidinterrupt.sys [50016 2016-07-16] (Microsoft Corporation) S3 HidIr; C:\WINDOWS\System32\drivers\hidir.sys [46592 2016-07-16] (Microsoft Corporation) R3 HidUsb; C:\WINDOWS\System32\drivers\hidusb.sys [38400 2016-08-06] (Microsoft Corporation) S0 HpSAMD; C:\WINDOWS\System32\drivers\HpSAMD.sys [64352 2016-07-16] (Hewlett-Packard Company) R3 HTTP; C:\WINDOWS\System32\drivers\HTTP.sys [1100128 2016-10-15] (Microsoft Corporation) S3 hvservice; C:\WINDOWS\System32\drivers\hvservice.sys [73568 2016-08-06] (Microsoft Corporation) S0 hwpolicy; C:\WINDOWS\System32\drivers\hwpolicy.sys [29536 2016-07-16] (Microsoft Corporation) S3 hyperkbd; C:\WINDOWS\System32\drivers\hyperkbd.sys [16384 2016-07-16] (Microsoft Corporation) S3 i8042prt; C:\WINDOWS\System32\drivers\i8042prt.sys [114176 2016-07-16] (Microsoft Corporation) S3 iagpio; C:\WINDOWS\System32\drivers\iagpio.sys [33280 2016-07-16] (Intel(R) Corporation) S3 iai2c; C:\WINDOWS\System32\drivers\iai2c.sys [81408 2016-07-16] (Intel(R) Corporation) S3 iaLPSS2i_GPIO2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [64512 2016-07-16] (Intel Corporation) S3 iaLPSS2i_I2C; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [176384 2016-07-16] (Intel Corporation) S3 iaLPSSi_GPIO; C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128 2016-07-16] (Intel Corporation) S3 iaLPSSi_I2C; C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152 2016-07-16] (Intel Corporation) S0 iaStorAV; C:\WINDOWS\System32\drivers\iaStorAV.sys [673120 2016-07-16] (Intel Corporation) S0 iaStorV; C:\WINDOWS\System32\drivers\iaStorV.sys [412000 2016-07-16] (Intel Corporation) S3 ibbus; C:\WINDOWS\System32\drivers\ibbus.sys [526176 2016-07-16] (Mellanox) S3 IndirectKmd; C:\WINDOWS\System32\drivers\IndirectKmd.sys [35840 2016-07-16] (Microsoft Corporation) S0 intelide; C:\WINDOWS\System32\drivers\intelide.sys [19296 2016-07-16] (Microsoft Corporation) R0 intelpep; C:\WINDOWS\System32\drivers\intelpep.sys [48152 2016-07-16] (Microsoft Corporation) S3 intelppm; C:\WINDOWS\System32\drivers\intelppm.sys [134144 2016-07-16] (Microsoft Corporation) R0 iorate; C:\WINDOWS\System32\drivers\iorate.sys [48992 2016-11-02] (Microsoft Corporation) S3 IpFilterDriver; C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [85504 2016-07-16] (Microsoft Corporation) S3 IPMIDRV; C:\WINDOWS\System32\drivers\IPMIDrv.sys [89952 2016-07-16] (Microsoft Corporation) S3 IPNAT; C:\WINDOWS\System32\drivers\ipnat.sys [212480 2016-07-16] (Microsoft Corporation) S3 irda; C:\WINDOWS\system32\drivers\irda.sys [120320 2016-07-16] (Microsoft Corporation) S3 IRENUM; C:\WINDOWS\System32\drivers\irenum.sys [19456 2016-07-16] (Microsoft Corporation) S0 isapnp; C:\WINDOWS\System32\drivers\isapnp.sys [22880 2016-07-16] (Microsoft Corporation) S3 iScsiPrt; C:\WINDOWS\System32\drivers\msiscsi.sys [277344 2016-07-16] (Microsoft Corporation) R3 kbdclass; C:\WINDOWS\System32\drivers\kbdclass.sys [62304 2016-07-16] (Microsoft Corporation) R3 kbdhid; C:\WINDOWS\System32\drivers\kbdhid.sys [39424 2016-09-15] (Microsoft Corporation) R3 kdnic; C:\WINDOWS\System32\drivers\kdnic.sys [25088 2016-07-16] (Microsoft Corporation) R3 Ke2200; C:\WINDOWS\System32\drivers\e22w7x64.sys [129200 2014-03-27] (Qualcomm Atheros, Inc.) R0 KSecDD; C:\WINDOWS\System32\Drivers\ksecdd.sys [133472 2016-09-07] (Microsoft Corporation) R0 KSecPkg; C:\WINDOWS\System32\Drivers\ksecpkg.sys [168800 2016-08-06] (Microsoft Corporation) R3 ksthunk; C:\WINDOWS\system32\drivers\ksthunk.sys [26112 2016-07-16] (Microsoft Corporation) S3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [45208 2016-08-30] (Logitech Inc.) R3 LGBusEnum; C:\WINDOWS\system32\drivers\LGBusEnum.sys [36496 2016-08-30] (Logitech Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) S3 LGJoyHidFilter; C:\WINDOWS\system32\drivers\LGJoyHidFilter.sys [58144 2015-06-11] (Logitech Inc.) S3 LGJoyHidLo; C:\WINDOWS\system32\drivers\LGJoyHidLo.sys [47656 2015-06-11] (Logitech Inc.) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-08-30] (Logitech Inc.) S3 LGSHidFilt; C:\WINDOWS\System32\drivers\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 LGVirHid; C:\WINDOWS\system32\drivers\LGVirHid.sys [26008 2016-08-30] (Logitech Inc.) R2 lltdio; C:\WINDOWS\System32\drivers\lltdio.sys [66048 2016-07-16] (Microsoft Corporation) S0 LSI_SAS; C:\WINDOWS\System32\drivers\lsi_sas.sys [108896 2016-07-16] (LSI Corporation) S0 LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [105824 2016-07-16] (LSI Corporation) S0 LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [101216 2016-07-16] (Avago Technologies) S0 LSI_SSS; C:\WINDOWS\System32\drivers\lsi_sss.sys [82776 2016-07-16] (LSI Corporation) R2 luafv; C:\WINDOWS\system32\drivers\luafv.sys [125952 2016-07-16] (Microsoft Corporation) R3 LVRS64; C:\WINDOWS\system32\DRIVERS\lvrs64.sys [351520 2012-10-26] (Logitech Inc.) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176064 2016-12-11] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [102856 2016-12-11] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2016-12-11] (Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [250816 2016-12-11] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [91584 2016-12-11] (Malwarebytes) S0 megasas; C:\WINDOWS\System32\drivers\megasas.sys [59744 2016-07-16] (Avago Technologies) S0 megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [64352 2016-10-05] (Avago Technologies) S0 megasr; C:\WINDOWS\System32\drivers\megasr.sys [575840 2016-07-16] (LSI Corporation, Inc.) S3 mlx4_bus; C:\WINDOWS\System32\drivers\mlx4_bus.sys [842584 2016-07-16] (Mellanox) R2 MMCSS; C:\WINDOWS\system32\drivers\mmcss.sys [48128 2016-07-16] (Microsoft Corporation) S3 Modem; C:\WINDOWS\System32\drivers\modem.sys [42496 2016-11-11] (Microsoft Corporation) R3 monitor; C:\WINDOWS\System32\drivers\monitor.sys [38400 2016-07-16] (Microsoft Corporation) R3 mouclass; C:\WINDOWS\System32\drivers\mouclass.sys [59232 2016-07-16] (Microsoft Corporation) R3 mouhid; C:\WINDOWS\System32\drivers\mouhid.sys [32256 2016-07-16] (Microsoft Corporation) R0 mountmgr; C:\WINDOWS\System32\drivers\mountmgr.sys [104800 2016-07-16] (Microsoft Corporation) R3 mpsdrv; C:\WINDOWS\System32\drivers\mpsdrv.sys [75776 2016-07-16] (Microsoft Corporation) S3 MRxDAV; C:\WINDOWS\system32\drivers\mrxdav.sys [143872 2016-10-05] (Microsoft Corporation) R3 mrxsmb; C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [450392 2016-09-07] (Microsoft Corporation) R2 mrxsmb10; C:\WINDOWS\System32\DRIVERS\mrxsmb10.sys [282624 2016-11-11] (Microsoft Corporation) R3 mrxsmb20; C:\WINDOWS\System32\DRIVERS\mrxsmb20.sys [223584 2016-11-11] (Microsoft Corporation) S3 MsBridge; C:\WINDOWS\System32\drivers\bridge.sys [114688 2016-07-16] (Microsoft Corporation) R1 Msfs; C:\Windows\System32\Drivers\Msfs.sys [31232 2016-07-16] (Microsoft Corporation) S3 msgpiowin32; C:\WINDOWS\System32\drivers\msgpiowin32.sys [50528 2016-07-16] (Microsoft Corporation) S3 mshidkmdf; C:\WINDOWS\System32\drivers\mshidkmdf.sys [8704 2016-07-16] (Microsoft Corporation) S3 mshidumdf; C:\WINDOWS\System32\drivers\mshidumdf.sys [11776 2016-07-16] (Microsoft Corporation) R0 msisadrv; C:\WINDOWS\System32\drivers\msisadrv.sys [18784 2016-07-16] (Microsoft Corporation) S3 MSKSSRV; C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys [27136 2016-07-16] (Microsoft Corporation) R2 MsLldp; C:\WINDOWS\System32\drivers\mslldp.sys [78336 2016-07-16] (Microsoft Corporation) S3 MSPCLOCK; C:\WINDOWS\system32\DRIVERS\MSPCLOCK.sys [10752 2016-07-16] (Microsoft Corporation) S3 MSPQM; C:\WINDOWS\system32\DRIVERS\MSPQM.sys [10752 2016-07-16] (Microsoft Corporation) S3 MsRPC; C:\Windows\System32\Drivers\MsRPC.sys [361312 2016-07-16] (Microsoft Corporation) R1 mssmbios; C:\WINDOWS\System32\drivers\mssmbios.sys [43360 2016-07-16] (Microsoft Corporation) S3 MSTEE; C:\WINDOWS\system32\DRIVERS\MSTEE.sys [12800 2016-07-16] (Microsoft Corporation) S3 MTConfig; C:\WINDOWS\System32\drivers\MTConfig.sys [15872 2016-07-16] (Microsoft Corporation) R0 Mup; C:\WINDOWS\System32\Drivers\mup.sys [126304 2016-07-16] (Microsoft Corporation) S0 mvumis; C:\WINDOWS\System32\drivers\mvumis.sys [63840 2016-07-16] (Marvell Semiconductor, Inc.) R3 NativeWifiP; C:\WINDOWS\System32\DRIVERS\nwifi.sys [533504 2016-07-16] (Microsoft Corporation) S3 ndfltr; C:\WINDOWS\System32\drivers\ndfltr.sys [108896 2016-07-16] (Mellanox) R0 NDIS; C:\WINDOWS\System32\drivers\ndis.sys [1181536 2016-10-05] (Microsoft Corporation) S3 NdisCap; C:\WINDOWS\System32\drivers\ndiscap.sys [50176 2016-07-16] (Microsoft Corporation) S3 NdisImPlatform; C:\WINDOWS\System32\drivers\NdisImPlatform.sys [126464 2016-07-16] (Microsoft Corporation) S3 NdisTapi; C:\WINDOWS\System32\DRIVERS\ndistapi.sys [26112 2016-07-16] (Microsoft Corporation) R3 Ndisuio; C:\WINDOWS\System32\drivers\ndisuio.sys [63488 2016-07-16] (Microsoft Corporation) R3 NdisVirtualBus; C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [20480 2016-07-16] (Microsoft Corporation) S3 NdisWan; C:\WINDOWS\System32\drivers\ndiswan.sys [189440 2016-07-16] (Microsoft Corporation) S3 ndiswanlegacy; C:\WINDOWS\System32\DRIVERS\ndiswan.sys [189440 2016-07-16] (Microsoft Corporation) S3 ndproxy; C:\WINDOWS\System32\DRIVERS\NDProxy.sys [60928 2016-07-16] (Microsoft Corporation) R2 Ndu; C:\WINDOWS\System32\drivers\Ndu.sys [125440 2016-07-16] (Microsoft Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R1 NetBIOS; C:\WINDOWS\System32\drivers\netbios.sys [57184 2016-07-16] (Microsoft Corporation) R1 NetBT; C:\WINDOWS\System32\DRIVERS\netbt.sys [279040 2016-07-16] (Microsoft Corporation) R1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [68608 2016-07-16] (Microsoft Corporation) R1 npsvctrig; C:\WINDOWS\System32\drivers\npsvctrig.sys [26624 2016-07-16] (Microsoft Corporation) R1 nsiproxy; C:\WINDOWS\System32\drivers\nsiproxy.sys [41984 2016-07-16] (Microsoft Corporation) R3 NTFS; C:\Windows\System32\Drivers\NTFS.sys [2255712 2016-11-02] (Microsoft Corporation) R1 Null; C:\Windows\System32\Drivers\Null.sys [7168 2016-07-16] (Microsoft Corporation) R3 NVHDA; C:\WINDOWS\system32\drivers\nvhda64v.sys [205456 2016-02-11] (NVIDIA Corporation) |
11.12.2016, 16:44 | #11 |
| Und das ist die 2. Hälfte R3 nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [12478528 2016-02-10] (NVIDIA Corporation) S0 nvraid; C:\WINDOWS\System32\drivers\nvraid.sys [150368 2016-07-16] (NVIDIA Corporation) S0 nvstor; C:\WINDOWS\System32\drivers\nvstor.sys [166240 2016-07-16] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation) S3 NvStUSB; C:\WINDOWS\System32\drivers\nvstusb.sys [460960 2015-08-29] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation) S3 Parport; C:\WINDOWS\System32\drivers\parport.sys [96768 2016-07-16] (Microsoft Corporation) R0 partmgr; C:\WINDOWS\System32\drivers\partmgr.sys [128352 2016-11-11] (Microsoft Corporation) R0 pci; C:\WINDOWS\System32\drivers\pci.sys [335712 2016-11-11] (Microsoft Corporation) S0 pciide; C:\WINDOWS\System32\drivers\pciide.sys [16224 2016-07-16] (Microsoft Corporation) S0 pcmcia; C:\WINDOWS\System32\drivers\pcmcia.sys [118112 2016-07-16] (Microsoft Corporation) R0 pcw; C:\WINDOWS\System32\drivers\pcw.sys [51552 2016-07-16] (Microsoft Corporation) R0 pdc; C:\WINDOWS\System32\drivers\pdc.sys [108384 2016-08-20] (Microsoft Corporation) R2 PEAUTH; C:\WINDOWS\System32\drivers\peauth.sys [723968 2016-07-16] (Microsoft Corporation) S0 percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [58720 2016-07-16] (Avago Technologies) S0 percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [61792 2016-07-16] (Avago Technologies) S3 PptpMiniport; C:\WINDOWS\System32\drivers\raspptp.sys [96256 2016-07-16] (Microsoft Corporation) S3 Processor; C:\WINDOWS\System32\drivers\processr.sys [119808 2016-07-16] (Microsoft Corporation) R1 Psched; C:\WINDOWS\System32\drivers\pacer.sys [160608 2016-07-16] (Microsoft Corporation) S3 QWAVEdrv; C:\WINDOWS\system32\drivers\qwavedrv.sys [48640 2016-07-16] (Microsoft Corporation) S3 RasAcd; C:\WINDOWS\System32\DRIVERS\rasacd.sys [17408 2016-07-16] (Microsoft Corporation) S3 RasAgileVpn; C:\WINDOWS\System32\drivers\AgileVpn.sys [107520 2016-07-16] (Microsoft Corporation) S3 Rasl2tp; C:\WINDOWS\System32\drivers\rasl2tp.sys [104960 2016-07-16] (Microsoft Corporation) S3 RasPppoe; C:\WINDOWS\System32\DRIVERS\raspppoe.sys [81408 2016-07-16] (Microsoft Corporation) S3 RasSstp; C:\WINDOWS\System32\drivers\rassstp.sys [77824 2016-07-16] (Microsoft Corporation) R1 rdbss; C:\WINDOWS\System32\DRIVERS\rdbss.sys [433504 2016-11-11] (Microsoft Corporation) R3 rdpbus; C:\WINDOWS\System32\drivers\rdpbus.sys [26112 2016-07-16] (Microsoft Corporation) S3 RDPDR; C:\WINDOWS\System32\drivers\rdpdr.sys [177152 2016-07-16] (Microsoft Corporation) S3 RdpVideoMiniport; C:\WINDOWS\System32\drivers\rdpvideominiport.sys [29536 2016-07-16] (Microsoft Corporation) R0 rdyboost; C:\WINDOWS\System32\drivers\rdyboost.sys [267104 2016-07-16] (Microsoft Corporation) S3 ReFSv1; C:\Windows\System32\Drivers\ReFSv1.sys [928608 2016-07-16] (Microsoft Corporation) R2 rspndr; C:\WINDOWS\System32\drivers\rspndr.sys [81408 2016-07-16] (Microsoft Corporation) R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5195776 2016-07-16] (Realtek Semiconductor Corporation ) S3 s3cap; C:\WINDOWS\System32\drivers\vms3cap.sys [9216 2016-07-16] (Microsoft Corporation) S0 sbp2port; C:\WINDOWS\System32\drivers\sbp2port.sys [110432 2016-07-16] (Microsoft Corporation) S3 scfilter; C:\WINDOWS\System32\DRIVERS\scfilter.sys [43008 2016-07-16] (Microsoft Corporation) S0 scmbus; C:\WINDOWS\System32\drivers\scmbus.sys [88416 2016-07-16] (Microsoft Corporation) S3 scmdisk0101; C:\WINDOWS\System32\drivers\scmdisk0101.sys [123904 2016-07-16] (Microsoft Corporation) S3 sdbus; C:\WINDOWS\System32\drivers\sdbus.sys [279904 2016-10-05] (Microsoft Corporation) S3 sdstor; C:\WINDOWS\System32\drivers\sdstor.sys [95072 2016-07-16] (Microsoft Corporation) S3 SerCx; C:\WINDOWS\System32\drivers\SerCx.sys [74592 2016-07-16] (Microsoft Corporation) S3 SerCx2; C:\WINDOWS\System32\drivers\SerCx2.sys [151904 2016-07-16] (Microsoft Corporation) R3 Serenum; C:\WINDOWS\System32\drivers\serenum.sys [25088 2016-07-16] (Microsoft Corporation) R3 Serial; C:\WINDOWS\System32\drivers\serial.sys [83968 2016-07-16] (Microsoft Corporation) S3 sermouse; C:\WINDOWS\System32\drivers\sermouse.sys [27648 2016-07-16] (Microsoft Corporation) S3 sfloppy; C:\WINDOWS\System32\drivers\sfloppy.sys [18432 2016-07-16] (Microsoft Corporation) S0 SiSRaid2; C:\WINDOWS\System32\drivers\SiSRaid2.sys [44896 2016-07-16] (Silicon Integrated Systems Corp.) S0 SiSRaid4; C:\WINDOWS\System32\drivers\sisraid4.sys [81760 2016-07-16] (Silicon Integrated Systems) R0 spaceport; C:\WINDOWS\System32\drivers\spaceport.sys [557408 2016-10-15] (Microsoft Corporation) S3 SpbCx; C:\WINDOWS\System32\drivers\SpbCx.sys [79200 2016-07-16] (Microsoft Corporation) R2 srv; C:\WINDOWS\System32\DRIVERS\srv.sys [409088 2016-09-07] (Microsoft Corporation) R3 srv2; C:\WINDOWS\System32\DRIVERS\srv2.sys [713216 2016-11-11] (Microsoft Corporation) R3 srvnet; C:\WINDOWS\System32\DRIVERS\srvnet.sys [248320 2016-09-07] (Microsoft Corporation) S0 stexstor; C:\WINDOWS\System32\drivers\stexstor.sys [31072 2016-07-16] (Promise Technology, Inc.) R0 storahci; C:\WINDOWS\System32\drivers\storahci.sys [130912 2016-09-15] (Microsoft Corporation) S0 storflt; C:\WINDOWS\System32\drivers\vmstorfl.sys [46944 2016-07-16] (Microsoft Corporation) S0 stornvme; C:\WINDOWS\System32\drivers\stornvme.sys [81760 2016-09-15] (Microsoft Corporation) R2 storqosflt; C:\WINDOWS\System32\drivers\storqosflt.sys [78336 2016-07-16] (Microsoft Corporation) S0 storufs; C:\WINDOWS\System32\drivers\storufs.sys [32096 2016-07-16] (Microsoft Corporation) S0 storvsc; C:\WINDOWS\System32\drivers\storvsc.sys [36192 2016-07-16] (Microsoft Corporation) R3 swenum; C:\WINDOWS\System32\drivers\swenum.sys [17760 2016-07-16] (Microsoft Corporation) S3 Synth3dVsc; C:\WINDOWS\System32\drivers\Synth3dVsc.sys [64000 2016-07-16] (Microsoft Corporation) R0 Tcpip; C:\WINDOWS\System32\drivers\tcpip.sys [2537824 2016-10-15] (Microsoft Corporation) S3 Tcpip6; C:\WINDOWS\System32\drivers\tcpip.sys [2537824 2016-10-15] (Microsoft Corporation) R2 tcpipreg; C:\WINDOWS\System32\drivers\tcpipreg.sys [52224 2016-07-16] (Microsoft Corporation) R1 tdx; C:\WINDOWS\system32\DRIVERS\tdx.sys [118112 2016-07-16] (Microsoft Corporation) S3 terminpt; C:\WINDOWS\System32\drivers\terminpt.sys [38752 2016-07-16] (Microsoft Corporation) S3 TPM; C:\WINDOWS\System32\drivers\tpm.sys [219488 2016-11-11] (Microsoft Corporation) S3 tsusbflt; C:\WINDOWS\System32\drivers\TsUsbFlt.sys [61440 2016-07-16] (Microsoft Corporation) S3 TsUsbGD; C:\WINDOWS\System32\drivers\TsUsbGD.sys [34304 2016-07-16] (Microsoft Corporation) R3 tunnel; C:\WINDOWS\System32\drivers\tunnel.sys [158208 2016-07-16] (Microsoft Corporation) S3 UASPStor; C:\WINDOWS\System32\drivers\uaspstor.sys [77152 2016-07-16] (Microsoft Corporation) S3 UcmCx0101; C:\WINDOWS\System32\Drivers\UcmCx.sys [95744 2016-07-16] (Microsoft Corporation) S3 UcmTcpciCx0101; C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [108544 2016-07-16] (Microsoft Corporation) S3 UcmUcsi; C:\WINDOWS\System32\drivers\UcmUcsi.sys [50688 2016-07-16] (Microsoft Corporation) R3 Ucx01000; C:\WINDOWS\System32\drivers\ucx01000.sys [210272 2016-07-16] (Microsoft Corporation) S3 UdeCx; C:\WINDOWS\System32\drivers\udecx.sys [45568 2016-07-16] (Microsoft Corporation) S4 udfs; C:\WINDOWS\System32\DRIVERS\udfs.sys [320000 2016-07-16] (Microsoft Corporation) R3 UEFI; C:\WINDOWS\System32\drivers\UEFI.sys [28512 2016-07-16] (Microsoft Corporation) S3 Ufx01000; C:\WINDOWS\System32\drivers\ufx01000.sys [263008 2016-07-16] (Microsoft Corporation) S3 UfxChipidea; C:\WINDOWS\System32\drivers\UfxChipidea.sys [96608 2016-07-16] (Microsoft Corporation) S3 ufxsynopsys; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [137056 2016-07-16] (Microsoft Corporation) R3 umbus; C:\WINDOWS\System32\drivers\umbus.sys [56832 2016-07-16] (Microsoft Corporation) S3 UmPass; C:\WINDOWS\System32\drivers\umpass.sys [13824 2016-07-16] (Microsoft Corporation) S3 UrsChipidea; C:\WINDOWS\System32\drivers\urschipidea.sys [28512 2016-07-16] (Microsoft Corporation) S3 UrsCx01000; C:\WINDOWS\System32\drivers\urscx01000.sys [57696 2016-07-16] (Microsoft Corporation) S3 UrsSynopsys; C:\WINDOWS\System32\drivers\urssynopsys.sys [27488 2016-07-16] (Microsoft Corporation) R3 usbaudio; C:\WINDOWS\system32\drivers\usbaudio.sys [132096 2016-07-16] (Microsoft Corporation) R3 usbccgp; C:\WINDOWS\System32\drivers\usbccgp.sys [169312 2016-07-16] (Microsoft Corporation) S3 usbcir; C:\WINDOWS\System32\drivers\usbcir.sys [102400 2016-07-16] (Microsoft Corporation) R3 usbehci; C:\WINDOWS\System32\drivers\usbehci.sys [96096 2016-07-16] (Microsoft Corporation) R3 usbhub; C:\WINDOWS\System32\drivers\usbhub.sys [501088 2016-07-16] (Microsoft Corporation) R3 USBHUB3; C:\WINDOWS\System32\drivers\UsbHub3.sys [535904 2016-07-16] (Microsoft Corporation) R3 usbohci; C:\WINDOWS\System32\drivers\usbohci.sys [30208 2016-07-16] (Microsoft Corporation) S3 usbprint; C:\WINDOWS\System32\drivers\usbprint.sys [27648 2016-07-16] (Microsoft Corporation) S3 usbser; C:\WINDOWS\System32\drivers\usbser.sys [69120 2016-07-16] (Microsoft Corporation) S3 USBSTOR; C:\WINDOWS\System32\drivers\USBSTOR.SYS [129888 2016-07-16] (Microsoft Corporation) S3 usbuhci; C:\WINDOWS\System32\drivers\usbuhci.sys [35328 2016-07-16] (Microsoft Corporation) R3 usbvideo; C:\WINDOWS\System32\Drivers\usbvideo.sys [226816 2016-08-06] (Microsoft Corporation) R3 USBXHCI; C:\WINDOWS\System32\drivers\USBXHCI.SYS [381792 2016-07-16] (Microsoft Corporation) R0 vdrvroot; C:\WINDOWS\System32\drivers\vdrvroot.sys [53088 2016-07-16] (Microsoft Corporation) S3 VerifierExt; C:\WINDOWS\System32\drivers\VerifierExt.sys [201056 2016-07-16] (Microsoft Corporation) S3 vhdmp; C:\WINDOWS\System32\drivers\vhdmp.sys [714592 2016-11-02] (Microsoft Corporation) S3 vhf; C:\WINDOWS\System32\drivers\vhf.sys [32256 2016-07-16] (Microsoft Corporation) S0 vmbus; C:\WINDOWS\System32\drivers\vmbus.sys [104288 2016-07-16] (Microsoft Corporation) S3 VMBusHID; C:\WINDOWS\System32\drivers\VMBusHID.sys [25088 2016-07-16] (Microsoft Corporation) S3 vmgid; C:\WINDOWS\System32\drivers\vmgid.sys [10240 2016-07-16] (Microsoft Corporation) R0 volmgr; C:\WINDOWS\System32\drivers\volmgr.sys [80224 2016-07-16] (Microsoft Corporation) R0 volmgrx; C:\WINDOWS\System32\drivers\volmgrx.sys [367456 2016-07-16] (Microsoft Corporation) R0 volsnap; C:\WINDOWS\System32\drivers\volsnap.sys [391520 2016-07-16] (Microsoft Corporation) R0 volume; C:\WINDOWS\System32\drivers\volume.sys [16224 2016-07-16] (Microsoft Corporation) S3 vpci; C:\WINDOWS\System32\drivers\vpci.sys [74080 2016-09-15] (Microsoft Corporation) S0 vsmraid; C:\WINDOWS\System32\drivers\vsmraid.sys [166752 2016-07-16] (VIA Technologies Inc.,Ltd) S0 VSTXRAID; C:\WINDOWS\System32\drivers\vstxraid.sys [305504 2016-07-16] (VIA Corporation) S3 VUSB3HUB; C:\WINDOWS\System32\drivers\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.) S3 VUSBSTOR; C:\WINDOWS\System32\Drivers\vusbstor.sys [86064 2013-01-18] (VIA Technologies, Inc.) R3 vwifibus; C:\WINDOWS\System32\drivers\vwifibus.sys [26624 2016-07-16] (Microsoft Corporation) R1 vwififlt; C:\WINDOWS\System32\drivers\vwififlt.sys [73216 2016-07-16] (Microsoft Corporation) R3 vwifimp; C:\WINDOWS\System32\drivers\vwifimp.sys [39936 2016-07-16] (Microsoft Corporation) S3 WacomPen; C:\WINDOWS\System32\drivers\wacompen.sys [30208 2016-07-16] (Microsoft Corporation) R2 wanarp; C:\WINDOWS\System32\DRIVERS\wanarp.sys [79872 2016-07-16] (Microsoft Corporation) S3 wanarpv6; C:\WINDOWS\System32\DRIVERS\wanarp.sys [79872 2016-07-16] (Microsoft Corporation) R2 wcifs; C:\WINDOWS\system32\drivers\wcifs.sys [119648 2016-09-15] (Microsoft Corporation) R2 wcnfs; C:\WINDOWS\system32\drivers\wcnfs.sys [66560 2016-07-16] (Microsoft Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 Wdf01000; C:\WINDOWS\System32\drivers\Wdf01000.sys [861296 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 wdiwifi; C:\WINDOWS\System32\DRIVERS\wdiwifi.sys [719360 2016-09-15] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R0 WFPLWFS; C:\WINDOWS\System32\drivers\wfplwfs.sys [156000 2016-07-16] (Microsoft Corporation) S3 WIMMount; C:\WINDOWS\System32\drivers\wimmount.sys [35680 2016-07-16] (Microsoft Corporation) R0 WindowsTrustedRT; C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [107032 2016-07-16] (Microsoft Corporation) R0 WindowsTrustedRTProxy; C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [17944 2016-07-16] (Microsoft Corporation) S3 WinMad; C:\WINDOWS\System32\drivers\winmad.sys [32096 2016-07-16] (Mellanox) S3 WINUSB; C:\WINDOWS\System32\drivers\WinUSB.SYS [89088 2016-07-16] (Microsoft Corporation) S3 WinVerbs; C:\WINDOWS\System32\drivers\winverbs.sys [64864 2016-07-16] (Mellanox) R3 WmiAcpi; C:\WINDOWS\System32\drivers\wmiacpi.sys [18432 2016-07-16] (Microsoft Corporation) R0 Wof; C:\Windows\System32\Drivers\Wof.sys [199008 2016-08-06] (Microsoft Corporation) S3 WpdUpFltr; C:\WINDOWS\System32\drivers\WpdUpFltr.sys [30560 2016-07-16] (Microsoft Corporation) S4 ws2ifsl; C:\WINDOWS\system32\drivers\ws2ifsl.sys [22528 2016-07-16] (Microsoft Corporation) R3 WSDPrintDevice; C:\WINDOWS\System32\drivers\WSDPrint.sys [22528 2016-07-16] (Microsoft Corporation) R3 WSDScan; C:\WINDOWS\system32\DRIVERS\WSDScan.sys [24576 2016-07-16] (Microsoft Corporation) R3 WudfPf; C:\WINDOWS\System32\drivers\WudfPf.sys [99328 2016-07-16] (Microsoft Corporation) R3 WUDFRd; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation) R3 WUDFWpdFs; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation) S3 xboxgip; C:\WINDOWS\System32\drivers\xboxgip.sys [258560 2016-11-11] (Microsoft Corporation) S3 xhcdrv; C:\WINDOWS\System32\drivers\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.) S3 xinputhid; C:\WINDOWS\System32\drivers\xinputhid.sys [43520 2016-08-20] (Microsoft Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 12:06 - 2016-12-11 12:06 - 00001904 _____ C:\Users\Moritz\Desktop\mbam textdatei.txt 2016-12-11 11:58 - 2016-12-11 11:58 - 00000000 ___HD C:\OneDriveTemp 2016-12-11 11:47 - 2016-12-11 11:57 - 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-12-11 11:47 - 2016-12-11 11:57 - 00102856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2016-12-11 11:47 - 2016-12-11 11:57 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2016-12-11 11:47 - 2016-12-11 11:57 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-12-11 11:47 - 2016-12-11 11:47 - 00176064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2016-12-11 11:47 - 2016-12-11 11:47 - 00001872 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2016-12-11 11:47 - 2016-12-11 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2016-12-11 11:47 - 2016-11-29 06:27 - 00077408 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2016-12-11 11:46 - 2016-12-11 11:46 - 51969976 _____ (Malwarebytes ) C:\Users\Moritz\Downloads\mb3-setup-consumer-3.0.4.1269.exe 2016-12-11 11:46 - 2016-12-11 11:46 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-12-11 11:46 - 2016-12-11 11:46 - 00000000 ____D C:\Program Files\Malwarebytes 2016-12-11 11:32 - 2016-12-11 11:33 - 03968464 _____ C:\Users\Moritz\Downloads\AdwCleaner_6.040 (1).exe 2016-12-11 11:05 - 2016-12-11 11:04 - 09296344 _____ C:\Users\Moritz\Desktop\RevoUninstaller_Portable201.zip 2016-12-11 11:04 - 2016-12-11 11:31 - 09503576 _____ C:\Users\Moritz\Downloads\RevoUninstaller_Portable201.zip 2016-12-11 01:51 - 2016-12-11 01:52 - 00055077 _____ C:\Users\Moritz\Downloads\Addition.txt 2016-12-11 01:49 - 2016-12-11 12:10 - 00087540 _____ C:\Users\Moritz\Downloads\FRST.txt 2016-12-11 01:47 - 2016-12-11 12:09 - 00000000 ____D C:\FRST 2016-12-11 01:46 - 2016-12-11 01:46 - 02420224 _____ (Farbar) C:\Users\Moritz\Downloads\FRST64.exe 2016-12-11 01:45 - 2016-12-11 01:47 - 01761792 _____ (Farbar) C:\Users\Moritz\Downloads\FRST.exe 2016-12-10 15:01 - 2016-12-11 11:36 - 00000000 ____D C:\AdwCleaner 2016-12-10 15:01 - 2016-12-10 15:01 - 03968464 _____ C:\Users\Moritz\Downloads\adwcleaner_6.040.exe 2016-12-09 17:05 - 2016-11-11 11:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-12-09 17:05 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2016-12-09 17:05 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-12-09 17:05 - 2016-11-11 10:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2016-12-09 17:05 - 2016-11-11 10:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-12-09 17:05 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-12-09 17:05 - 2016-11-11 10:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-12-09 17:05 - 2016-11-11 10:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-12-09 17:05 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2016-12-09 17:05 - 2016-11-11 10:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-12-09 17:05 - 2016-11-11 10:17 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-12-09 17:05 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2016-12-09 17:05 - 2016-11-11 10:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-12-09 17:05 - 2016-11-11 10:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-12-09 17:05 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-12-09 17:05 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2016-12-09 17:05 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-12-09 17:05 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-12-09 17:05 - 2016-11-11 10:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-12-09 17:05 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-12-09 17:05 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-12-09 17:04 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2016-12-09 17:04 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2016-12-09 17:04 - 2016-11-11 11:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2016-12-09 17:04 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2016-12-09 17:04 - 2016-11-11 11:13 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-12-09 17:04 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-12-09 17:04 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2016-12-09 17:04 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-12-09 17:04 - 2016-11-11 11:09 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-12-09 17:04 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-12-09 17:04 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-12-09 17:04 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-12-09 17:04 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-12-09 17:04 - 2016-11-11 11:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-12-09 17:04 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2016-12-09 17:04 - 2016-11-11 10:59 - 02913136 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-12-09 17:04 - 2016-11-11 10:59 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 08170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-12-09 17:04 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-12-09 17:04 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2016-12-09 17:04 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-12-09 17:04 - 2016-11-11 10:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-12-09 17:04 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2016-12-09 17:04 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-12-09 17:04 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2016-12-09 17:04 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll 2016-12-09 17:04 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys 2016-12-09 17:04 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2016-12-09 17:04 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll 2016-12-09 17:04 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2016-12-09 17:04 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-12-09 17:04 - 2016-11-11 10:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-12-09 17:04 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2016-12-09 17:04 - 2016-11-11 10:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2016-12-09 17:04 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-12-09 17:04 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-12-09 17:04 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll 2016-12-09 17:04 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll 2016-12-09 17:04 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-12-09 17:04 - 2016-11-11 10:10 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-12-09 17:04 - 2016-11-11 10:09 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2016-12-09 17:04 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-12-09 17:04 - 2016-11-11 10:08 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-12-09 17:04 - 2016-11-11 10:06 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-12-09 17:04 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2016-12-09 17:04 - 2016-11-11 10:04 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-12-09 17:04 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-12-09 17:04 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-12-09 17:04 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-12-09 17:04 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-12-09 17:04 - 2016-11-11 10:01 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-12-09 17:04 - 2016-11-11 09:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-12-09 17:04 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-12-09 17:04 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-12-09 17:04 - 2016-11-11 08:56 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-12-09 17:04 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-12-09 17:04 - 2016-11-11 08:45 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-12-09 17:04 - 2016-11-11 08:45 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 06668032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll 2016-12-09 17:04 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-12-09 17:04 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe 2016-12-09 17:04 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-12-09 17:04 - 2016-11-11 08:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-12-09 17:04 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-12-09 17:04 - 2016-11-11 08:26 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-12-09 17:04 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-12-09 17:04 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-12-09 17:04 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-12-09 17:04 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-12-09 17:04 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-12-09 17:04 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2016-12-09 17:04 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-12-09 17:04 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-12-09 17:04 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2016-12-09 17:04 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2016-12-09 17:04 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2016-12-09 17:04 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2016-12-09 17:04 - 2016-11-11 08:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-12-09 17:04 - 2016-11-11 08:13 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-12-09 17:04 - 2016-11-11 08:11 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll 2016-12-09 17:04 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-12-09 17:04 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-12-09 17:04 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-12-09 17:04 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll 2016-12-09 17:04 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-12-09 17:04 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2016-12-09 17:04 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-12-09 17:04 - 2016-11-11 08:01 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-12-09 17:04 - 2016-11-11 07:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-12-09 17:03 - 2016-11-11 11:01 - 02189152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-12-09 17:03 - 2016-11-11 11:01 - 01738048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-12-09 17:03 - 2016-11-11 11:01 - 00658264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-12-09 17:03 - 2016-11-11 11:01 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-12-09 17:03 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-12-09 17:03 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-12-09 17:03 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-12-09 17:03 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe 2016-12-09 17:03 - 2016-11-11 10:51 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2016-12-09 17:03 - 2016-11-11 10:31 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-12-09 17:03 - 2016-11-11 10:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-12-09 17:03 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll 2016-12-09 17:03 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-12-09 17:03 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe 2016-12-09 17:03 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-12-09 17:03 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-12-09 17:03 - 2016-11-11 10:24 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-12-09 17:03 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-12-09 17:03 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-12-09 17:03 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2016-12-09 17:03 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-12-09 17:03 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2016-12-09 17:03 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2016-12-09 17:03 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2016-12-09 17:03 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-12-09 17:03 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2016-12-09 17:03 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-12-09 17:03 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll 2016-12-09 17:03 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-12-09 17:03 - 2016-11-11 10:11 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-12-09 17:03 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll 2016-12-09 17:03 - 2016-11-11 10:10 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-12-09 17:03 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2016-12-09 17:03 - 2016-11-11 10:08 - 08127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2016-12-09 17:03 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-12-09 17:03 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-12-09 17:03 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-12-09 17:03 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-12-09 17:03 - 2016-11-11 10:04 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-12-09 17:03 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2016-12-09 17:03 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-12-09 17:03 - 2016-11-11 10:02 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2016-12-09 17:03 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll 2016-12-09 17:03 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-12-09 17:03 - 2016-11-11 08:47 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2016-12-09 17:03 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe 2016-12-09 17:03 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe 2016-12-09 17:03 - 2016-11-11 08:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-12-09 17:03 - 2016-11-11 08:20 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-12-09 17:03 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-12-09 17:03 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2016-12-09 17:03 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2016-12-09 17:03 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2016-12-09 17:03 - 2016-11-11 08:17 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-12-09 17:03 - 2016-11-11 08:14 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-12-09 17:03 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll 2016-12-09 17:03 - 2016-11-11 08:09 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2016-12-09 17:03 - 2016-11-11 08:06 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-12-09 17:03 - 2016-11-11 08:06 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2016-12-09 17:03 - 2016-11-11 08:05 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-12-09 17:03 - 2016-11-11 08:04 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2016-12-09 17:03 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-12-09 17:03 - 2016-11-11 08:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-12-09 16:34 - 2016-12-09 16:34 - 00003256 _____ C:\WINDOWS\System32\Tasks\{C957B167-54F3-473A-ABC0-BB93E1A35F4B} 2016-12-09 15:45 - 2016-12-09 15:47 - 00543244 _____ C:\WINDOWS\Minidump\120916-49953-01.dmp 2016-12-09 14:07 - 2016-12-09 15:45 - 804615481 _____ C:\WINDOWS\MEMORY.DMP 2016-12-09 14:07 - 2016-12-09 14:09 - 00543348 _____ C:\WINDOWS\Minidump\120916-75234-01.dmp 2016-12-08 23:05 - 2016-12-08 23:04 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll 2016-12-08 22:27 - 2016-12-08 22:27 - 00001454 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2016-12-08 22:25 - 2016-02-17 07:40 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll 2016-12-08 22:25 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll 2016-12-08 22:25 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2016-12-08 18:52 - 2016-12-08 18:52 - 00592057 _____ C:\Users\Moritz\Documents\open office flüchtlinge presentation.odp 2016-12-08 18:52 - 2016-12-08 18:52 - 00000125 ____H C:\Users\Moritz\Documents\.~lock.open office flüchtlinge presentation.odp# 2016-12-08 16:33 - 2016-12-08 16:33 - 00000000 ___SD C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3 2016-12-08 16:33 - 2016-12-08 16:33 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\OpenOffice 2016-12-08 16:32 - 2016-12-08 16:32 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2016-12-08 16:29 - 2016-12-08 16:31 - 171330228 _____ C:\Users\Moritz\Documents\Apache_OpenOffice_4.1.3_Win_x86_install_de.exe 2016-12-07 21:01 - 2016-12-09 15:45 - 00000000 ____D C:\WINDOWS\Minidump 2016-12-07 20:56 - 2016-12-09 16:12 - 00000356 _____ C:\WINDOWS\system32\config\afw_hm.conf 2016-12-07 20:56 - 2016-12-09 16:12 - 00000004 _____ C:\WINDOWS\system32\config\afw_db.conf 2016-12-07 20:54 - 2016-12-07 21:15 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\BullGuard 2016-12-07 20:51 - 2016-12-07 20:51 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\QuickScan 2016-12-07 20:50 - 2016-12-09 16:12 - 00000000 ____D C:\ProgramData\BullGuard 2016-12-07 20:13 - 2016-12-07 20:13 - 00000000 ____D C:\ProgramData\UniqueId 2016-12-07 20:12 - 2016-12-07 20:28 - 00000000 ____D C:\ProgramData\WinZip 2016-12-07 20:12 - 2016-12-07 20:12 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinZip 21.0 2016-12-07 20:11 - 2016-12-07 20:31 - 00000000 ____D C:\Users\Moritz\AppData\Local\chromium 2016-12-07 20:09 - 2016-12-11 11:36 - 00000008 __RSH C:\ProgramData\ntuser.pol 2016-11-24 11:04 - 2016-11-24 11:04 - 00001496 _____ C:\Users\Moritz\Desktop\Von Microsoft.lnk 2016-11-19 17:49 - 2016-11-19 17:49 - 00000000 ____D C:\Users\Moritz\Documents\League of Legends 2016-11-17 10:59 - 2016-11-17 10:59 - 00000992 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk 2016-11-17 10:59 - 2016-11-17 10:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm 2016-11-17 10:27 - 2016-12-10 22:07 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 12:09 - 2016-02-22 17:39 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Origin 2016-12-11 12:07 - 2016-02-26 20:24 - 00000000 ____D C:\Users\Moritz\AppData\Local\CrashDumps 2016-12-11 12:04 - 2016-02-25 18:20 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Spotify 2016-12-11 12:02 - 2016-08-30 14:13 - 00000000 ____D C:\Users\Moritz 2016-12-11 12:02 - 2016-02-22 15:55 - 00000000 ____D C:\Program Files (x86)\Steam 2016-12-11 12:01 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-12-11 12:00 - 2016-04-17 19:15 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Skype 2016-12-11 11:59 - 2016-02-25 18:20 - 00000000 ____D C:\Users\Moritz\AppData\Local\Spotify 2016-12-11 11:59 - 2016-02-22 17:37 - 00000000 ____D C:\ProgramData\Origin 2016-12-11 11:58 - 2016-02-21 21:05 - 00000000 ___RD C:\Users\Moritz\OneDrive 2016-12-11 11:57 - 2016-02-22 21:30 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2016-12-11 11:56 - 2016-08-30 14:24 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-12-11 11:56 - 2016-08-30 14:09 - 00000000 ____D C:\ProgramData\NVIDIA 2016-12-11 11:55 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2016-12-11 11:28 - 2016-08-30 14:07 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-12-11 01:36 - 2016-04-07 23:01 - 00000000 ____D C:\Users\Moritz\AppData\Local\Battle.net 2016-12-11 00:56 - 2016-04-07 22:49 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-12-10 13:07 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2016-12-10 13:06 - 2016-07-16 23:51 - 01280698 _____ C:\WINDOWS\system32\perfh007.dat 2016-12-10 13:06 - 2016-07-16 23:51 - 00314160 _____ C:\WINDOWS\system32\perfc007.dat 2016-12-10 13:06 - 2016-02-21 21:05 - 02926944 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-12-10 12:59 - 2016-08-30 14:06 - 00223720 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-12-10 12:59 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing 2016-12-09 18:37 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-12-09 16:18 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-12-09 16:11 - 2016-05-18 22:22 - 00000000 ____D C:\Program Files\e2dd5c3297ced70539992c1daa0a22bf 2016-12-09 07:22 - 2016-02-26 20:14 - 00000000 ____D C:\ProgramData\Oracle 2016-12-08 23:05 - 2016-04-02 14:34 - 00000000 ____D C:\Program Files\Java 2016-12-08 23:05 - 2016-02-26 20:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-12-08 23:05 - 2016-02-26 20:14 - 00000000 ____D C:\Program Files (x86)\Java 2016-12-08 23:04 - 2016-04-02 14:34 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2016-12-08 23:04 - 2016-02-26 20:14 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-12-08 22:27 - 2016-02-22 21:22 - 00000000 ____D C:\Users\Moritz\AppData\Local\NVIDIA 2016-12-08 22:26 - 2016-08-30 14:08 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-12-08 22:25 - 2016-08-30 14:08 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-08 22:25 - 2016-08-30 14:08 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-08 22:25 - 2016-02-22 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2016-12-08 22:24 - 2016-08-30 15:05 - 00000000 ___DC C:\WINDOWS\Panther 2016-12-08 11:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-12-08 11:55 - 2016-02-22 21:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\NVIDIA Corporation 2016-12-07 22:20 - 2016-02-22 19:58 - 00001389 _____ C:\Users\Public\Desktop\STAR WARS Battlefront.lnk 2016-12-07 21:39 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2016-12-07 20:50 - 2016-02-21 16:37 - 00000000 ____D C:\Users\Default.migrated 2016-12-06 14:04 - 2016-02-22 17:37 - 00000000 ____D C:\Program Files (x86)\Origin 2016-12-06 14:03 - 2016-04-17 19:15 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-12-06 14:03 - 2016-04-17 19:15 - 00000000 ____D C:\ProgramData\Skype 2016-12-05 20:43 - 2016-08-04 18:29 - 00000000 ____D C:\Program Files (x86)\Overwatch 2016-12-05 15:53 - 2016-03-01 22:26 - 00000000 ____D C:\Users\Moritz\AppData\Local\ElevatedDiagnostics 2016-12-03 11:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-12-02 21:01 - 2016-09-09 19:54 - 00000000 ____D C:\Program Files (x86)\Overwolf 2016-12-02 20:52 - 2016-02-21 21:02 - 00000000 ____D C:\Users\Moritz\AppData\Local\Packages 2016-12-02 20:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache 2016-11-28 22:43 - 2016-04-02 14:29 - 00000000 ____D C:\ftb 2016-11-23 20:34 - 2016-03-24 22:24 - 00000000 ____D C:\Users\Moritz\Desktop\game 2016-11-22 17:30 - 2016-05-16 18:20 - 00001749 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-11-21 16:53 - 2016-06-11 09:00 - 00000000 ____D C:\Program Files\4319cafc0373b1ce231caf7b853b1dc0 2016-11-20 18:05 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2016-11-20 14:19 - 2016-03-21 22:14 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\TS3Client 2016-11-14 21:19 - 2016-02-22 22:29 - 00000000 ____D C:\Users\Moritz\Documents\My Games 2016-11-13 09:53 - 2016-04-02 14:29 - 00000000 ____D C:\Users\Moritz\AppData\Local\ftblauncher 2016-11-12 19:28 - 2016-02-26 20:08 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\.minecraft 2016-11-12 19:16 - 2016-02-21 21:02 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-11-12 18:51 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\migwiz Einige Dateien in TEMP: ==================== C:\Users\Moritz\AppData\Local\Temp\jre-8u111-windows-au.exe C:\Users\Moritz\AppData\Local\Temp\libeay32.dll C:\Users\Moritz\AppData\Local\Temp\msvcr120.dll C:\Users\Moritz\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-12-04 16:53 ==================== Ende von FRST.txt ============================ |
11.12.2016, 18:42 | #12 |
/// Malwareteam | wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichts Wieso hast du die Haken bei den Ausnahmen rausgemacht? Schritt: 1 ESET Online Scanner
Hinweis: Dieser Scan kann schon einmal mehrere Stunden dauern... Schritt: 2 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen. Achte auf alle gesetzte Haken unter "Ausnahmen" und den Haken bei "Addition.txt" unter "Optionaler Scan"
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
11.12.2016, 23:11 | #13 |
| Welchen Haken bei Ausnahmen? Ich bin mir nicht ganz sicher welchen Haken du meinst aber wenns hilft kann ich das nochmal machen und dir zuschicken. lg molp ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=71cecb5afbb81b4fbf611ba8797c8379 # end=init # utc_time=2016-12-11 07:04:59 # local_time=2016-12-11 08:04:59 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 31701 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=71cecb5afbb81b4fbf611ba8797c8379 # end=updated # utc_time=2016-12-11 07:07:39 # local_time=2016-12-11 08:07:39 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=71cecb5afbb81b4fbf611ba8797c8379 # engine=31701 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2016-12-11 07:09:32 # local_time=2016-12-11 08:09:32 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 33796 12813988 0 0 # scanned=5891 # found=0 # cleaned=0 # scan_time=112 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=71cecb5afbb81b4fbf611ba8797c8379 # end=init # utc_time=2016-12-11 07:11:19 # local_time=2016-12-11 08:11:19 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download esets_scanner_update returned -1 esets_gle=53251 Update Finalize Updated modules version: 31701 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=71cecb5afbb81b4fbf611ba8797c8379 # end=updated # utc_time=2016-12-11 07:11:59 # local_time=2016-12-11 08:11:59 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=71cecb5afbb81b4fbf611ba8797c8379 # engine=31701 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2016-12-11 09:36:55 # local_time=2016-12-11 10:36:55 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 39039 12822831 0 0 # scanned=265113 # found=0 # cleaned=0 # scan_time=8695 FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016 durchgeführt von Moritz (Administrator) auf DESKTOP-ERBVLM6 (11-12-2016 23:08:09) Gestartet von C:\Users\Moritz\Downloads Geladene Profile: Moritz (Verfügbare Profile: Moritz) Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Edge) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe () C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe (RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Spotify Ltd) C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWebHelper.exe (© 2015 Microsoft Corporation) C:\Users\Moritz\AppData\Local\Microsoft\BingSvc\BingSvc.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe () C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Valve Corporation) C:\Program Files (x86)\Steam\GameOverlayUI.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [16286840 2016-08-30] (Logitech Inc.) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2786768 2016-11-29] (Malwarebytes) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2860832 2016-10-13] (Valve Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3044848 2016-12-06] (Electronic Arts) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Spotify Web Helper] => C:\Users\Moritz\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-09] (Spotify Ltd) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Spotify] => C:\Users\Moritz\AppData\Roaming\Spotify\Spotify.exe [7095408 2016-12-09] (Spotify Ltd) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [BingSvc] => C:\Users\Moritz\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27219928 2016-11-15] (Skype Technologies S.A.) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [Chromium] => c:\users\moritz\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Run: [~Resuming Profile - Vollständiger Scan] => "C:\Program Files\BullGuard Ltd\BullGuard\BgScan.exe" "profilepath: C:\Users\Moritz\AppData\Roaming\BullGuard\Antivirus\Profiles\~Resuming Profile - Vollständiger Scan.xml" HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{17ee23ff-c454-4ac7-aafe-24a47b714173}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{2c9c1031-1c58-4a0c-a510-c4b9546a53b7}: [DhcpNameServer] 172.17.2.1 Tcpip\..\Interfaces\{beb9c673-971c-479c-96ad-efdd872d05fa}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Start Page = HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-12-08] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-08] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-12-08] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-08] (Oracle Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-08] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32.dll [2016-02-22] () FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-08] (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [245544 2016-07-12] (EasyAntiCheat Ltd) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation) U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-10-10] (Hi-Rez Studios) [Datei ist nicht signiert] R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-08-30] (Logitech Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-11-29] (Malwarebytes) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation) S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-12-06] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2016-12-06] (Electronic Arts) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1316080 2016-11-23] (Overwolf LTD) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-05-28] () R2 RemoteMouseService; C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe [18432 2016-05-17] () [Datei ist nicht signiert] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77408 2016-11-29] () R3 Ke2200; C:\WINDOWS\System32\drivers\e22w7x64.sys [129200 2014-03-27] (Qualcomm Atheros, Inc.) S3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [45208 2016-08-30] (Logitech Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) S3 LGJoyHidFilter; C:\WINDOWS\system32\drivers\LGJoyHidFilter.sys [58144 2015-06-11] (Logitech Inc.) S3 LGJoyHidLo; C:\WINDOWS\system32\drivers\LGJoyHidLo.sys [47656 2015-06-11] (Logitech Inc.) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-08-30] (Logitech Inc.) S3 LGSHidFilt; C:\WINDOWS\System32\drivers\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176064 2016-12-11] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [102856 2016-12-11] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2016-12-11] (Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [250816 2016-12-11] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [91584 2016-12-11] (Malwarebytes) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation) R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5195776 2016-07-16] (Realtek Semiconductor Corporation ) S3 VUSB3HUB; C:\WINDOWS\System32\drivers\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.) S3 VUSBSTOR; C:\WINDOWS\System32\Drivers\vusbstor.sys [86064 2013-01-18] (VIA Technologies, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) S3 xhcdrv; C:\WINDOWS\System32\drivers\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 15:01 - 2016-12-11 15:01 - 00000934 _____ C:\Users\Public\Desktop\Overwatch Test.lnk 2016-12-11 15:01 - 2016-12-11 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch Test 2016-12-11 14:09 - 2016-12-11 15:03 - 00000000 ____D C:\Program Files (x86)\Overwatch Test 2016-12-11 12:06 - 2016-12-11 12:06 - 00001904 _____ C:\Users\Moritz\Desktop\mbam textdatei.txt 2016-12-11 11:58 - 2016-12-11 11:58 - 00000000 ___HD C:\OneDriveTemp 2016-12-11 11:47 - 2016-12-11 11:57 - 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-12-11 11:47 - 2016-12-11 11:57 - 00102856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2016-12-11 11:47 - 2016-12-11 11:57 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2016-12-11 11:47 - 2016-12-11 11:57 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-12-11 11:47 - 2016-12-11 11:47 - 00176064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2016-12-11 11:47 - 2016-12-11 11:47 - 00001872 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2016-12-11 11:47 - 2016-12-11 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2016-12-11 11:47 - 2016-11-29 06:27 - 00077408 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2016-12-11 11:46 - 2016-12-11 11:46 - 51969976 _____ (Malwarebytes ) C:\Users\Moritz\Downloads\mb3-setup-consumer-3.0.4.1269.exe 2016-12-11 11:46 - 2016-12-11 11:46 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-12-11 11:46 - 2016-12-11 11:46 - 00000000 ____D C:\Program Files\Malwarebytes 2016-12-11 11:32 - 2016-12-11 11:33 - 03968464 _____ C:\Users\Moritz\Downloads\AdwCleaner_6.040 (1).exe 2016-12-11 11:05 - 2016-12-11 11:04 - 09296344 _____ C:\Users\Moritz\Desktop\RevoUninstaller_Portable201.zip 2016-12-11 11:04 - 2016-12-11 11:31 - 09503576 _____ C:\Users\Moritz\Downloads\RevoUninstaller_Portable201.zip 2016-12-11 01:51 - 2016-12-11 12:12 - 00054625 _____ C:\Users\Moritz\Downloads\Addition.txt 2016-12-11 01:49 - 2016-12-11 23:08 - 00015866 _____ C:\Users\Moritz\Downloads\FRST.txt 2016-12-11 01:47 - 2016-12-11 23:08 - 00000000 ____D C:\FRST 2016-12-11 01:46 - 2016-12-11 01:46 - 02420224 _____ (Farbar) C:\Users\Moritz\Downloads\FRST64.exe 2016-12-11 01:45 - 2016-12-11 01:47 - 01761792 _____ (Farbar) C:\Users\Moritz\Downloads\FRST.exe 2016-12-10 15:01 - 2016-12-11 11:36 - 00000000 ____D C:\AdwCleaner 2016-12-10 15:01 - 2016-12-10 15:01 - 03968464 _____ C:\Users\Moritz\Downloads\adwcleaner_6.040.exe 2016-12-09 17:05 - 2016-11-11 11:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-12-09 17:05 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2016-12-09 17:05 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-12-09 17:05 - 2016-11-11 10:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2016-12-09 17:05 - 2016-11-11 10:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-12-09 17:05 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-12-09 17:05 - 2016-11-11 10:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-12-09 17:05 - 2016-11-11 10:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-12-09 17:05 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2016-12-09 17:05 - 2016-11-11 10:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-12-09 17:05 - 2016-11-11 10:17 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-12-09 17:05 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2016-12-09 17:05 - 2016-11-11 10:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-12-09 17:05 - 2016-11-11 10:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-12-09 17:05 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-12-09 17:05 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2016-12-09 17:05 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-12-09 17:05 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-12-09 17:05 - 2016-11-11 10:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-12-09 17:05 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-12-09 17:05 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-12-09 17:04 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2016-12-09 17:04 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2016-12-09 17:04 - 2016-11-11 11:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2016-12-09 17:04 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2016-12-09 17:04 - 2016-11-11 11:13 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-12-09 17:04 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-12-09 17:04 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2016-12-09 17:04 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-12-09 17:04 - 2016-11-11 11:09 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-12-09 17:04 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2016-12-09 17:04 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-12-09 17:04 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-12-09 17:04 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-12-09 17:04 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-12-09 17:04 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-12-09 17:04 - 2016-11-11 11:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-12-09 17:04 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2016-12-09 17:04 - 2016-11-11 10:59 - 02913136 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-12-09 17:04 - 2016-11-11 10:59 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 08170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-12-09 17:04 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll 2016-12-09 17:04 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2016-12-09 17:04 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-12-09 17:04 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-12-09 17:04 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2016-12-09 17:04 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-12-09 17:04 - 2016-11-11 10:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-12-09 17:04 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2016-12-09 17:04 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-12-09 17:04 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2016-12-09 17:04 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll 2016-12-09 17:04 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys 2016-12-09 17:04 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2016-12-09 17:04 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-12-09 17:04 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-12-09 17:04 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll 2016-12-09 17:04 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2016-12-09 17:04 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-12-09 17:04 - 2016-11-11 10:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2016-12-09 17:04 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-12-09 17:04 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 17:04 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-12-09 17:04 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2016-12-09 17:04 - 2016-11-11 10:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2016-12-09 17:04 - 2016-11-11 10:17 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2016-12-09 17:04 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2016-12-09 17:04 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2016-12-09 17:04 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-12-09 17:04 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-12-09 17:04 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll 2016-12-09 17:04 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll 2016-12-09 17:04 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-12-09 17:04 - 2016-11-11 10:10 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-12-09 17:04 - 2016-11-11 10:09 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2016-12-09 17:04 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-12-09 17:04 - 2016-11-11 10:08 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-12-09 17:04 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-12-09 17:04 - 2016-11-11 10:06 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-12-09 17:04 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-12-09 17:04 - 2016-11-11 10:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2016-12-09 17:04 - 2016-11-11 10:04 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-12-09 17:04 - 2016-11-11 10:04 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-12-09 17:04 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-12-09 17:04 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll 2016-12-09 17:04 - 2016-11-11 10:03 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-12-09 17:04 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-12-09 17:04 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-12-09 17:04 - 2016-11-11 10:01 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-12-09 17:04 - 2016-11-11 09:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-12-09 17:04 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-12-09 17:04 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-12-09 17:04 - 2016-11-11 08:56 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2016-12-09 17:04 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-12-09 17:04 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-12-09 17:04 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-12-09 17:04 - 2016-11-11 08:45 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-12-09 17:04 - 2016-11-11 08:45 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 06668032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll 2016-12-09 17:04 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll 2016-12-09 17:04 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-12-09 17:04 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe 2016-12-09 17:04 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-12-09 17:04 - 2016-11-11 08:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-12-09 17:04 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-12-09 17:04 - 2016-11-11 08:26 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-12-09 17:04 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-12-09 17:04 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-12-09 17:04 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-12-09 17:04 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-12-09 17:04 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-12-09 17:04 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-12-09 17:04 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2016-12-09 17:04 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-12-09 17:04 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-12-09 17:04 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2016-12-09 17:04 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-12-09 17:04 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2016-12-09 17:04 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2016-12-09 17:04 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2016-12-09 17:04 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2016-12-09 17:04 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2016-12-09 17:04 - 2016-11-11 08:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-12-09 17:04 - 2016-11-11 08:13 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-12-09 17:04 - 2016-11-11 08:11 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-12-09 17:04 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll 2016-12-09 17:04 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-12-09 17:04 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-12-09 17:04 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-12-09 17:04 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-12-09 17:04 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll 2016-12-09 17:04 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-12-09 17:04 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-12-09 17:04 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-12-09 17:04 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2016-12-09 17:04 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-12-09 17:04 - 2016-11-11 08:01 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-12-09 17:04 - 2016-11-11 07:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-12-09 17:03 - 2016-11-11 11:01 - 02189152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-12-09 17:03 - 2016-11-11 11:01 - 01738048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-12-09 17:03 - 2016-11-11 11:01 - 00658264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-12-09 17:03 - 2016-11-11 11:01 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-12-09 17:03 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-12-09 17:03 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-12-09 17:03 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-12-09 17:03 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe 2016-12-09 17:03 - 2016-11-11 10:51 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2016-12-09 17:03 - 2016-11-11 10:31 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-12-09 17:03 - 2016-11-11 10:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-12-09 17:03 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll 2016-12-09 17:03 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-12-09 17:03 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe 2016-12-09 17:03 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-12-09 17:03 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-12-09 17:03 - 2016-11-11 10:24 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-12-09 17:03 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-12-09 17:03 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-12-09 17:03 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2016-12-09 17:03 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-12-09 17:03 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2016-12-09 17:03 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2016-12-09 17:03 - 2016-11-11 10:19 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-12-09 17:03 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2016-12-09 17:03 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2016-12-09 17:03 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2016-12-09 17:03 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-12-09 17:03 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2016-12-09 17:03 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-12-09 17:03 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll 2016-12-09 17:03 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-12-09 17:03 - 2016-11-11 10:11 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-12-09 17:03 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll 2016-12-09 17:03 - 2016-11-11 10:10 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-12-09 17:03 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2016-12-09 17:03 - 2016-11-11 10:08 - 08127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2016-12-09 17:03 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2016-12-09 17:03 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-12-09 17:03 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-12-09 17:03 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-12-09 17:03 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-12-09 17:03 - 2016-11-11 10:04 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-12-09 17:03 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-12-09 17:03 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-12-09 17:03 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2016-12-09 17:03 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-12-09 17:03 - 2016-11-11 10:02 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2016-12-09 17:03 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2016-12-09 17:03 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll 2016-12-09 17:03 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-12-09 17:03 - 2016-11-11 08:47 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-12-09 17:03 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2016-12-09 17:03 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe 2016-12-09 17:03 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe 2016-12-09 17:03 - 2016-11-11 08:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-12-09 17:03 - 2016-11-11 08:20 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-12-09 17:03 - 2016-11-11 08:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-12-09 17:03 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-12-09 17:03 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2016-12-09 17:03 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2016-12-09 17:03 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2016-12-09 17:03 - 2016-11-11 08:17 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 17:03 - 2016-11-11 08:16 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-12-09 17:03 - 2016-11-11 08:14 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-12-09 17:03 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll 2016-12-09 17:03 - 2016-11-11 08:09 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2016-12-09 17:03 - 2016-11-11 08:06 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-12-09 17:03 - 2016-11-11 08:06 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2016-12-09 17:03 - 2016-11-11 08:05 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-12-09 17:03 - 2016-11-11 08:04 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2016-12-09 17:03 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-12-09 17:03 - 2016-11-11 08:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-12-09 16:34 - 2016-12-09 16:34 - 00003256 _____ C:\WINDOWS\System32\Tasks\{C957B167-54F3-473A-ABC0-BB93E1A35F4B} 2016-12-09 15:45 - 2016-12-09 15:47 - 00543244 _____ C:\WINDOWS\Minidump\120916-49953-01.dmp 2016-12-09 14:07 - 2016-12-09 15:45 - 804615481 _____ C:\WINDOWS\MEMORY.DMP 2016-12-09 14:07 - 2016-12-09 14:09 - 00543348 _____ C:\WINDOWS\Minidump\120916-75234-01.dmp 2016-12-08 23:05 - 2016-12-08 23:04 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll 2016-12-08 22:27 - 2016-12-08 22:27 - 00001454 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2016-12-08 22:25 - 2016-02-17 07:40 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2016-12-08 22:25 - 2016-02-17 07:40 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll 2016-12-08 22:25 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll 2016-12-08 22:25 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2016-12-08 18:52 - 2016-12-08 18:52 - 00592057 _____ C:\Users\Moritz\Documents\open office flüchtlinge presentation.odp 2016-12-08 18:52 - 2016-12-08 18:52 - 00000125 ____H C:\Users\Moritz\Documents\.~lock.open office flüchtlinge presentation.odp# 2016-12-08 16:33 - 2016-12-08 16:33 - 00000000 ___SD C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3 2016-12-08 16:33 - 2016-12-08 16:33 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\OpenOffice 2016-12-08 16:32 - 2016-12-08 16:32 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2016-12-08 16:29 - 2016-12-08 16:31 - 171330228 _____ C:\Users\Moritz\Documents\Apache_OpenOffice_4.1.3_Win_x86_install_de.exe 2016-12-07 21:01 - 2016-12-09 15:45 - 00000000 ____D C:\WINDOWS\Minidump 2016-12-07 20:56 - 2016-12-09 16:12 - 00000356 _____ C:\WINDOWS\system32\config\afw_hm.conf 2016-12-07 20:56 - 2016-12-09 16:12 - 00000004 _____ C:\WINDOWS\system32\config\afw_db.conf 2016-12-07 20:54 - 2016-12-07 21:15 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\BullGuard 2016-12-07 20:51 - 2016-12-07 20:51 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\QuickScan 2016-12-07 20:50 - 2016-12-09 16:12 - 00000000 ____D C:\ProgramData\BullGuard 2016-12-07 20:13 - 2016-12-07 20:13 - 00000000 ____D C:\ProgramData\UniqueId 2016-12-07 20:12 - 2016-12-07 20:28 - 00000000 ____D C:\ProgramData\WinZip 2016-12-07 20:12 - 2016-12-07 20:12 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinZip 21.0 2016-12-07 20:11 - 2016-12-07 20:31 - 00000000 ____D C:\Users\Moritz\AppData\Local\chromium 2016-12-07 20:09 - 2016-12-11 11:36 - 00000008 __RSH C:\ProgramData\ntuser.pol 2016-11-24 11:04 - 2016-11-24 11:04 - 00001496 _____ C:\Users\Moritz\Desktop\Von Microsoft.lnk 2016-11-19 17:49 - 2016-11-19 17:49 - 00000000 ____D C:\Users\Moritz\Documents\League of Legends 2016-11-17 10:59 - 2016-11-17 10:59 - 00000992 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk 2016-11-17 10:59 - 2016-11-17 10:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm 2016-11-17 10:27 - 2016-12-10 22:07 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 23:07 - 2016-02-22 17:39 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Origin 2016-12-11 23:00 - 2016-04-17 19:15 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Skype 2016-12-11 23:00 - 2016-02-25 18:20 - 00000000 ____D C:\Users\Moritz\AppData\Local\Spotify 2016-12-11 22:55 - 2016-04-07 23:01 - 00000000 ____D C:\Users\Moritz\AppData\Local\Battle.net 2016-12-11 21:56 - 2016-08-30 14:07 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-12-11 20:31 - 2016-02-25 18:20 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Spotify 2016-12-11 20:15 - 2016-04-07 22:49 - 00000000 ____D C:\Program Files (x86)\Battle.net 2016-12-11 15:56 - 2016-03-20 16:19 - 00000000 ____D C:\Users\Moritz\AppData\Local\Warframe 2016-12-11 14:22 - 2016-02-22 15:55 - 00000000 ____D C:\Program Files (x86)\Steam 2016-12-11 13:27 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2016-12-11 12:07 - 2016-02-26 20:24 - 00000000 ____D C:\Users\Moritz\AppData\Local\CrashDumps 2016-12-11 12:02 - 2016-08-30 14:13 - 00000000 ____D C:\Users\Moritz 2016-12-11 12:01 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-12-11 11:59 - 2016-02-22 17:37 - 00000000 ____D C:\ProgramData\Origin 2016-12-11 11:58 - 2016-02-21 21:05 - 00000000 ___RD C:\Users\Moritz\OneDrive 2016-12-11 11:57 - 2016-02-22 21:30 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2016-12-11 11:56 - 2016-08-30 14:24 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-12-11 11:56 - 2016-08-30 14:09 - 00000000 ____D C:\ProgramData\NVIDIA 2016-12-11 11:55 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2016-12-10 13:07 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2016-12-10 13:06 - 2016-07-16 23:51 - 01280698 _____ C:\WINDOWS\system32\perfh007.dat 2016-12-10 13:06 - 2016-07-16 23:51 - 00314160 _____ C:\WINDOWS\system32\perfc007.dat 2016-12-10 13:06 - 2016-02-21 21:05 - 02926944 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-12-10 12:59 - 2016-08-30 14:06 - 00223720 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-12-09 21:04 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-12-09 21:04 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing 2016-12-09 18:37 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-12-09 16:18 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-12-09 16:11 - 2016-05-18 22:22 - 00000000 ____D C:\Program Files\e2dd5c3297ced70539992c1daa0a22bf 2016-12-09 07:22 - 2016-02-26 20:14 - 00000000 ____D C:\ProgramData\Oracle 2016-12-08 23:05 - 2016-04-02 14:34 - 00000000 ____D C:\Program Files\Java 2016-12-08 23:05 - 2016-02-26 20:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-12-08 23:05 - 2016-02-26 20:14 - 00000000 ____D C:\Program Files (x86)\Java 2016-12-08 23:04 - 2016-04-02 14:34 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2016-12-08 23:04 - 2016-02-26 20:14 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-12-08 22:27 - 2016-02-22 21:22 - 00000000 ____D C:\Users\Moritz\AppData\Local\NVIDIA 2016-12-08 22:26 - 2016-08-30 14:08 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-12-08 22:25 - 2016-08-30 14:08 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-08 22:25 - 2016-08-30 14:08 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-08 22:25 - 2016-02-22 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2016-12-08 22:24 - 2016-08-30 15:05 - 00000000 ___DC C:\WINDOWS\Panther 2016-12-08 11:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-12-08 11:55 - 2016-02-22 21:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\NVIDIA Corporation 2016-12-07 22:20 - 2016-02-22 19:58 - 00001389 _____ C:\Users\Public\Desktop\STAR WARS Battlefront.lnk 2016-12-07 21:39 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2016-12-07 20:50 - 2016-02-21 16:37 - 00000000 ____D C:\Users\Default.migrated 2016-12-06 14:04 - 2016-02-22 17:37 - 00000000 ____D C:\Program Files (x86)\Origin 2016-12-06 14:03 - 2016-04-17 19:15 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-12-06 14:03 - 2016-04-17 19:15 - 00000000 ____D C:\ProgramData\Skype 2016-12-05 20:43 - 2016-08-04 18:29 - 00000000 ____D C:\Program Files (x86)\Overwatch 2016-12-05 15:53 - 2016-03-01 22:26 - 00000000 ____D C:\Users\Moritz\AppData\Local\ElevatedDiagnostics 2016-12-03 11:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-12-02 21:01 - 2016-09-09 19:54 - 00000000 ____D C:\Program Files (x86)\Overwolf 2016-12-02 20:52 - 2016-02-21 21:02 - 00000000 ____D C:\Users\Moritz\AppData\Local\Packages 2016-12-02 20:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache 2016-11-28 22:43 - 2016-04-02 14:29 - 00000000 ____D C:\ftb 2016-11-23 20:34 - 2016-03-24 22:24 - 00000000 ____D C:\Users\Moritz\Desktop\game 2016-11-22 17:30 - 2016-05-16 18:20 - 00001749 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-11-21 16:53 - 2016-06-11 09:00 - 00000000 ____D C:\Program Files\4319cafc0373b1ce231caf7b853b1dc0 2016-11-20 18:05 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2016-11-20 14:19 - 2016-03-21 22:14 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\TS3Client 2016-11-14 21:19 - 2016-02-22 22:29 - 00000000 ____D C:\Users\Moritz\Documents\My Games 2016-11-13 09:53 - 2016-04-02 14:29 - 00000000 ____D C:\Users\Moritz\AppData\Local\ftblauncher 2016-11-12 19:28 - 2016-02-26 20:08 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\.minecraft 2016-11-12 19:16 - 2016-02-21 21:02 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-11-12 18:51 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\migwiz Einige Dateien in TEMP: ==================== C:\Users\Moritz\AppData\Local\Temp\jre-8u111-windows-au.exe C:\Users\Moritz\AppData\Local\Temp\libeay32.dll C:\Users\Moritz\AppData\Local\Temp\msvcr120.dll C:\Users\Moritz\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-12-04 16:53 ==================== Ende von FRST.txt ============================ |
11.12.2016, 23:12 | #14 |
| wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichts FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016 durchgeführt von Moritz (11-12-2016 23:09:18) Gestartet von C:\Users\Moritz\Downloads Windows 10 Home Version 1607 (X64) (2016-08-30 13:33:30) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1352620464-1759978224-1981204074-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1352620464-1759978224-1981204074-503 - Limited - Disabled) Gast (S-1-5-21-1352620464-1759978224-1981204074-501 - Limited - Disabled) Moritz (S-1-5-21-1352620464-1759978224-1981204074-1001 - Administrator - Enabled) => C:\Users\Moritz ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.3.183.90 - Adobe Systems Incorporated) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Blacklight: Retribution (HKLM\...\Steam App 209870) (Version: - Hardsuit Labs) Brawlhalla (HKLM\...\Steam App 291550) (Version: - Blue Mammoth Games) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{6DBD132B-7F42-4594-BBE7-0BB677EB2926}) (Version: 4.4.2 - SEIKO EPSON CORPORATION) EPSON WF-2540 Series Printer Uninstall (HKLM\...\EPSON WF-2540 Series) (Version: - SEIKO EPSON Corporation) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HiPatch (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}) (Version: 5.0.6.4 - Hi-Rez Studios) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games) League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden Logitech Gaming Software 8.87 (HKLM\...\Logitech Gaming Software) (Version: 8.87.116 - Logitech Inc.) Malwarebytes Version 3.0.4.1269 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.4.1269 - Malwarebytes) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.91 - NVIDIA Corporation) NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation) NVIDIA Grafiktreiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.91 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) OpenOffice 4.1.3 (HKLM-x32\...\{8D5FCC56-BB9F-4122-923C-71753F50F6F5}) (Version: 4.13.9783 - Apache Software Foundation) Orcs Must Die! Unchained (HKLM\...\Steam App 427270) (Version: - Robot Entertainment) Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwatch Test (HKLM-x32\...\Overwatch Test) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.100.9.0 - Overwolf Ltd.) Paladins (HKLM\...\Steam App 444090) (Version: - Hi-Rez Studios) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Remote Mouse version 3.000 (HKLM-x32\...\{01E4BC6D-3ACC-45E1-8928-C2FF626F63F3}_is1) (Version: 3.000 - Remote Mouse) Shakes and Fidget (HKLM\...\Steam App 438040) (Version: - Playa Games GmbH) SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.) SMITE (HKLM-x32\...\Steam App 386360) (Version: - Hi-Rez Studios) Spotify (HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\Spotify) (Version: 1.0.44.100.ga60c0ce1 - Spotify AB) STAR WARS™ Battlefront™ (HKLM-x32\...\{E402D891-4E45-4ce9-B41F-DD35864EF170}) (Version: 1.0.7.36460 - Electronic Arts) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) Teeworlds (HKLM\...\Steam App 380840) (Version: - Teeworlds Team) Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes) WinRAR 5.31 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {25B783C7-77FC-4693-83BD-D956AA8C830B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {26149F4E-DC4B-4588-8D07-F7C17210003F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {3A0F445C-6D63-4C05-B4CA-20A7ABF9B97F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {6DC3ABB3-D7D4-422D-B48B-1EE597905C66} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-11-23] (Overwolf LTD) Task: {71112587-2E61-4271-BEDD-358C33D3B436} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {798FE0A8-AF38-4A03-9042-5A3A814677D4} - System32\Tasks\{C957B167-54F3-473A-ABC0-BB93E1A35F4B} => pcalua.exe -a C:\WINDOWS\a956be449a292952e1127356ecac2673.exe Task: {AEE8E303-B56E-4C79-A68E-7E06D07312A1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {D27E911F-1BB6-4487-BD05-FCB65ABC007D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-11-10] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-08-30 14:09 - 2016-02-09 06:29 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-06-14 19:49 - 2016-05-17 22:15 - 00018432 _____ () C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe 2016-05-27 10:08 - 2016-05-28 12:32 - 00076888 _____ () C:\WINDOWS\SysWoW64\PnkBstrA.exe 2016-12-11 11:47 - 2016-11-29 06:27 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2016-12-11 11:47 - 2016-11-29 06:27 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2016-12-11 11:47 - 2016-11-29 06:27 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2016-12-09 17:04 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-08-31 13:06 - 2016-08-31 13:06 - 01864384 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll 2016-09-17 23:18 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-12-09 17:03 - 2016-11-11 10:23 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll 2016-11-17 14:11 - 2016-11-17 14:11 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-11-17 14:11 - 2016-11-17 14:11 - 00178688 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-11-17 14:11 - 2016-11-17 14:11 - 41609728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-08-30 01:17 - 2016-08-30 01:17 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-08-30 01:17 - 2016-08-30 01:17 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 00022024 _____ () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe 2016-03-19 22:32 - 2016-10-28 14:12 - 00145920 _____ () C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe 2016-11-23 15:16 - 2016-11-23 15:16 - 00019456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-11-23 15:16 - 2016-11-23 15:16 - 20433408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-06-03 17:09 - 2016-06-03 17:10 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2016-11-23 15:16 - 2016-11-23 15:16 - 01046528 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll 2016-11-23 15:16 - 2016-11-23 15:16 - 00353792 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Photos.Inking.dll 2016-11-10 17:21 - 2016-11-02 11:15 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-10 17:21 - 2016-11-02 11:21 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-10 17:21 - 2016-11-02 11:14 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-11-10 17:21 - 2016-11-02 11:15 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-11-10 17:21 - 2016-11-02 11:16 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-10 17:21 - 2016-11-02 11:17 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2016-06-14 19:49 - 2015-05-26 18:54 - 00152576 _____ () C:\Program Files (x86)\Remote Mouse\FileS.dll 2016-02-22 21:22 - 2016-02-17 08:02 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-12-11 11:46 - 2016-11-08 09:46 - 00693248 _____ () C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-08-31 13:05 - 2016-08-31 13:06 - 01383616 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\ClientTelemetry.dll 2016-08-31 13:06 - 2016-08-31 13:06 - 00118976 _____ () C:\Users\Moritz\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncViews.dll 2016-02-22 15:57 - 2016-09-08 04:14 - 00784672 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 02321696 _____ () C:\Program Files (x86)\Steam\video.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2016-02-22 15:57 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2016-02-22 15:57 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 00836896 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2016-03-12 16:04 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2016-12-02 20:37 - 2016-12-06 14:03 - 00012288 _____ () C:\Program Files (x86)\Origin\libEGL.DLL 2016-02-22 17:39 - 2016-06-11 09:25 - 00266240 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll 2016-10-14 15:18 - 2016-08-04 21:56 - 49825056 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.winxp\libcef.dll 2016-02-22 15:57 - 2016-10-13 02:58 - 00380704 _____ () C:\Program Files (x86)\Steam\steam.dll 2016-02-22 15:57 - 2015-09-25 00:52 - 00119208 _____ () C:\Program Files (x86)\Steam\winh264.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\.DEFAULT\...\amazon.de -> hxxps://amazon.de IE trusted site: HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\...\amazon.de -> hxxps://amazon.de ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2016-02-21 16:47 - 2016-12-10 12:59 - 00002024 ____A C:\WINDOWS\system32\Drivers\etc\hosts 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com 0.0.0.0 media.opencandy.com 0.0.0.0 cdn.opencandy.com 0.0.0.0 tracking.opencandy.com 0.0.0.0 api.opencandy.com 0.0.0.0 api.recommendedsw.com 0.0.0.0 installer.betterinstaller.com 0.0.0.0 installer.filebulldog.com 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net 0.0.0.0 inno.bisrv.com 0.0.0.0 nsis.bisrv.com 0.0.0.0 cdn.file2desktop.com 0.0.0.0 cdn.goateastcach.us 0.0.0.0 cdn.guttastatdk.us 0.0.0.0 cdn.inskinmedia.com 0.0.0.0 cdn.insta.oibundles2.com 0.0.0.0 cdn.insta.playbryte.com 0.0.0.0 cdn.llogetfastcach.us 0.0.0.0 cdn.montiera.com 0.0.0.0 cdn.msdwnld.com 0.0.0.0 cdn.mypcbackup.com 0.0.0.0 cdn.ppdownload.com 0.0.0.0 cdn.riceateastcach.us 0.0.0.0 cdn.shyapotato.us 0.0.0.0 cdn.solimba.com 0.0.0.0 cdn.tuto4pc.com 0.0.0.0 cdn.appround.biz 0.0.0.0 cdn.bigspeedpro.com 0.0.0.0 cdn.bispd.com Da befinden sich 4 zusätzliche Einträge. ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1352620464-1759978224-1981204074-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Moritz\Pictures\league-of-legends-fan-art.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [UDP Query User{171B2627-DEFC-41AA-B3C9-287E47EC6BBA}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [TCP Query User{749023EB-D8FD-4420-9AC7-E4E2230DAE73}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{98AF7DC9-0EF2-4532-B489-A4115A2708A9}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [TCP Query User{59F600E4-2200-4891-88DE-517505BF8757}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [{4D24FBC9-55D8-4B79-9ADB-04369415B741}] => C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe FirewallRules: [{E7808F84-D012-4EA7-87FE-8E3C370DAC15}] => C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe FirewallRules: [{87D8D5FC-7CF6-4C97-B326-0D1EB719A5B8}] => C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe FirewallRules: [{3B1A788A-A056-4B28-8576-C94B0A918614}] => C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe FirewallRules: [{08DDDF30-6604-498E-86A5-94783B392A1C}] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [{00403A52-43F9-4F6A-BBD6-D92751A20E50}] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe FirewallRules: [{9915B4E2-FDB5-4B54-8F27-8BDD9B798392}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\teeworlds.exe FirewallRules: [{5BC6397F-C273-4ABE-BD16-0711CAB6413A}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\teeworlds.exe FirewallRules: [UDP Query User{6303235C-A172-4FE9-BA7E-E1826F97589D}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{4291F196-3B7C-4AEF-A99E-C9958ACF6C7E}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{5ABB841B-A52E-4318-8005-4BE953951A94}] => C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{300ED332-6ABF-4B0E-BF07-D1D3D36A99E9}] => C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{C4889F50-917F-41A9-9F71-7BCD93B9B456}] => C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{B87C0EE9-6F0F-4113-BBE8-80C887005D97}] => C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{E8AD663F-43A5-44F3-854B-2CB30C5C0CFA}] => C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [{204CC8CE-6B0D-4735-B5DA-1352BF537E4C}] => C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [UDP Query User{A3A16CD8-074A-46D7-B7F7-FB03119C0C79}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe] => C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe FirewallRules: [TCP Query User{E2B2F661-5DE8-4AFF-8FE2-D265B6BEC8E4}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe] => C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe FirewallRules: [{EC67536D-BCB8-4CB0-A339-004C85A8DA10}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Binaries\Win32\FoxGame-win32-Shipping.exe FirewallRules: [{A2B487E7-F928-4B8B-82C3-8A00A4BC05D6}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Binaries\Win32\FoxGame-win32-Shipping.exe FirewallRules: [{1811FF59-D55E-4F62-AC77-48B8DACD52CD}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Blacklight Retribution.exe FirewallRules: [{F1EB0788-FEFC-463D-AE09-A26AAE6964F8}] => C:\Program Files (x86)\Steam\steamapps\common\blacklightretribution\Blacklight Retribution.exe FirewallRules: [UDP Query User{90BCB480-9F75-4D62-BF93-6886F634BEF2}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{FAE64EC6-55C3-4205-997F-5B61ABAB4FF7}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{ADEA7124-1035-40D8-B4F8-1362C2A859A2}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [UDP Query User{F0CC8E85-FFE5-458D-B4B9-5418324B320F}C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe] => C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{0F2CA579-7B22-47BE-8709-005FA88A56FF}C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe] => C:\program files (x86)\heroes of the storm\versions\base42178\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{82465579-118B-4D56-BC78-0624CFEA80EC}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{DDA6F10F-71B5-4694-9C1B-C002DEEF3BED}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [{464D4A29-7E85-4763-ACFE-59AFD75FFC94}] => C:\Program Files (x86)\Steam\steamapps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe FirewallRules: [{98BE2BB8-A4F4-45DC-9077-173B13FC89F1}] => C:\Program Files (x86)\Steam\steamapps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe FirewallRules: [UDP Query User{C7F328C5-3448-4E3B-8923-745F18B6B69D}C:\program files\java\jre1.8.0_77\bin\javaw.exe] => C:\program files\java\jre1.8.0_77\bin\javaw.exe FirewallRules: [TCP Query User{7B9E4ED8-B00E-4B6C-AD29-6D59094BC041}C:\program files\java\jre1.8.0_77\bin\javaw.exe] => C:\program files\java\jre1.8.0_77\bin\javaw.exe FirewallRules: [UDP Query User{3683ABD1-BC68-4613-9248-DAB35856F894}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [TCP Query User{4584F67A-7676-442A-8DFE-7786F2E6422F}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [{6CE777BD-F20F-495A-B551-91ECDB0A2B73}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{BF10500B-7853-4C35-9A4D-8BA2A1D76A8B}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{C0C18B0D-8D00-4AF6-BB0E-73A7768CD092}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{10139860-2EB1-45D7-89C5-D68DDB3974F9}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{6A20F085-40ED-4F64-A008-F40C99A6399A}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{782C462A-0BF5-4549-9D98-623647C71E54}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{41682100-C0DC-4C38-8168-F54C65A31801}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{21C35BA2-02D4-4151-BB19-635617D0568E}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{C3EAFBB4-815A-4983-87F5-06A0FED02851}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{585C2009-6DD4-4CF9-88E9-3064555B8202}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{F00BF74C-F4D0-4581-A49F-1DF81B19B1BA}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{8C1A674C-3E46-40CD-B3CA-E22B5D8236BF}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{FD61E35D-3DC2-4A77-98B4-8ACC077D6011}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{6B1F40FB-A095-43E7-9ADD-8C14ADBBDD0D}] => C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [UDP Query User{6DA33C40-3A41-4E03-BB49-B35B54C7167C}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [TCP Query User{83C9BC60-7DF4-4BCA-ADF3-C6150DB744C8}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{7358A27E-138E-4010-8E38-4FC515D76BB6}] => C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe FirewallRules: [{335B9884-E9BE-4BCF-9B0F-269CA40E0C7A}] => C:\Program Files (x86)\Steam\steamapps\common\Shakes & Fidget\Shakes and Fidget.exe FirewallRules: [UDP Query User{EB46B116-E7A9-4D33-B690-D2DB686FC6DE}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{25921E86-572F-4994-9C7C-3980BFE43D08}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{D5FC44E7-B5CC-40F9-AFAD-080B59F5EC66}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{A155E99F-64CB-4D38-9F73-23E607304839}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{D5F55766-8EDC-4B27-B5DC-8036A86BEA58}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{BE0690AF-EC4A-4327-AE4C-112C86A23A26}C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{D107C374-1551-40C4-AC0F-256F7DFF0D42}C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{1FDAAFEC-507D-4409-9134-E0C2C27393EA}C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\moritz\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{A0B0DCCF-8216-46FC-A565-7BB7157044AF}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{CDFFADA9-4E90-41E4-A78A-F7323A2F1862}C:\users\moritz\appdata\roaming\spotify\spotify.exe] => C:\users\moritz\appdata\roaming\spotify\spotify.exe FirewallRules: [{F966CE5A-21BB-4D85-8E70-5486993429B0}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [{B3F90A16-384F-4FD7-911B-6893AE3705E1}] => C:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe FirewallRules: [UDP Query User{7A5B186C-42F8-4A6C-A004-BEF58410831D}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [TCP Query User{76C38497-D952-4C31-829E-24F515DC48F3}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{B3EFC0CB-D60F-4A2C-978E-A7ED96F593AA}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{01D94F18-D1F6-462B-9665-9ED85762D28E}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0A7572F5-F406-467C-818D-6377BD0BABF3}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{7EBEC089-B19F-4BF1-8EB2-43E8C0B9040D}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{702BC7BD-5D0C-4D79-A410-ED88619871AE}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{CB550C66-A6F9-44AF-BEB1-5CEA66134640}] => C:\Program Files (x86)\Steam\steamapps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{3E31854E-0C16-4180-BEAD-3FD58B0FE854}] => C:\Program Files (x86)\Steam\steamapps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{AA95820B-D85B-4D30-97CF-8D4CA424CA37}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{280EDB2E-0E0D-4FBF-9106-C5E119691307}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{FCD9861F-DA32-499F-8B21-3B043D56AE26}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{49B3847A-833D-4400-B6B7-DBD7B22C98D4}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D738736C-DC9E-4B28-83A6-A3720EEDC79A}] => C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{126FA278-51A6-4ACE-BABC-A6336844C571}] => C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{BB3B13F8-0DA7-4649-8072-BD4BCDA38CAD}] => C:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{61FF8878-D5AC-4109-B189-568AC4D1EE50}] => C:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [TCP Query User{7C1DE088-EA81-4EE5-AD2C-AC18A5D516FA}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{16B7420E-25A3-4586-A99D-FE0FB0388B17}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [{B354E948-19B1-4508-8F39-7880B00E9535}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [{8E35D1DC-0DA9-46C3-834E-0D4DE55DBE93}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [TCP Query User{C0052537-C009-4AF4-8BFE-AE488884B62E}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{08FF909C-48FD-42A2-BFC9-BD19D747E47E}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{F929E1A5-48A6-4DF2-8214-D9910E425982}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [UDP Query User{CB57CC95-700D-456C-B147-3F13FB86368B}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [{B1E04A7D-2190-42B0-BF88-A4F4D1868580}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe FirewallRules: [{8FCCBCCA-7344-497C-A379-C3C1AFC1C5BA}] => C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe FirewallRules: [{FA2AE04F-9F73-448C-8091-0A2F53EDE480}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{7D4FACC6-D66D-41E7-9B1B-831F7376E15B}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [TCP Query User{CED088EC-A141-41D6-ADA8-A87A09F322C2}C:\program files (x86)\overwatch test\overwatch.exe] => C:\program files (x86)\overwatch test\overwatch.exe FirewallRules: [UDP Query User{52083AF1-D427-42FF-8191-DE30757A40EF}C:\program files (x86)\overwatch test\overwatch.exe] => C:\program files (x86)\overwatch test\overwatch.exe ==================== Wiederherstellungspunkte ========================= 09-12-2016 16:31:31 OpenOffice 4.1.3 wird entfernt 11-12-2016 11:10:43 Removed Amazon 1Button App ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (12/11/2016 10:58:27 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Moritz\Downloads\esetsmartinstaller_deu (1).exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 10:58:27 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Moritz\Downloads\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 10:50:32 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 08:12:07 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 08:11:12 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Moritz\Downloads\esetsmartinstaller_deu (1).exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 08:10:56 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Moritz\Downloads\esetsmartinstaller_deu (1).exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 08:09:59 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 08:09:46 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\eset\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 08:06:10 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Error: (12/11/2016 08:05:34 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Systemfehler: ============= Error: (12/11/2016 08:11:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (12/11/2016 08:11:50 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Moritz\AppData\Local\Temp\ehdrv.sys Error: (12/11/2016 08:11:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (12/11/2016 08:11:49 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Moritz\AppData\Local\Temp\ehdrv.sys Error: (12/11/2016 08:11:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (12/11/2016 08:11:49 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Moritz\AppData\Local\Temp\ehdrv.sys Error: (12/11/2016 08:11:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (12/11/2016 08:11:49 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Moritz\AppData\Local\Temp\ehdrv.sys Error: (12/11/2016 08:11:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (12/11/2016 08:11:48 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Moritz\AppData\Local\Temp\ehdrv.sys CodeIntegrity: =================================== Date: 2016-12-11 11:47:36.891 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2016-12-11 11:47:36.891 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:23:20.954 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:19.180 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:19.161 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:15.030 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 21:22:15.008 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:47:02.958 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:47:02.940 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. Date: 2016-12-07 17:40:33.287 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\ProgramData\SecurityUtility\ZZYWNZCC64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: AMD FX(tm)-4300 Quad-Core Processor Prozentuale Nutzung des RAM: 50% Installierter physikalischer RAM: 8140.34 MB Verfügbarer physikalischer RAM: 4046.76 MB Summe virtueller Speicher: 10520.17 MB Verfügbarer virtueller Speicher: 5388.96 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:1862.46 GB) (Free:1606.81 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ==================== Ende von Addition.txt ============================ |
11.12.2016, 23:47 | #15 |
/// Malwareteam | wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichtsHast du noch irgendwelche Probleme mit deinem Rechner?
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
Themen zu wajam nich deinstallieren,falsche fenster im browser öffnen sich, malware nachrichten, windowsdefender findet nichts |
anderes, anmelden, anti-malware, browser, bullguard, daten, falsche, fehlermeldung, herunterfahren, hilfe, internetseite, irql, malware, melden, nichts, not, problem, programm, programme, rechner, reset, schutz, seite, virenscanner ergebnislos, wajam, wajam etfernen, werbung, windows, öffnen |