![]() |
Log-Analyse und Auswertung: Gaming Laptop mit Win10 Home wird immer langsamerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
![]() | #1 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hi, hab leider seit einiger Zeit das Problem das mein Rechner immer langsammer wird. Asus ROG G751JY-T7328T 43,9 cm (17,3 Zoll mattes FHD) Notebook (Intel Core i7-4720HQ, 16GB RAM, 1TB HDD+ 256GB SSD, NVIDIA GeForce GTX 980. Auch die Eingabe hier lagt um so stärker um so länger der Rechner läuft scheinbar. Betroffen auch Firefox etc. und das Windows Menue links unten, dauert beim öffnen und hängt dann Hab schon Adware , Malewarebyte und AVG verwendet, welche das eine oder andere gefunden und entfernt haben, das aber scheinbar nicht ie Ursache ist. Weis leider nicht was ich noch drüber laufen lassen soll..... Allerdings habe ich keinen Skill die FRST liste zu filtern, wo der "Hacken" steckt. ![]() |
![]() | #2 |
/// Malwareteam ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer![]() Mein Name ist Dennis und ich werde dir bei der Bereinigung helfen. Bitte beachte, dass es ein paar Regeln gibt:
Sollte ich nicht innerhalb von 48h antworten, schreibe mir eine PM! Schritt # 1: Posten in CODE-Test ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Wir benötigen für eine sinnvolle Analyse zuerst ein FRST-Log. Schritt # 1: FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Schritt # 2: Bitte Posten
__________________ |
![]() | #3 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hi Dennis vielen Dank schon mal.
__________________Hier die Daten. By the way, gibt es auch eine "wie helf ich mir selbst Anleitung" Soll heisen wie werte ich die Protokolle aus und entscheide mit welchem Schritten Tools ich weiter mache? Hab aus andere Threats einiges adaptiert, leider mit wenig Erfog für meine Probs. (P.s weis natürlich nicht obs wirklich ein Virus ist) FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 01-01-2017 durchgeführt von Magic (Administrator) auf OUTLAW (04-01-2017 20:47:14) Gestartet von C:\Users\Magic\Downloads\Spam entfernen Geladene Profile: Magic (Verfügbare Profile: Magic) Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe () C:\Program Files (x86)\Lexware\AAVUpdateManager\aavus.exe (ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\\AsusWSWinService.exe () C:\Windows\SysWOW64\ASGT.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (StagWare) C:\Program Files (x86)\NoteBook FanControl\NbfcService.exe (Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (CyberLink) C:\Program Files\CyberLink\Shared files\RichVideo64.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Windows\SysWOW64\UMonit64.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\SpotifyCrashService.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe (AppWork GmbH) C:\Users\Magic\AppData\Local\JDownloader v2.0\JDownloader2.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe () C:\ProgramData\firemin_2086\Firemin.exe () C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe (Heiko Sommerfeldt) C:\Program Files (x86)\PhonerLite\PhonerLite.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [UMonit] => C:\WINDOWS\SysWOW64\UMonit64.exe [53832 2015-07-16] () HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-08-26] (NVIDIA Corporation) HKLM-x32\...\Run: [ROGNB] => C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe [463872 2013-05-15] () HKLM-x32\...\Run: [ASUS ROG MacroKey] => C:\Program Files (x86)\ASUS\ASUS ROG MacroKey\Hid.exe [2036224 2014-07-30] (ASUS) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Run: [Spotify Web Helper] => C:\Users\Magic\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-23] (Spotify Ltd) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Run: [Spotify] => C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe [7153264 2016-12-23] (Spotify Ltd) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\MountPoints2: {0941fcab-5bc4-11e4-8252-806e6f6e6963} - "G:\setup.exe" Lsa: [Notification Packages] ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) Startup: C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Firemin.lnk [2016-12-27] ShortcutTarget: Firemin.lnk -> C:\ProgramData\firemin_2086\Firemin.exe () ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{5c03a8e7-7c1d-473a-a896-16f731705c55}: [DhcpNameServer] Tcpip\..\Interfaces\{757bfc45-60e4-46e3-904d-5b95852b4717}: [DhcpNameServer] Tcpip\..\Interfaces\{917549de-333b-4c66-96de-c24c7380048d}: [DhcpNameServer] Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {89A7941E-C9C5-4D83-A5C6-E0C6803564A7} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {B04CD7FA-8569-4EA1-9969-7D1FC2BC81A8} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {B1CCEA68-E65F-43F7-B333-F36D145B95AA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {D54C87D2-13A5-4BF7-A4D4-C48F2BAC633C} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-06] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-06] (Oracle Corporation) FireFox: ======== FF DefaultProfile: ozg7dh2g.default FF ProfilePath: C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default [2017-01-04] FF user.js: detected! => C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\user.js [2016-12-27] FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\ozg7dh2g.default -> FF SearchEngineOrder.2: Mozilla\Firefox\Profiles\ozg7dh2g.default -> FF SearchEngineOrder.US.1: Mozilla\Firefox\Profiles\ozg7dh2g.default -> FF Homepage: Mozilla\Firefox\Profiles\ozg7dh2g.default -> about:home FF Session Restore: Mozilla\Firefox\Profiles\ozg7dh2g.default -> ist aktiviert. FF Extension: (AdBlocker Ultimate) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\adblockultimate@adblockultimate.net.xpi [2016-12-28] FF Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\firefox@zenmate.com.xpi [2016-09-30] FF Extension: (WhatsApp Panel) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\whatsapppanel@alejandrobrizuela.com.ar.xpi [2016-04-28] FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2016-08-27] FF Extension: (Flash Updater Pro) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{27cfe898-bf77-41da-8fd1-5ff664ac0003}.xpi [2015-12-19] [ist nicht signiert] FF Extension: (HTML5 Converter) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{2e2632fa-3b8f-4f13-94f9-69d6eb4c505e}.xpi [2016-05-29] [ist nicht signiert] FF Extension: (Video DownloadHelper) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-12-30] FF Extension: (Adblock Plus) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24] FF Extension: (OkayFreedom) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi [2016-12-22] FF Extension: (Tab Manager) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{de51b06d-3899-422c-9909-4e7edb0f4bae}.xpi [2015-12-25] [ist nicht signiert] FF Extension: (Web2PDF converter) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi [2016-04-28] FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Privacy Suite 17\spmplugin3 FF Extension: (Kein Name) - C:\Program Files (x86)\Steganos Privacy Suite 17\spmplugin3 [2015-12-31] [ist nicht signiert] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-21] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-21] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-10-23] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-10-23] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-06] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-06] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-25] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-25] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-12-20] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-12-20] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] () FF Plugin HKU\S-1-5-21-2786200759-2278858845-1295660402-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-06-18] () ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AAV UpdateService; C:\Program Files (x86)\Lexware\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [Datei ist nicht signiert] R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\\AsusWSWinService.exe [71680 2014-02-25] (ASUS Cloud Corporation) [Datei ist nicht signiert] S2 AsusGameFirstService; C:\Program Files (x86)\ASUS\ROG Game First III\AsusGameFirstService.exe [345912 2014-08-29] (ASUSTeK) S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [971160 2016-12-15] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5337600 2016-12-15] (AVG Technologies CZ, s.r.o.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [725976 2016-12-15] (AVG Technologies CZ, s.r.o.) S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [486936 2016-12-13] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [470552 2016-12-13] (BlueStack Systems, Inc.) S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [511512 2016-12-13] (BlueStack Systems, Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [42096 2016-12-21] (Dropbox, Inc.) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [344288 2015-03-20] (Futuremark) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-28] (WildTangent) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Datei ist nicht signiert] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel(R) Corporation) [Datei ist nicht signiert] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-10-23] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-10-23] (Intel Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 NbfcService; C:\Program Files (x86)\NoteBook FanControl\NbfcService.exe [7168 2015-05-09] (StagWare) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-08-26] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-08-26] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-08-26] (NVIDIA Corporation) R2 OkayFreedom VPN Starter Service; C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe [353792 2016-11-09] (Steganos Software GmbH) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-12-20] () R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2014-10-20] (CyberLink) R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-03] (DEVGURU Co., LTD.) S3 ThunderboltService; C:\Program Files\Intel\Thunderbolt Software\tbtsvc.exe [1179944 2014-05-13] (Intel Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [4788496 2016-11-25] (AVG Technologies CZ, s.r.o.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580144 2015-08-06] (WiseCleaner.com) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [19768 2013-07-02] (ASUSTek Computer Inc.) S0 Avgboota; C:\WINDOWS\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\WINDOWS\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdrivera.sys [312576 2016-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\WINDOWS\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\WINDOWS\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\WINDOWS\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\WINDOWS\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\WINDOWS\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.) R0 Avguniva; C:\WINDOWS\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys [313096 2016-08-04] (AVG Technologies CZ, s.r.o.) S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-12-13] (BlueStack Systems) S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-11-08] (Bluestack System Inc. ) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 GeneStor; C:\WINDOWS\system32\DRIVERS\GeneStor.sys [115704 2015-07-16] (GenesysLogic) R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2015-11-20] (Glarysoft Ltd) R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230144 2016-11-11] (Intel Corporation) R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [88256 2015-06-09] (Intel Corporation) R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-01-03] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 NETwNb64; C:\WINDOWS\system32\DRIVERS\Netwbw02.sys [4112656 2015-09-23] (Intel Corporation) R1 NFC_Driver; C:\WINDOWS\System32\drivers\NFC_Driver.sys [48336 2014-03-27] (Titan ARC Corp.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_fd2cdd92cf7ee187\nvlddmkm.sys [14216760 2016-08-27] (NVIDIA Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-08-26] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-06-03] (NVIDIA Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [896272 2016-01-19] (Realtek ) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-11-25] (AVG Netherlands B.V.) S1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-09-08] (Oracle Corporation) R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [146072 2015-09-08] (Oracle Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R1 WinRing0_1_2_0; C:\Program Files (x86)\NoteBook FanControl\WinRing0x64.sys [14544 2015-06-02] (OpenLibSys.org) R2 WiseFs; C:\Windows\WiseFs64.sys [13264 2015-12-29] (WiseCleaner.com) S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2015-12-23] (wisecleaner.com) R1 WiseUnlock; C:\Windows\WiseUnlock64.sys [12240 2015-05-19] (WiseCleaner.com) S3 dbx; system32\DRIVERS\dbx.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-04 20:40 - 2017-01-04 20:47 - 00000000 ____D C:\FRST 2017-01-02 00:11 - 2017-01-02 00:12 - 05419373 _____ C:\Users\Magic\Downloads\Outdoor und Wander- Navigation v1.5.0 (Full).zip 2017-01-01 20:21 - 2017-01-01 20:21 - 00000000 ____D C:\Program Files (x86)\ESET 2017-01-01 19:16 - 2017-01-01 19:16 - 00000767 _____ C:\Users\Public\Desktop\HELI-X6.1.lnk 2017-01-01 19:16 - 2017-01-01 19:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HELI-X6.1 2017-01-01 19:13 - 2017-01-01 19:14 - 00000000 ____D C:\Users\Magic\Downloads\Devo 7 2017-01-01 12:46 - 2017-01-01 12:46 - 06798851 _____ C:\Users\Magic\Downloads\tm-fon.zip 2017-01-01 10:53 - 2017-01-01 19:14 - 161052285 _____ (HELI-X.net ) C:\Users\Magic\Downloads\setupHeli-X61_win64.exe 2016-12-31 21:52 - 2016-12-31 21:52 - 00001229 _____ C:\Users\Public\Desktop\FileRestorePlus.lnk 2016-12-31 21:36 - 2016-12-31 21:51 - 03366304 _____ (Copyright © 2010 eSupport.com • All Rights Reserved ) C:\Users\Magic\Downloads\FileRestorePlus06_setup.exe 2016-12-31 03:16 - 2016-12-31 03:16 - 00000000 ____D C:\Program Files\CloneSpy 2016-12-31 03:09 - 2016-12-31 03:15 - 04473411 _____ (Marcus Kleinehagenbrock) C:\Users\Magic\Downloads\cspy331.exe 2016-12-31 02:25 - 2016-12-31 21:51 - 00000000 ____D C:\Program Files\Recuva 2016-12-31 02:25 - 2016-12-31 02:25 - 00001701 _____ C:\Users\Public\Desktop\Recuva.lnk 2016-12-31 02:25 - 2016-12-31 02:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva 2016-12-31 02:24 - 2016-12-31 02:24 - 05562976 _____ (Piriform Ltd) C:\Users\Magic\Downloads\rcsetup153.exe 2016-12-31 01:24 - 2016-12-31 01:24 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp.lnk 2016-12-31 01:24 - 2016-12-31 01:24 - 00002576 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk 2016-12-31 01:24 - 2016-11-25 13:45 - 00053008 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\TURegOpt.exe 2016-12-31 00:04 - 2016-12-31 00:04 - 00000000 ____D C:\Users\Magic\AppData\Local\Apple Computer 2016-12-30 12:00 - 2016-12-30 12:00 - 00003976 _____ C:\WINDOWS\System32\Tasks\Update Checker 2016-12-30 11:10 - 2016-12-30 11:12 - 00000000 ____D C:\Users\Magic\Downloads\Android 2016-12-29 23:48 - 2016-12-29 23:49 - 00098822 _____ C:\TDSSKiller. 2016-12-29 23:47 - 2016-12-29 23:48 - 00114772 _____ C:\TDSSKiller. 2016-12-29 22:50 - 2017-01-01 15:35 - 00003320 _____ C:\WINDOWS\PFRO.log 2016-12-29 22:47 - 2017-01-04 20:47 - 00000000 ____D C:\Users\Magic\Downloads\Spam entfernen 2016-12-29 21:48 - 2017-01-04 20:20 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log 2016-12-29 20:30 - 2016-12-31 02:44 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2016-12-29 20:29 - 2016-12-31 02:44 - 00000000 ____D C:\Users\Magic\Desktop\mbar 2016-12-29 18:19 - 2016-12-29 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts 2016-12-29 18:18 - 2016-12-29 18:18 - 00000695 _____ C:\Users\Magic\Desktop\Play Star Wars Jedi Knight Jedi Academy.lnk 2016-12-29 15:28 - 2016-12-29 15:28 - 00000000 ____D C:\Users\Public\Desktop\SWAT 4 Gold Edition 2016-12-29 15:28 - 2016-12-29 15:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWAT 4 Gold Edition 2016-12-29 14:45 - 2016-12-29 14:45 - 00231961 _____ C:\Users\Magic\Downloads\20161228125550157.pdf 2016-12-29 13:29 - 2016-12-29 13:29 - 00351824 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-12-29 02:16 - 2017-01-03 01:34 - 01131652 ____H C:\Users\Magic\AppData\Local\IconCache.db 2016-12-29 01:30 - 2016-12-29 01:30 - 00000000 ____D C:\Users\Magic\AppData\Local\AVG Netherlands BV 2016-12-28 21:22 - 2017-01-02 22:22 - 00000000 ___HD C:\$AVG 2016-12-28 21:01 - 2016-12-28 21:01 - 00000829 _____ C:\Users\Public\Desktop\Hitman Codename 47.lnk 2016-12-28 21:01 - 2016-12-28 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hitman Codename 47 [GOG.com] 2016-12-28 19:15 - 2016-12-28 19:15 - 00000842 _____ C:\Users\Magic\Desktop\The Evil Within Language Selector.lnk 2016-12-28 19:15 - 2016-12-28 19:15 - 00000815 _____ C:\Users\Magic\Desktop\The Evil Within.lnk 2016-12-28 17:35 - 2016-12-28 17:35 - 00000905 _____ C:\Users\Magic\Desktop\Call of Duty Modern Warfare 3.lnk 2016-12-28 15:54 - 2016-12-28 18:34 - 00000000 ____D C:\Users\Magic\Downloads\Bilder 2016-12-27 22:52 - 2016-12-27 22:52 - 00003798 _____ C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater 2016-12-27 15:11 - 2016-12-27 15:11 - 00001221 _____ C:\Users\Magic\Desktop\Firemin.lnk 2016-12-27 14:41 - 2016-12-27 15:10 - 00000000 ____D C:\ProgramData\firemin_2086 2016-12-27 00:43 - 2016-12-27 00:44 - 00000000 ____D C:\Users\Magic\Downloads\Polarlichter 2016-12-26 02:25 - 2017-01-03 01:33 - 00000000 ____D C:\AdwCleaner 2016-12-26 01:58 - 2016-12-26 01:58 - 00000000 ____D C:\WINDOWS\Panther 2016-12-24 23:16 - 2016-07-01 04:31 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StikyNot.exe 2016-12-24 23:16 - 2015-10-30 19:34 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StikyNot.exe.mui 2016-12-24 20:42 - 2016-11-23 14:37 - 00000570 _____ C:\Users\Magic\AppData\Local\TroubleshooterConfig.json 2016-12-24 20:41 - 2016-12-24 20:42 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2016-12-24 20:41 - 2016-12-24 20:41 - 00001648 _____ C:\Users\Public\Desktop\BlueStacks.lnk 2016-12-24 20:41 - 2016-12-24 20:41 - 00001648 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk 2016-12-24 20:40 - 2016-12-24 20:40 - 00000000 ____D C:\Users\Magic\AppData\Local\Bluestacks 2016-12-24 20:39 - 2016-12-24 20:41 - 00000000 ____D C:\Program Files (x86)\Bluestacks 2016-12-24 20:39 - 2016-12-13 18:27 - 00000000 ____D C:\ProgramData\Bluestacks 2016-12-24 13:59 - 2016-12-24 13:59 - 00000000 ____D C:\Users\Magic\AppData\Local\Chromium 2016-12-24 13:02 - 2016-12-24 13:02 - 00000774 _____ C:\Users\Public\Desktop\Office Vorlagen Teil 2.lnk 2016-12-23 15:14 - 2016-12-24 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis 2016-12-23 15:14 - 2016-12-23 15:14 - 00000774 _____ C:\Users\Public\Desktop\Office Vorlagen Teil 1.lnk 2016-12-23 14:38 - 2016-12-23 14:38 - 00000000 ____D C:\ProgramData\Logs 2016-12-23 12:04 - 2016-12-23 12:04 - 16752312 _____ C:\Users\Magic\Downloads\gup566setup_chip.exe 2016-12-23 00:30 - 2016-12-23 00:30 - 00000000 ____D C:\Users\Magic\AppData\Local\Zak2 2016-12-23 00:19 - 2016-12-23 00:19 - 00000611 _____ C:\Users\Magic\Desktop\Zak McKracken – Between Time and Space.lnk 2016-12-23 00:19 - 2016-12-23 00:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zak McKracken – Between Time and Space 2016-12-22 23:34 - 2016-12-26 01:58 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Steganos VPN 2016-12-22 23:34 - 2016-12-22 23:35 - 00000000 ____D C:\Program Files (x86)\OkayFreedom 2016-12-22 23:34 - 2016-12-22 23:34 - 00001148 _____ C:\Users\Public\Desktop\OkayFreedom.lnk 2016-12-22 23:34 - 2016-12-22 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom 2016-12-22 20:53 - 2016-12-22 20:53 - 00000786 _____ C:\Users\Public\Desktop\Dreamfall The Longest Journey.lnk 2016-12-22 20:53 - 2016-12-22 20:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dreamfall The Longest Journey 2016-12-22 11:15 - 2016-12-22 11:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-12-21 19:15 - 2016-12-21 19:15 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2016-12-21 19:15 - 2016-12-21 19:15 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2016-12-21 19:15 - 2016-12-21 19:15 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2016-12-21 19:15 - 2016-12-21 19:15 - 00042096 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2016-12-21 14:47 - 2016-12-21 14:47 - 00004042 _____ C:\WINDOWS\System32\Tasks\Wise Turbo Checker.job 2016-12-21 13:37 - 2016-12-09 11:32 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-12-21 13:37 - 2016-12-09 11:29 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-12-21 13:37 - 2016-12-09 11:19 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-12-21 13:37 - 2016-12-09 11:18 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2016-12-21 13:37 - 2016-12-09 11:18 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2016-12-21 13:37 - 2016-12-09 11:18 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi 2016-12-21 13:37 - 2016-12-09 11:18 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe 2016-12-21 13:37 - 2016-12-09 11:15 - 08168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-12-21 13:37 - 2016-12-09 11:15 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-12-21 13:37 - 2016-12-09 11:14 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-12-21 13:37 - 2016-12-09 11:01 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2016-12-21 13:37 - 2016-12-09 11:01 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-12-21 13:37 - 2016-12-09 10:57 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-12-21 13:37 - 2016-12-09 10:52 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2016-12-21 13:37 - 2016-12-09 10:51 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll 2016-12-21 13:37 - 2016-12-09 10:45 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll 2016-12-21 13:37 - 2016-12-09 10:41 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll 2016-12-21 13:37 - 2016-12-09 10:38 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2016-12-21 13:37 - 2016-12-09 10:37 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-12-21 13:37 - 2016-12-09 10:33 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-12-21 13:37 - 2016-12-09 10:33 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2016-12-21 13:37 - 2016-12-09 10:31 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-12-21 13:37 - 2016-12-09 10:30 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-12-21 13:37 - 2016-12-09 10:28 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-12-21 13:37 - 2016-12-09 10:27 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2016-12-21 13:37 - 2016-12-09 10:26 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-12-21 13:37 - 2016-12-09 10:24 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-12-21 13:37 - 2016-12-09 10:23 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-12-21 13:37 - 2016-12-09 10:22 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-12-21 13:37 - 2016-12-09 10:22 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll 2016-12-21 13:37 - 2016-12-09 10:18 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-12-21 13:37 - 2016-12-09 10:16 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2016-12-21 13:37 - 2016-12-09 10:15 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-12-21 13:37 - 2016-12-09 10:15 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2016-12-21 13:37 - 2016-12-09 10:15 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll 2016-12-21 13:37 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2016-12-21 13:37 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2016-12-21 13:37 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2016-12-21 13:37 - 2016-11-11 11:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2016-12-21 13:37 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-12-21 13:37 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-12-21 13:37 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2016-12-21 13:37 - 2016-11-11 10:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-12-21 13:37 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2016-12-21 13:37 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-12-21 13:37 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe 2016-12-21 13:37 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll 2016-12-21 13:37 - 2016-11-11 10:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-12-21 13:37 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2016-12-21 13:37 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-12-21 13:37 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2016-12-21 13:37 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll 2016-12-21 13:37 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2016-12-21 13:37 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys 2016-12-21 13:37 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-12-21 13:37 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-12-21 13:37 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-12-21 13:37 - 2016-11-11 10:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-12-21 13:37 - 2016-11-11 10:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-12-21 13:37 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2016-12-21 13:37 - 2016-11-11 10:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-12-21 13:37 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-12-21 13:37 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-12-21 13:37 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-21 13:37 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2016-12-21 13:37 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-12-21 13:37 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-12-21 13:37 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-12-21 13:37 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll 2016-12-21 13:37 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-12-21 13:37 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-12-21 13:37 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-12-21 13:37 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-12-21 13:37 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-12-21 13:37 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-12-21 13:37 - 2016-11-11 10:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2016-12-21 13:37 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-12-21 13:37 - 2016-11-11 10:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-12-21 13:37 - 2016-11-11 10:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-12-21 13:37 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-12-21 13:37 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-12-21 13:37 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2016-12-21 13:37 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll 2016-12-21 13:37 - 2016-11-11 08:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2016-12-21 13:37 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-12-21 13:37 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-12-21 13:37 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll 2016-12-21 13:37 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-12-21 13:37 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe 2016-12-21 13:37 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-12-21 13:37 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-12-21 13:37 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-12-21 13:37 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-12-21 13:37 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-12-21 13:37 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-12-21 13:37 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-12-21 13:37 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-12-21 13:37 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-12-21 13:37 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-12-21 13:37 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2016-12-21 13:37 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-12-21 13:37 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-12-21 13:37 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2016-12-21 13:37 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2016-12-21 13:37 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2016-12-21 13:37 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-12-21 13:37 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2016-12-21 13:37 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2016-12-21 13:37 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2016-12-21 13:37 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-12-21 13:37 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-12-21 13:37 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-12-21 13:37 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2016-12-21 13:37 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-12-21 13:37 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll 2016-12-21 13:37 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-12-21 13:37 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-12-21 13:37 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll 2016-12-21 13:37 - 2016-11-11 08:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-12-21 13:37 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2016-12-21 13:37 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2016-12-21 13:37 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll 2016-12-21 13:37 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-12-21 13:37 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2016-12-21 13:37 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-12-21 13:37 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-12-21 13:37 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-12-21 13:37 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-12-21 13:36 - 2016-12-09 11:42 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2016-12-21 13:36 - 2016-12-09 11:42 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2016-12-21 13:36 - 2016-12-09 11:34 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-12-21 13:36 - 2016-12-09 11:34 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-12-21 13:36 - 2016-12-09 11:33 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-12-21 13:36 - 2016-12-09 11:33 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-12-21 13:36 - 2016-12-09 11:30 - 00377184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2016-12-21 13:36 - 2016-12-09 11:28 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-12-21 13:36 - 2016-12-09 11:19 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll 2016-12-21 13:36 - 2016-12-09 11:18 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-12-21 13:36 - 2016-12-09 11:18 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-12-21 13:36 - 2016-12-09 11:18 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-12-21 13:36 - 2016-12-09 11:14 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2016-12-21 13:36 - 2016-12-09 11:10 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2016-12-21 13:36 - 2016-12-09 11:10 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2016-12-21 13:36 - 2016-12-09 11:09 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2016-12-21 13:36 - 2016-12-09 11:01 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-12-21 13:36 - 2016-12-09 11:00 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll 2016-12-21 13:36 - 2016-12-09 10:59 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-12-21 13:36 - 2016-12-09 10:59 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-12-21 13:36 - 2016-12-09 10:57 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-12-21 13:36 - 2016-12-09 10:52 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2016-12-21 13:36 - 2016-12-09 10:45 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-12-21 13:36 - 2016-12-09 10:41 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-12-21 13:36 - 2016-12-09 10:40 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-12-21 13:36 - 2016-12-09 10:37 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-12-21 13:36 - 2016-12-09 10:34 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-12-21 13:36 - 2016-12-09 10:31 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-12-21 13:36 - 2016-12-09 10:30 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-12-21 13:36 - 2016-12-09 10:29 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-12-21 13:36 - 2016-12-09 10:28 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-12-21 13:36 - 2016-12-09 10:27 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-12-21 13:36 - 2016-12-09 10:27 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2016-12-21 13:36 - 2016-12-09 10:22 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-12-21 13:36 - 2016-12-09 10:21 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-12-21 13:36 - 2016-12-09 10:21 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-12-21 13:36 - 2016-12-09 10:20 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2016-12-21 13:36 - 2016-12-09 10:20 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-12-21 13:36 - 2016-12-09 10:20 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-12-21 13:36 - 2016-12-09 10:18 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-12-21 13:36 - 2016-12-09 10:17 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2016-12-21 13:36 - 2016-12-09 10:17 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-12-21 13:36 - 2016-12-09 10:16 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-12-21 13:36 - 2016-12-09 10:16 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-12-21 13:36 - 2016-12-09 09:54 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-12-21 13:36 - 2016-11-11 11:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2016-12-21 13:36 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2016-12-21 13:36 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-12-21 13:36 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-12-21 13:36 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-12-21 13:36 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll 2016-12-21 13:36 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-12-21 13:36 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-12-21 13:36 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-12-21 13:36 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-12-21 13:36 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-12-21 13:36 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2016-12-21 13:36 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-12-21 13:36 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-12-21 13:36 - 2016-11-11 10:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-12-21 13:36 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2016-12-21 13:36 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll 2016-12-21 13:36 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe 2016-12-21 13:36 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2016-12-21 13:36 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-12-21 13:36 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2016-12-21 13:36 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-12-21 13:36 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-12-21 13:36 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-12-21 13:36 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2016-12-21 13:36 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2016-12-21 13:36 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-12-21 13:36 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2016-12-21 13:36 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll 2016-12-21 13:36 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2016-12-21 13:36 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-12-21 13:36 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-12-21 13:36 - 2016-11-11 10:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-12-21 13:36 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-12-21 13:36 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2016-12-21 13:36 - 2016-11-11 10:18 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-12-21 13:36 - 2016-11-11 10:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-12-21 13:36 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-12-21 13:36 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll 2016-12-21 13:36 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-12-21 13:36 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll 2016-12-21 13:36 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-12-21 13:36 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2016-12-21 13:36 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2016-12-21 13:36 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-12-21 13:36 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-12-21 13:36 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-12-21 13:36 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2016-12-21 13:36 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-12-21 13:36 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-12-21 13:36 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll 2016-12-21 13:36 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-12-21 13:36 - 2016-11-11 09:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-12-21 13:36 - 2016-11-11 09:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2016-12-21 13:36 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2016-12-21 13:36 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-12-21 13:36 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-12-21 13:36 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-12-21 13:36 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-12-21 13:36 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-12-21 13:36 - 2016-11-11 08:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2016-12-21 13:36 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll 2016-12-21 13:36 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe 2016-12-21 13:36 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2016-12-21 13:36 - 2016-11-11 08:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-12-21 13:36 - 2016-11-11 08:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-12-21 13:36 - 2016-11-11 08:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-12-21 13:36 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2016-12-21 13:36 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2016-12-21 13:36 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-12-21 13:36 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2016-12-21 13:36 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-21 13:36 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2016-12-21 13:36 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2016-12-21 13:36 - 2016-11-11 08:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-12-21 13:36 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll 2016-12-21 13:36 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-12-21 13:36 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-12-21 13:36 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-12-21 13:36 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2016-12-21 13:35 - 2016-12-09 11:27 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll 2016-12-21 13:35 - 2016-12-09 11:20 - 02677544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2016-12-21 13:35 - 2016-12-09 11:20 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-12-21 13:35 - 2016-12-09 11:20 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-12-21 13:35 - 2016-12-09 11:20 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-12-21 13:35 - 2016-12-09 11:20 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-12-21 13:35 - 2016-12-09 11:11 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-12-21 13:35 - 2016-12-09 10:56 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-12-21 13:35 - 2016-12-09 10:47 - 22563328 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-12-21 13:35 - 2016-12-09 10:42 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-12-21 13:35 - 2016-12-09 10:37 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-12-21 13:35 - 2016-12-09 10:36 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2016-12-21 13:35 - 2016-12-09 10:34 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-12-21 13:35 - 2016-12-09 10:32 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-12-21 13:35 - 2016-12-09 10:31 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-12-21 13:35 - 2016-12-09 10:30 - 23677952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-12-21 13:35 - 2016-12-09 10:27 - 19417088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-12-21 13:35 - 2016-12-09 10:26 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-12-21 13:35 - 2016-12-09 10:25 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll 2016-12-21 13:35 - 2016-12-09 10:21 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-12-21 13:35 - 2016-12-09 10:21 - 01512960 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-12-21 13:35 - 2016-12-09 10:20 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-12-21 13:35 - 2016-12-09 10:20 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-12-21 13:35 - 2016-12-09 10:18 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-12-21 13:35 - 2016-11-11 11:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-12-21 13:35 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2016-12-21 13:35 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-12-21 13:35 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-12-21 13:35 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-12-21 13:35 - 2016-11-11 11:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-12-21 13:35 - 2016-11-11 10:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-12-21 13:35 - 2016-11-11 10:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2016-12-21 13:35 - 2016-11-11 10:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-12-21 13:35 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll 2016-12-21 13:35 - 2016-11-11 10:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-12-21 13:35 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-12-21 13:35 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-12-21 13:35 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-21 13:35 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-12-21 13:35 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-12-21 13:35 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2016-12-21 13:35 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2016-12-21 13:35 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2016-12-21 13:35 - 2016-11-11 10:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-12-21 13:35 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2016-12-21 13:35 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2016-12-21 13:35 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2016-12-21 13:35 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2016-12-21 13:35 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2016-12-21 13:35 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-12-21 13:35 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2016-12-21 13:35 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2016-12-21 13:35 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2016-12-21 13:35 - 2016-11-11 10:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-12-21 13:35 - 2016-11-11 10:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-12-21 13:35 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll 2016-12-21 13:35 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-12-21 13:35 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-12-21 13:35 - 2016-11-11 10:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-12-21 13:35 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-12-21 13:35 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2016-12-21 13:35 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-12-21 13:35 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2016-12-21 13:35 - 2016-11-11 08:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-12-21 13:35 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe 2016-12-21 13:35 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-21 13:35 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-12-21 13:35 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-12-21 13:35 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-12-21 13:35 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-12-21 02:38 - 2016-12-21 02:38 - 00001525 _____ C:\Users\Magic\Desktop\adwcleaner_6.041.lnk ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-04 20:26 - 2016-10-02 10:42 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Spotify 2017-01-04 20:20 - 2016-11-26 11:36 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-01-04 19:56 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-01-04 19:56 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-01-04 19:55 - 2016-11-26 11:42 - 00003550 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update1 2017-01-04 19:55 - 2016-11-26 11:42 - 00003540 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update2 2017-01-04 19:55 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2017-01-04 19:54 - 2015-12-24 21:09 - 00000000 ____D C:\ProgramData\MFAData 2017-01-04 19:52 - 2015-05-16 11:02 - 00000093 _____ C:\Users\Magic\AppData\Roaming\sp_data.sys 2017-01-04 19:51 - 2016-10-02 10:42 - 00000000 ____D C:\Users\Magic\AppData\Local\Spotify 2017-01-03 23:48 - 2016-11-26 11:42 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task 2017-01-03 22:00 - 2016-07-16 23:51 - 00839070 _____ C:\WINDOWS\system32\perfh007.dat 2017-01-03 22:00 - 2016-07-16 23:51 - 00183804 _____ C:\WINDOWS\system32\perfc007.dat 2017-01-03 22:00 - 2016-06-14 20:32 - 02094532 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-01-03 19:57 - 2015-06-20 20:25 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-01-03 19:57 - 2015-06-11 19:58 - 00000000 ____D C:\Users\Magic\AppData\Local\JDownloader v2.0 2017-01-03 19:55 - 2016-11-26 11:37 - 00000000 ____D C:\Users\Magic 2017-01-03 01:34 - 2016-11-26 11:42 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-01-03 01:34 - 2016-11-26 11:36 - 00000000 ____D C:\ProgramData\NVIDIA 2017-01-03 01:34 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2017-01-02 22:23 - 2016-04-16 21:29 - 00001011 _____ C:\Users\Public\Desktop\AVG Protection.lnk 2017-01-02 00:55 - 2015-06-10 21:37 - 00000000 ____D C:\Users\Magic\AppData\Roaming\vlc 2017-01-01 12:09 - 2016-04-16 18:14 - 00000000 ____D C:\Users\Magic\AppData\Roaming\PhonerLite 2016-12-31 17:23 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Pictures 2016-12-31 16:47 - 2015-12-24 21:05 - 00000000 ____D C:\Users\Magic\AppData\Local\AvgSetupLog 2016-12-31 03:16 - 2016-07-16 07:04 - 00000000 ___RD C:\Program Files 2016-12-31 02:15 - 2015-06-20 20:24 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-12-31 02:14 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Desktop 2016-12-30 20:01 - 2016-02-21 13:57 - 00000000 ____D C:\Users\Magic\Downloads\Musik Videos 2016-12-30 12:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\debug 2016-12-30 00:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Branding 2016-12-30 00:33 - 2013-08-22 16:36 - 00000000 ___RD C:\Users\Public\Documents 2016-12-29 22:53 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Tasks 2016-12-29 22:51 - 2015-12-23 23:56 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Wise Care 365 2016-12-29 22:51 - 2015-11-20 20:30 - 00000000 ____D C:\Program Files (x86)\Glary Utilities 5 2016-12-29 21:47 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Globalization 2016-12-29 20:30 - 2016-07-16 12:47 - 00000000 ___HD C:\ProgramData 2016-12-29 18:18 - 2014-10-24 22:28 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-12-29 13:43 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\config\RegBack 2016-12-29 13:29 - 2015-07-18 21:45 - 00001226 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 2016-12-29 02:16 - 2016-11-26 11:37 - 00524288 ___SH C:\Users\Magic\NTUSER.DAT{1560ce3f-b3c4-11e6-9fc7-baad05ad66c3}.TMContainer00000000000000000001.regtrans-ms 2016-12-29 01:39 - 2014-10-24 22:45 - 00000000 ____D C:\Program Files (x86)\Steam 2016-12-29 01:38 - 2015-06-21 16:59 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2016-12-28 23:06 - 2015-07-11 22:19 - 00000000 ____D C:\Users\Magic\dwhelper 2016-12-28 22:16 - 2016-11-26 11:42 - 00003740 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA 2016-12-28 22:16 - 2016-11-26 11:42 - 00003556 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-12-28 22:16 - 2016-11-26 11:42 - 00003332 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-12-28 22:16 - 2016-11-26 11:42 - 00002782 _____ C:\WINDOWS\System32\Tasks\ATK Package 36D18D69AFC3 2016-12-28 22:16 - 2016-11-26 11:42 - 00002224 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2016-12-28 22:16 - 2016-11-26 11:42 - 00002072 _____ C:\WINDOWS\System32\Tasks\ATK Package A22126881260 2016-12-28 20:13 - 2016-07-16 07:04 - 00000000 ____D C:\Program Files (x86)\Common Files 2016-12-28 20:02 - 2015-10-16 22:45 - 00000711 _____ C:\Users\Magic\Desktop\Fahrenheit.lnk 2016-12-28 19:33 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Saved Games 2016-12-28 18:31 - 2015-01-10 15:26 - 00000000 ____D C:\Users\Magic\Downloads\ZZR 1100 Werkstatthandbuch 2016-12-28 17:35 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\Logs 2016-12-28 16:03 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Documents 2016-12-28 15:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Music 2016-12-28 00:16 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\catroot2 2016-12-27 22:51 - 2016-11-20 11:57 - 00000000 ____D C:\Users\Magic\AppData\Local\Battle.net 2016-12-27 22:50 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2016-12-27 22:50 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-12-27 22:16 - 2015-12-24 21:07 - 00000000 ____D C:\ProgramData\Avg 2016-12-27 22:16 - 2015-12-24 21:07 - 00000000 ____D C:\Program Files (x86)\AVG 2016-12-27 22:16 - 2015-12-24 21:05 - 00000000 ____D C:\Users\Magic\AppData\Local\Avg 2016-12-27 17:51 - 2014-10-24 22:25 - 00000000 ____D C:\WINDOWS\SoftwareDistribution 2016-12-27 16:29 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2016-12-26 02:18 - 2016-10-03 11:13 - 00000000 ____D C:\Program Files\AdwCleaner 2016-12-26 02:06 - 2015-07-02 22:05 - 00000000 ____D C:\Program Files\CCleaner 2016-12-26 02:03 - 2015-07-02 22:05 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-12-26 01:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\LogFiles 2016-12-26 01:56 - 2015-12-20 00:23 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Steganos 2016-12-26 01:56 - 2015-12-20 00:22 - 00000000 ____D C:\Program Files (x86)\Steganos Privacy Suite 17 2016-12-26 01:56 - 2015-11-14 21:59 - 00002242 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-12-26 01:56 - 2015-11-14 21:59 - 00002242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-12-26 01:10 - 2015-07-14 19:37 - 00000000 ____D C:\Users\Magic\AppData\Local\Diagnostics 2016-12-26 00:39 - 2015-07-25 12:35 - 00000000 __RDO C:\Users\Magic\OneDrive 2016-12-26 00:38 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Searches 2016-12-26 00:28 - 2015-05-08 18:03 - 00000000 __SHD C:\System Volume Information 2016-12-25 23:46 - 2016-07-16 12:47 - 00000000 ___RD C:\Users\Public 2016-12-25 15:03 - 2016-07-16 07:04 - 42991616 _____ C:\WINDOWS\system32\config\COMPONENTS 2016-12-25 14:17 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-12-24 23:40 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64 2016-12-24 23:04 - 2016-11-26 11:37 - 00000000 ___HD C:\Users\Magic\AppData 2016-12-24 22:51 - 2015-07-11 22:35 - 00000000 ____D C:\ProgramData\Ashampoo 2016-12-24 20:41 - 2016-07-16 12:47 - 00000000 __RHD C:\Users\Public\Libraries 2016-12-24 19:10 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache 2016-12-24 17:43 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\config 2016-12-24 16:15 - 2016-11-26 11:37 - 00524288 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000002.regtrans-ms 2016-12-24 16:15 - 2016-11-26 11:37 - 00524288 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000001.regtrans-ms 2016-12-24 16:15 - 2016-11-26 11:37 - 00065536 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TM.blf 2016-12-24 14:50 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\WinSxS 2016-12-24 14:50 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\DriverStore 2016-12-24 14:44 - 2016-07-16 12:47 - 00000000 __RSD C:\WINDOWS\assembly 2016-12-24 14:00 - 2015-06-21 16:03 - 00000000 ____D C:\Users\Magic\AppData\Local\Steam 2016-12-23 20:57 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WDI 2016-12-23 20:56 - 2015-10-06 20:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-12-23 20:55 - 2016-11-26 12:05 - 00000174 ___SH C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini 2016-12-23 20:55 - 2016-11-26 12:05 - 00000000 ____D C:\Users\Magic\AppData\Local\PackageStaging 2016-12-23 20:55 - 2016-11-26 11:37 - 00000000 ___RD C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs 2016-12-23 20:55 - 2016-07-16 07:04 - 00262144 _____ C:\Users\Default\NTUSER.DAT 2016-12-23 20:55 - 2016-04-27 06:56 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-12-23 20:55 - 2015-05-16 11:02 - 00000402 ___SH C:\Users\Magic\Documents\desktop.ini 2016-12-23 20:55 - 2015-05-16 11:02 - 00000282 ___SH C:\Users\Magic\Downloads\desktop.ini 2016-12-23 20:55 - 2015-05-16 11:02 - 00000174 ___SH C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Videos 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Links 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Favorites 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Contacts 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2016-12-23 20:54 - 2016-11-26 11:35 - 00524288 ___SH C:\WINDOWS\system32\config\DRIVERS{f8d8b5e8-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000001.regtrans-ms 2016-12-23 20:54 - 2016-11-26 11:35 - 00065536 ___SH C:\WINDOWS\system32\config\DRIVERS{f8d8b5e8-4ba6-11e6-80cd-0026b955b121}.TM.blf 2016-12-23 20:53 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\config\TxR 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\de-DE 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\wbem 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-CS 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\de-DE 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Boot 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppPatch 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Internet Explorer 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Internet Explorer 2016-12-23 20:52 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-12-23 20:52 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-12-23 20:52 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing 2016-12-23 20:50 - 2016-07-16 12:47 - 00000796 ___SH C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini 2016-12-23 20:48 - 2016-03-02 21:16 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-12-22 23:37 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\CatRoot 2016-12-22 23:34 - 2016-11-26 11:37 - 00000000 ____D C:\Users\Magic\AppData\Roaming 2016-12-22 22:56 - 2016-07-16 07:04 - 00000000 ___RD C:\Users 2016-12-22 11:29 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-12-22 11:19 - 2015-06-02 21:31 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-12-22 11:15 - 2015-07-18 21:45 - 00000000 ____D C:\Program Files (x86)\Dropbox 2016-12-22 03:35 - 2015-06-02 21:31 - 135632432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-12-21 14:40 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files 2016-12-21 14:23 - 2016-11-26 11:42 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-12-21 14:23 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-12-21 14:23 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-12-21 13:17 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-12-20 15:27 - 2015-07-12 09:56 - 00000000 ____D C:\Users\Magic\AppData\Local\ElevatedDiagnostics 2016-12-20 14:24 - 2015-05-16 11:02 - 00000000 ____D C:\Users\Magic\AppData\Local\Packages 2016-12-12 00:56 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-12-12 00:56 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-05-16 11:02 - 2017-01-04 19:52 - 0000093 _____ () C:\Users\Magic\AppData\Roaming\sp_data.sys 2015-06-20 19:57 - 2015-06-20 19:57 - 0000122 _____ () C:\Users\Magic\AppData\Roaming\System Monitor II_UptimeRecord.ini 2015-05-31 20:15 - 2015-05-31 20:15 - 0007605 _____ () C:\Users\Magic\AppData\Local\Resmon.ResmonCfg 2016-12-24 20:42 - 2016-11-23 14:37 - 0000570 _____ () C:\Users\Magic\AppData\Local\TroubleshooterConfig.json 2016-11-26 11:37 - 2016-11-26 11:37 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2014-05-15 16:58 - 2012-09-07 12:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd 2014-05-15 16:58 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe 2014-05-15 16:58 - 2012-09-07 12:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS Einige Dateien in TEMP: ==================== C:\Users\Magic\AppData\Local\Temp\libeay32.dll C:\Users\Magic\AppData\Local\Temp\msvcr120.dll C:\Users\Magic\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-12-29 13:43 ==================== Ende von FRST.txt ============================ |
![]() | #4 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Part 2 FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 01-01-2017 durchgeführt von Magic (04-01-2017 20:49:13) Gestartet von C:\Users\Magic\Downloads\Spam entfernen Windows 10 Home Version 1607 (X64) (2016-11-26 10:57:10) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2786200759-2278858845-1295660402-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2786200759-2278858845-1295660402-503 - Limited - Disabled) Gast (S-1-5-21-2786200759-2278858845-1295660402-501 - Limited - Disabled) Magic (S-1-5-21-2786200759-2278858845-1295660402-1001 - Administrator - Enabled) => C:\Users\Magic ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG AntiVirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 10.000 Office Vorlagen Teil 1 (HKLM-x32\...\10.000 Office Vorlagen Teil 1_is1) (Version: - ) 10.000 Office Vorlagen Teil 2 (HKLM-x32\...\10.000 Office Vorlagen Teil 2_is1) (Version: - ) 3DMark (HKLM-x32\...\{f5aa1c48-f2dc-4f4f-a71d-65bd7d0dc5c5}) (Version: 1.5.893.0 - Futuremark) 3DMark (Version: 1.5.893.0 - Futuremark) Hidden 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) 7-Zip 9.38 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0938-000001000000}) (Version: - Igor Pavlov) 8GadgetPack (HKLM-x32\...\{CA2865AD-EFF4-44F0-A2C9-DCDC0A90F27E}) (Version: 14.0.0 - Helmut Buhler) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated) Alan Wake Complete Collection Version (HKLM-x32\...\{2DE8F160-BBFF-445B-8B8E-4092A1C106DA}_is1) (Version: - Remedy Entertainment) Aliens vs Predator Dedicated Server (HKLM-x32\...\Steam App 34120) (Version: - ) A-Men Technologies USB-to-Serial (HKLM-x32\...\{1805BD6D-C441-4A1C-802D-AFF0232DAACD}) (Version: - ) Ansel (Version: 372.70 - NVIDIA Corporation) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.) Arma 3 Server (HKLM-x32\...\Steam App 233780) (Version: - Bohemia Interactive) Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Ashampoo ClipFinder HD 2 v.2.47 (HKLM-x32\...\{0A11EA01-0BAC-AC96-8FAD-1840C13B6803}_is1) (Version: 2.47 - Ashampoo GmbH & Co. KG) ASUS Gaming Center (HKLM-x32\...\{23C8A788-4790-4F3C-B103-0ACC7D9DC5BE}) (Version: 1.0.2 - ASUS) ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: - ASUSTek COMPUTER INC.) ASUS GPU Tweak (x32 Version: - ASUSTek COMPUTER INC.) Hidden ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.4.3 - ASUS) ASUS ROG Gaming Mouse (HKLM-x32\...\{3B9E171F-A955-4834-B877-447C0A437260}) (Version: 2.00.026 - ASUS) ASUS ROG MacroKey (HKLM-x32\...\{348022C5-F497-4333-AFEE-208F22F169F2}_is1) (Version: - G-spy Co., Ltd) ASUS Screen Saver (HKLM-x32\...\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 2.0.5 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.02.0001 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.0.1 - ASUS) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0038 - ASUS) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) AVG (Version: 16.141.7996 - AVG Technologies) Hidden AVG 2016 (Version: 16.0.4749 - AVG Technologies) Hidden AVG PC TuneUp (HKLM-x32\...\AVG PC TuneUp) (Version: - AVG Technologies) AVG PC TuneUp (x32 Version: 16.63.4 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG) (Version: 2016.141.7996 - AVG Technologies) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: - BlueStack Systems, Inc.) calibre 64bit (HKLM\...\{0224350E-9A3E-4932-8FC8-5D0590F1AF8A}) (Version: 2.55.0 - Kovid Goyal) Call of Duty Modern Warfare 3 1.0 (HKLM-x32\...\Call of Duty Modern Warfare 3 1.0) (Version: - ) Call of Duty(R) 4 - Modern Warfare(TM) (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.00.0000 - Activision) Call of Duty(R) 4 - Modern Warfare(TM) (x32 Version: 1.00.0000 - Activision) Hidden Call of Duty: Modern Warfare 3 - Dedicated Server (HKLM-x32\...\Steam App 42750) (Version: - Infinity Ward - Sledgehammer Games) CBR (HKLM-x32\...\{91604354-2B64-4A59-AF15-81E85CB4F9BB}) (Version: 0.7 - G.Waser) CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: - CDBurnerXP) concept/design onlineTV 11 (HKLM-x32\...\{8A4C3184-DA2F-4553-BF61-83F5690C3048}_is1) (Version: - concept/design GmbH) ConvertHelper 3.1.1 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version: - DownloadHelper) CPUID CPU-Z 1.75 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.29 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) CPU-M Benchmark version 1.5 (HKLM-x32\...\{819B2F72-CADC-4C41-BA29-2BA97D7F68CE}_is1) (Version: 1.5 - Major Share (MajorShare.com)) CrystalDiskInfo 6.7.5 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.7.5 - Crystal Dew World) CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.) CyberLink PowerDirector 14 (HKLM-x32\...\{6BADCD73-E925-46F7-A295-FF2448632728}) (Version: 14.0.2019.0 - CyberLink Corp.) Disk Doctors Undelete Version 1.0.0 (HKLM-x32\...\Disk Doctors Undelete_is1) (Version: - Disk Doctor Labs, Inc.) DLL-Files.com Client (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_DLL-Files.c~79141F26_is1) (Version: 2.1.1000.4462 - DLL-Files.com Client) Dr. Langeskov, The Tiger, and The Terribly Cursed Emerald: A Whirlwind Heist (HKLM-x32\...\Steam App 409160) (Version: - Crows Crows Crows) Dreamfall The Longest Journey Version 1.0 (HKLM-x32\...\Dreamfall The Longest Journey_is1) (Version: 1.0 - Funcom) <==== ACHTUNG Dropbox (HKLM-x32\...\Dropbox) (Version: 16.4.30 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: - Dropbox, Inc.) Hidden Dying Light Version 1.2 (HKLM-x32\...\Dying Light_is1) (Version: 1.2 - RFT) eBook Converter (HKLM-x32\...\eBookConverter) (Version: 1.2.1 - eBook Converter) ELAN Touchpad (HKLM\...\Elantech) (Version: - ELAN Microelectronic Corp.) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fahrenheit (HKLM-x32\...\{BA10AC78-E687-4523-8B93-540428FC256F}) (Version: 1.1 - Ihr Firmenname) Far Cry (Patch 1.4) (x32 Version: 1.00.0000 - Ubisoft) Hidden Far Cry (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden Far Cry 3 Blood Dragon (HKLM-x32\...\{A071F478-73E0-4143-AE55-4DD6BABD74F5}) (Version: 1.02 - Ubisoft) FileRestorePlus™ (HKLM-x32\...\FileRestorePlus™_is1) (Version: - Copyright © 2010 eSupport.com • All Rights Reserved) FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden Future Pinball (HKLM-x32\...\Future Pinball_is1) (Version: Version - Chris Leathley) Futuremark SystemInfo (HKLM-x32\...\{79659071-4B68-4EC8-833C-49C97B68FCD0}) (Version: 4.36.512.0 - Futuremark) Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: - Genesys Logic) Ghost Recon Phantoms - EU (HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\61e5da2b7c463135) (Version: 1.36.9879.2 - Ubisoft) Glary Utilities 5.38 (HKLM-x32\...\Glary Utilities 5) (Version: - Glarysoft Ltd) GOM Software V8 (HKLM\...\GOM v8.0) (Version: - GOM mbH, Mittelweg 7-8, 38106 Braunschweig, Germany) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Earth Pro (HKLM-x32\...\{35DAA04C-1720-4BE3-A920-A03731EC6A1D}) (Version: - Google) Google Update Helper (x32 Version: - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North) GSM SIM Utility 9.0 (HKLM-x32\...\{E1ACEF2E-C3C0-43F5-A815-5F0BB968DA70}) (Version: - ) Helium (HKLM-x32\...\{9A781940-AC41-4D5E-8E1E-76A04B916FB9}) (Version: 1.0.0 - ClockworkMod) HELI-X 6.1 Demo (HKLM-x32\...\EC916548-FECF-4545-B3A0-E8956AB32821_is1) (Version: - HELI-X.net) Heroes & Generals (HKLM-x32\...\Steam App 227940) (Version: - Reto-Moto) Hitman Absolution - Professional Edition (HKLM-x32\...\Hitman Absolution - Professional Edition_is1) (Version: - ) Hitman Codename 47 (HKLM-x32\...\GOGPACKANHITMAN1_is1) (Version: - GOG.com) Intel Collaborative Processor Performance Control (HKLM-x32\...\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1419.2) (HKLM\...\{302600C1-6BDF-4FD1-1405-148929CC1385}) (Version: 17.0.1405.0464 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{85b9d34f-7397-4e39-8600-07942ef6ca04}) (Version: 17.0.5 - Intel Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) LAV Filters 0.66 (HKLM-x32\...\lavfilters_is1) (Version: 0.66 - Hendrik Leppkes) LockHunter 3.1, 32/64 bit (HKLM\...\LockHunter_is1) (Version: - Crystal Rich Ltd) Malwarebytes Anti-Malware Version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes) Maniac Mansion Deluxe (HKLM-x32\...\Maniac Mansion Deluxe) (Version: - ) Maxx Audio Installer (x64) (Version: 1.6.5073.106 - Waves Audio Ltd.) Hidden Medusa's Labyrinth (HKLM-x32\...\Steam App 436110) (Version: - Guru Games) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 47.0.1 (x64 de) (HKLM\...\Mozilla Firefox 47.0.1 (x64 de)) (Version: 47.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: - Mozilla) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger) NewBlue Titler Pro for Windows (HKLM-x32\...\NewBlue Titler Pro for Windows) (Version: 1.0 - NewBlue) NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue) NewBlue Video Essentials V for Windows (HKLM-x32\...\NewBlue Video Essentials V for Windows) (Version: 3.0 - NewBlue) NewBlue Video Essentials VI for Windows (HKLM-x32\...\NewBlue Video Essentials VI for Windows) (Version: 3.0 - NewBlue) NewBlue Video Essentials VII for Windows (HKLM-x32\...\NewBlue Video Essentials VII for Windows) (Version: 3.0 - NewBlue) No Man’s Sky Incl. Update 4 MULTi14 1.07 (HKLM-x32\...\No Man’s Sky Incl. Update 4 MULTi14 1.07) (Version: - ) NoteBook FanControl (HKLM-x32\...\{542c1677-eab5-49ee-99aa-5a08eeb3033c}) (Version: - Stefan Hirschmann - StagWare) NoteBook FanControl (x32 Version: - Stefan Hirschmann - StagWare) Hidden NVIDIA 3D Vision Treiber 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 372.70 - NVIDIA Corporation) NVIDIA Grafiktreiber 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 372.70 - NVIDIA Corporation) NVIDIA HD-Audiotreiber (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: - NVIDIA Corporation) NVIDIA Miracast Virtueller Ton 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.30 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) OkayFreedom (HKLM-x32\...\{3F3FB10C-7175-4D38-9335-3488B89C12AF}) (Version: 1.7.4 - Steganos Software GmbH) OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation) Oracle VM VirtualBox 5.0.4 (HKLM\...\{FC191F32-1A67-4231-91D0-0059A57C99A8}) (Version: 5.0.4 - Oracle Corporation) PhonerLite 2.45 (HKLM-x32\...\PhonerLite_is1) (Version: 2.45 - Heiko Sommerfeldt) PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.00.000 - Prolific Technology INC) proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: - proDAD GmbH) Q500 GUI version 1.0 (HKLM-x32\...\{05282008-69B0-409A-8B05-CB77A5E0D99E}_is1) (Version: 1.0 - Yuneec) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: - Apple Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.34.617.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) Relic Hunters Zero (HKLM-x32\...\Steam App 382490) (Version: - Rogue Snail) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: - Rockstar Games) ROG Game First III (HKLM-x32\...\{0C6E32E1-31D9-49F1-B67F-2941994002D5}) (Version: 1.00.16 - ASUSTeK Computer Inc.) Run and Fire (HKLM-x32\...\Steam App 360760) (Version: - ) S.T.A.L.K.E.R. - Shadow of Chernobyl (HKLM-x32\...\S.T.A.L.K.E.R. - Shadow of Chernobyl_is1) (Version: 1.0000 - THQ) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16044.2 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.16044.2 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: - SAMSUNG Electronics Co., Ltd.) ScummVM 1.4.1 (HKLM-x32\...\ScummVM_is1) (Version: - The ScummVM Team) SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: - NVIDIA Corporation) Hidden Shutdown Timer (HKLM\...\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}) (Version: 3.3.4 - Sinvise Systems) Shutdown7 Version 2.1.2 (HKLM-x32\...\{37D95233-83D5-4511-8FFA-E6110FBB1F3E}_is1) (Version: 2.1.2 - Marius Lutz) SIM MAX (HKLM-x32\...\{DAC0B889-5359-4FDC-893A-2B8EF6B71B6F}) (Version: 1.00.0000 - SIM MAX) Singularity German Uncut Edition 1.1 (HKLM-x32\...\Singularity German Uncut Edition 1.1) (Version: - ) Sleeping Dogs Game Of The Year (30 DLCs) 1.0 (HKLM-x32\...\Sleeping Dogs Game Of The Year (30 DLCs) 1.0) (Version: 1.0 - .x.X.RIDDICK.X.x.) SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.8 - SmartSound Software Inc.) SmartSound Quicktracks 5 (x32 Version: 5.1.8 - SmartSound Software Inc.) Hidden Sniper Elite 3 Dedicated Server (HKLM-x32\...\Steam App 266910) (Version: - ) SOMA (HKLM\...\U09NQQ==_is1) (Version: 1 - ) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spotify (HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Spotify) (Version: - Spotify AB) Star Wars Jedi Knight Jedi Academy (HKLM-x32\...\{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}) (Version: - ) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) SWAT 4 Gold Edition MULTi7 - ElAmigos Version 1.1 (HKLM-x32\...\{C5A3E12F-8EA1-4698-80A8-32C9C87A11EF}_is1) (Version: 1.1 - Sierra) TAXMAN 2015 (HKLM-x32\...\{5613CAD3-71ED-4207-95A0-1BA0BF465E38}) (Version: 20.22.94 - Haufe-Lexware GmbH & Co.KG) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) TECUNIONLINE (HKLM-x32\...\TECUNIONLINE) (Version: - ShenZhen ruike Electronics Co.,Ltd) TeraCopy 2.3 (HKLM\...\TeraCopy_is1) (Version: - Code Sector) The Evil Within MULTi2 1.0 (HKLM-x32\...\The Evil Within MULTi2 1.0) (Version: - ) The Four Kings Casino and Slots (HKLM-x32\...\Steam App 260430) (Version: - Digital Leisure Inc.) Thunderbolt(TM) Software (HKLM\...\{BED2816F-D47A-41DA-AFCF-44E1B257C368}) (Version: - Intel(R) Corporation) TimeComX Basic (64-Bit) (HKLM-x32\...\TimeComX Basic 64-Bit) (Version: - Bitdreamers) Tomb Raider [2013] Collectors Edition MULTI-2 1.01.748.0 (HKLM-x32\...\Tomb Raider [2013] Collectors Edition MULTI-2 1.01.748.0) (Version: - ) Tomb Raider 1 + 2 + 3 (HKLM-x32\...\Tomb Raider 1 + 2 + 3_is1) (Version: - GOG.com) Universal Adb Driver (HKLM-x32\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Unreal (HKLM-x32\...\Unreal) (Version: - ) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Uplay (HKLM-x32\...\Uplay) (Version: 2.1 - Ubisoft) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: - Elaborate Bytes) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) Vulkan Run Time Libraries (HKLM\...\VulkanRT1.0.11.1) (Version: - LunarG, Inc.) WavePad Audio-Editor (HKLM-x32\...\WavePad) (Version: 6.12 - NCH Software) WebStorage (HKLM-x32\...\WebStorage) (Version: - ASUS Cloud Corporation) WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-asus) (Version: - WildTangent) Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.0.1 - ASUS) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Wise Care 365 3.95 (HKLM-x32\...\Wise Care 365_is1) (Version: 3.95 - WiseCleaner.com, Inc.) Wise Data Recovery 3.82 (HKLM-x32\...\Wise Data Recovery_is1) (Version: 3.82 - WiseCleaner.com, Inc.) Wise Folder Hider 3.25 (HKLM-x32\...\Wise Folder Hider_is1) (Version: 3.25 - WiseCleaner.com, Inc.) Wise Force Deleter 1.23 (HKLM-x32\...\Wise Force Deleter_is1) (Version: 1.23 - WiseCleaner.com, Inc.) X-Mouse Button Control 2.14 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.14 - Highresolution Enterprises) Zak McKracken – Between Time and Space Version v2 (HKLM-x32\...\Zak2_is1) (Version: v2 - Artificial Hair Bros.) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\Magic\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler) CustomCLSID: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Magic\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {02DFFCB2-3023-4270-A6A5-F634C39094C1} - System32\Tasks\WiseCleaner\WFDSkipUAC => C:\Program Files (x86)\Wise\Wise Force Deleter\WiseDeleter.exe [2015-09-11] (WiseCleaner.com) Task: {038C0AE1-850F-4787-9992-66638585ED62} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {041EC183-7E61-4AC6-A3B9-A38EFB3ECDAD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {04F6987D-26CA-40B1-8689-482DFDE3E68B} - System32\Tasks\WiseCleaner\WFHFreeSkipUAC => C:\Program Files (x86)\Wise\Wise Folder Hider\WiseFolderHider.exe [2015-12-28] (WiseCleaner.com) Task: {0B61B4D1-FD9B-41A3-B066-E017FDB8707A} - \Microsoft\Windows\Setup\gwx\rundetector -> Keine Datei <==== ACHTUNG Task: {0D202C58-7664-45C4-849E-0767A07005F7} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.) Task: {11297B15-450D-498C-8532-812410922210} - System32\Tasks\{76510113-A991-43AD-BA59-4E768F1E4D23} => pcalua.exe -a G:\CM108(7.1)\USB-108-100318-\Program\CmElv.exe -d G:\CM108(7.1)\USB-108-100318-\Program Task: {1DE59105-4D61-4520-B402-38EB12995DD5} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {25DE50C4-AC1F-497F-9017-E556670099F9} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {27EEB4FF-4196-41CA-8C88-6335B4BAFEE7} - \Winsta Update -> Keine Datei <==== ACHTUNG Task: {2997AACB-9A21-4336-9F3E-89FAD5B54E41} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] () Task: {299CC0B5-2E81-446A-B9A9-87B63726CF64} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {3397CBD6-EE58-4124-8762-40DDC1078D88} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {38DA5EF2-A658-489A-BD08-2DB863E287C0} - System32\Tasks\{C481FA0A-06A3-4E3A-8A4A-87B51B1D8847} => pcalua.exe -a C:\BlackMesa-Setup.exe -d C:\ Task: {3C3C6874-0AC9-48A6-B9BB-78BDD9180F1C} - System32\Tasks\{3BC09844-F4EF-44F1-B708-E936EFF8B69A} => pcalua.exe -a H:\FahrenheitAutoRun.exe -d H:\ Task: {417E63E1-0816-4F71-AAA9-479BCC90D3A5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-12-21] (Adobe Systems Incorporated) Task: {4D3CBD94-09F6-47C8-AF2E-32F8535747E3} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] () Task: {5AD09BC0-F001-492A-8EE1-A5EC966EA30E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.) Task: {795A745C-8A04-4E7E-A1E3-06F27CE1CC0D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.) Task: {7EC08BD6-275A-4FC1-86B8-1251DBC65C57} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-09-22] (Oracle Corporation) Task: {80DF9B7D-43AE-465B-942E-90412B11C5A9} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] () Task: {8A0D5CB2-6D41-4CF8-9D60-196773A10B32} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {8A6EABB4-E890-4149-BD5C-910123342B4A} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-08-06] (Realtek Semiconductor) Task: {900AF312-89A6-41DA-9DE1-EB0506D351A3} - \keepup -> Keine Datei <==== ACHTUNG Task: {97BB35B8-0317-45F6-B0A7-1BC8A184F847} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2016-12-22] (Microsoft Corporation) Task: {A314A88C-AFDB-470A-BADC-531068FA7CFD} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG Task: {AE0A2B22-6D11-4360-B87C-B57539AE796E} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Keine Datei <==== ACHTUNG Task: {AFA17095-B02F-4F6D-BD41-FEA6E473C667} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {B7EC1178-7401-49CB-A673-7E2078897724} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {BC9A6AE0-F474-40EE-8D19-DEAC32A7672F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => Thunderbolt.exe Task: {C1861428-E1EF-4E59-8DCB-1F86BFB82C23} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2015-11-09] (Glarysoft Ltd) Task: {C1D22689-ACD4-4D22-9F02-714ADADA6437} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => start ThunderboltService Task: {C88A9FB9-551C-428D-8BBA-8FDE021C2822} - \Convertor -> Keine Datei <==== ACHTUNG Task: {C88ACA29-A7C0-4A66-8A75-D73EA1B9590C} - System32\Tasks\{6DDDBEB5-27E0-410D-806E-613EC08E3078} => pcalua.exe -a H:\FarCryAutoCD.exe -d H:\ Task: {C8DE3303-1801-4CBC-BDB8-9EADEC70A462} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {C9EE5C93-FDCF-463D-8149-D682F1480612} - System32\Tasks\{6B71DFFD-F7AE-4A6D-A0B3-26FD428303D3} => pcalua.exe -a I:\_isauto.exe -d I:\ Task: {D3CFE796-23AC-4F92-A3C5-4DDAE5871AF6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {D49C32E1-654B-4E2A-97AC-340CE4796170} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {D5400EAB-6F55-4487-B8F1-47FE5A5FF456} - \WPD\SqmUpload_S-1-5-21-2786200759-2278858845-1295660402-1001 -> Keine Datei <==== ACHTUNG Task: {D8A21171-7310-4137-95FF-A1B5E1B64E40} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => tbtsvc.exe Task: {D9DD9300-3117-43D6-A0AE-D77874AA2721} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {DF5AEB94-DA0D-4D51-8BF4-429BE1BB1B5C} - System32\Tasks\WiseCleaner\WDRSkipUAC => C:\Program Files (x86)\Wise\Wise Data Recovery\WiseDataRecovery.exe [2015-08-28] (WiseCleaner.com) Task: {E07FEEE5-C35D-4E14-A008-FCAF4EF0C0D7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner64.exe [2016-12-06] (Piriform Ltd) Task: {E13A3BFF-B63D-4C74-AF3A-52B98619CC24} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {E415E5D5-1449-4CF8-AE6F-86074AEFAB06} - \DriverMgr -> Keine Datei <==== ACHTUNG Task: {E42190F5-458B-4385-8915-DDBD26FF151D} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2014-06-03] (ASUS) Task: {EAB75945-DAD7-4BB4-8AFD-B8FCE23DB0D1} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.) Task: {EADE8BF1-7DC3-4C30-9763-14507819D5A6} - System32\Tasks\{C7C2286E-82AC-4DA0-B9E3-9BF42B0B9C92} => pcalua.exe -a "C:\Users\Magic\Downloads\Simcard Reader\Usb-SIM9.0\Setup.exe" -d "C:\Users\Magic\Downloads\Simcard Reader\Usb-SIM9.0" Task: {EBCCBF76-3C91-457D-9258-2D8A627B00CC} - \WinKit -> Keine Datei <==== ACHTUNG Task: {EF95605B-2020-4607-B540-621824F3038D} - \WordShark Auto Updater Pending Update -> Keine Datei <==== ACHTUNG Task: {F6833A5A-E639-43FF-B225-E1BAF8EBF77D} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2014-07-09] (ASUSTek Computer Inc.) Task: {F83BD2D4-7F58-42E1-A3E1-034D35B254F6} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {FA9EC439-B980-4F45-925A-6BCCFB8B2E0F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => Thunderbolt.exe Task: {FB599219-0404-4FAC-BC17-76DC020A4C7E} - System32\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2015-12-18] (WiseCleaner.COM) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\Magic\Favorites\Downloadseite von NCH Software.lnk -> hxxp://www.nch.com.au/de/index.htm Shortcut: C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eBook Converter\Website.lnk -> hxxp://www.ebook-converter.com Shortcut: C:\Users\Public\Desktop\HELI-X6.1.lnk -> E:\Spiele\HELI-X6.1\runHELI-X.bat () ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-21 13:37 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-26 11:36 - 2016-08-25 22:12 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2008-10-24 16:35 - 2008-10-24 16:35 - 00128296 _____ () C:\Program Files (x86)\Lexware\AAVUpdateManager\aavus.exe 2012-01-17 10:24 - 2012-01-17 10:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2016-08-20 15:07 - 2016-08-26 00:27 - 00288192 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 00367552 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 03611584 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll 2015-12-20 11:09 - 2015-12-20 12:15 - 00066872 _____ () C:\WINDOWS\SysWoW64\PnkBstrA.exe 2016-09-25 00:20 - 2016-09-25 00:21 - 00189264 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2016-08-20 15:07 - 2016-08-26 00:27 - 02665920 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 01988544 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 01840576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 00207296 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll 2016-12-21 13:37 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-11-26 12:07 - 2016-11-26 12:07 - 01864384 _____ () C:\Users\Magic\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll 2016-11-26 11:32 - 2016-11-26 11:32 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-12-20 14:20 - 2016-12-20 14:21 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-12-20 14:20 - 2016-12-20 14:21 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-12-20 14:20 - 2016-12-20 14:21 - 42130432 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2016-12-20 14:20 - 2016-12-20 14:21 - 02216448 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\roottools.dll 2015-06-21 14:31 - 2015-07-16 00:54 - 00053832 _____ () C:\Windows\SysWOW64\UMonit64.exe 2017-01-03 19:57 - 2017-01-03 19:57 - 00566439 _____ () C:\Users\Magic\AppData\Local\JDownloader v2.0\tmp\7zip\SevenZipJBinding-FKPz9\libgcc_s_sjlj-1.dll 2017-01-03 19:57 - 2017-01-03 19:57 - 04078962 _____ () C:\Users\Magic\AppData\Local\JDownloader v2.0\tmp\7zip\SevenZipJBinding-FKPz9\lib7-Zip-JBinding.dll 2016-12-27 14:41 - 2016-12-27 14:42 - 01274880 _____ () C:\ProgramData\firemin_2086\Firemin.exe 2014-10-24 22:41 - 2013-05-15 14:39 - 00463872 _____ () C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe 2016-08-20 15:07 - 2016-08-26 00:27 - 00034240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 00920000 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll 2014-10-24 22:35 - 2013-10-23 13:44 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00117248 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00037936 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00018992 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDColorEnhance.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00020528 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDRegammaAndGamut.dll 2015-06-11 23:41 - 2016-08-26 00:27 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-02 10:42 - 2016-12-23 20:55 - 51777648 _____ () C:\Users\Magic\AppData\Roaming\Spotify\libcef.dll 2016-10-31 23:31 - 2016-12-23 20:55 - 00110192 _____ () C:\Users\Magic\AppData\Roaming\Spotify\SpotifyWinRT.dll 2016-10-02 10:42 - 2016-12-23 20:55 - 01803888 _____ () C:\Users\Magic\AppData\Roaming\Spotify\libglesv2.dll 2016-10-02 10:42 - 2016-12-23 20:55 - 00086128 _____ () C:\Users\Magic\AppData\Roaming\Spotify\libegl.dll 2016-12-04 11:12 - 2016-12-04 11:12 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll 2013-04-27 09:24 - 2013-04-27 09:24 - 00071680 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\checkmetro.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\localhost -> localhost ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run32: => "WebStorage" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "Steganos HotKeys" HKLM\...\StartupApproved\Run32: => "SSS17 Chrome Autofill Relay" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "GUDelayStartup" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "SSS17 Browser Monitor" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "SSS17_Update" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [{A3378399-CD48-4CB5-84D7-AA5D39FC70F8}] => LPort=26675 FirewallRules: [{2E84CC4C-E897-4C77-A27C-F46453FF57A0}] => %systemroot%\WindowsMobile\wmdHost.exe FirewallRules: [{BBDD3259-07C6-44F6-ACDA-C30926B10CD6}] => %systemroot%\WindowsMobile\wmdHost.exe FirewallRules: [{7C7D8964-26FE-4394-BADF-F9E74C8CD7BB}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [{528E3B20-13FB-46C9-AF58-9068915F9CB0}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [UDP Query User{6D3D8870-60B9-477F-9EF4-10A7A077D974}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{557C37B9-4614-478A-A144-7BDBC0F71E55}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{E22BCAAB-75C3-42D0-9B33-1479B209D63C}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{F5DBFFDF-EBC9-4C1C-9B44-C236D70E03F7}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [{D6220419-1177-47AA-BCCE-4354EE6502E4}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [UDP Query User{AA1BE5BE-4662-43B4-B05A-8C595D6A63AE}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [TCP Query User{B59E3605-07DD-4DA6-B107-4CDF3267B3C3}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [{0E9A4A87-8F02-48AE-9CD8-97EC18EEDEC6}] => D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{8C45D2C4-3DB8-4EE8-85D0-8885DBA46BDB}] => D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{107F23C2-6F3F-4987-B09E-6F79EC2669AA}] => E:\Steamgames\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [{08A2F34E-AE03-4118-BF08-018EF54299B9}] => E:\Steamgames\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [UDP Query User{364DDEA2-DBB2-474A-85E0-FC444ADEE1EF}D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe] => D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe FirewallRules: [TCP Query User{D1D2AB1D-B0A3-4567-80CF-9CF793E2AC55}D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe] => D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe FirewallRules: [{A2122F0D-4041-4156-BAE3-B4018F51C907}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{DD7EB97E-8B1F-48C5-B2A4-53302643EB22}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7D321605-0DAF-44BA-BFC5-8988B33C7531}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0704D41B-6043-4C9F-AA02-1ACC4C8046D4}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{EC6E740D-1623-4157-AC11-8D2A333FC11C}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{B3592C47-CB5A-4520-82B2-F5DAC935DFF8}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{7AE4DFFB-BAEE-423C-A3F8-4DD46D0A95AE}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{25102AAE-6315-4BFD-9E4E-AD686C0715A4}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{463E20D5-6EA5-439F-BDE9-E50E3A04997C}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{C4D4FB5B-57E9-44B4-97FA-4272D4559CE7}] => C:\WINDOWS\SysWOW64\ftp.exe FirewallRules: [{C8785C4F-5F64-4205-8BAA-997112F77B0B}] => C:\WINDOWS\SysWOW64\ftp.exe FirewallRules: [{C070B80D-B7FA-4CD3-A06E-C49C4425DEB3}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [{24990052-623D-4BCE-8DD3-3E16C6BA298D}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [UDP Query User{A70A266F-DAD4-4595-9E4C-C01235C6232E}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [TCP Query User{1B1E6CF6-3A42-415C-8E46-9A567FF849D1}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [{9134E917-73DC-418D-B780-83B47836859E}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe FirewallRules: [{F8696992-A57B-49B0-AC0E-DAFC89EF92E5}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe FirewallRules: [{BE08A6D6-27E4-4D0F-AFCD-D1A7321611BC}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe FirewallRules: [{F694934A-23E9-4515-8528-6E664F5FC484}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe FirewallRules: [{9A3BCAAF-4EAA-4D4D-9936-86C5EDD9CC4F}] => C:\Program Files (x86)\Steam\steamapps\common\Relic Hunters Zero\RelicHuntersZero.exe FirewallRules: [{82323557-1750-4503-88E9-1E11AFB3DBBC}] => C:\Program Files (x86)\Steam\steamapps\common\Relic Hunters Zero\RelicHuntersZero.exe FirewallRules: [{86AA60AF-AF2B-4EA9-AA7A-DD5A61A762CA}] => E:\Steamgames\steamapps\common\Medusa's Labyrinth\Medusa.exe FirewallRules: [{61904DB6-14ED-487B-9E54-CE31551B0BFE}] => E:\Steamgames\steamapps\common\Medusa's Labyrinth\Medusa.exe FirewallRules: [{479A9F15-CD8A-40ED-9D69-273651CAE1CE}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{8886E1F9-2343-42CF-9464-617EFDBA1349}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{E4B521B9-D8EC-4808-9515-36A56A1C58A4}] => C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{6C406380-A7C6-4C1C-A0E6-7C5674715F8D}] => C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{DF849CE4-D117-4CCE-A3DE-4B88B7CE20FB}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{8CE6309B-8A99-4C41-8E8C-4AD09DAD8382}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{CE249E79-E128-432D-A150-374BA9575B96}] => C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{61CD42B7-590C-4E0B-8FF1-A9C91EC91EEC}] => C:\Program Files (x86)\AVG\Av\avgemca.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/04/2017 08:20:17 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode. Error: (01/04/2017 08:20:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/03/2017 11:58:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/03/2017 10:05:31 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.LockApp_10.0.14393.0_neutral__cw5n1h2txyewy+WindowsDefaultLockScreen“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/03/2017 10:01:36 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.LockApp_10.0.14393.0_neutral__cw5n1h2txyewy+WindowsDefaultLockScreen“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/03/2017 10:01:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/03/2017 08:00:31 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/03/2017 08:00:28 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm SearchUI.exe, Version 10.0.14393.447 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 3ea8 Startzeit: 01d265f3946500eb Beendigungszeit: 4294967295 Anwendungspfad: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Berichts-ID: df887f14-d1e6-11e6-832b-ac9e17909450 Vollständiger Name des fehlerhaften Pakets: Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy Auf das fehlerhafte Paket bezogene Anwendungs-ID: CortanaUI Error: (01/03/2017 08:00:21 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy+CortanaUI“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/03/2017 08:00:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.14393.576_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Systemfehler: ============= Error: (01/04/2017 07:51:46 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (01/03/2017 09:59:44 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (01/03/2017 07:57:32 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} und der APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (01/03/2017 01:34:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "AsusGameFirstService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/03/2017 01:34:38 AM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT-AUTORITÄT) Description: Fehler "87" beim Laden der Kennwortbenachrichtigungs-DLL "". Stellen Sie sicher, dass der in der Registrierung definierte DLL-Pfad "HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages" sich auf einen korrekten und absoluten Pfad (<Laufwerk>:\<Pfad>\<Dateiname>.<Erw.>) bezieht und nicht auf einen relativen oder ungültigen Pfad. Wenn der DLL-Pfad falsch ist, stellen Sie sicher, dass sich alle Hilfsdateien im gleichen Verzeichnis befinden und dass das Systemkonto sowohl auf den DLL-Pfad als auch die Hilfsdateien Lesezugriff hat. Wenden Sie sich an den Anbieter der Benachrichtigungs-DLL, um weitere Unterstützung zu erhalten. Weitere Informationen finden Sie im Internet unter "hxxp://go.microsoft.com/fwlink/?LinkId=245898". Error: (01/03/2017 01:34:07 AM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: Zugriff verweigert Error: (01/03/2017 01:34:06 AM) (Source: DCOM) (EventID: 10010) (User: OUTLAW) Description: Der Server "{9BA05972-F6A8-11CF-A442-00A0C90A8F39}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/03/2017 01:34:06 AM) (Source: DCOM) (EventID: 10010) (User: OUTLAW) Description: Der Server "{9BA05972-F6A8-11CF-A442-00A0C90A8F39}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/03/2017 01:34:05 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: Es wird bereits eine Instanz des Dienstes ausgeführt. Error: (01/03/2017 01:33:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Cyberlink RichVideo64 Service(CRVS)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. CodeIntegrity: =================================== Date: 2017-01-04 19:55:08.143 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-04 19:55:00.046 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-04 19:54:56.485 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-04 19:54:54.268 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-04 19:54:54.192 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-04 19:54:53.507 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-04 19:54:47.840 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-03 22:02:57.963 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-03 22:02:50.607 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-03 22:02:50.282 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-4710HQ CPU @ 2.50GHz Prozentuale Nutzung des RAM: 25% Installierter physikalischer RAM: 16333.16 MB Verfügbarer physikalischer RAM: 12214.14 MB Summe virtueller Speicher: 18765.16 MB Verfügbarer virtueller Speicher: 13650.23 MB ==================== Laufwerke ================================ Drive c: (OS) (Fixed) (Total:95.39 GB) (Free:20.68 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive d: (Data) (Fixed) (Total:130.86 GB) (Free:8.2 GB) NTFS Drive e: (Data1) (Fixed) (Total:465.75 GB) (Free:81.36 GB) NTFS Drive f: (Data2) (Fixed) (Total:465.76 GB) (Free:10.77 GB) NTFS Drive g: (STALKER) (CDROM) (Total:3.12 GB) (Free:0 GB) UDF Drive h: (ESD-USB) (Removable) (Total:119.74 GB) (Free:13.99 GB) exFAT ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: C56CCB18) Partition: GPT. ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: EAAFBC5E) Partition: GPT. ======================================================== Disk: 2 (Size: 119.7 GB) (Disk ID: 0930975D) Partition 1: (Not Active) - (Size=119.7 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ Suche jetzt ob von den alten Logfiles noch was da ist.. Grüße Code:
ATTFilter 23:47:14.0542 0x3874 TDSS rootkit removing tool Nov 7 2016 07:10:01 23:47:14.0542 0x3874 UEFI system 23:47:21.0336 0x3874 ============================================================ 23:47:21.0337 0x3874 Current date / time: 2016/12/29 23:47:21.0336 23:47:21.0337 0x3874 SystemInfo: 23:47:21.0337 0x3874 23:47:21.0337 0x3874 OS Version: 10.0.14393 ServicePack: 0.0 23:47:21.0337 0x3874 Product type: Workstation 23:47:21.0337 0x3874 ComputerName: OUTLAW 23:47:21.0337 0x3874 UserName: Magic 23:47:21.0338 0x3874 Windows directory: C:\WINDOWS 23:47:21.0338 0x3874 System windows directory: C:\WINDOWS 23:47:21.0338 0x3874 Running under WOW64 23:47:21.0338 0x3874 Processor architecture: Intel x64 23:47:21.0338 0x3874 Number of processors: 8 23:47:21.0338 0x3874 Page size: 0x1000 23:47:21.0338 0x3874 Boot type: Normal boot 23:47:21.0338 0x3874 CodeIntegrityOptions = 0x00000001 23:47:21.0338 0x3874 ============================================================ 23:47:21.0647 0x3874 KLMD registered as C:\WINDOWS\system32\drivers\07768363.sys 23:47:21.0647 0x3874 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.576, osProperties = 0x19 23:47:22.0521 0x3874 System UUID: {0A786863-56D2-3542-01D2-8B2A6CA8FB50} 23:47:23.0451 0x3874 Drive \Device\Harddisk0\DR0 - Size: 0x3B9E656000 ( 238.47 Gb ), SectorSize: 0x200, Cylinders: 0x799A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:47:23.0729 0x3874 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:47:24.0848 0x3874 Drive \Device\Harddisk2\DR2 - Size: 0x1DEFF00000 ( 119.75 Gb ), SectorSize: 0x200, Cylinders: 0x3D10, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 23:47:24.0852 0x3874 ============================================================ 23:47:24.0852 0x3874 \Device\Harddisk0\DR0: 23:47:24.0853 0x3874 GPT partitions: 23:47:24.0854 0x3874 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {7A6B32F8-C932-4E8B-A54A-DE07D0BB066A}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x32000 23:47:24.0854 0x3874 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {8EED4308-643D-4896-90C9-3AC676459633}, Name: Microsoft reserved partition, StartLBA 0x32800, BlocksNum 0x40000 23:47:24.0855 0x3874 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {EC98BE07-4CC1-4D95-9DCD-7A1E5709A54C}, Name: Basic data partition, StartLBA 0x72800, BlocksNum 0xBEC6000 23:47:24.0855 0x3874 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {EEED34BB-AE47-4C2C-BDD6-998300B1DA85}, Name: Basic data partition, StartLBA 0xBF38800, BlocksNum 0x105B9800 23:47:24.0855 0x3874 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {740C8B9D-D48F-40C4-887F-F8E2A7732315}, Name: Basic data partition, StartLBA 0x1C4F2000, BlocksNum 0x1801000 23:47:24.0855 0x3874 MBR partitions: 23:47:24.0855 0x3874 \Device\Harddisk1\DR1: 23:47:24.0855 0x3874 GPT partitions: 23:47:24.0856 0x3874 \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {1D8C42B2-F515-47D5-AAC2-9A5F9BD589AB}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x3A382800 23:47:24.0856 0x3874 \Device\Harddisk1\DR1\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {0FD799F3-9B31-4A93-9915-988F6F0E4792}, Name: Basic data partition, StartLBA 0x3A383000, BlocksNum 0x3A383800 23:47:24.0856 0x3874 MBR partitions: 23:47:24.0856 0x3874 \Device\Harddisk2\DR2: 23:47:24.0857 0x3874 MBR partitions: 23:47:24.0857 0x3874 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xEF7F7C1 23:47:24.0857 0x3874 ============================================================ 23:47:24.0860 0x3874 C: <-> \Device\Harddisk0\DR0\Partition3 Code:
ATTFilter 23:48:15.0196 0x34d4 TDSS rootkit removing tool Nov 7 2016 07:10:01 23:48:15.0196 0x34d4 UEFI system 23:48:18.0401 0x34d4 ============================================================ 23:48:18.0401 0x34d4 Current date / time: 2016/12/29 23:48:18.0401 23:48:18.0402 0x34d4 SystemInfo: 23:48:18.0402 0x34d4 23:48:18.0402 0x34d4 OS Version: 10.0.14393 ServicePack: 0.0 23:48:18.0402 0x34d4 Product type: Workstation 23:48:18.0402 0x34d4 ComputerName: OUTLAW 23:48:18.0402 0x34d4 UserName: Magic 23:48:18.0402 0x34d4 Windows directory: C:\WINDOWS 23:48:18.0402 0x34d4 System windows directory: C:\WINDOWS 23:48:18.0402 0x34d4 Running under WOW64 23:48:18.0402 0x34d4 Processor architecture: Intel x64 23:48:18.0402 0x34d4 Number of processors: 8 23:48:18.0402 0x34d4 Page size: 0x1000 23:48:18.0402 0x34d4 Boot type: Normal boot 23:48:18.0402 0x34d4 CodeIntegrityOptions = 0x00000001 23:48:18.0402 0x34d4 ============================================================ 23:48:18.0406 0x34d4 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.576, osProperties = 0x19 23:48:19.0096 0x34d4 System UUID: {0A786863-56D2-3542-01D2-8B2A6CA8FB50} 23:48:19.0972 0x34d4 Drive \Device\Harddisk0\DR0 - Size: 0x3B9E656000 ( 238.47 Gb ), SectorSize: 0x200, Cylinders: 0x799A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:48:20.0249 0x34d4 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:48:21.0342 0x34d4 Drive \Device\Harddisk2\DR2 - Size: 0x1DEFF00000 ( 119.75 Gb ), SectorSize: 0x200, Cylinders: 0x3D10, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 23:48:21.0346 0x34d4 ============================================================ 23:48:21.0346 0x34d4 \Device\Harddisk0\DR0: 23:48:21.0347 0x34d4 GPT partitions: 23:48:21.0348 0x34d4 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {7A6B32F8-C932-4E8B-A54A-DE07D0BB066A}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x32000 23:48:21.0349 0x34d4 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {8EED4308-643D-4896-90C9-3AC676459633}, Name: Microsoft reserved partition, StartLBA 0x32800, BlocksNum 0x40000 23:48:21.0349 0x34d4 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {EC98BE07-4CC1-4D95-9DCD-7A1E5709A54C}, Name: Basic data partition, StartLBA 0x72800, BlocksNum 0xBEC6000 23:48:21.0349 0x34d4 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {EEED34BB-AE47-4C2C-BDD6-998300B1DA85}, Name: Basic data partition, StartLBA 0xBF38800, BlocksNum 0x105B9800 23:48:21.0349 0x34d4 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {740C8B9D-D48F-40C4-887F-F8E2A7732315}, Name: Basic data partition, StartLBA 0x1C4F2000, BlocksNum 0x1801000 23:48:21.0349 0x34d4 MBR partitions: 23:48:21.0349 0x34d4 \Device\Harddisk1\DR1: 23:48:21.0391 0x34d4 GPT partitions: 23:48:21.0392 0x34d4 \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {1D8C42B2-F515-47D5-AAC2-9A5F9BD589AB}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x3A382800 23:48:21.0392 0x34d4 \Device\Harddisk1\DR1\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {0FD799F3-9B31-4A93-9915-988F6F0E4792}, Name: Basic data partition, StartLBA 0x3A383000, BlocksNum 0x3A383800 23:48:21.0392 0x34d4 MBR partitions: 23:48:21.0392 0x34d4 \Device\Harddisk2\DR2: 23:48:21.0393 0x34d4 MBR partitions: 23:48:21.0393 0x34d4 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xEF7F7C1 23:48:21.0393 0x34d4 ============================================================ 23:48:21.0396 0x34d4 C: <-> \Device\Harddisk0\DR0\Partition3 23:48:21.0398 0x34d4 D: <-> \Device\Harddisk0\DR0\Partition4 23:48:21.0412 0x34d4 E: <-> \Device\Harddisk1\DR1\Partition1 23:48:21.0450 0x34d4 F: <-> \Device\Harddisk1\DR1\Partition2 23:48:21.0450 0x34d4 ============================================================ 23:48:21.0450 0x34d4 Initialize success 23:48:21.0450 0x34d4 ============================================================ 23:48:23.0400 0x34e4 ============================================================ 23:48:23.0400 0x34e4 Scan started 23:48:23.0400 0x34e4 Mode: Manual; 23:48:23.0400 0x34e4 ============================================================ 23:48:23.0400 0x34e4 KSN ping started 23:48:23.0429 0x34e4 KSN ping finished: false Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.8 (09.20.2016) Operating System: Windows 10 Home x64 Ran by Magic (Administrator) on 04.01.2017 at 21:10:05,31 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 4 Successfully deleted: C:\Users\Magic\AppData\Roaming\dll-files.com (Folder) Successfully deleted: C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\user.js (File) Successfully deleted: C:\WINDOWS\system32\Tasks\Wise Turbo Checker.job (Task) Successfully deleted: C:\WINDOWS\prefetch\OKAYFREEDOMCLIENT.EXE-74E257E5.pf (File) Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.01.2017 at 21:17:48,56 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ avast-browser-cleanup und esetsmartinstaller_deu (alles in der Grundkonfiguration ,bzw. automatisch entfernen.) lief schon, bei letzterem wurden 4 Sachen gefunden hat aber ca. 9h gedauert ;-(( |
![]() | #5 | |
/// Malwareteam ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hi, Zitat:
Mach mal bitte das hier: Zustand der Festplatte herausfinden - so gehts - Anleitungen |
![]() | #6 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hi Dennis, hier das Ergebnis. Code:
ATTFilter ---------------------------------------------------------------------------- CrystalDiskInfo 7.0.5 (C) 2008-2016 hiyohiyo Crystal Dew World : hxxp://crystalmark.info/ ---------------------------------------------------------------------------- OS : Windows 10 [10.0 Build 14393] (x64) Date : 2017/01/05 23:22:46 -- Controller Map ---------------------------------------------------------- + Standardmäßiger SATA AHCI- Controller [ATA] - SAMSUNG MZHPU256HCGL-00004 + Intel(R) 8 Series Chipset Family SATA AHCI Controller [ATA] - MATSHITA BD-CMB UJ172 S - HGST HTS721010A9E630 - Microsoft-Controller für Speicherplätze [SCSI] - Virtual CloneDrive [SCSI] -- Disk List --------------------------------------------------------------- (1) SAMSUNG MZHPU256HCGL-00004 : 256,0 GB [0/0/0, pd1] - sg (2) HGST HTS721010A9E630 : 1000,2 GB [1/1/0, pd1] ---------------------------------------------------------------------------- (1) SAMSUNG MZHPU256HCGL-00004 ---------------------------------------------------------------------------- Model : SAMSUNG MZHPU256HCGL-00004 Firmware : UXM6601Q Serial Number : S1NCNYAF901359 Disk Size : 256,0 GB (8,4/137,4/256,0/256,0) Buffer Size : Unbekannt Queue Depth : 32 # of Sectors : 500118192 Rotation Rate : ---- (SSD) Interface : Serial ATA Major Version : ACS-2 Minor Version : ATA8-ACS version 4c Transfer Mode : SATA/600 | SATA/600 Power On Hours : 2490 Std. Power On Count : 908 mal Wear Level Count : 309 Temperature : Unbekannt Health Status : Gut (92 %) Features : S.M.A.R.T., 48bit LBA, NCQ, TRIM APM Level : ---- AAM Level : ---- Drive Letter : C: D: -- S.M.A.R.T. -------------------------------------------------------------- ID Cur Wor Thr RawValues(6) Attribute Name 09 _99 _99 __0 0000000009BA Betriebsstunden 0C _99 _99 __0 00000000038C Anz. Geräte-Einschaltvorgänge B1 _91 _91 _17 000000000135 Verschleißregulierung B2 _92 _92 _10 0000000000C4 Benutzte reservierte Blöcke (Chip) B3 _92 _92 _10 000000000182 Benutzte reservierte Blöcke (gesamt) B4 _92 _92 _10 0000000012FE Unbenutzte reservierte Blöcke (gesamt) B7 100 100 _10 000000000000 Laufzeit schlechter Blöcke (gesamt) -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000 010: 5331 4E43 4E59 4146 3930 3133 3539 2020 2020 2020 020: 0000 0000 0000 5558 4D36 3630 3151 5341 4D53 554E 030: 4720 4D5A 4850 5532 3536 4843 474C 2D30 3030 3034 040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00 050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB D110 060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0E00 070: 0000 0000 0000 0000 0000 001F 850E 0006 0064 0160 080: 03FC 0039 746B 7D01 4163 7469 BC01 4163 207F 0003 090: 0010 0000 FFFE 0000 0000 0000 0000 0000 0000 0000 100: 32B0 1DCF 0000 0000 0000 0008 4000 0000 5002 5386 110: 0004 09DA 0000 0000 0000 0000 0000 0000 0000 401E 120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000 130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0001 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000 210: 0000 0000 0000 0000 0000 0000 0000 0001 0000 0000 220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0000 0800 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 D465 F26B A6F7 787E -- SMART_READ_DATA --------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 01 00 09 32 00 63 63 BA 09 00 00 00 00 00 0C 32 010: 00 63 63 8C 03 00 00 00 00 00 B1 13 00 5B 5B 35 020: 01 00 00 00 00 00 B2 13 00 5C 5C C4 00 00 00 00 030: 00 00 B3 13 00 5C 5C 82 01 00 00 00 00 00 B4 13 040: 00 5C 5C FE 12 00 00 00 00 00 B7 13 00 64 64 00 050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5F 170: 03 00 01 00 02 0A 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 26 -- SMART_READ_THRESHOLD ---------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 01 00 09 00 00 00 00 00 00 00 00 00 00 00 0C 00 010: 00 00 00 00 00 00 00 00 00 00 B1 11 00 00 00 00 020: 00 00 00 00 00 00 B2 0A 00 00 00 00 00 00 00 00 030: 00 00 B3 0A 00 00 00 00 00 00 00 00 00 00 B4 0A 040: 00 00 00 00 00 00 00 00 00 00 B7 0A 00 00 00 00 050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 ---------------------------------------------------------------------------- (2) HGST HTS721010A9E630 ---------------------------------------------------------------------------- Model : HGST HTS721010A9E630 Firmware : JB0OA3J0 Serial Number : JR10006P0NLWAF Disk Size : 1000,2 GB (8,4/137,4/1000,2/1000,2) Buffer Size : 32767 KB Queue Depth : 32 # of Sectors : 1953525168 Rotation Rate : 7200 RPM Interface : Serial ATA Major Version : ATA8-ACS Minor Version : ATA8-ACS version 6 Transfer Mode : SATA/300 | SATA/600 Power On Hours : 2486 Std. Power On Count : 743 mal Temperature : 33 C (91 F) Health Status : Gut Features : S.M.A.R.T., APM, 48bit LBA, NCQ APM Level : 4080h [ON] AAM Level : ---- Drive Letter : E: F: -- S.M.A.R.T. -------------------------------------------------------------- ID Cur Wor Thr RawValues(6) Attribute Name 01 100 100 _62 000000000000 Lesefehlerrate ↓ 02 100 100 _40 000000000000 Datendurchsatz-Leistung ↑ 03 125 125 _33 001600000002 Mittl. Anlaufzeit ↓ 04 100 100 __0 0000000003BF Start/Stopp-Zyklen d. Spindel 05 100 100 __5 000000000000 Anz. wiederzugewiesener Sektoren ↓ 07 100 100 _67 000000000000 Anz. Suchfehler 08 100 100 _40 000000000000 Güte der Suchoperationen ↑ 09 _95 _95 __0 0000000009B6 Betriebsstunden 0A 100 100 _60 000000000000 Anz. misslungener Spindelanläufe ↓ 0C 100 100 __0 0000000002E7 Anz. Geräte-Einschaltvorgänge BF 100 100 __0 000000000000 G-Sensor-Fehlerrate ↓ C0 100 100 __0 000000000006 Ausschaltungsabbrüche ↓ C1 _96 _96 __0 00000000A8A2 Laden/Entladen-Zyklen ↓ C2 181 181 __0 002F00090021 Temperatur ↓ C4 100 100 __0 000000000000 Wiederzuweisungsereignisse ↓ C5 100 100 __0 000000000000 Aktuell schwebende Sektoren ↓ C6 100 100 __0 000000000000 Nicht korrigierbare Sektoren ↓ C7 200 200 __0 000000000000 UltraDMA-CRC-Fehler ↓ DF 100 100 __0 000000000000 Laden/Entladen-Wiederholungen -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 045A 3FFF C837 0010 0000 0000 003F 0000 0000 0000 010: 2020 2020 2020 4A52 3130 3030 3650 304E 4C57 4146 020: 0003 FFFF 0004 4A42 304F 4133 4A30 4847 5354 2048 030: 5453 3732 3130 3130 4139 4536 3330 2020 2020 2020 040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00 050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110 060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000 070: 0000 0000 0000 0000 0000 001F 9F0E 0004 005E 004C 080: 01FC 0028 746B 7D69 6163 7469 BC49 6163 407F 004F 090: 0050 4080 FFFE 0000 0000 0000 0000 0000 0000 0000 100: 6DB0 7470 0000 0000 0000 0000 6003 74DC 5000 CCA7 110: DCC9 5E4D 0000 0000 0000 0000 0000 0000 0000 401C 120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 000B 130: 0000 0000 2182 1CF1 FA00 0000 4000 0400 0004 0000 140: 0000 0803 0602 0702 0702 0000 0000 0000 0000 0000 150: 0000 0005 3033 4233 0000 6804 0000 5DBD 97B0 8000 160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000 210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000 220: 0000 0000 103F 0021 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0001 03E0 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 0000 0000 0000 0EA5 -- SMART_READ_DATA --------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 10 00 01 0B 00 64 64 00 00 00 00 00 00 00 02 05 010: 00 64 64 00 00 00 00 00 00 00 03 07 00 7D 7D 02 020: 00 00 00 16 00 00 04 12 00 64 64 BF 03 00 00 00 030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 0B 040: 00 64 64 00 00 00 00 00 00 00 08 05 00 64 64 00 050: 00 00 00 00 00 00 09 12 00 5F 5F B6 09 00 00 00 060: 00 00 0A 13 00 64 64 00 00 00 00 00 00 00 0C 32 070: 00 64 64 E7 02 00 00 00 00 00 BF 0A 00 64 64 00 080: 00 00 00 00 00 00 C0 32 00 64 64 06 00 00 00 00 090: 00 00 C1 12 00 60 60 A2 A8 00 00 00 00 00 C2 02 0A0: 00 B5 B5 21 00 09 00 2F 00 00 C4 32 00 64 64 00 0B0: 00 00 00 00 00 00 C5 22 00 64 64 00 00 00 00 00 0C0: 00 00 C6 08 00 64 64 00 00 00 00 00 00 00 C7 0A 0D0: 00 C8 C8 00 00 00 00 00 00 00 DF 0A 00 64 64 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 2D 00 01 5B 170: 03 00 01 00 02 9F 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 7E -- SMART_READ_THRESHOLD ---------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 10 00 01 3E 00 00 00 00 00 00 00 00 00 00 02 28 010: 00 00 00 00 00 00 00 00 00 00 03 21 00 00 00 00 020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 030: 00 00 05 05 00 00 00 00 00 00 00 00 00 00 07 43 040: 00 00 00 00 00 00 00 00 00 00 08 28 00 00 00 00 050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00 060: 00 00 0A 3C 00 00 00 00 00 00 00 00 00 00 0C 00 070: 00 00 00 00 00 00 00 00 00 00 BF 00 00 00 00 00 080: 00 00 00 00 00 00 C0 00 00 00 00 00 00 00 00 00 090: 00 00 C1 00 00 00 00 00 00 00 00 00 00 00 C2 00 0A0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00 0B0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00 0C0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00 0D0: 00 00 00 00 00 00 00 00 00 00 DF 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 89 Code:
ATTFilter ---------------------------------------------------------------------------- CrystalDiskInfo 7.0.5 (C) 2008-2016 hiyohiyo Crystal Dew World : hxxp://crystalmark.info/ ---------------------------------------------------------------------------- OS : Windows 10 [10.0 Build 14393] (x64) Date : 2017/01/05 23:26:42 -- Controller Map ---------------------------------------------------------- + Standardmäßiger SATA AHCI- Controller [ATA] - SAMSUNG MZHPU256HCGL-00004 + Intel(R) 8 Series Chipset Family SATA AHCI Controller [ATA] - MATSHITA BD-CMB UJ172 S - HGST HTS721010A9E630 - Microsoft-Controller für Speicherplätze [SCSI] - Virtual CloneDrive [SCSI] -- Disk List --------------------------------------------------------------- (1) SAMSUNG MZHPU256HCGL-00004 : 256,0 GB [0/0/0, pd1] - sg (2) HGST HTS721010A9E630 : 1000,2 GB [1/1/0, pd1] ---------------------------------------------------------------------------- (1) SAMSUNG MZHPU256HCGL-00004 ---------------------------------------------------------------------------- Model : SAMSUNG MZHPU256HCGL-00004 Firmware : UXM6601Q Serial Number : S1NCNYAF901359 Disk Size : 256,0 GB (8,4/137,4/256,0/256,0) Buffer Size : Unbekannt Queue Depth : 32 # of Sectors : 500118192 Rotation Rate : ---- (SSD) Interface : Serial ATA Major Version : ACS-2 Minor Version : ATA8-ACS version 4c Transfer Mode : SATA/600 | SATA/600 Power On Hours : 2490 Std. Power On Count : 908 mal Wear Level Count : 309 Temperature : Unbekannt Health Status : Gut (92 %) Features : S.M.A.R.T., 48bit LBA, NCQ, TRIM APM Level : ---- AAM Level : ---- Drive Letter : C: D: -- S.M.A.R.T. -------------------------------------------------------------- ID Cur Wor Thr RawValues(6) Attribute Name 09 _99 _99 __0 0000000009BA Betriebsstunden 0C _99 _99 __0 00000000038C Anz. Geräte-Einschaltvorgänge B1 _91 _91 _17 000000000135 Verschleißregulierung B2 _92 _92 _10 0000000000C4 Benutzte reservierte Blöcke (Chip) B3 _92 _92 _10 000000000182 Benutzte reservierte Blöcke (gesamt) B4 _92 _92 _10 0000000012FE Unbenutzte reservierte Blöcke (gesamt) B7 100 100 _10 000000000000 Laufzeit schlechter Blöcke (gesamt) -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000 010: 5331 4E43 4E59 4146 3930 3133 3539 2020 2020 2020 020: 0000 0000 0000 5558 4D36 3630 3151 5341 4D53 554E 030: 4720 4D5A 4850 5532 3536 4843 474C 2D30 3030 3034 040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00 050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB D110 060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0E00 070: 0000 0000 0000 0000 0000 001F 850E 0006 0064 0160 080: 03FC 0039 746B 7D01 4163 7469 BC01 4163 207F 0003 090: 0010 0000 FFFE 0000 0000 0000 0000 0000 0000 0000 100: 32B0 1DCF 0000 0000 0000 0008 4000 0000 5002 5386 110: 0004 09DA 0000 0000 0000 0000 0000 0000 0000 401E 120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000 130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0001 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000 210: 0000 0000 0000 0000 0000 0000 0000 0001 0000 0000 220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0000 0800 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 D465 F26B A6F7 787E -- SMART_READ_DATA --------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 01 00 09 32 00 63 63 BA 09 00 00 00 00 00 0C 32 010: 00 63 63 8C 03 00 00 00 00 00 B1 13 00 5B 5B 35 020: 01 00 00 00 00 00 B2 13 00 5C 5C C4 00 00 00 00 030: 00 00 B3 13 00 5C 5C 82 01 00 00 00 00 00 B4 13 040: 00 5C 5C FE 12 00 00 00 00 00 B7 13 00 64 64 00 050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5F 170: 03 00 01 00 02 0A 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 26 -- SMART_READ_THRESHOLD ---------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 01 00 09 00 00 00 00 00 00 00 00 00 00 00 0C 00 010: 00 00 00 00 00 00 00 00 00 00 B1 11 00 00 00 00 020: 00 00 00 00 00 00 B2 0A 00 00 00 00 00 00 00 00 030: 00 00 B3 0A 00 00 00 00 00 00 00 00 00 00 B4 0A 040: 00 00 00 00 00 00 00 00 00 00 B7 0A 00 00 00 00 050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 ---------------------------------------------------------------------------- (2) HGST HTS721010A9E630 ---------------------------------------------------------------------------- Model : HGST HTS721010A9E630 Firmware : JB0OA3J0 Serial Number : JR10006P0NLWAF Disk Size : 1000,2 GB (8,4/137,4/1000,2/1000,2) Buffer Size : 32767 KB Queue Depth : 32 # of Sectors : 1953525168 Rotation Rate : 7200 RPM Interface : Serial ATA Major Version : ATA8-ACS Minor Version : ATA8-ACS version 6 Transfer Mode : SATA/300 | SATA/600 Power On Hours : 2486 Std. Power On Count : 743 mal Temperature : 33 C (91 F) Health Status : Gut Features : S.M.A.R.T., APM, 48bit LBA, NCQ APM Level : 4080h [ON] AAM Level : ---- Drive Letter : E: F: -- S.M.A.R.T. -------------------------------------------------------------- ID Cur Wor Thr RawValues(6) Attribute Name 01 100 100 _62 000000000000 Lesefehlerrate ↓ 02 100 100 _40 000000000000 Datendurchsatz-Leistung ↑ 03 125 125 _33 001600000002 Mittl. Anlaufzeit ↓ 04 100 100 __0 0000000003BF Start/Stopp-Zyklen d. Spindel 05 100 100 __5 000000000000 Anz. wiederzugewiesener Sektoren ↓ 07 100 100 _67 000000000000 Anz. Suchfehler 08 100 100 _40 000000000000 Güte der Suchoperationen ↑ 09 _95 _95 __0 0000000009B6 Betriebsstunden 0A 100 100 _60 000000000000 Anz. misslungener Spindelanläufe ↓ 0C 100 100 __0 0000000002E7 Anz. Geräte-Einschaltvorgänge BF 100 100 __0 000000000000 G-Sensor-Fehlerrate ↓ C0 100 100 __0 000000000006 Ausschaltungsabbrüche ↓ C1 _96 _96 __0 00000000A8A2 Laden/Entladen-Zyklen ↓ C2 181 181 __0 002F00090021 Temperatur ↓ C4 100 100 __0 000000000000 Wiederzuweisungsereignisse ↓ C5 100 100 __0 000000000000 Aktuell schwebende Sektoren ↓ C6 100 100 __0 000000000000 Nicht korrigierbare Sektoren ↓ C7 200 200 __0 000000000000 UltraDMA-CRC-Fehler ↓ DF 100 100 __0 000000000000 Laden/Entladen-Wiederholungen -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 045A 3FFF C837 0010 0000 0000 003F 0000 0000 0000 010: 2020 2020 2020 4A52 3130 3030 3650 304E 4C57 4146 020: 0003 FFFF 0004 4A42 304F 4133 4A30 4847 5354 2048 030: 5453 3732 3130 3130 4139 4536 3330 2020 2020 2020 040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00 050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110 060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000 070: 0000 0000 0000 0000 0000 001F 9F0E 0004 005E 004C 080: 01FC 0028 746B 7D69 6163 7469 BC49 6163 407F 004F 090: 0050 4080 FFFE 0000 0000 0000 0000 0000 0000 0000 100: 6DB0 7470 0000 0000 0000 0000 6003 74DC 5000 CCA7 110: DCC9 5E4D 0000 0000 0000 0000 0000 0000 0000 401C 120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 000B 130: 0000 0000 2182 1CF1 FA00 0000 4000 0400 0004 0000 140: 0000 0803 0602 0702 0702 0000 0000 0000 0000 0000 150: 0000 0005 3033 4233 0000 6804 0000 5DBD 97B0 8000 160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000 210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000 220: 0000 0000 103F 0021 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0001 03E0 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 0000 0000 0000 0EA5 -- SMART_READ_DATA --------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 10 00 01 0B 00 64 64 00 00 00 00 00 00 00 02 05 010: 00 64 64 00 00 00 00 00 00 00 03 07 00 7D 7D 02 020: 00 00 00 16 00 00 04 12 00 64 64 BF 03 00 00 00 030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 0B 040: 00 64 64 00 00 00 00 00 00 00 08 05 00 64 64 00 050: 00 00 00 00 00 00 09 12 00 5F 5F B6 09 00 00 00 060: 00 00 0A 13 00 64 64 00 00 00 00 00 00 00 0C 32 070: 00 64 64 E7 02 00 00 00 00 00 BF 0A 00 64 64 00 080: 00 00 00 00 00 00 C0 32 00 64 64 06 00 00 00 00 090: 00 00 C1 12 00 60 60 A2 A8 00 00 00 00 00 C2 02 0A0: 00 B5 B5 21 00 09 00 2F 00 00 C4 32 00 64 64 00 0B0: 00 00 00 00 00 00 C5 22 00 64 64 00 00 00 00 00 0C0: 00 00 C6 08 00 64 64 00 00 00 00 00 00 00 C7 0A 0D0: 00 C8 C8 00 00 00 00 00 00 00 DF 0A 00 64 64 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 2D 00 01 5B 170: 03 00 01 00 02 9F 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 7E -- SMART_READ_THRESHOLD ---------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 10 00 01 3E 00 00 00 00 00 00 00 00 00 00 02 28 010: 00 00 00 00 00 00 00 00 00 00 03 21 00 00 00 00 020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 030: 00 00 05 05 00 00 00 00 00 00 00 00 00 00 07 43 040: 00 00 00 00 00 00 00 00 00 00 08 28 00 00 00 00 050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00 060: 00 00 0A 3C 00 00 00 00 00 00 00 00 00 00 0C 00 070: 00 00 00 00 00 00 00 00 00 00 BF 00 00 00 00 00 080: 00 00 00 00 00 00 C0 00 00 00 00 00 00 00 00 00 090: 00 00 C1 00 00 00 00 00 00 00 00 00 00 00 C2 00 0A0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00 0B0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00 0C0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00 0D0: 00 00 00 00 00 00 00 00 00 00 DF 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 89 |
![]() | #7 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer ESET onlinescaner alss ich gerade wieder laufen und er hat bisher 7 Bedrohungen gefunden. Leider funktionieren jetzt z.B. File Restore Plus nicht mehr. Muss denn Vierenscannern zum Opfer gefallen sein. Hab ich aber von Seiten wie Chip.de. genauso wie Christal Disk weil ich bei Links/Seiten wie deiner oben kein gutes Gefühl habe..... |
![]() | #8 | |
/// Malwareteam ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hi, poste mal bitte das Log von ESET. Das sollte hier sein: Code:
ATTFilter C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) Zitat:
![]() | #9 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Ich installiere immer manuel und schau das nirgends ein Hacken für unnötige Programme gesetzt ist ;-) aber man ist trotdem nie sicher. Das Logfile, leider ist es abgebrochen, hab aber mit snipping tool ein Bild der gefundenen Dateien gemacht. War leider auch etwas dabei das ich noch brauche ;-(( P.S. jetzt weis ich auch warum Cristal Disk Info nicht mehr läuft. Eset hat das auch gelöscht, hab automatisches entfernen aktiviert, grrrr aber du meindest doch das das o.k ist!?!? Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # EOSSerial=25d1b23389c946478de727fbc1bc1037 # end=init # utc_time=2017-01-01 07:21:07 # local_time=2017-01-01 08:21:07 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 31924 # product=EOS # version=8 # OnlineScannerApp.exe= # EOSSerial=25d1b23389c946478de727fbc1bc1037 # end=updated # utc_time=2017-01-01 07:24:04 # local_time=2017-01-01 08:24:04 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.1.1 # EOSSerial=25d1b23389c946478de727fbc1bc1037 # engine=31924 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2017-01-02 04:42:18 # local_time=2017-01-02 05:42:18 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 3175737 34886400 0 0 # scanned=388022 # found=4 # cleaned=4 # scan_time=33493 sh=C3BE7FE84753C7B85092EF643E8B3660D3A947BF ft=0 fh=0000000000000000 vn="JS/BrowseFox.A evtl. unerwünschte Anwendung (gelöscht)" ac=C fn="C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\extensions\{992cd662-eda8-4827-aa8e-aba08a61ba86}.xpi" sh=725494C5A53143828219CDB22654374274CFD29F ft=1 fh=fd26318bbc84deb1 vn="Win32/Somoto.E evtl. unerwünschte Anwendung (gelöscht)" ac=C fn="E:\Downloads C\setup-cpu-m-benchmark.exe" sh=4BBF2B99150F7933FD1BB92577EF91948AA6DDD6 ft=1 fh=48effa1be0e9c9c2 vn="Win32/Somoto.Q evtl. unerwünschte Anwendung (gelöscht)" ac=C fn="E:\Downloads C\Shutdown7_212Setup.exe" sh=B86573030AB1B8EA1777ACE10B5493C2FD7EE6ED ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.Themida verdächtige Datei (gelöscht)" ac=C fn="E:\Downloads C\5t66DAEMON Tools Pro v6.1.0.0483-P2P _ Multilanguage-Deutschmah99x2u5t9\htoolDTP6100483.rar" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # EOSSerial=25d1b23389c946478de727fbc1bc1037 # end=init # utc_time=2017-01-04 08:23:41 # local_time=2017-01-04 09:23:41 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 31958 # product=EOS # version=8 # OnlineScannerApp.exe= # EOSSerial=25d1b23389c946478de727fbc1bc1037 # end=updated # utc_time=2017-01-04 08:25:38 # local_time=2017-01-04 09:25:38 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.1.1 # EOSSerial=25d1b23389c946478de727fbc1bc1037 # engine=31958 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2017-01-04 11:14:02 # local_time=2017-01-05 12:14:02 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 3418841 35125904 0 0 # scanned=372915 # found=0 # cleaned=0 # scan_time=10103 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # EOSSerial=25d1b23389c946478de727fbc1bc1037 # end=init # utc_time=2017-01-05 09:50:13 # local_time=2017-01-05 10:50:13 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 31970 # product=EOS # version=8 # OnlineScannerApp.exe= # EOSSerial=25d1b23389c946478de727fbc1bc1037 # end=updated # utc_time=2017-01-05 09:52:36 # local_time=2017-01-05 10:52:36 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.1.1 # EOSSerial=25d1b23389c946478de727fbc1bc1037 # engine=31970 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2017-01-07 10:03:10 # local_time=2017-01-07 11:03:10 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 3626989 35337652 0 0 # scanned=292771 # found=10 # cleaned=0 # scan_time=43832 sh=812C8E84D0B76D7FCCF0A87EAD6B8EB44BC2C5D2 ft=1 fh=fa2f1d203bfb9aee vn="Variante von Win64/NetFilter.A potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\ASUS\ROG Game First III\drivers\Driver\amd64\NFC_Driver.sys" sh=B62FD5BC1AAFEE7128A30993F0396B578E3FEC18 ft=1 fh=2b65f41ee7ee5cf9 vn="Variante von Win32/NetFilter.A potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\ASUS\ROG Game First III\drivers\Driver\i386\NFC_Driver.sys" sh=AFF54496996FAD920FA7DBA198A7452B4FEDCBC8 ft=1 fh=6d8a21e072e7411e vn="Variante von Win32/Bundled.Toolbar.Google.C potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe" sh=4A3CDBD119BB149FFD96BAB9DDDB768E505460B0 ft=1 fh=95211c5bd1dd164e vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Users\Magic\Downloads\rcsetup153.exe" sh=812C8E84D0B76D7FCCF0A87EAD6B8EB44BC2C5D2 ft=1 fh=fa2f1d203bfb9aee vn="Variante von Win64/NetFilter.A potenziell unsichere Anwendung" ac=I fn="C:\Windows\System32\drivers\NFC_Driver.sys" sh=65D401FF46E54CBEC63AB26C918811D82719C0D1 ft=0 fh=0000000000000000 vn="Variante von Win32/Keygen.AU potenziell unsichere Anwendung" ac=I fn="E:\Downloads\CyberLink.PowerDirector.Ultimate.v14.0.2527 del\CyberLink.PowerDirector.Ultimate.v14.0.2527.0.Multilingual-P2P\Keygen-CORE\CyberLink.PowerDirector.Ultimate.Suite.v14.Multilingual.Keymaker.Only-CORE.rar" sh=07B6A238D75C538203DD7F980E8E0D4B9F38408B ft=0 fh=0000000000000000 vn="Variante von Win32/HackTool.Crack.ES potenziell unsichere Anwendung" ac=I fn="E:\Downloads\O4riA6TBl6indFo7restUpd2-elamigos del\O4riA6TBl6indFo7restUpd2-elamigos.rar" sh=A3CB09EE9D3B805CB3A41781E35C76E292BD5D2D ft=0 fh=0000000000000000 vn="Variante von Win32/HackTool.Crack.DW potenziell unsichere Anwendung" ac=I fn="E:\Downloads\Universe Sandbox 2 Alpha del\Universe.Sandbox.2.Alpha.131.rar" sh=4D409389244F98A61DF7D79ADD53BF4FADE32773 ft=1 fh=f7301b6d1a6273dd vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="E:\Downloads C\aTube_Catcher_3.8.7980.exe" sh=CCC987D06A17A36D1F439E76D7287A611189A4E3 ft=1 fh=69db4cf38c7a0a92 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="E:\Downloads C\CrystalDiskInfo6_5_2-en.exe" |
![]() | #10 |
/// Malwareteam ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hi, es ist auch OK, nur im Installer ist Adware, die muss man halt abhakerln. Code:
ATTFilter E:\Downloads\CyberLink.PowerDirector.Ultimate.v14.0.2527 del\CyberLink.PowerDirector.Ultimate.v14.0.2527.0.Multilingual-P2P\Keygen-CORE\CyberLink.PowerDirector.Ultimate.Suite.v14.Multilingual.Keymaker.Only-CORE.rar |
![]() | #11 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Das hab ich von einem Kumpel, bei ihm läuft es ohne Props, habs aber gelöscht da ichs doch nicht mehr brauche. grüße |
![]() | #12 |
/// Malwareteam ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hi, Dann mal frische FRST-Logs von FRST mit Additions.txt posten. |
![]() | #13 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Oh nochmal bei 0. grüße FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 08-01-2017 durchgeführt von Magic (Administrator) auf OUTLAW (10-01-2017 22:06:00) Gestartet von C:\Users\Magic\Downloads\Spam entfernen Geladene Profile: Magic (Verfügbare Profile: Magic) Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe () C:\Program Files (x86)\Lexware\AAVUpdateManager\aavus.exe (ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\\AsusWSWinService.exe () C:\Windows\SysWOW64\ASGT.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (StagWare) C:\Program Files (x86)\NoteBook FanControl\NbfcService.exe (Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (CyberLink) C:\Program Files\CyberLink\Shared files\RichVideo64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_1.3.0.0_x64__8wekyb3d8bbwe\Microsoft.StickyNotes.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Windows\SysWOW64\UMonit64.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\SpotifyCrashService.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe () C:\ProgramData\firemin_2086\Firemin.exe () C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (AppWork GmbH) C:\Users\Magic\AppData\Local\JDownloader v2.0\JDownloader2.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe (Heiko Sommerfeldt) C:\Program Files (x86)\PhonerLite\PhonerLite.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.350_none_43278ee965418581\TiWorker.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [UMonit] => C:\WINDOWS\SysWOW64\UMonit64.exe [53832 2015-07-16] () HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-08-26] (NVIDIA Corporation) HKLM-x32\...\Run: [ROGNB] => C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe [463872 2013-05-15] () HKLM-x32\...\Run: [ASUS ROG MacroKey] => C:\Program Files (x86)\ASUS\ASUS ROG MacroKey\Hid.exe [2036224 2014-07-30] (ASUS) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Run: [Spotify Web Helper] => C:\Users\Magic\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-23] (Spotify Ltd) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Run: [Spotify] => C:\Users\Magic\AppData\Roaming\Spotify\Spotify.exe [7153264 2016-12-23] (Spotify Ltd) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9288408 2016-12-06] (Piriform Ltd) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\MountPoints2: {0941fcab-5bc4-11e4-8252-806e6f6e6963} - "G:\setup.exe" Lsa: [Notification Packages] ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-21] (Dropbox, Inc.) Startup: C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Firemin.lnk [2017-01-07] ShortcutTarget: Firemin.lnk -> C:\ProgramData\firemin_2086\Firemin.exe () ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{5c03a8e7-7c1d-473a-a896-16f731705c55}: [DhcpNameServer] Tcpip\..\Interfaces\{757bfc45-60e4-46e3-904d-5b95852b4717}: [DhcpNameServer] Tcpip\..\Interfaces\{917549de-333b-4c66-96de-c24c7380048d}: [DhcpNameServer] Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {89A7941E-C9C5-4D83-A5C6-E0C6803564A7} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {B04CD7FA-8569-4EA1-9969-7D1FC2BC81A8} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {B1CCEA68-E65F-43F7-B333-F36D145B95AA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001 -> {D54C87D2-13A5-4BF7-A4D4-C48F2BAC633C} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-06] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-06] (Oracle Corporation) FireFox: ======== FF DefaultProfile: ozg7dh2g.default FF ProfilePath: C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default [2017-01-10] FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\ozg7dh2g.default -> FF SearchEngineOrder.2: Mozilla\Firefox\Profiles\ozg7dh2g.default -> FF SearchEngineOrder.US.1: Mozilla\Firefox\Profiles\ozg7dh2g.default -> FF Homepage: Mozilla\Firefox\Profiles\ozg7dh2g.default -> about:home FF Session Restore: Mozilla\Firefox\Profiles\ozg7dh2g.default -> ist aktiviert. FF Extension: (AdBlocker Ultimate) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\adblockultimate@adblockultimate.net.xpi [2016-12-28] FF Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\firefox@zenmate.com.xpi [2016-09-30] FF Extension: (WhatsApp Panel) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\whatsapppanel@alejandrobrizuela.com.ar.xpi [2016-04-28] FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2016-08-27] FF Extension: (Flash Updater Pro) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{27cfe898-bf77-41da-8fd1-5ff664ac0003}.xpi [2015-12-19] [ist nicht signiert] FF Extension: (HTML5 Converter) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{2e2632fa-3b8f-4f13-94f9-69d6eb4c505e}.xpi [2016-05-29] [ist nicht signiert] FF Extension: (Video DownloadHelper) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-12-30] FF Extension: (Adblock Plus) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24] FF Extension: (OkayFreedom) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi [2016-12-22] FF Extension: (Tab Manager) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{de51b06d-3899-422c-9909-4e7edb0f4bae}.xpi [2015-12-25] [ist nicht signiert] FF Extension: (Web2PDF converter) - C:\Users\Magic\AppData\Roaming\Mozilla\Firefox\Profiles\ozg7dh2g.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi [2016-04-28] FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Privacy Suite 17\spmplugin3 FF Extension: (Kein Name) - C:\Program Files (x86)\Steganos Privacy Suite 17\spmplugin3 [2015-12-31] [ist nicht signiert] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-21] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-21] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-10-23] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-10-23] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-06] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-06] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-25] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-25] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-12-20] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-12-20] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] () FF Plugin HKU\S-1-5-21-2786200759-2278858845-1295660402-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-06-18] () ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AAV UpdateService; C:\Program Files (x86)\Lexware\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [Datei ist nicht signiert] R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\\AsusWSWinService.exe [71680 2014-02-25] (ASUS Cloud Corporation) [Datei ist nicht signiert] S2 AsusGameFirstService; C:\Program Files (x86)\ASUS\ROG Game First III\AsusGameFirstService.exe [345912 2014-08-29] (ASUSTeK) S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [971160 2016-12-15] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5337600 2016-12-15] (AVG Technologies CZ, s.r.o.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [725976 2016-12-15] (AVG Technologies CZ, s.r.o.) S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [486936 2016-12-13] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [470552 2016-12-13] (BlueStack Systems, Inc.) S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [511512 2016-12-13] (BlueStack Systems, Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [42096 2016-12-21] (Dropbox, Inc.) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [344288 2015-03-20] (Futuremark) S2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-28] (WildTangent) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Datei ist nicht signiert] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel(R) Corporation) [Datei ist nicht signiert] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-10-23] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-10-23] (Intel Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 NbfcService; C:\Program Files (x86)\NoteBook FanControl\NbfcService.exe [7168 2015-05-09] (StagWare) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-08-26] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-08-26] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-08-26] (NVIDIA Corporation) R2 OkayFreedom VPN Starter Service; C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe [353792 2016-11-09] (Steganos Software GmbH) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-12-20] () R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2014-10-20] (CyberLink) R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-03] (DEVGURU Co., LTD.) S3 ThunderboltService; C:\Program Files\Intel\Thunderbolt Software\tbtsvc.exe [1179944 2014-05-13] (Intel Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [4788496 2016-11-25] (AVG Technologies CZ, s.r.o.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580144 2015-08-06] (WiseCleaner.com) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [19768 2013-07-02] (ASUSTek Computer Inc.) S0 Avgboota; C:\WINDOWS\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\WINDOWS\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdrivera.sys [312576 2016-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\WINDOWS\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\WINDOWS\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\WINDOWS\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\WINDOWS\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\WINDOWS\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.) R0 Avguniva; C:\WINDOWS\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys [313096 2016-08-04] (AVG Technologies CZ, s.r.o.) S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-12-13] (BlueStack Systems) S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-11-08] (Bluestack System Inc. ) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 GeneStor; C:\WINDOWS\system32\DRIVERS\GeneStor.sys [115704 2015-07-16] (GenesysLogic) R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2015-11-20] (Glarysoft Ltd) R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230144 2016-11-11] (Intel Corporation) R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [88256 2015-06-09] (Intel Corporation) R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( ) R1 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [109272 2017-01-05] (Malwarebytes) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-01-08] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 NETwNb64; C:\WINDOWS\system32\DRIVERS\Netwbw02.sys [4112656 2015-09-23] (Intel Corporation) R1 NFC_Driver; C:\WINDOWS\System32\drivers\NFC_Driver.sys [48336 2014-03-27] (Titan ARC Corp.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_fd2cdd92cf7ee187\nvlddmkm.sys [14216760 2016-08-27] (NVIDIA Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-08-26] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-06-03] (NVIDIA Corporation) U0 rjaty; C:\WINDOWS\System32\drivers\imofugc.sys [79064 2017-01-05] (Malwarebytes Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [896272 2016-01-19] (Realtek ) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-11-25] (AVG Netherlands B.V.) S1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-09-08] (Oracle Corporation) R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [146072 2015-09-08] (Oracle Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R1 WinRing0_1_2_0; C:\Program Files (x86)\NoteBook FanControl\WinRing0x64.sys [14544 2015-06-02] (OpenLibSys.org) R2 WiseFs; C:\Windows\WiseFs64.sys [13264 2015-12-29] (WiseCleaner.com) S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2015-12-23] (wisecleaner.com) R1 WiseUnlock; C:\Windows\WiseUnlock64.sys [12240 2015-05-19] (WiseCleaner.com) S3 dbx; system32\DRIVERS\dbx.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-10 00:03 - 2017-01-10 00:03 - 00002904 _____ C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance 2017-01-08 22:43 - 2017-01-08 22:43 - 08767615 _____ C:\Users\Magic\Downloads\Kaufhilfe_FAKTUM.pdf 2017-01-08 22:43 - 2017-01-08 22:43 - 00260977 _____ C:\Users\Magic\Downloads\Kaufhilfe_FAKTUMFRONTEN.pdf 2017-01-07 23:38 - 2017-01-07 23:38 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple 2017-01-07 23:38 - 2017-01-07 23:38 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2017-01-07 23:03 - 2017-01-07 23:03 - 00001680 _____ C:\Users\Magic\Desktop\DiskInfo64 - Verknüpfung.lnk 2017-01-07 16:57 - 2017-01-07 16:57 - 00000000 ____D C:\Users\Magic\Downloads\Blade Nano CP s 2017-01-05 23:21 - 2017-01-05 23:21 - 00079064 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\imofugc.sys 2017-01-05 19:40 - 2017-01-08 00:52 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo7_0_5-en 2017-01-04 20:40 - 2017-01-10 22:06 - 00000000 ____D C:\FRST 2017-01-01 20:21 - 2017-01-01 20:21 - 00000000 ____D C:\Program Files (x86)\ESET 2017-01-01 19:16 - 2017-01-07 22:15 - 00000767 _____ C:\Users\Public\Desktop\HELI-X6.1.lnk 2017-01-01 19:16 - 2017-01-01 19:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HELI-X6.1 2017-01-01 19:13 - 2017-01-01 19:14 - 00000000 ____D C:\Users\Magic\Downloads\Devo 7 2017-01-01 12:46 - 2017-01-01 12:46 - 06798851 _____ C:\Users\Magic\Downloads\tm-fon.zip 2016-12-31 21:36 - 2016-12-31 21:51 - 03366304 _____ (Copyright © 2010 eSupport.com • All Rights Reserved ) C:\Users\Magic\Downloads\FileRestorePlus06_setup.exe 2016-12-31 03:16 - 2016-12-31 03:16 - 00000000 ____D C:\Program Files\CloneSpy 2016-12-31 03:09 - 2016-12-31 03:15 - 04473411 _____ (Marcus Kleinehagenbrock) C:\Users\Magic\Downloads\cspy331.exe 2016-12-31 02:25 - 2017-01-07 22:15 - 00001739 _____ C:\Users\Public\Desktop\Recuva.lnk 2016-12-31 02:25 - 2016-12-31 21:51 - 00000000 ____D C:\Program Files\Recuva 2016-12-31 02:25 - 2016-12-31 02:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva 2016-12-31 02:24 - 2016-12-31 02:24 - 05562976 _____ (Piriform Ltd) C:\Users\Magic\Downloads\rcsetup153.exe 2016-12-31 01:24 - 2017-01-07 22:15 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp.lnk 2016-12-31 01:24 - 2017-01-07 22:14 - 00002570 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk 2016-12-31 01:24 - 2016-11-25 13:45 - 00053008 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\TURegOpt.exe 2016-12-31 00:04 - 2016-12-31 00:04 - 00000000 ____D C:\Users\Magic\AppData\Local\Apple Computer 2016-12-30 12:00 - 2016-12-30 12:00 - 00003976 _____ C:\WINDOWS\System32\Tasks\Update Checker 2016-12-30 11:10 - 2017-01-08 16:37 - 00000000 ____D C:\Users\Magic\Downloads\Android 2016-12-29 23:48 - 2016-12-29 23:49 - 00098822 _____ C:\TDSSKiller. 2016-12-29 23:47 - 2016-12-29 23:48 - 00114772 _____ C:\TDSSKiller. 2016-12-29 22:47 - 2017-01-10 22:05 - 00000000 ____D C:\Users\Magic\Downloads\Spam entfernen 2016-12-29 20:30 - 2017-01-07 22:15 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2016-12-29 20:29 - 2017-01-05 23:23 - 00000000 ____D C:\Users\Magic\Desktop\mbar 2016-12-29 18:19 - 2016-12-29 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts 2016-12-29 18:18 - 2017-01-07 22:13 - 00000695 _____ C:\Users\Magic\Desktop\Play Star Wars Jedi Knight Jedi Academy.lnk 2016-12-29 15:28 - 2016-12-29 15:28 - 00000000 ____D C:\Users\Public\Desktop\SWAT 4 Gold Edition 2016-12-29 15:28 - 2016-12-29 15:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWAT 4 Gold Edition 2016-12-29 13:29 - 2016-12-29 13:29 - 00351824 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-12-29 01:30 - 2016-12-29 01:30 - 00000000 ____D C:\Users\Magic\AppData\Local\AVG Netherlands BV 2016-12-28 21:22 - 2017-01-02 22:22 - 00000000 ___HD C:\$AVG 2016-12-28 21:01 - 2017-01-07 22:15 - 00000829 _____ C:\Users\Public\Desktop\Hitman Codename 47.lnk 2016-12-28 21:01 - 2016-12-28 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hitman Codename 47 [GOG.com] 2016-12-28 19:15 - 2017-01-07 22:13 - 00000842 _____ C:\Users\Magic\Desktop\The Evil Within Language Selector.lnk 2016-12-28 19:15 - 2017-01-07 22:13 - 00000815 _____ C:\Users\Magic\Desktop\The Evil Within.lnk 2016-12-28 17:35 - 2017-01-07 22:13 - 00000905 _____ C:\Users\Magic\Desktop\Call of Duty Modern Warfare 3.lnk 2016-12-28 15:54 - 2016-12-28 18:34 - 00000000 ____D C:\Users\Magic\Downloads\Bilder 2016-12-27 22:52 - 2016-12-27 22:52 - 00003798 _____ C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater 2016-12-27 15:11 - 2017-01-07 22:13 - 00001221 _____ C:\Users\Magic\Desktop\Firemin.lnk 2016-12-27 14:41 - 2016-12-27 15:10 - 00000000 ____D C:\ProgramData\firemin_2086 2016-12-27 00:43 - 2016-12-27 00:44 - 00000000 ____D C:\Users\Magic\Downloads\Polarlichter 2016-12-26 02:25 - 2017-01-03 01:33 - 00000000 ____D C:\AdwCleaner 2016-12-24 23:16 - 2016-07-01 04:31 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StikyNot.exe 2016-12-24 23:16 - 2015-10-30 19:34 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StikyNot.exe.mui 2016-12-24 20:42 - 2016-11-23 14:37 - 00000570 _____ C:\Users\Magic\AppData\Local\TroubleshooterConfig.json 2016-12-24 20:41 - 2017-01-07 22:14 - 00001654 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk 2016-12-24 20:41 - 2017-01-07 22:14 - 00001642 _____ C:\Users\Public\Desktop\BlueStacks.lnk 2016-12-24 20:41 - 2016-12-24 20:42 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2016-12-24 20:40 - 2016-12-24 20:40 - 00000000 ____D C:\Users\Magic\AppData\Local\Bluestacks 2016-12-24 20:39 - 2016-12-24 20:41 - 00000000 ____D C:\Program Files (x86)\Bluestacks 2016-12-24 20:39 - 2016-12-13 18:27 - 00000000 ____D C:\ProgramData\Bluestacks 2016-12-24 13:59 - 2016-12-24 13:59 - 00000000 ____D C:\Users\Magic\AppData\Local\Chromium 2016-12-24 13:02 - 2017-01-07 22:15 - 00000774 _____ C:\Users\Public\Desktop\Office Vorlagen Teil 2.lnk 2016-12-23 15:14 - 2017-01-07 22:15 - 00000774 _____ C:\Users\Public\Desktop\Office Vorlagen Teil 1.lnk 2016-12-23 15:14 - 2016-12-24 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis 2016-12-23 14:38 - 2016-12-23 14:38 - 00000000 ____D C:\ProgramData\Logs 2016-12-23 12:04 - 2016-12-23 12:04 - 16752312 _____ C:\Users\Magic\Downloads\gup566setup_chip.exe 2016-12-23 00:30 - 2016-12-23 00:30 - 00000000 ____D C:\Users\Magic\AppData\Local\Zak2 2016-12-23 00:19 - 2016-12-23 00:19 - 00000611 _____ C:\Users\Magic\Desktop\Zak McKracken – Between Time and Space.lnk 2016-12-23 00:19 - 2016-12-23 00:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zak McKracken – Between Time and Space 2016-12-22 23:34 - 2017-01-07 22:15 - 00001142 _____ C:\Users\Public\Desktop\OkayFreedom.lnk 2016-12-22 23:34 - 2016-12-26 01:58 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Steganos VPN 2016-12-22 23:34 - 2016-12-22 23:35 - 00000000 ____D C:\Program Files (x86)\OkayFreedom 2016-12-22 23:34 - 2016-12-22 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom 2016-12-22 20:53 - 2017-01-07 22:15 - 00000786 _____ C:\Users\Public\Desktop\Dreamfall The Longest Journey.lnk 2016-12-22 20:53 - 2016-12-22 20:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dreamfall The Longest Journey 2016-12-22 11:15 - 2016-12-22 11:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-12-21 19:15 - 2016-12-21 19:15 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2016-12-21 19:15 - 2016-12-21 19:15 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2016-12-21 19:15 - 2016-12-21 19:15 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2016-12-21 19:15 - 2016-12-21 19:15 - 00042096 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2016-12-21 13:37 - 2016-12-09 11:32 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-12-21 13:37 - 2016-12-09 11:29 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-12-21 13:37 - 2016-12-09 11:19 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-12-21 13:37 - 2016-12-09 11:18 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2016-12-21 13:37 - 2016-12-09 11:18 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2016-12-21 13:37 - 2016-12-09 11:18 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi 2016-12-21 13:37 - 2016-12-09 11:18 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe 2016-12-21 13:37 - 2016-12-09 11:15 - 08168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-12-21 13:37 - 2016-12-09 11:15 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-12-21 13:37 - 2016-12-09 11:14 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-12-21 13:37 - 2016-12-09 11:01 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2016-12-21 13:37 - 2016-12-09 11:01 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-12-21 13:37 - 2016-12-09 10:57 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-12-21 13:37 - 2016-12-09 10:52 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2016-12-21 13:37 - 2016-12-09 10:51 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll 2016-12-21 13:37 - 2016-12-09 10:45 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll 2016-12-21 13:37 - 2016-12-09 10:41 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll 2016-12-21 13:37 - 2016-12-09 10:38 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2016-12-21 13:37 - 2016-12-09 10:37 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2016-12-21 13:37 - 2016-12-09 10:36 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-12-21 13:37 - 2016-12-09 10:33 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-12-21 13:37 - 2016-12-09 10:33 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2016-12-21 13:37 - 2016-12-09 10:31 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-12-21 13:37 - 2016-12-09 10:30 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-12-21 13:37 - 2016-12-09 10:28 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-12-21 13:37 - 2016-12-09 10:27 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2016-12-21 13:37 - 2016-12-09 10:26 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-12-21 13:37 - 2016-12-09 10:24 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-12-21 13:37 - 2016-12-09 10:23 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-12-21 13:37 - 2016-12-09 10:22 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-12-21 13:37 - 2016-12-09 10:22 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2016-12-21 13:37 - 2016-12-09 10:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll 2016-12-21 13:37 - 2016-12-09 10:18 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-12-21 13:37 - 2016-12-09 10:16 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2016-12-21 13:37 - 2016-12-09 10:15 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-12-21 13:37 - 2016-12-09 10:15 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2016-12-21 13:37 - 2016-12-09 10:15 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll 2016-12-21 13:37 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2016-12-21 13:37 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2016-12-21 13:37 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2016-12-21 13:37 - 2016-11-11 11:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2016-12-21 13:37 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-12-21 13:37 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-12-21 13:37 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2016-12-21 13:37 - 2016-11-11 10:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-12-21 13:37 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2016-12-21 13:37 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-12-21 13:37 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe 2016-12-21 13:37 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll 2016-12-21 13:37 - 2016-11-11 10:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-12-21 13:37 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2016-12-21 13:37 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-12-21 13:37 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2016-12-21 13:37 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll 2016-12-21 13:37 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2016-12-21 13:37 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys 2016-12-21 13:37 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-12-21 13:37 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2016-12-21 13:37 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-12-21 13:37 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-12-21 13:37 - 2016-11-11 10:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-12-21 13:37 - 2016-11-11 10:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-12-21 13:37 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2016-12-21 13:37 - 2016-11-11 10:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-12-21 13:37 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-12-21 13:37 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-12-21 13:37 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-21 13:37 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2016-12-21 13:37 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2016-12-21 13:37 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-12-21 13:37 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-12-21 13:37 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-12-21 13:37 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll 2016-12-21 13:37 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-12-21 13:37 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-12-21 13:37 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-12-21 13:37 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-12-21 13:37 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-12-21 13:37 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-12-21 13:37 - 2016-11-11 10:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2016-12-21 13:37 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-12-21 13:37 - 2016-11-11 10:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-12-21 13:37 - 2016-11-11 10:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-12-21 13:37 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-12-21 13:37 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-12-21 13:37 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2016-12-21 13:37 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll 2016-12-21 13:37 - 2016-11-11 08:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2016-12-21 13:37 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-12-21 13:37 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-12-21 13:37 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-12-21 13:37 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll 2016-12-21 13:37 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-12-21 13:37 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe 2016-12-21 13:37 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-12-21 13:37 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-12-21 13:37 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-12-21 13:37 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-12-21 13:37 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-12-21 13:37 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-12-21 13:37 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-12-21 13:37 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-12-21 13:37 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-12-21 13:37 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-12-21 13:37 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2016-12-21 13:37 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-12-21 13:37 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-12-21 13:37 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2016-12-21 13:37 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2016-12-21 13:37 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2016-12-21 13:37 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-12-21 13:37 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2016-12-21 13:37 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2016-12-21 13:37 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2016-12-21 13:37 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-12-21 13:37 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-12-21 13:37 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-12-21 13:37 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2016-12-21 13:37 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-12-21 13:37 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll 2016-12-21 13:37 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-12-21 13:37 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-12-21 13:37 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll 2016-12-21 13:37 - 2016-11-11 08:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-12-21 13:37 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2016-12-21 13:37 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2016-12-21 13:37 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll 2016-12-21 13:37 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-12-21 13:37 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-12-21 13:37 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2016-12-21 13:37 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-12-21 13:37 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-12-21 13:37 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-12-21 13:37 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-12-21 13:36 - 2016-12-09 11:42 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2016-12-21 13:36 - 2016-12-09 11:42 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2016-12-21 13:36 - 2016-12-09 11:34 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-12-21 13:36 - 2016-12-09 11:34 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-12-21 13:36 - 2016-12-09 11:33 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-12-21 13:36 - 2016-12-09 11:33 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-12-21 13:36 - 2016-12-09 11:30 - 00377184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2016-12-21 13:36 - 2016-12-09 11:28 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-12-21 13:36 - 2016-12-09 11:19 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll 2016-12-21 13:36 - 2016-12-09 11:18 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-12-21 13:36 - 2016-12-09 11:18 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-12-21 13:36 - 2016-12-09 11:18 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-12-21 13:36 - 2016-12-09 11:14 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2016-12-21 13:36 - 2016-12-09 11:10 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2016-12-21 13:36 - 2016-12-09 11:10 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2016-12-21 13:36 - 2016-12-09 11:09 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2016-12-21 13:36 - 2016-12-09 11:01 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-12-21 13:36 - 2016-12-09 11:00 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll 2016-12-21 13:36 - 2016-12-09 10:59 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-12-21 13:36 - 2016-12-09 10:59 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-12-21 13:36 - 2016-12-09 10:57 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-12-21 13:36 - 2016-12-09 10:52 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2016-12-21 13:36 - 2016-12-09 10:45 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-12-21 13:36 - 2016-12-09 10:41 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-12-21 13:36 - 2016-12-09 10:40 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-12-21 13:36 - 2016-12-09 10:37 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-12-21 13:36 - 2016-12-09 10:34 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-12-21 13:36 - 2016-12-09 10:31 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-12-21 13:36 - 2016-12-09 10:30 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-12-21 13:36 - 2016-12-09 10:29 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-12-21 13:36 - 2016-12-09 10:28 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-12-21 13:36 - 2016-12-09 10:27 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-12-21 13:36 - 2016-12-09 10:27 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2016-12-21 13:36 - 2016-12-09 10:22 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-12-21 13:36 - 2016-12-09 10:21 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-12-21 13:36 - 2016-12-09 10:21 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-12-21 13:36 - 2016-12-09 10:20 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2016-12-21 13:36 - 2016-12-09 10:20 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-12-21 13:36 - 2016-12-09 10:20 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-12-21 13:36 - 2016-12-09 10:18 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-12-21 13:36 - 2016-12-09 10:17 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2016-12-21 13:36 - 2016-12-09 10:17 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-12-21 13:36 - 2016-12-09 10:16 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-12-21 13:36 - 2016-12-09 10:16 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-12-21 13:36 - 2016-12-09 09:54 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-12-21 13:36 - 2016-11-11 11:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2016-12-21 13:36 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2016-12-21 13:36 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-12-21 13:36 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-12-21 13:36 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-12-21 13:36 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll 2016-12-21 13:36 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-12-21 13:36 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-12-21 13:36 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-12-21 13:36 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-12-21 13:36 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-12-21 13:36 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2016-12-21 13:36 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-12-21 13:36 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-12-21 13:36 - 2016-11-11 10:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-12-21 13:36 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2016-12-21 13:36 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll 2016-12-21 13:36 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe 2016-12-21 13:36 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2016-12-21 13:36 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-12-21 13:36 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2016-12-21 13:36 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-12-21 13:36 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-12-21 13:36 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-12-21 13:36 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2016-12-21 13:36 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2016-12-21 13:36 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-12-21 13:36 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2016-12-21 13:36 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll 2016-12-21 13:36 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2016-12-21 13:36 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-12-21 13:36 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-12-21 13:36 - 2016-11-11 10:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-12-21 13:36 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-12-21 13:36 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-12-21 13:36 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2016-12-21 13:36 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2016-12-21 13:36 - 2016-11-11 10:18 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-12-21 13:36 - 2016-11-11 10:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-12-21 13:36 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-12-21 13:36 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll 2016-12-21 13:36 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-12-21 13:36 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll 2016-12-21 13:36 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-12-21 13:36 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2016-12-21 13:36 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-12-21 13:36 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2016-12-21 13:36 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-12-21 13:36 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-12-21 13:36 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-12-21 13:36 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-12-21 13:36 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2016-12-21 13:36 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-12-21 13:36 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-12-21 13:36 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll 2016-12-21 13:36 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-12-21 13:36 - 2016-11-11 09:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-12-21 13:36 - 2016-11-11 09:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2016-12-21 13:36 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2016-12-21 13:36 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-12-21 13:36 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-12-21 13:36 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-12-21 13:36 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-12-21 13:36 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-12-21 13:36 - 2016-11-11 08:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2016-12-21 13:36 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll 2016-12-21 13:36 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe 2016-12-21 13:36 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2016-12-21 13:36 - 2016-11-11 08:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-12-21 13:36 - 2016-11-11 08:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-12-21 13:36 - 2016-11-11 08:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-12-21 13:36 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2016-12-21 13:36 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2016-12-21 13:36 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-12-21 13:36 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2016-12-21 13:36 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-21 13:36 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2016-12-21 13:36 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2016-12-21 13:36 - 2016-11-11 08:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-12-21 13:36 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll 2016-12-21 13:36 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-12-21 13:36 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-12-21 13:36 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-12-21 13:36 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2016-12-21 13:35 - 2016-12-09 11:27 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll 2016-12-21 13:35 - 2016-12-09 11:20 - 02677544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2016-12-21 13:35 - 2016-12-09 11:20 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-12-21 13:35 - 2016-12-09 11:20 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-12-21 13:35 - 2016-12-09 11:20 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-12-21 13:35 - 2016-12-09 11:20 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-12-21 13:35 - 2016-12-09 11:11 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-12-21 13:35 - 2016-12-09 10:56 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-12-21 13:35 - 2016-12-09 10:47 - 22563328 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-12-21 13:35 - 2016-12-09 10:42 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-12-21 13:35 - 2016-12-09 10:37 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-12-21 13:35 - 2016-12-09 10:36 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2016-12-21 13:35 - 2016-12-09 10:34 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-12-21 13:35 - 2016-12-09 10:32 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-12-21 13:35 - 2016-12-09 10:31 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-12-21 13:35 - 2016-12-09 10:30 - 23677952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-12-21 13:35 - 2016-12-09 10:27 - 19417088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-12-21 13:35 - 2016-12-09 10:26 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-12-21 13:35 - 2016-12-09 10:25 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll 2016-12-21 13:35 - 2016-12-09 10:21 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-12-21 13:35 - 2016-12-09 10:21 - 01512960 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-12-21 13:35 - 2016-12-09 10:20 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-12-21 13:35 - 2016-12-09 10:20 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-12-21 13:35 - 2016-12-09 10:18 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-12-21 13:35 - 2016-11-11 11:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-12-21 13:35 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2016-12-21 13:35 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-12-21 13:35 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-12-21 13:35 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-12-21 13:35 - 2016-11-11 11:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-12-21 13:35 - 2016-11-11 10:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-12-21 13:35 - 2016-11-11 10:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2016-12-21 13:35 - 2016-11-11 10:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-12-21 13:35 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll 2016-12-21 13:35 - 2016-11-11 10:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-12-21 13:35 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-12-21 13:35 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-12-21 13:35 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-21 13:35 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-12-21 13:35 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-12-21 13:35 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2016-12-21 13:35 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2016-12-21 13:35 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2016-12-21 13:35 - 2016-11-11 10:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-12-21 13:35 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2016-12-21 13:35 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2016-12-21 13:35 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2016-12-21 13:35 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2016-12-21 13:35 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2016-12-21 13:35 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-12-21 13:35 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2016-12-21 13:35 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2016-12-21 13:35 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2016-12-21 13:35 - 2016-11-11 10:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-12-21 13:35 - 2016-11-11 10:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-12-21 13:35 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll 2016-12-21 13:35 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-12-21 13:35 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-12-21 13:35 - 2016-11-11 10:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-12-21 13:35 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-12-21 13:35 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-12-21 13:35 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2016-12-21 13:35 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-12-21 13:35 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2016-12-21 13:35 - 2016-11-11 08:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-12-21 13:35 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe 2016-12-21 13:35 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-21 13:35 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-12-21 13:35 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-12-21 13:35 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-12-21 13:35 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-12-21 13:35 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-12-21 02:38 - 2017-01-07 22:13 - 00001525 _____ C:\Users\Magic\Desktop\adwcleaner_6.041.lnk ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-10 21:53 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-01-10 21:22 - 2015-06-11 19:58 - 00000000 ____D C:\Users\Magic\AppData\Local\JDownloader v2.0 2017-01-10 21:20 - 2016-10-02 10:42 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Spotify 2017-01-10 21:20 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-01-10 21:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-01-10 21:18 - 2015-12-24 21:09 - 00000000 ____D C:\ProgramData\MFAData 2017-01-10 21:15 - 2015-05-16 11:02 - 00000093 _____ C:\Users\Magic\AppData\Roaming\sp_data.sys 2017-01-10 00:37 - 2016-11-26 11:36 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-01-10 00:25 - 2016-11-26 11:42 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task 2017-01-09 22:55 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2017-01-08 21:42 - 2015-06-10 21:37 - 00000000 ____D C:\Users\Magic\AppData\Roaming\vlc 2017-01-08 12:40 - 2015-06-20 20:25 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-01-08 12:00 - 2016-11-26 11:42 - 00003550 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update1 2017-01-08 12:00 - 2016-11-26 11:42 - 00003540 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update2 2017-01-07 23:38 - 2016-03-01 23:09 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2017-01-07 22:15 - 2016-12-04 00:43 - 00001194 _____ C:\Users\Public\Desktop\DLL-Files.com Client.lnk 2017-01-07 22:15 - 2016-11-28 20:35 - 00000930 _____ C:\Users\Public\Desktop\S.T.A.L.K.E.R. - Shadow of Chernobyl.lnk 2017-01-07 22:15 - 2016-11-26 11:40 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-01-07 22:15 - 2016-11-20 18:05 - 00002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk 2017-01-07 22:15 - 2016-10-31 22:47 - 00001052 _____ C:\Users\Public\Desktop\Q500 GUI.lnk 2017-01-07 22:15 - 2016-10-12 21:57 - 00001371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioWizard.lnk 2017-01-07 22:15 - 2016-09-04 21:52 - 00001232 _____ C:\Users\Public\Desktop\OpenOffice 4.1.2.lnk 2017-01-07 22:15 - 2016-09-04 11:36 - 00001056 _____ C:\Users\Public\Desktop\PEARL.lnk 2017-01-07 22:15 - 2016-06-18 11:26 - 00000649 _____ C:\Users\Public\Desktop\Hitman Absolution - Professional Edition.lnk 2017-01-07 22:15 - 2016-05-15 15:55 - 00001985 _____ C:\Users\Public\Desktop\Samsung Kies 3.lnk 2017-01-07 22:15 - 2016-05-02 22:36 - 00001930 _____ C:\Users\Public\Desktop\DOSBox 0.74.lnk 2017-01-07 22:15 - 2016-04-16 12:48 - 00002597 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\C.B.R.lnk 2017-01-07 22:15 - 2016-03-25 19:16 - 00000982 _____ C:\Users\Public\Desktop\Tomb Raider 1.lnk 2017-01-07 22:15 - 2016-03-25 19:16 - 00000960 _____ C:\Users\Public\Desktop\Tomb Raider 3.lnk 2017-01-07 22:15 - 2016-03-25 19:16 - 00000960 _____ C:\Users\Public\Desktop\Tomb Raider 2.lnk 2017-01-07 22:15 - 2016-03-01 23:10 - 00001853 _____ C:\Users\Public\Desktop\QuickTime Player.lnk 2017-01-07 22:15 - 2016-03-01 23:01 - 00002165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Screen Recorder.lnk 2017-01-07 22:15 - 2016-03-01 23:01 - 00002147 _____ C:\Users\Public\Desktop\CyberLink Screen Recorder.lnk 2017-01-07 22:15 - 2016-03-01 23:01 - 00002082 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 14 (64-bit).lnk 2017-01-07 22:15 - 2016-03-01 23:01 - 00002064 _____ C:\Users\Public\Desktop\CyberLink PowerDirector 14 (64-bit).lnk 2017-01-07 22:15 - 2016-02-19 23:07 - 00001750 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2017-01-07 22:15 - 2016-02-19 22:42 - 00001836 _____ C:\Users\Public\Desktop\GOM Inspect V8.lnk 2017-01-07 22:15 - 2016-02-14 23:24 - 00002063 _____ C:\Users\Public\Desktop\TAXMAN 2015.lnk 2017-01-07 22:15 - 2016-01-20 22:17 - 00000697 _____ C:\Users\Public\Desktop\World of Tanks.lnk 2017-01-07 22:15 - 2015-12-29 13:49 - 00001220 _____ C:\Users\Public\Desktop\Wise Folder Hider.lnk 2017-01-07 22:15 - 2015-12-29 13:46 - 00001207 _____ C:\Users\Public\Desktop\Wise Force Deleter.lnk 2017-01-07 22:15 - 2015-12-29 13:44 - 00001232 _____ C:\Users\Public\Desktop\Wise Data Recovery.lnk 2017-01-07 22:15 - 2015-12-25 17:00 - 00001174 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Audio-Editor.lnk 2017-01-07 22:15 - 2015-12-25 17:00 - 00001156 _____ C:\Users\Public\Desktop\WavePad Audio-Editor.lnk 2017-01-07 22:15 - 2015-12-25 00:49 - 00001037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk 2017-01-07 22:15 - 2015-12-23 23:56 - 00001172 _____ C:\Users\Public\Desktop\Wise Care 365.lnk 2017-01-07 22:15 - 2015-11-20 20:30 - 00001110 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk 2017-01-07 22:15 - 2015-11-20 20:30 - 00001092 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk 2017-01-07 22:15 - 2015-11-17 16:55 - 00001657 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk 2017-01-07 22:15 - 2015-11-14 21:59 - 00002266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-01-07 22:15 - 2015-11-14 21:59 - 00002248 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-01-07 22:15 - 2015-10-25 19:16 - 00000451 _____ C:\Users\Public\Desktop\SOMA.lnk 2017-01-07 22:15 - 2015-10-25 19:16 - 00000451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SOMA.lnk 2017-01-07 22:15 - 2015-09-28 23:29 - 00000734 _____ C:\Users\Public\Desktop\Far Cry.lnk 2017-01-07 22:15 - 2015-09-28 22:22 - 00001266 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk 2017-01-07 22:15 - 2015-09-27 08:02 - 00001088 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk 2017-01-07 22:15 - 2015-07-26 21:27 - 00001031 _____ C:\Users\Public\Desktop\Shutdown7.lnk 2017-01-07 22:15 - 2015-07-23 18:45 - 00001110 _____ C:\Users\Public\Desktop\SIM Scanner v9.0.lnk 2017-01-07 22:15 - 2015-07-23 18:45 - 00001105 _____ C:\Users\Public\Desktop\SIM Editor v9.0.lnk 2017-01-07 22:15 - 2015-07-12 18:52 - 00002069 _____ C:\Users\Public\Desktop\MyPhoneExplorer.lnk 2017-01-07 22:15 - 2015-06-21 16:00 - 00000975 _____ C:\Users\Public\Desktop\Steam.lnk 2017-01-07 22:15 - 2015-06-20 20:24 - 00001114 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2017-01-07 22:15 - 2015-06-11 19:40 - 00001293 _____ C:\Users\Public\Desktop\WebStorage.lnk 2017-01-07 22:15 - 2015-06-10 21:36 - 00000927 _____ C:\Users\Public\Desktop\VLC media player.lnk 2017-01-07 22:15 - 2015-06-10 20:17 - 00001177 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-01-07 22:15 - 2015-06-10 20:17 - 00001159 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-01-07 22:15 - 2014-05-15 16:59 - 00002476 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games App - asus.lnk 2017-01-07 22:14 - 2016-11-20 11:57 - 00000908 _____ C:\Users\Public\Desktop\Battle.net.lnk 2017-01-07 22:14 - 2016-10-12 21:57 - 00001353 _____ C:\Users\Public\Desktop\AudioWizard.lnk 2017-01-07 22:14 - 2016-09-04 11:36 - 00001068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PEARL.lnk 2017-01-07 22:14 - 2016-04-16 21:29 - 00001005 _____ C:\Users\Public\Desktop\AVG Protection.lnk 2017-01-07 22:14 - 2016-04-16 12:48 - 00002579 _____ C:\Users\Public\Desktop\C.B.R.lnk 2017-01-07 22:14 - 2016-04-16 12:24 - 00000938 _____ C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2017-01-07 22:14 - 2016-03-08 22:01 - 00000703 _____ C:\Users\Public\Desktop\ Dying Light.lnk 2017-01-07 22:14 - 2016-02-21 17:03 - 00001319 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio FREE.lnk 2017-01-07 22:14 - 2016-02-19 23:07 - 00001794 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2017-01-07 22:14 - 2015-12-25 00:49 - 00001019 _____ C:\Users\Public\Desktop\Audacity.lnk 2017-01-07 22:14 - 2015-09-13 14:00 - 00001055 _____ C:\Users\Public\Desktop\ASUS GPU Tweak.lnk 2017-01-07 22:14 - 2015-07-11 22:35 - 00001276 _____ C:\Users\Public\Desktop\Ashampoo ClipFinder HD 2.lnk 2017-01-07 22:14 - 2015-07-02 22:05 - 00000903 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-01-07 22:14 - 2015-06-30 23:24 - 00001103 _____ C:\Users\Public\Desktop\CPU-M Benchmark.lnk 2017-01-07 22:14 - 2015-05-31 22:48 - 00001015 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk 2017-01-07 22:14 - 2015-05-31 22:43 - 00000925 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2017-01-07 22:13 - 2016-11-26 22:13 - 00002053 _____ C:\Users\Magic\Desktop\XMouseButtonControl.lnk 2017-01-07 22:13 - 2016-11-26 21:06 - 00000538 _____ C:\Users\Magic\Desktop\Sleeping Dogs Game Of The Year (30 DLCs).lnk 2017-01-07 22:13 - 2016-11-26 11:37 - 00000000 ____D C:\Users\Magic 2017-01-07 22:13 - 2016-10-02 10:42 - 00001852 _____ C:\Users\Magic\Desktop\Spotify.lnk 2017-01-07 22:13 - 2016-10-02 10:42 - 00001838 _____ C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2017-01-07 22:13 - 2016-10-02 10:42 - 00000000 ____D C:\Users\Magic\AppData\Local\Spotify 2017-01-07 22:13 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-01-07 22:13 - 2016-06-14 20:48 - 00002389 _____ C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-01-07 22:13 - 2016-05-10 21:11 - 00001337 _____ C:\Users\Magic\Desktop\Tomb Raider [2013] Collectors Edition.lnk 2017-01-07 22:13 - 2016-05-01 12:22 - 00001464 _____ C:\Users\Magic\Desktop\h2testw.exe.lnk 2017-01-07 22:13 - 2016-04-16 18:14 - 00001106 _____ C:\Users\Magic\Desktop\PhonerLite.lnk 2017-01-07 22:13 - 2016-03-06 11:18 - 00000798 _____ C:\Users\Magic\Desktop\Future Pinball.lnk 2017-01-07 22:13 - 2016-03-05 19:22 - 00001210 _____ C:\Users\Magic\Desktop\ProPinball.exe.lnk 2017-01-07 22:13 - 2016-02-21 21:04 - 00001281 _____ C:\Users\Magic\Desktop\eBook Converter.lnk 2017-01-07 22:13 - 2015-12-31 12:46 - 00003228 _____ C:\Users\Magic\Desktop\Reaper.exe.lnk 2017-01-07 22:13 - 2015-12-20 17:16 - 00000875 _____ C:\Users\Magic\Desktop\iw3mp.exe.lnk 2017-01-07 22:13 - 2015-12-20 17:15 - 00000875 _____ C:\Users\Magic\Desktop\iw3sp.exe.lnk 2017-01-07 22:13 - 2015-12-20 16:16 - 00001247 _____ C:\Users\Magic\Desktop\onlineTV 11.lnk 2017-01-07 22:13 - 2015-11-20 21:33 - 00001131 _____ C:\Users\Magic\Desktop\Disk Doctors Undelete.lnk 2017-01-07 22:13 - 2015-11-17 17:00 - 00001108 _____ C:\Users\Magic\Desktop\googleearth.lnk 2017-01-07 22:13 - 2015-10-16 22:45 - 00000711 _____ C:\Users\Magic\Desktop\Fahrenheit.lnk 2017-01-07 22:13 - 2015-08-20 19:40 - 00001871 _____ C:\Users\Magic\Desktop\Cache -Gadget.lnk 2017-01-07 22:13 - 2015-07-26 23:01 - 00001742 _____ C:\Users\Magic\Desktop\Shutdown Timer.exe.lnk 2017-01-07 22:13 - 2015-07-18 21:48 - 00001236 _____ C:\Users\Magic\Desktop\Dropbox.lnk 2017-01-07 22:13 - 2015-07-18 13:58 - 00000984 _____ C:\Users\Magic\Desktop\Temp Windows.lnk 2017-01-07 22:13 - 2015-07-16 00:33 - 00001068 _____ C:\Users\Magic\Desktop\TimeComX.lnk 2017-01-07 22:13 - 2015-07-12 13:01 - 00001611 _____ C:\Users\Magic\Desktop\Carbon.exe.lnk 2017-01-07 22:13 - 2015-07-10 21:50 - 00001358 _____ C:\Users\Magic\Desktop\Temp.lnk 2017-01-07 22:13 - 2015-06-21 15:48 - 00001651 _____ C:\Users\Magic\Desktop\NoteBookFanControl.lnk 2017-01-07 22:13 - 2015-06-11 20:59 - 00001223 _____ C:\Users\Magic\Desktop\Uplay.lnk 2017-01-07 22:13 - 2015-06-11 20:15 - 00002124 _____ C:\Users\Magic\Desktop\JDownloader 2.lnk 2017-01-07 22:13 - 2015-06-10 19:11 - 00001025 _____ C:\Users\Magic\Desktop\SpeedFan.lnk 2017-01-07 22:13 - 2015-05-31 22:42 - 00000981 _____ C:\Users\Magic\Desktop\TechPowerUp GPU-Z.lnk 2017-01-07 22:13 - 2015-01-10 22:47 - 00000577 _____ C:\Users\Magic\Desktop\iw4sp.exe.lnk 2017-01-07 22:13 - 2014-10-24 22:46 - 00001392 _____ C:\Users\Magic\Desktop\CyberLink MediaStory.lnk 2017-01-07 16:20 - 2015-07-11 22:19 - 00000000 ____D C:\Users\Magic\dwhelper 2017-01-05 23:21 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Globalization 2017-01-05 22:46 - 2015-06-20 20:24 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2017-01-05 19:53 - 2015-07-12 09:56 - 00000000 ____D C:\Users\Magic\AppData\Local\ElevatedDiagnostics 2017-01-04 19:55 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2017-01-03 22:00 - 2016-07-16 23:51 - 00839070 _____ C:\WINDOWS\system32\perfh007.dat 2017-01-03 22:00 - 2016-07-16 23:51 - 00183804 _____ C:\WINDOWS\system32\perfc007.dat 2017-01-03 22:00 - 2016-06-14 20:32 - 02094532 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-01-03 01:34 - 2016-11-26 11:42 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-01-03 01:34 - 2016-11-26 11:36 - 00000000 ____D C:\ProgramData\NVIDIA 2017-01-03 01:34 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2017-01-01 12:09 - 2016-04-16 18:14 - 00000000 ____D C:\Users\Magic\AppData\Roaming\PhonerLite 2016-12-31 16:47 - 2015-12-24 21:05 - 00000000 ____D C:\Users\Magic\AppData\Local\AvgSetupLog 2016-12-31 03:16 - 2016-07-16 07:04 - 00000000 ___RD C:\Program Files 2016-12-30 20:01 - 2016-02-21 13:57 - 00000000 ____D C:\Users\Magic\Downloads\Musik Videos 2016-12-30 00:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Branding 2016-12-30 00:33 - 2013-08-22 16:36 - 00000000 ___RD C:\Users\Public\Documents 2016-12-29 22:53 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Tasks 2016-12-29 22:51 - 2015-12-23 23:56 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Wise Care 365 2016-12-29 22:51 - 2015-11-20 20:30 - 00000000 ____D C:\Program Files (x86)\Glary Utilities 5 2016-12-29 20:30 - 2016-07-16 12:47 - 00000000 ___HD C:\ProgramData 2016-12-29 18:18 - 2014-10-24 22:28 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-12-29 13:29 - 2015-07-18 21:45 - 00001226 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 2016-12-29 02:16 - 2016-11-26 11:37 - 00524288 ___SH C:\Users\Magic\NTUSER.DAT{1560ce3f-b3c4-11e6-9fc7-baad05ad66c3}.TMContainer00000000000000000001.regtrans-ms 2016-12-29 01:39 - 2014-10-24 22:45 - 00000000 ____D C:\Program Files (x86)\Steam 2016-12-29 01:38 - 2015-06-21 16:59 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2016-12-28 22:16 - 2016-11-26 11:42 - 00003740 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA 2016-12-28 22:16 - 2016-11-26 11:42 - 00003556 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-12-28 22:16 - 2016-11-26 11:42 - 00003332 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-12-28 22:16 - 2016-11-26 11:42 - 00002782 _____ C:\WINDOWS\System32\Tasks\ATK Package 36D18D69AFC3 2016-12-28 22:16 - 2016-11-26 11:42 - 00002224 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2016-12-28 22:16 - 2016-11-26 11:42 - 00002072 _____ C:\WINDOWS\System32\Tasks\ATK Package A22126881260 2016-12-28 20:13 - 2016-07-16 07:04 - 00000000 ____D C:\Program Files (x86)\Common Files 2016-12-28 19:33 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Saved Games 2016-12-28 18:31 - 2015-01-10 15:26 - 00000000 ____D C:\Users\Magic\Downloads\ZZR 1100 Werkstatthandbuch 2016-12-28 16:03 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Documents 2016-12-28 15:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Music 2016-12-27 22:51 - 2016-11-20 11:57 - 00000000 ____D C:\Users\Magic\AppData\Local\Battle.net 2016-12-27 22:50 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-12-27 22:16 - 2015-12-24 21:07 - 00000000 ____D C:\ProgramData\Avg 2016-12-27 22:16 - 2015-12-24 21:07 - 00000000 ____D C:\Program Files (x86)\AVG 2016-12-27 22:16 - 2015-12-24 21:05 - 00000000 ____D C:\Users\Magic\AppData\Local\Avg 2016-12-27 16:29 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2016-12-26 02:18 - 2016-10-03 11:13 - 00000000 ____D C:\Program Files\AdwCleaner 2016-12-26 02:06 - 2015-07-02 22:05 - 00000000 ____D C:\Program Files\CCleaner 2016-12-26 01:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\LogFiles 2016-12-26 01:56 - 2015-12-20 00:23 - 00000000 ____D C:\Users\Magic\AppData\Roaming\Steganos 2016-12-26 01:56 - 2015-12-20 00:22 - 00000000 ____D C:\Program Files (x86)\Steganos Privacy Suite 17 2016-12-26 01:10 - 2015-07-14 19:37 - 00000000 ____D C:\Users\Magic\AppData\Local\Diagnostics 2016-12-26 00:39 - 2015-07-25 12:35 - 00000000 __RDO C:\Users\Magic\OneDrive 2016-12-26 00:38 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Searches 2016-12-26 00:28 - 2015-05-08 18:03 - 00000000 __SHD C:\System Volume Information 2016-12-25 23:46 - 2016-07-16 12:47 - 00000000 ___RD C:\Users\Public 2016-12-25 15:03 - 2016-07-16 07:04 - 45350912 _____ C:\WINDOWS\system32\config\COMPONENTS 2016-12-24 23:40 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64 2016-12-24 23:04 - 2016-11-26 11:37 - 00000000 ___HD C:\Users\Magic\AppData 2016-12-24 22:51 - 2015-07-11 22:35 - 00000000 ____D C:\ProgramData\Ashampoo 2016-12-24 20:41 - 2016-07-16 12:47 - 00000000 __RHD C:\Users\Public\Libraries 2016-12-24 19:10 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache 2016-12-24 16:15 - 2016-11-26 11:37 - 00524288 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000002.regtrans-ms 2016-12-24 16:15 - 2016-11-26 11:37 - 00524288 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000001.regtrans-ms 2016-12-24 16:15 - 2016-11-26 11:37 - 00065536 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TM.blf 2016-12-24 14:50 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\DriverStore 2016-12-24 14:44 - 2016-07-16 12:47 - 00000000 __RSD C:\WINDOWS\assembly 2016-12-24 14:00 - 2015-06-21 16:03 - 00000000 ____D C:\Users\Magic\AppData\Local\Steam 2016-12-23 20:57 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WDI 2016-12-23 20:56 - 2015-10-06 20:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-12-23 20:55 - 2016-11-26 12:05 - 00000174 ___SH C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini 2016-12-23 20:55 - 2016-11-26 12:05 - 00000000 ____D C:\Users\Magic\AppData\Local\PackageStaging 2016-12-23 20:55 - 2016-11-26 11:37 - 00000000 ___RD C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs 2016-12-23 20:55 - 2016-07-16 07:04 - 00262144 _____ C:\Users\Default\NTUSER.DAT 2016-12-23 20:55 - 2016-04-27 06:56 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-12-23 20:55 - 2015-05-16 11:02 - 00000402 ___SH C:\Users\Magic\Documents\desktop.ini 2016-12-23 20:55 - 2015-05-16 11:02 - 00000282 ___SH C:\Users\Magic\Downloads\desktop.ini 2016-12-23 20:55 - 2015-05-16 11:02 - 00000174 ___SH C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Videos 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Links 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Favorites 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\Contacts 2016-12-23 20:55 - 2015-05-16 11:02 - 00000000 ___RD C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2016-12-23 20:54 - 2016-11-26 11:35 - 00524288 ___SH C:\WINDOWS\system32\config\DRIVERS{f8d8b5e8-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000001.regtrans-ms 2016-12-23 20:54 - 2016-11-26 11:35 - 00065536 ___SH C:\WINDOWS\system32\config\DRIVERS{f8d8b5e8-4ba6-11e6-80cd-0026b955b121}.TM.blf 2016-12-23 20:53 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\config\TxR 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\de-DE 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\wbem 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-CS 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\de-DE 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Boot 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppPatch 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Internet Explorer 2016-12-23 20:52 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Internet Explorer 2016-12-23 20:52 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-12-23 20:52 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-12-23 20:52 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing 2016-12-23 20:50 - 2016-07-16 12:47 - 00000796 ___SH C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini 2016-12-23 20:48 - 2016-03-02 21:16 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-12-22 23:37 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\CatRoot 2016-12-22 22:56 - 2016-07-16 07:04 - 00000000 ___RD C:\Users 2016-12-22 11:19 - 2015-06-02 21:31 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-12-22 11:15 - 2015-07-18 21:45 - 00000000 ____D C:\Program Files (x86)\Dropbox 2016-12-22 03:35 - 2015-06-02 21:31 - 135632432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-12-21 14:40 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files 2016-12-21 14:23 - 2016-11-26 11:42 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-12-21 14:23 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-12-21 14:23 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-12-21 13:17 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-12-20 14:24 - 2015-05-16 11:02 - 00000000 ____D C:\Users\Magic\AppData\Local\Packages 2016-12-12 00:56 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-12-12 00:56 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-05-16 11:02 - 2017-01-10 21:15 - 0000093 _____ () C:\Users\Magic\AppData\Roaming\sp_data.sys 2015-06-20 19:57 - 2015-06-20 19:57 - 0000122 _____ () C:\Users\Magic\AppData\Roaming\System Monitor II_UptimeRecord.ini 2015-05-31 20:15 - 2015-05-31 20:15 - 0007605 _____ () C:\Users\Magic\AppData\Local\Resmon.ResmonCfg 2016-12-24 20:42 - 2016-11-23 14:37 - 0000570 _____ () C:\Users\Magic\AppData\Local\TroubleshooterConfig.json 2016-11-26 11:37 - 2016-11-26 11:37 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2014-05-15 16:58 - 2012-09-07 12:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd 2014-05-15 16:58 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe 2014-05-15 16:58 - 2012-09-07 12:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-01-08 12:54 ==================== Ende von FRST.txt ============================ |
![]() | #14 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 08-01-2017 durchgeführt von Magic (10-01-2017 22:08:25) Gestartet von C:\Users\Magic\Downloads\Spam entfernen Windows 10 Home Version 1607 (X64) (2016-11-26 10:57:10) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2786200759-2278858845-1295660402-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2786200759-2278858845-1295660402-503 - Limited - Disabled) Gast (S-1-5-21-2786200759-2278858845-1295660402-501 - Limited - Disabled) Magic (S-1-5-21-2786200759-2278858845-1295660402-1001 - Administrator - Enabled) => C:\Users\Magic ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG AntiVirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 10.000 Office Vorlagen Teil 1 (HKLM-x32\...\10.000 Office Vorlagen Teil 1_is1) (Version: - ) 10.000 Office Vorlagen Teil 2 (HKLM-x32\...\10.000 Office Vorlagen Teil 2_is1) (Version: - ) 3DMark (HKLM-x32\...\{f5aa1c48-f2dc-4f4f-a71d-65bd7d0dc5c5}) (Version: 1.5.893.0 - Futuremark) 3DMark (Version: 1.5.893.0 - Futuremark) Hidden 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) 7-Zip 9.38 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0938-000001000000}) (Version: - Igor Pavlov) 8GadgetPack (HKLM-x32\...\{CA2865AD-EFF4-44F0-A2C9-DCDC0A90F27E}) (Version: 14.0.0 - Helmut Buhler) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated) Alan Wake Complete Collection Version (HKLM-x32\...\{2DE8F160-BBFF-445B-8B8E-4092A1C106DA}_is1) (Version: - Remedy Entertainment) Aliens vs Predator Dedicated Server (HKLM-x32\...\Steam App 34120) (Version: - ) A-Men Technologies USB-to-Serial (HKLM-x32\...\{1805BD6D-C441-4A1C-802D-AFF0232DAACD}) (Version: - ) Ansel (Version: 372.70 - NVIDIA Corporation) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: - Apple Inc.) Arma 3 Server (HKLM-x32\...\Steam App 233780) (Version: - Bohemia Interactive) Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Ashampoo ClipFinder HD 2 v.2.47 (HKLM-x32\...\{0A11EA01-0BAC-AC96-8FAD-1840C13B6803}_is1) (Version: 2.47 - Ashampoo GmbH & Co. KG) ASUS Gaming Center (HKLM-x32\...\{23C8A788-4790-4F3C-B103-0ACC7D9DC5BE}) (Version: 1.0.2 - ASUS) ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: - ASUSTek COMPUTER INC.) ASUS GPU Tweak (x32 Version: - ASUSTek COMPUTER INC.) Hidden ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.4.3 - ASUS) ASUS ROG Gaming Mouse (HKLM-x32\...\{3B9E171F-A955-4834-B877-447C0A437260}) (Version: 2.00.026 - ASUS) ASUS ROG MacroKey (HKLM-x32\...\{348022C5-F497-4333-AFEE-208F22F169F2}_is1) (Version: - G-spy Co., Ltd) ASUS Screen Saver (HKLM-x32\...\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 2.0.5 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.02.0001 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.0.1 - ASUS) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0038 - ASUS) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) AVG (Version: 16.141.7996 - AVG Technologies) Hidden AVG 2016 (Version: 16.0.4749 - AVG Technologies) Hidden AVG PC TuneUp (HKLM-x32\...\AVG PC TuneUp) (Version: - AVG Technologies) AVG PC TuneUp (x32 Version: 16.63.4 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG) (Version: 2016.141.7996 - AVG Technologies) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: - BlueStack Systems, Inc.) calibre 64bit (HKLM\...\{0224350E-9A3E-4932-8FC8-5D0590F1AF8A}) (Version: 2.55.0 - Kovid Goyal) Call of Duty Modern Warfare 3 1.0 (HKLM-x32\...\Call of Duty Modern Warfare 3 1.0) (Version: - ) Call of Duty(R) 4 - Modern Warfare(TM) (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.00.0000 - Activision) Call of Duty(R) 4 - Modern Warfare(TM) (x32 Version: 1.00.0000 - Activision) Hidden Call of Duty: Modern Warfare 3 - Dedicated Server (HKLM-x32\...\Steam App 42750) (Version: - Infinity Ward - Sledgehammer Games) CBR (HKLM-x32\...\{91604354-2B64-4A59-AF15-81E85CB4F9BB}) (Version: 0.7 - G.Waser) CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: - CDBurnerXP) concept/design onlineTV 11 (HKLM-x32\...\{8A4C3184-DA2F-4553-BF61-83F5690C3048}_is1) (Version: - concept/design GmbH) ConvertHelper 3.1.1 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version: - DownloadHelper) CPUID CPU-Z 1.75 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.29 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) CPU-M Benchmark version 1.5 (HKLM-x32\...\{819B2F72-CADC-4C41-BA29-2BA97D7F68CE}_is1) (Version: 1.5 - Major Share (MajorShare.com)) CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.) CyberLink PowerDirector 14 (HKLM-x32\...\{6BADCD73-E925-46F7-A295-FF2448632728}) (Version: 14.0.2019.0 - CyberLink Corp.) Disk Doctors Undelete Version 1.0.0 (HKLM-x32\...\Disk Doctors Undelete_is1) (Version: - Disk Doctor Labs, Inc.) DLL-Files.com Client (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_DLL-Files.c~79141F26_is1) (Version: 2.1.1000.4462 - DLL-Files.com Client) Dr. Langeskov, The Tiger, and The Terribly Cursed Emerald: A Whirlwind Heist (HKLM-x32\...\Steam App 409160) (Version: - Crows Crows Crows) Dreamfall The Longest Journey Version 1.0 (HKLM-x32\...\Dreamfall The Longest Journey_is1) (Version: 1.0 - Funcom) <==== ACHTUNG Dropbox (HKLM-x32\...\Dropbox) (Version: 16.4.30 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: - Dropbox, Inc.) Hidden Dying Light Version 1.2 (HKLM-x32\...\Dying Light_is1) (Version: 1.2 - RFT) eBook Converter (HKLM-x32\...\eBookConverter) (Version: 1.2.1 - eBook Converter) ELAN Touchpad (HKLM\...\Elantech) (Version: - ELAN Microelectronic Corp.) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fahrenheit (HKLM-x32\...\{BA10AC78-E687-4523-8B93-540428FC256F}) (Version: 1.1 - Ihr Firmenname) Far Cry (Patch 1.4) (x32 Version: 1.00.0000 - Ubisoft) Hidden Far Cry (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden Far Cry 3 Blood Dragon (HKLM-x32\...\{A071F478-73E0-4143-AE55-4DD6BABD74F5}) (Version: 1.02 - Ubisoft) FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden Future Pinball (HKLM-x32\...\Future Pinball_is1) (Version: Version - Chris Leathley) Futuremark SystemInfo (HKLM-x32\...\{79659071-4B68-4EC8-833C-49C97B68FCD0}) (Version: 4.36.512.0 - Futuremark) Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: - Genesys Logic) Ghost Recon Phantoms - EU (HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\61e5da2b7c463135) (Version: 1.36.9879.2 - Ubisoft) Glary Utilities 5.38 (HKLM-x32\...\Glary Utilities 5) (Version: - Glarysoft Ltd) GOM Software V8 (HKLM\...\GOM v8.0) (Version: - GOM mbH, Mittelweg 7-8, 38106 Braunschweig, Germany) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Earth Pro (HKLM-x32\...\{35DAA04C-1720-4BE3-A920-A03731EC6A1D}) (Version: - Google) Google Update Helper (x32 Version: - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North) GSM SIM Utility 9.0 (HKLM-x32\...\{E1ACEF2E-C3C0-43F5-A815-5F0BB968DA70}) (Version: - ) Helium (HKLM-x32\...\{9A781940-AC41-4D5E-8E1E-76A04B916FB9}) (Version: 1.0.0 - ClockworkMod) HELI-X 6.1 Demo (HKLM-x32\...\EC916548-FECF-4545-B3A0-E8956AB32821_is1) (Version: - HELI-X.net) Heroes & Generals (HKLM-x32\...\Steam App 227940) (Version: - Reto-Moto) Hitman Absolution - Professional Edition (HKLM-x32\...\Hitman Absolution - Professional Edition_is1) (Version: - ) Hitman Codename 47 (HKLM-x32\...\GOGPACKANHITMAN1_is1) (Version: - GOG.com) Intel Collaborative Processor Performance Control (HKLM-x32\...\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1419.2) (HKLM\...\{302600C1-6BDF-4FD1-1405-148929CC1385}) (Version: 17.0.1405.0464 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{85b9d34f-7397-4e39-8600-07942ef6ca04}) (Version: 17.0.5 - Intel Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) LAV Filters 0.66 (HKLM-x32\...\lavfilters_is1) (Version: 0.66 - Hendrik Leppkes) LockHunter 3.1, 32/64 bit (HKLM\...\LockHunter_is1) (Version: - Crystal Rich Ltd) Malwarebytes Anti-Malware Version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes) Maniac Mansion Deluxe (HKLM-x32\...\Maniac Mansion Deluxe) (Version: - ) Maxx Audio Installer (x64) (Version: 1.6.5073.106 - Waves Audio Ltd.) Hidden Medusa's Labyrinth (HKLM-x32\...\Steam App 436110) (Version: - Guru Games) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 47.0.1 (x64 de) (HKLM\...\Mozilla Firefox 47.0.1 (x64 de)) (Version: 47.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: - Mozilla) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger) NewBlue Titler Pro for Windows (HKLM-x32\...\NewBlue Titler Pro for Windows) (Version: 1.0 - NewBlue) NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue) NewBlue Video Essentials V for Windows (HKLM-x32\...\NewBlue Video Essentials V for Windows) (Version: 3.0 - NewBlue) NewBlue Video Essentials VI for Windows (HKLM-x32\...\NewBlue Video Essentials VI for Windows) (Version: 3.0 - NewBlue) NewBlue Video Essentials VII for Windows (HKLM-x32\...\NewBlue Video Essentials VII for Windows) (Version: 3.0 - NewBlue) No Man’s Sky Incl. Update 4 MULTi14 1.07 (HKLM-x32\...\No Man’s Sky Incl. Update 4 MULTi14 1.07) (Version: - ) NoteBook FanControl (HKLM-x32\...\{542c1677-eab5-49ee-99aa-5a08eeb3033c}) (Version: - Stefan Hirschmann - StagWare) NoteBook FanControl (x32 Version: - Stefan Hirschmann - StagWare) Hidden NVIDIA 3D Vision Treiber 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 372.70 - NVIDIA Corporation) NVIDIA Grafiktreiber 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 372.70 - NVIDIA Corporation) NVIDIA HD-Audiotreiber (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: - NVIDIA Corporation) NVIDIA Miracast Virtueller Ton 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.30 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) OkayFreedom (HKLM-x32\...\{3F3FB10C-7175-4D38-9335-3488B89C12AF}) (Version: 1.7.4 - Steganos Software GmbH) OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation) Oracle VM VirtualBox 5.0.4 (HKLM\...\{FC191F32-1A67-4231-91D0-0059A57C99A8}) (Version: 5.0.4 - Oracle Corporation) PhonerLite 2.45 (HKLM-x32\...\PhonerLite_is1) (Version: 2.45 - Heiko Sommerfeldt) PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.00.000 - Prolific Technology INC) proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: - proDAD GmbH) Q500 GUI version 1.0 (HKLM-x32\...\{05282008-69B0-409A-8B05-CB77A5E0D99E}_is1) (Version: 1.0 - Yuneec) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: - Apple Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.34.617.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) Relic Hunters Zero (HKLM-x32\...\Steam App 382490) (Version: - Rogue Snail) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: - Rockstar Games) ROG Game First III (HKLM-x32\...\{0C6E32E1-31D9-49F1-B67F-2941994002D5}) (Version: 1.00.16 - ASUSTeK Computer Inc.) Run and Fire (HKLM-x32\...\Steam App 360760) (Version: - ) S.T.A.L.K.E.R. - Shadow of Chernobyl (HKLM-x32\...\S.T.A.L.K.E.R. - Shadow of Chernobyl_is1) (Version: 1.0000 - THQ) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16044.2 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.16044.2 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: - SAMSUNG Electronics Co., Ltd.) ScummVM 1.4.1 (HKLM-x32\...\ScummVM_is1) (Version: - The ScummVM Team) SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: - NVIDIA Corporation) Hidden Shutdown Timer (HKLM\...\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}) (Version: 3.3.4 - Sinvise Systems) Shutdown7 Version 2.1.2 (HKLM-x32\...\{37D95233-83D5-4511-8FFA-E6110FBB1F3E}_is1) (Version: 2.1.2 - Marius Lutz) SIM MAX (HKLM-x32\...\{DAC0B889-5359-4FDC-893A-2B8EF6B71B6F}) (Version: 1.00.0000 - SIM MAX) Singularity German Uncut Edition 1.1 (HKLM-x32\...\Singularity German Uncut Edition 1.1) (Version: - ) Sleeping Dogs Game Of The Year (30 DLCs) 1.0 (HKLM-x32\...\Sleeping Dogs Game Of The Year (30 DLCs) 1.0) (Version: 1.0 - .x.X.RIDDICK.X.x.) SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.8 - SmartSound Software Inc.) SmartSound Quicktracks 5 (x32 Version: 5.1.8 - SmartSound Software Inc.) Hidden Sniper Elite 3 Dedicated Server (HKLM-x32\...\Steam App 266910) (Version: - ) SOMA (HKLM\...\U09NQQ==_is1) (Version: 1 - ) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spotify (HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\Spotify) (Version: - Spotify AB) Star Wars Jedi Knight Jedi Academy (HKLM-x32\...\{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}) (Version: - ) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) SWAT 4 Gold Edition MULTi7 - ElAmigos Version 1.1 (HKLM-x32\...\{C5A3E12F-8EA1-4698-80A8-32C9C87A11EF}_is1) (Version: 1.1 - Sierra) TAXMAN 2015 (HKLM-x32\...\{5613CAD3-71ED-4207-95A0-1BA0BF465E38}) (Version: 20.22.94 - Haufe-Lexware GmbH & Co.KG) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) TECUNIONLINE (HKLM-x32\...\TECUNIONLINE) (Version: - ShenZhen ruike Electronics Co.,Ltd) TeraCopy 2.3 (HKLM\...\TeraCopy_is1) (Version: - Code Sector) The Evil Within MULTi2 1.0 (HKLM-x32\...\The Evil Within MULTi2 1.0) (Version: - ) The Four Kings Casino and Slots (HKLM-x32\...\Steam App 260430) (Version: - Digital Leisure Inc.) Thunderbolt(TM) Software (HKLM\...\{BED2816F-D47A-41DA-AFCF-44E1B257C368}) (Version: - Intel(R) Corporation) TimeComX Basic (64-Bit) (HKLM-x32\...\TimeComX Basic 64-Bit) (Version: - Bitdreamers) Tomb Raider [2013] Collectors Edition MULTI-2 1.01.748.0 (HKLM-x32\...\Tomb Raider [2013] Collectors Edition MULTI-2 1.01.748.0) (Version: - ) Tomb Raider 1 + 2 + 3 (HKLM-x32\...\Tomb Raider 1 + 2 + 3_is1) (Version: - GOG.com) Universal Adb Driver (HKLM-x32\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Unreal (HKLM-x32\...\Unreal) (Version: - ) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Uplay (HKLM-x32\...\Uplay) (Version: 2.1 - Ubisoft) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: - Elaborate Bytes) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) Vulkan Run Time Libraries (HKLM\...\VulkanRT1.0.11.1) (Version: - LunarG, Inc.) WavePad Audio-Editor (HKLM-x32\...\WavePad) (Version: 6.12 - NCH Software) WebStorage (HKLM-x32\...\WebStorage) (Version: - ASUS Cloud Corporation) WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-asus) (Version: - WildTangent) Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.0.1 - ASUS) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Wise Care 365 3.95 (HKLM-x32\...\Wise Care 365_is1) (Version: 3.95 - WiseCleaner.com, Inc.) Wise Data Recovery 3.82 (HKLM-x32\...\Wise Data Recovery_is1) (Version: 3.82 - WiseCleaner.com, Inc.) Wise Folder Hider 3.25 (HKLM-x32\...\Wise Folder Hider_is1) (Version: 3.25 - WiseCleaner.com, Inc.) Wise Force Deleter 1.23 (HKLM-x32\...\Wise Force Deleter_is1) (Version: 1.23 - WiseCleaner.com, Inc.) X-Mouse Button Control 2.14 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.14 - Highresolution Enterprises) Zak McKracken – Between Time and Space Version v2 (HKLM-x32\...\Zak2_is1) (Version: v2 - Artificial Hair Bros.) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\Magic\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler) CustomCLSID: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Magic\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {02DFFCB2-3023-4270-A6A5-F634C39094C1} - System32\Tasks\WiseCleaner\WFDSkipUAC => C:\Program Files (x86)\Wise\Wise Force Deleter\WiseDeleter.exe [2015-09-11] (WiseCleaner.com) Task: {038C0AE1-850F-4787-9992-66638585ED62} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {041EC183-7E61-4AC6-A3B9-A38EFB3ECDAD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {04F6987D-26CA-40B1-8689-482DFDE3E68B} - System32\Tasks\WiseCleaner\WFHFreeSkipUAC => C:\Program Files (x86)\Wise\Wise Folder Hider\WiseFolderHider.exe [2015-12-28] (WiseCleaner.com) Task: {0B61B4D1-FD9B-41A3-B066-E017FDB8707A} - \Microsoft\Windows\Setup\gwx\rundetector -> Keine Datei <==== ACHTUNG Task: {0D202C58-7664-45C4-849E-0767A07005F7} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.) Task: {11297B15-450D-498C-8532-812410922210} - System32\Tasks\{76510113-A991-43AD-BA59-4E768F1E4D23} => pcalua.exe -a G:\CM108(7.1)\USB-108-100318-\Program\CmElv.exe -d G:\CM108(7.1)\USB-108-100318-\Program Task: {1DE59105-4D61-4520-B402-38EB12995DD5} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {25DE50C4-AC1F-497F-9017-E556670099F9} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {299CC0B5-2E81-446A-B9A9-87B63726CF64} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {3397CBD6-EE58-4124-8762-40DDC1078D88} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {38DA5EF2-A658-489A-BD08-2DB863E287C0} - System32\Tasks\{C481FA0A-06A3-4E3A-8A4A-87B51B1D8847} => pcalua.exe -a C:\BlackMesa-Setup.exe -d C:\ Task: {3C3C6874-0AC9-48A6-B9BB-78BDD9180F1C} - System32\Tasks\{3BC09844-F4EF-44F1-B708-E936EFF8B69A} => pcalua.exe -a H:\FahrenheitAutoRun.exe -d H:\ Task: {417E63E1-0816-4F71-AAA9-479BCC90D3A5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-12-21] (Adobe Systems Incorporated) Task: {42FBE9ED-844D-4C82-93CC-D21EC98F17C1} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] () Task: {4D3CBD94-09F6-47C8-AF2E-32F8535747E3} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] () Task: {5AD09BC0-F001-492A-8EE1-A5EC966EA30E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.) Task: {6A7A6D59-D63E-475C-8560-72287105F73E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {73BB4A9C-D5F6-4E0F-ACD9-A78A1DCE58C6} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe [2016-11-25] (AVG Technologies CZ, s.r.o.) Task: {795A745C-8A04-4E7E-A1E3-06F27CE1CC0D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.) Task: {7EC08BD6-275A-4FC1-86B8-1251DBC65C57} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-09-22] (Oracle Corporation) Task: {8A0D5CB2-6D41-4CF8-9D60-196773A10B32} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {8A6EABB4-E890-4149-BD5C-910123342B4A} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-08-06] (Realtek Semiconductor) Task: {97BB35B8-0317-45F6-B0A7-1BC8A184F847} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2016-12-22] (Microsoft Corporation) Task: {A314A88C-AFDB-470A-BADC-531068FA7CFD} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG Task: {AE0A2B22-6D11-4360-B87C-B57539AE796E} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Keine Datei <==== ACHTUNG Task: {AFA17095-B02F-4F6D-BD41-FEA6E473C667} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {B3833129-0A7D-45D5-91F6-83D5A466C673} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] () Task: {B7EC1178-7401-49CB-A673-7E2078897724} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {BC9A6AE0-F474-40EE-8D19-DEAC32A7672F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => Thunderbolt.exe Task: {C1861428-E1EF-4E59-8DCB-1F86BFB82C23} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2015-11-09] (Glarysoft Ltd) Task: {C1D22689-ACD4-4D22-9F02-714ADADA6437} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => start ThunderboltService Task: {C88ACA29-A7C0-4A66-8A75-D73EA1B9590C} - System32\Tasks\{6DDDBEB5-27E0-410D-806E-613EC08E3078} => pcalua.exe -a H:\FarCryAutoCD.exe -d H:\ Task: {C8DE3303-1801-4CBC-BDB8-9EADEC70A462} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {C9EE5C93-FDCF-463D-8149-D682F1480612} - System32\Tasks\{6B71DFFD-F7AE-4A6D-A0B3-26FD428303D3} => pcalua.exe -a I:\_isauto.exe -d I:\ Task: {D3CFE796-23AC-4F92-A3C5-4DDAE5871AF6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {D49C32E1-654B-4E2A-97AC-340CE4796170} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {D5400EAB-6F55-4487-B8F1-47FE5A5FF456} - \WPD\SqmUpload_S-1-5-21-2786200759-2278858845-1295660402-1001 -> Keine Datei <==== ACHTUNG Task: {D8A21171-7310-4137-95FF-A1B5E1B64E40} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => tbtsvc.exe Task: {D9DD9300-3117-43D6-A0AE-D77874AA2721} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {DF5AEB94-DA0D-4D51-8BF4-429BE1BB1B5C} - System32\Tasks\WiseCleaner\WDRSkipUAC => C:\Program Files (x86)\Wise\Wise Data Recovery\WiseDataRecovery.exe [2015-08-28] (WiseCleaner.com) Task: {E07FEEE5-C35D-4E14-A008-FCAF4EF0C0D7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner64.exe [2016-12-06] (Piriform Ltd) Task: {E42190F5-458B-4385-8915-DDBD26FF151D} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2014-06-03] (ASUS) Task: {EAB75945-DAD7-4BB4-8AFD-B8FCE23DB0D1} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.) Task: {EADE8BF1-7DC3-4C30-9763-14507819D5A6} - System32\Tasks\{C7C2286E-82AC-4DA0-B9E3-9BF42B0B9C92} => pcalua.exe -a "C:\Users\Magic\Downloads\Simcard Reader\Usb-SIM9.0\Setup.exe" -d "C:\Users\Magic\Downloads\Simcard Reader\Usb-SIM9.0" Task: {F6833A5A-E639-43FF-B225-E1BAF8EBF77D} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2014-07-09] (ASUSTek Computer Inc.) Task: {F83BD2D4-7F58-42E1-A3E1-034D35B254F6} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {FA9EC439-B980-4F45-925A-6BCCFB8B2E0F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => Thunderbolt.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\Magic\Favorites\Downloadseite von NCH Software.lnk -> hxxp://www.nch.com.au/de/index.htm Shortcut: C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eBook Converter\Website.lnk -> hxxp://www.ebook-converter.com Shortcut: C:\Users\Public\Desktop\HELI-X6.1.lnk -> E:\Spiele\HELI-X6.1\runHELI-X.bat () ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2008-10-24 16:35 - 2008-10-24 16:35 - 00128296 _____ () C:\Program Files (x86)\Lexware\AAVUpdateManager\aavus.exe 2012-01-17 10:24 - 2012-01-17 10:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2016-08-20 15:07 - 2016-08-26 00:27 - 00288192 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 00367552 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 03611584 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll 2015-12-20 11:09 - 2015-12-20 12:15 - 00066872 _____ () C:\WINDOWS\SysWoW64\PnkBstrA.exe 2016-09-25 00:20 - 2016-09-25 00:21 - 00189264 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2016-08-20 15:07 - 2016-08-26 00:27 - 02665920 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 01988544 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 01840576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 00207296 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-21 13:37 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-11-26 11:36 - 2016-08-25 22:12 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-12-21 13:37 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-12-21 13:37 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-11-26 12:07 - 2016-11-26 12:07 - 01864384 _____ () C:\Users\Magic\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll 2010-07-15 05:44 - 2010-07-15 05:44 - 00020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll 2015-07-02 19:47 - 2012-01-20 13:55 - 00678400 _____ () C:\Program Files\TeraCopy\TeraCopyExt64.dll 2016-11-29 19:39 - 2016-11-29 19:39 - 01787080 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_1.3.0.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2016-12-20 14:21 - 2016-12-20 14:21 - 00381440 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_1.3.0.0_x64__8wekyb3d8bbwe\Microsoft.Notes.Upgrade.dll 2016-12-20 14:20 - 2016-12-20 14:21 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-12-20 14:20 - 2016-12-20 14:21 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-12-20 14:20 - 2016-12-20 14:21 - 42130432 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2016-12-20 14:20 - 2016-12-20 14:21 - 02216448 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\roottools.dll 2016-11-26 11:32 - 2016-11-26 11:32 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-06-21 14:31 - 2015-07-16 00:54 - 00053832 _____ () C:\Windows\SysWOW64\UMonit64.exe 2016-12-27 14:41 - 2016-12-27 14:42 - 01274880 _____ () C:\ProgramData\firemin_2086\Firemin.exe 2014-10-24 22:41 - 2013-05-15 14:39 - 00463872 _____ () C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe 2017-01-07 22:14 - 2017-01-07 22:14 - 00566439 _____ () C:\Users\Magic\AppData\Local\JDownloader v2.0\tmp\7zip\SevenZipJBinding-FKPz9\libgcc_s_sjlj-1.dll 2017-01-07 22:14 - 2017-01-07 22:14 - 04078962 _____ () C:\Users\Magic\AppData\Local\JDownloader v2.0\tmp\7zip\SevenZipJBinding-FKPz9\lib7-Zip-JBinding.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00152000 _____ () C:\Program Files\VideoLAN\VLC\libvlc.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 02763200 _____ () C:\Program Files\VideoLAN\VLC\libvlccore.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00626624 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libdshow_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00046016 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00042944 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 12298176 _____ () C:\Program Files\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 01487808 _____ () C:\Program Files\VideoLAN\VLC\plugins\misc\libxml_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00091072 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00083392 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 02568640 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00118720 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00267712 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00091072 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libvdr_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00059328 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00074176 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00684480 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00833984 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00140224 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libzip_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00055232 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\librar_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00026560 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00150464 _____ () C:\Program Files\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 01605056 _____ () C:\Program Files\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00349120 _____ () C:\Program Files\VideoLAN\VLC\plugins\lua\liblua_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00028608 _____ () C:\Program Files\VideoLAN\VLC\plugins\control\libwin_msg_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00068032 _____ () C:\Program Files\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll 2016-06-01 15:45 - 2016-06-01 15:45 - 00238016 _____ () C:\Program Files\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00051648 _____ () C:\Program Files\VideoLAN\VLC\plugins\control\libwin_hotkeys_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00049600 _____ () C:\Program Files\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00330688 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libjpeg_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00031168 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00347584 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libpng_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 01521088 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00844736 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00339392 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00032704 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libdts_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00049600 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00056256 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libsubstx3g_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00437696 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libflac_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00038848 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libg711_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00028096 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00199616 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 03009472 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00426432 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00031680 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\liba52_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00031168 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00035264 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00455616 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libopus_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00135104 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libdvbsub_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 00032192 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll 2016-06-01 15:47 - 2016-06-01 15:47 - 15975872 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00916928 _____ () C:\Program Files\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00051136 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_sse2_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00037824 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_mmx_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00816576 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libswscale_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00041920 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_sse2_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00133056 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_sse2_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00068032 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_mmx_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00033216 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_mmx_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00046528 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00030656 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00059840 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00042944 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00053696 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00043456 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00027072 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00027072 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00026560 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00026560 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 00034240 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll 2016-06-01 15:46 - 2016-06-01 15:46 - 01515456 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll 2016-12-06 15:09 - 2016-12-06 15:09 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 00034240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll 2016-08-20 15:07 - 2016-08-26 00:27 - 00920000 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll 2014-10-24 22:35 - 2013-10-23 13:44 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00117248 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00037936 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00018992 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDColorEnhance.dll 2014-06-03 20:01 - 2014-06-03 20:01 - 00020528 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDRegammaAndGamut.dll 2015-06-11 23:41 - 2016-08-26 00:27 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-02 10:42 - 2016-12-23 20:55 - 51777648 _____ () C:\Users\Magic\AppData\Roaming\Spotify\libcef.dll 2016-10-31 23:31 - 2016-12-23 20:55 - 00110192 _____ () C:\Users\Magic\AppData\Roaming\Spotify\SpotifyWinRT.dll 2016-10-02 10:42 - 2016-12-23 20:55 - 01803888 _____ () C:\Users\Magic\AppData\Roaming\Spotify\libglesv2.dll 2016-10-02 10:42 - 2016-12-23 20:55 - 00086128 _____ () C:\Users\Magic\AppData\Roaming\Spotify\libegl.dll 2016-12-04 11:12 - 2016-12-04 11:12 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll 2013-04-27 09:24 - 2013-04-27 09:24 - 00071680 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\checkmetro.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\localhost -> localhost ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Magic\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run32: => "WebStorage" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "Steganos HotKeys" HKLM\...\StartupApproved\Run32: => "SSS17 Chrome Autofill Relay" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "GUDelayStartup" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "SSS17 Browser Monitor" HKU\S-1-5-21-2786200759-2278858845-1295660402-1001\...\StartupApproved\Run: => "SSS17_Update" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [{A3378399-CD48-4CB5-84D7-AA5D39FC70F8}] => LPort=26675 FirewallRules: [{2E84CC4C-E897-4C77-A27C-F46453FF57A0}] => %systemroot%\WindowsMobile\wmdHost.exe FirewallRules: [{BBDD3259-07C6-44F6-ACDA-C30926B10CD6}] => %systemroot%\WindowsMobile\wmdHost.exe FirewallRules: [{7C7D8964-26FE-4394-BADF-F9E74C8CD7BB}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [{528E3B20-13FB-46C9-AF58-9068915F9CB0}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [UDP Query User{6D3D8870-60B9-477F-9EF4-10A7A077D974}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{557C37B9-4614-478A-A144-7BDBC0F71E55}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{E22BCAAB-75C3-42D0-9B33-1479B209D63C}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{F5DBFFDF-EBC9-4C1C-9B44-C236D70E03F7}C:\users\magic\appdata\roaming\spotify\spotify.exe] => C:\users\magic\appdata\roaming\spotify\spotify.exe FirewallRules: [{D6220419-1177-47AA-BCCE-4354EE6502E4}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [UDP Query User{AA1BE5BE-4662-43B4-B05A-8C595D6A63AE}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [TCP Query User{B59E3605-07DD-4DA6-B107-4CDF3267B3C3}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [{0E9A4A87-8F02-48AE-9CD8-97EC18EEDEC6}] => D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{8C45D2C4-3DB8-4EE8-85D0-8885DBA46BDB}] => D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{107F23C2-6F3F-4987-B09E-6F79EC2669AA}] => E:\Steamgames\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [{08A2F34E-AE03-4118-BF08-018EF54299B9}] => E:\Steamgames\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [UDP Query User{364DDEA2-DBB2-474A-85E0-FC444ADEE1EF}D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe] => D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe FirewallRules: [TCP Query User{D1D2AB1D-B0A3-4567-80CF-9CF793E2AC55}D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe] => D:\steamlibrary\steamapps\common\call of duty modern warfare 3\iw5mp_server.exe FirewallRules: [{A2122F0D-4041-4156-BAE3-B4018F51C907}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{DD7EB97E-8B1F-48C5-B2A4-53302643EB22}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7D321605-0DAF-44BA-BFC5-8988B33C7531}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0704D41B-6043-4C9F-AA02-1ACC4C8046D4}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{EC6E740D-1623-4157-AC11-8D2A333FC11C}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{B3592C47-CB5A-4520-82B2-F5DAC935DFF8}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{7AE4DFFB-BAEE-423C-A3F8-4DD46D0A95AE}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{25102AAE-6315-4BFD-9E4E-AD686C0715A4}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{463E20D5-6EA5-439F-BDE9-E50E3A04997C}] => C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{C4D4FB5B-57E9-44B4-97FA-4272D4559CE7}] => C:\WINDOWS\SysWOW64\ftp.exe FirewallRules: [{C8785C4F-5F64-4205-8BAA-997112F77B0B}] => C:\WINDOWS\SysWOW64\ftp.exe FirewallRules: [{C070B80D-B7FA-4CD3-A06E-C49C4425DEB3}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [{24990052-623D-4BCE-8DD3-3E16C6BA298D}] => C:\WINDOWS\system32\ftp.exe FirewallRules: [UDP Query User{A70A266F-DAD4-4595-9E4C-C01235C6232E}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [TCP Query User{1B1E6CF6-3A42-415C-8E46-9A567FF849D1}C:\program files (x86)\phonerlite\phonerlite.exe] => C:\program files (x86)\phonerlite\phonerlite.exe FirewallRules: [{9134E917-73DC-418D-B780-83B47836859E}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe FirewallRules: [{F8696992-A57B-49B0-AC0E-DAFC89EF92E5}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe FirewallRules: [{BE08A6D6-27E4-4D0F-AFCD-D1A7321611BC}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe FirewallRules: [{F694934A-23E9-4515-8528-6E664F5FC484}] => H:\Stalker\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe FirewallRules: [{9A3BCAAF-4EAA-4D4D-9936-86C5EDD9CC4F}] => C:\Program Files (x86)\Steam\steamapps\common\Relic Hunters Zero\RelicHuntersZero.exe FirewallRules: [{82323557-1750-4503-88E9-1E11AFB3DBBC}] => C:\Program Files (x86)\Steam\steamapps\common\Relic Hunters Zero\RelicHuntersZero.exe FirewallRules: [{86AA60AF-AF2B-4EA9-AA7A-DD5A61A762CA}] => E:\Steamgames\steamapps\common\Medusa's Labyrinth\Medusa.exe FirewallRules: [{61904DB6-14ED-487B-9E54-CE31551B0BFE}] => E:\Steamgames\steamapps\common\Medusa's Labyrinth\Medusa.exe FirewallRules: [{479A9F15-CD8A-40ED-9D69-273651CAE1CE}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{8886E1F9-2343-42CF-9464-617EFDBA1349}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{E4B521B9-D8EC-4808-9515-36A56A1C58A4}] => C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{6C406380-A7C6-4C1C-A0E6-7C5674715F8D}] => C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{DF849CE4-D117-4CCE-A3DE-4B88B7CE20FB}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{8CE6309B-8A99-4C41-8E8C-4AD09DAD8382}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{CE249E79-E128-432D-A150-374BA9575B96}] => C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{61CD42B7-590C-4E0B-8FF1-A9C91EC91EEC}] => C:\Program Files (x86)\AVG\Av\avgemca.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/10/2017 09:23:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.14393.576_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/10/2017 12:37:08 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/10/2017 12:26:45 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.14393.576_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/09/2017 11:47:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.14393.576_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/09/2017 11:43:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.14393.576_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/09/2017 11:16:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.14393.576_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/09/2017 10:53:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe+MicrosoftEdge“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/09/2017 10:06:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.14393.576_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/09/2017 10:02:56 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (01/08/2017 09:51:52 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: OUTLAW) Description: Das Paket „Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte. Systemfehler: ============= Error: (01/10/2017 09:15:22 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (01/09/2017 10:02:58 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (01/08/2017 08:34:09 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (01/07/2017 10:13:35 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} und der APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (01/07/2017 10:12:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "GamesAppIntegrationService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/07/2017 10:12:20 PM) (Source: DCOM) (EventID: 10010) (User: OUTLAW) Description: Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/07/2017 10:12:20 PM) (Source: DCOM) (EventID: 10010) (User: OUTLAW) Description: Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/07/2017 10:12:20 PM) (Source: DCOM) (EventID: 10010) (User: OUTLAW) Description: Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/07/2017 10:12:20 PM) (Source: DCOM) (EventID: 10010) (User: OUTLAW) Description: Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/07/2017 10:12:20 PM) (Source: DCOM) (EventID: 10010) (User: OUTLAW) Description: Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. CodeIntegrity: =================================== Date: 2017-01-10 21:18:45.853 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 21:18:34.725 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 21:18:30.851 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 21:18:29.612 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 21:18:29.553 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 21:18:29.089 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 21:18:25.209 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 00:06:44.588 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 00:06:35.218 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-10 00:06:34.888 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume3\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-4710HQ CPU @ 2.50GHz Prozentuale Nutzung des RAM: 34% Installierter physikalischer RAM: 16333.16 MB Verfügbarer physikalischer RAM: 10750.68 MB Summe virtueller Speicher: 18765.16 MB Verfügbarer virtueller Speicher: 12009 MB ==================== Laufwerke ================================ Drive c: (OS) (Fixed) (Total:95.39 GB) (Free:20.3 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive d: (Data) (Fixed) (Total:130.86 GB) (Free:12.1 GB) NTFS Drive e: (Data1) (Fixed) (Total:465.75 GB) (Free:80.8 GB) NTFS Drive f: (Data2) (Fixed) (Total:465.76 GB) (Free:10.76 GB) NTFS Drive g: (STALKER) (CDROM) (Total:3.12 GB) (Free:0 GB) UDF Drive h: (ESD-USB) (Removable) (Total:119.74 GB) (Free:13.99 GB) exFAT ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: C56CCB18) Partition: GPT. ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: EAAFBC5E) Partition: GPT. ======================================================== Disk: 2 (Size: 119.7 GB) (Disk ID: 0930975D) Partition 1: (Not Active) - (Size=119.7 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
![]() | #15 |
![]() ![]() ![]() | ![]() Gaming Laptop mit Win10 Home wird immer langsamer Hallo noch jemand da? |
![]() |
Themen zu Gaming Laptop mit Win10 Home wird immer langsamer |
adware, avg, entfernt, filter, firefox, geforce, hacken, home, hängt, intel, lag, langsamer, laptop, links, liste, notebook, nvidia, problem, ram, rechner, runter, win, windows, zoll, öffnen |