|
Plagegeister aller Art und deren Bekämpfung: Windows 7: Malware blockiert InternetverbindungenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.03.2017, 11:35 | #1 |
| Windows 7: Malware blockiert Internetverbindungen Hallo zusammen, ich habe seit dem 25.12.2016, also seit nun mehr wie 3 Monaten das Problem, dass meine Internet-/Netzwerkeinstellungen sporadisch manipuliert werden. Verbindungen über eine LAN-Verbindung und eine zusätzlich eingebaute WLAN-Karte sind seitdem auch nicht mehr möglich. WLAN Netze werden angezeigt, aber der Verbindungsaufbau schlägt fehl. Die LAN-Verbindung ist erfolgreich, aber mit dem weiter genannten Problem belastet: Beim öffnen einer Internetseite kommt die Meldung "Die Verbindung wurde zurückgesetzt während die Seite geladen wurde." Egal ob Firefox, Thunderbird, Internet Explorer, Chrome, FileZilla FTP, ... Das einzigstes Programm, dass soweit uneingeschränkt funktioniert ist Steam. Temporäre Lösung für das Problem ist bisher das zurücksetzen der Netzwerkkonfiguration (WinSock & IpConfig), Durchlauf eines WinFix von Microsoft und die Startzeitprüfung von Avast. Dies ist sehr Zeitaufwendig und nervenaufreibend, da nach erfolgreicher Lösung bereits Sekunden nach der Anmeldung das Problem erneut auftreten kann. Am 25.12.2016 wurden Spiele in Steam installiert und ein Upgrade von Avast ausgeführt. Fakten zum PC: - System: Windows 7 Professional 64bit (Im Oktober 2016 aufgesetzt) - Virensoftware: Avast (Keine Malware findbar) - Windows Firewall ist aktiviert und wird von keinem fremden Programm bewusst beeinflusst - Hosts-Datei ist im Orginalzustand Ich danke bereits für eure Zeit euch mein Problem anzuhören und hoffe auf Hilfe :-) Die Version des WinFix kann ich noch heraussuchen, falls dies Relevant wäre. Das WinFix findet Probleme, behebt diese. Leider konnte ich bisher dazu keine Log mit genaueren Infos finden. Mit freundlichen Grüßen Sebastian |
26.03.2017, 13:53 | #2 |
/// TB-Ausbilder | Windows 7: Malware blockiert InternetverbindungenMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Um die Bereinigung möchlichst effektiv und schnell gestalten zu können, bitte ich um Beachtung der folgenden Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Schritt 2 Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Bitte poste mit deiner nächsten Antwort
|
26.03.2017, 14:02 | #3 |
| Windows 7: Malware blockiert Internetverbindungen Hallo, hier die gewünschten Dateien:
__________________FRST: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017 durchgeführt von Seb (Administrator) auf GAMING-PC (26-03-2017 14:31:31) Gestartet von C:\Users\Seb\Desktop Geladene Profile: Seb (Verfügbare Profile: Seb) Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe (OSBASE) C:\Windows\System32\ddmgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (pdfforge GmbH) P:\Programme\PDF Architect 4\creator-ws.exe (© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (DEVGURU Co., LTD.) P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngine.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\SIV\thermald.exe (Solvusoft Corporation) C:\Program Files (x86)\Solvusoft\Tray\SolvusoftTray.exe () C:\Windows\System32\flvga_tray.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-27] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [CommonToolkitTray_Solvusoft] => C:\Program Files (x86)\Solvusoft\Tray\SolvusoftTray.exe [1686088 2015-09-23] (Solvusoft Corporation) HKLM\...\Run: [flvga_tray64] => C:\Windows\system32\flvga_tray.exe [419328 2015-05-14] () HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-18] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM-x32\...\RunOnce: [EasyTuneEngineService] => C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EngineRunOnce.exe [14632 2016-05-03] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [EasyTune] => C:\Program Files (x86)\GIGABYTE\EasyTune\etro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [SIV] => C:\Program Files (x86)\GIGABYTE\SIV\sivro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe [14632 2016-02-26] () HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-03-23] (Valve Corporation) HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\MountPoints2: {d30ece49-96c7-11e6-bcff-806e6f6e6963} - D:\ZToolBar.exe ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-18] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-18] (AVAST Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-10-20] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{EE112510-05F2-423F-9B82-4CF134C99522}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== SearchScopes: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NS&chn=oem&geo=DE&ver=22&locale=de_DE&gct=sb&qsrc=2869 SearchScopes: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> {DA6F9CB8-5F1C-45FC-AB8D-6C4B3457583F} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-01-29] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-01-29] (Microsoft Corporation) BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-29] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-29] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2016-08-05] (pdfforge GmbH) Toolbar: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: 8i010wxq.default FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default [2017-03-26] FF NetworkProxy: Mozilla\Firefox\Profiles\8i010wxq.default -> type", 0 FF Extension: (Flash Video Downloader - YouTube HD Download [4K]) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\artur.dubovoy@gmail.com [2017-02-20] FF Extension: (Search and New Tab by Yahoo) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\jid1-16aeif9OQIRKxA@jetpack.xpi [2016-11-18] FF Extension: (ColorZilla) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-03-09] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\jgc1n486.Standard-Benutzer [2016-12-27] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\xs280j99.Standard-Benutzer1 [2016-12-27] FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension FF Extension: (PDF Architect 4 Creator) - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension [2017-01-08] [ist nicht signiert] FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-11-10] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-11-10] (VideoLAN) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-01-29] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH) Chrome: ======= CHR DefaultSearchURL: Default -> hxxp://www.startfenster.de/suche/?q={searchTerms} CHR DefaultSearchKeyword: Default -> Startfenster CHR DefaultSuggestURL: Default -> hxxp://www.startfenster.de/api/?q={searchTerms}&language={lang} CHR Profile: C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default [2017-02-02] CHR Extension: (Google Präsentationen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-20] CHR Extension: (Google Docs) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-20] CHR Extension: (Google Drive) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-20] CHR Extension: (YouTube) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-20] CHR Extension: (Google-Suche) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-10-20] CHR Extension: (Search Manager) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\djhangopedggnlnicpbjklghlckmndge [2016-12-28] CHR Extension: (Yahoo Partner) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabhkdeopjkcpkmofliimbjckmocfiom [2016-12-28] CHR Extension: (Google Tabellen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-20] CHR Extension: (Google Docs Offline) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-01] CHR Extension: (Avast Online Security) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-28] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-20] CHR Extension: (Google Mail) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-20] CHR Extension: (Chrome Media Router) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-28] CHR HKLM-x32\...\Chrome\Extension: [djhangopedggnlnicpbjklghlckmndge] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fabhkdeopjkcpkmofliimbjckmocfiom] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-18] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-18] (AVAST Software) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3704520 2017-02-18] (Microsoft Corporation) R2 ddmgr; C:\Windows\system32\ddmgr.exe [1659040 2016-01-04] (OSBASE) S3 Disc Soft Lite Bus Service; P:\Programme\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1468608 2016-10-06] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-25] (EasyAntiCheat Ltd) R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [142656 2016-06-01] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 ElfoService; P:\Programme\ElsterFormular Update Service\bin\ElfoService.exe [1283376 2017-02-13] () R2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [Datei ist nicht signiert] S3 HwmRecordService; C:\Program Files (x86)\GIGABYTE\SIV\HwmRecordService.exe [118568 2016-05-24] (GIGA-BYTE TECHNOLOGY CO., LTD.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21184 2016-03-29] (Microsoft Corporation) R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-02-12] (Rivet Networks) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440 2017-03-17] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-02-23] (NVIDIA Corporation) S2 OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [127272 2016-05-20] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2121736 2017-01-24] (Electronic Arts) S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2183696 2017-01-24] (Electronic Arts) S3 PDF Architect 4; P:\Programme\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH) S3 PDF Architect 4 CrashHandler; P:\Programme\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Creator; P:\Programme\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-11-06] () R2 ss_conn_service; P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.) S3 Te.Service; C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [137216 2016-03-29] (Microsoft Corporation) [Datei ist nicht signiert] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10362608 2016-12-15] (TeamViewer GmbH) S3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [1831064 2015-11-04] (Intel Corporation) S3 VSStandardCollectorService140; P:\Programme (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] () R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [309272 2017-03-18] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-18] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334600 2017-03-18] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-18] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-18] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [126600 2017-03-18] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [100640 2017-03-18] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-18] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [993608 2017-03-18] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [548928 2017-03-21] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162528 2017-03-18] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [337592 2017-03-18] (AVAST Software) R3 ausb3hub; C:\Windows\System32\DRIVERS\ausb3hub.sys [404480 2016-10-20] (Intel Corporation) R3 ausb3xhc; C:\Windows\System32\DRIVERS\ausb3xhc.sys [817664 2016-10-20] (Intel Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-02-12] (Rivet Networks, LLC.) R4 ddkmd; C:\Windows\system32\drivers\ddkmd.sys [254968 2016-01-04] (OSBASE) [Datei ist nicht signiert] R0 ddkmdldr; C:\Windows\System32\drivers\ddkmdldr.sys [16888 2016-01-04] (OSBASE) [Datei ist nicht signiert] S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-10-22] (Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-10-22] (Disc Soft Ltd) R3 FLxHCIv; C:\Windows\System32\Drivers\FLxHCIv.sys [199304 2016-01-08] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31728 2015-11-12] (Intel Corporation) R3 KillerEth; C:\Windows\System32\DRIVERS\e2xw7x64.sys [134296 2016-02-12] (Qualcomm Atheros, Inc.) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation) S3 nhi; C:\Windows\System32\DRIVERS\tbt70x.sys [126464 2015-11-10] (Intel Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-02-23] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2017-01-20] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (The OpenVPN Project) [Datei ist nicht signiert] S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] () S3 vmulti; C:\Windows\System32\DRIVERS\vmulti.sys [19504 2016-01-13] (Windows (R) Win 7 DDK provider) R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-26 14:31 - 2017-03-26 14:31 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Seb\Desktop\tdsskiller.exe 2017-03-26 14:31 - 2017-03-26 14:31 - 00025354 _____ C:\Users\Seb\Desktop\FRST.txt 2017-03-26 14:31 - 2017-03-26 14:31 - 00000000 ____D C:\FRST 2017-03-26 14:30 - 2017-03-26 14:30 - 02424832 _____ (Farbar) C:\Users\Seb\Desktop\FRST64.exe 2017-03-26 14:29 - 2017-03-26 14:29 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-03-24 20:49 - 2017-03-26 14:29 - 00196286 _____ C:\Windows\SysWOW64\bios.ini 2017-03-24 20:44 - 2017-03-24 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE 2017-03-24 12:54 - 2017-03-24 12:54 - 00038955 _____ C:\Users\Seb\Downloads\Augenaerztlicher_Vorabbefund.pdf 2017-03-22 02:10 - 2017-03-22 02:10 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Playsport Games 2017-03-22 00:24 - 2017-03-22 00:24 - 00000222 _____ C:\Users\Seb\Desktop\Motorsport Manager.url 2017-03-22 00:02 - 2017-03-22 00:02 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-03-22 00:02 - 2017-03-17 00:56 - 00134592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-03-22 00:02 - 2017-01-26 02:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-03-22 00:02 - 2017-01-26 02:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe 2017-03-22 00:00 - 2017-03-17 02:59 - 40190400 _____ C:\Windows\system32\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 34952760 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 28223544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 17282648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 16400616 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14674712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14434360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 11122912 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 04064088 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03627064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03187256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 01053240 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00989120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00912440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00504104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00492560 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00425104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00408272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 00170360 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00153368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:31 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-03-21 23:49 - 2017-03-08 06:22 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:18 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-03-21 23:49 - 2017-03-08 06:07 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:06 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-03-21 23:49 - 2017-03-04 19:24 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 18:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 10:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-03-21 23:49 - 2017-03-04 10:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-03-21 23:49 - 2017-03-04 10:02 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-03-21 23:49 - 2017-03-04 10:01 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-04 09:59 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-03-21 23:49 - 2017-03-04 09:52 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-03-21 23:49 - 2017-03-04 09:51 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-03-21 23:49 - 2017-03-04 09:48 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-03-21 23:49 - 2017-03-04 09:46 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-03-21 23:49 - 2017-03-04 09:45 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-03-21 23:49 - 2017-03-04 09:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-03-21 23:49 - 2017-03-04 09:36 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-03-21 23:49 - 2017-03-04 09:32 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-03-21 23:49 - 2017-03-04 09:31 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-03-21 23:49 - 2017-03-04 09:23 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-04 09:21 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-03-21 23:49 - 2017-03-04 09:13 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-03-21 23:49 - 2017-03-04 09:11 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-03-21 23:49 - 2017-03-04 08:57 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-03-21 23:49 - 2017-03-04 08:55 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-03-21 23:49 - 2017-03-04 08:54 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-03-21 23:49 - 2017-03-04 08:52 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-03-21 23:49 - 2017-03-04 08:52 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-04 08:26 - 15259648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-03-21 23:49 - 2017-03-04 08:25 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-03-21 23:49 - 2017-03-04 08:12 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-03-21 23:49 - 2017-03-04 08:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-03-21 23:49 - 2017-03-04 06:18 - 20281856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-03-21 23:49 - 2017-03-02 20:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-03-21 23:49 - 2017-03-02 20:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-03-21 23:49 - 2017-03-02 20:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-02 20:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-02 19:55 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-03-21 23:49 - 2017-03-02 19:54 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-03-21 23:49 - 2017-03-02 19:53 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-03-21 23:49 - 2017-03-02 19:51 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-03-21 23:49 - 2017-03-02 19:50 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-03-21 23:49 - 2017-03-02 19:49 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-03-21 23:49 - 2017-03-02 19:49 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-03-21 23:49 - 2017-03-02 19:41 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-03-21 23:49 - 2017-03-02 19:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-02 19:35 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-03-21 23:49 - 2017-03-02 19:32 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-03-21 23:49 - 2017-03-02 19:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-03-21 23:49 - 2017-03-02 19:29 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-03-21 23:49 - 2017-03-02 19:28 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-03-21 23:49 - 2017-03-02 19:22 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-03-21 23:49 - 2017-03-02 19:21 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-03-21 23:49 - 2017-03-02 19:19 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-03-21 23:49 - 2017-03-02 19:17 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-03-21 23:49 - 2017-03-02 19:17 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-02 19:11 - 13654528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-03-21 23:49 - 2017-03-02 18:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 01312768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-03-21 23:49 - 2017-02-14 18:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-03-21 23:49 - 2017-02-14 18:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-03-21 23:49 - 2017-02-11 18:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-03-21 23:49 - 2017-02-11 18:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-03-21 23:49 - 2017-02-11 17:58 - 00462848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-03-21 23:49 - 2017-02-10 18:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:32 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-03-21 23:49 - 2017-02-10 16:33 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-03-21 23:49 - 2017-02-09 18:36 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:35 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-03-21 23:49 - 2017-02-09 18:35 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-03-21 23:49 - 2017-02-09 18:33 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:19 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-03-21 23:49 - 2017-02-09 18:19 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:16 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-03-21 23:49 - 2017-02-09 18:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-03-21 23:49 - 2017-02-09 18:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-03-21 23:49 - 2017-02-09 18:02 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-03-21 23:49 - 2017-02-09 18:00 - 03220480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-03-21 23:49 - 2017-02-09 17:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-03-21 23:49 - 2017-02-09 17:58 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-03-21 23:49 - 2017-02-09 17:55 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-03-21 23:49 - 2017-02-09 17:54 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-03-21 23:49 - 2017-02-09 17:54 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-03-21 23:49 - 2017-02-09 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-03-21 23:49 - 2017-02-09 17:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-03-21 23:49 - 2017-02-09 17:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-03-21 23:49 - 2017-02-06 18:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-03-21 23:49 - 2017-01-18 17:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-03-21 23:49 - 2017-01-06 20:00 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-03-21 23:49 - 2017-01-06 19:44 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437892.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437892.dll 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-03-21 23:27 - 2017-03-21 23:27 - 00000000 ____D C:\ProgramData\Codemasters 2017-03-21 19:23 - 2017-02-23 01:42 - 00084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-03-21 19:23 - 2017-02-23 01:37 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 01609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00398408 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-03-03 19:42 - 2017-03-03 19:42 - 00001416 _____ C:\Users\Seb\Desktop\RAGEPluginHook.exe - Verknüpfung (2).lnk 2017-02-27 00:37 - 2017-02-27 00:58 - 00000000 ____D C:\Users\Seb\Downloads\GTA 5 Mods 2017-02-26 21:04 - 2017-02-27 00:37 - 00000000 ____D C:\Users\Seb\Downloads\GTA 5 mods - installed 2017-02-25 21:43 - 2017-02-25 21:43 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Promotion Software GmbH 2017-02-25 20:47 - 2017-02-26 21:09 - 00000000 ____D C:\Users\Seb\Downloads\Neuer Ordner (2) 2017-02-25 20:02 - 2017-02-25 20:02 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2017-02-25 20:01 - 2017-02-25 20:01 - 00001132 _____ C:\Users\Public\Desktop\DLL-Files.com Client.lnk 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\Users\Seb\AppData\Roaming\DLL-files.com 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\Users\Seb\AppData\Roaming\DFXCT 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DLL-Files.com Client 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\Program Files (x86)\DLL-Files.com Client 2017-02-25 19:15 - 2017-02-25 19:15 - 00000222 _____ C:\Users\Seb\Desktop\Emergency 2017.url 2017-02-25 18:58 - 2017-02-25 18:58 - 00000222 _____ C:\Users\Seb\Desktop\Helicopter 2015 Natural Disasters.url ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-26 14:31 - 2017-02-05 19:58 - 00000364 _____ C:\Windows\Tasks\WinThruster64-Seb-Startup.job 2017-03-26 14:30 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\NVIDIA 2017-03-26 14:29 - 2017-02-05 19:55 - 00000372 _____ C:\Windows\Tasks\WinThruster64-Seb-Notification.job 2017-03-26 14:29 - 2016-11-25 19:53 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Mozilla 2017-03-26 14:29 - 2016-10-29 09:31 - 00026192 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2017-03-26 14:29 - 2016-10-20 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2017-03-26 14:28 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-24 21:17 - 2010-11-21 08:50 - 00700130 _____ C:\Windows\system32\perfh007.dat 2017-03-24 21:17 - 2010-11-21 08:50 - 00149768 _____ C:\Windows\system32\perfc007.dat 2017-03-24 21:17 - 2009-07-14 07:13 - 01622706 _____ C:\Windows\system32\PerfStringBackup.INI 2017-03-24 21:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2017-03-24 21:15 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-24 21:15 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-24 21:01 - 2016-10-21 20:20 - 00000000 ____D C:\Users\Seb\AppData\Roaming\FileZilla 2017-03-24 20:44 - 2016-10-29 09:29 - 00000000 ____D C:\Program Files (x86)\GIGABYTE 2017-03-24 19:37 - 2017-02-17 05:06 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2017-03-24 15:34 - 2016-10-20 18:43 - 00000000 ____D C:\Users\Seb\AppData\Roaming\vlc 2017-03-24 12:55 - 2016-03-30 09:16 - 00000000 ____D C:\Users\Seb\Documents\Bewerbungen 2017-03-22 00:24 - 2016-10-20 18:58 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-03-22 00:19 - 2009-07-14 06:45 - 00556104 _____ C:\Windows\system32\FNTCACHE.DAT 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ___SD C:\Windows\system32\CompatTel 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ____D C:\Windows\system32\appraiser 2017-03-22 00:03 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-03-22 00:03 - 2016-10-20 15:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-03-21 23:53 - 2016-10-29 07:22 - 00000000 ____D C:\Windows\system32\MRT 2017-03-21 23:51 - 2016-10-29 07:22 - 138634176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-03-21 23:50 - 2017-02-13 03:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-03-21 23:45 - 2016-11-08 20:50 - 00000000 ____D C:\ProgramData\Skype 2017-03-21 23:27 - 2016-10-25 17:51 - 00000000 ____D C:\Users\Seb\Documents\My Games 2017-03-21 23:24 - 2016-11-30 16:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-21 23:24 - 2016-10-20 15:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-21 23:18 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-03-21 23:06 - 2017-02-02 21:35 - 00004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2017-02-02 21:35 - 00001419 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2017-03-21 23:06 - 2016-10-29 09:20 - 00003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-20 15:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-03-21 23:06 - 2016-10-20 15:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-03-21 19:25 - 2017-01-03 00:52 - 00548928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2017-03-18 17:46 - 2017-01-03 00:52 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00334600 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00309272 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-03-18 17:45 - 2017-01-03 00:52 - 00993608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00547904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.148985196613904 2017-03-18 17:45 - 2017-01-03 00:52 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.148985196721606 2017-03-18 17:45 - 2017-01-03 00:52 - 00162528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00126600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00100640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2017-03-17 02:59 - 2017-02-15 02:55 - 19883600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 13378096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 03583744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2017-03-17 02:59 - 2016-10-20 15:47 - 00042686 _____ C:\Windows\system32\nvinfo.pb 2017-03-17 02:59 - 2015-11-06 12:23 - 01600056 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2017-03-17 01:31 - 2016-10-29 09:20 - 00001951 _____ C:\Windows\NvContainerRecovery.bat 2017-03-17 01:16 - 2016-10-29 09:32 - 00549944 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2017-03-17 01:16 - 2016-10-29 09:32 - 00081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 02477504 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2017-03-16 11:39 - 2016-10-20 15:47 - 07813427 _____ C:\Windows\system32\nvcoproc.bin 2017-03-09 20:52 - 2016-12-10 12:46 - 00000000 ____D C:\Users\Seb\Desktop\Steuer 2017-03-03 20:14 - 2016-10-21 15:41 - 00000000 ____D C:\Fraps 2017-03-03 18:28 - 2016-10-26 18:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-03-03 18:27 - 2016-10-20 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-03-02 22:42 - 2016-12-19 01:43 - 00000000 ____D C:\Users\Seb\Documents\Visual Studio 2015 2017-02-28 19:44 - 2016-10-22 11:21 - 00000000 ____D C:\Users\Seb\AppData\Local\Deployment 2017-02-27 01:22 - 2016-10-25 17:56 - 00000000 ____D C:\Users\Seb\AppData\Local\CrashDumps 2017-02-26 21:05 - 2017-02-18 20:20 - 00000000 ____D C:\Users\Seb\AppData\Local\Albo1125 2017-02-26 13:13 - 2016-10-22 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2017-02-25 19:56 - 2016-08-10 15:38 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2017-02-25 19:52 - 2016-10-20 15:49 - 00000000 ____D C:\Users\Seb\AppData\Local\NVIDIA Corporation ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-10-26 18:41 - 2016-11-11 20:08 - 0000104 _____ () C:\Users\Seb\AppData\Roaming\Camdata.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamLayout.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamShapes.ini 2016-10-26 18:41 - 2016-11-11 17:06 - 0004535 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.cfg 2016-11-11 17:06 - 2016-11-11 17:06 - 0000000 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.Data.ini 2016-11-11 17:06 - 2016-11-11 17:06 - 0001206 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.ini 2016-10-26 18:41 - 2016-11-11 18:13 - 0000096 _____ () C:\Users\Seb\AppData\Roaming\version2.xml 2016-11-25 20:37 - 2017-01-06 22:17 - 0007602 _____ () C:\Users\Seb\AppData\Local\resmon.resmoncfg 2016-10-20 15:26 - 2016-10-20 15:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2016-10-22 11:23 - 2016-10-22 11:23 - 0000185 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2016-02-28 19:58 - 2016-02-28 19:58 - 0010218 _____ () C:\ProgramData\regid.2015-05.exe.textpad_83F5EF12-C2F9-4C11-A5C5-57A7B2D7AD25.swidtag Einige Dateien in TEMP: ==================== 2016-11-20 15:25 - 2017-02-10 00:39 - 0754168 _____ (NVIDIA Corporation) C:\Users\Seb\AppData\Local\Temp\nvSCPAPI.dll 2017-03-21 23:49 - 2017-02-10 00:39 - 0352704 _____ (NVIDIA Corporation) C:\Users\Seb\AppData\Local\Temp\nvStInst.exe 2017-03-21 23:44 - 2017-03-21 23:44 - 14456872 _____ (Microsoft Corporation) C:\Users\Seb\AppData\Local\Temp\vc_redist.x86.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-03-18 18:59 ==================== Ende von FRST.txt ============================ |
26.03.2017, 14:03 | #4 |
| Windows 7: Malware blockiert Internetverbindungen Addition: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017 durchgeführt von Seb (26-03-2017 14:31:49) Gestartet von C:\Users\Seb\Desktop Windows 7 Professional Service Pack 1 (X64) (2016-10-19 19:46:39) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-844095808-1650209266-980683291-500 - Administrator - Disabled) Gast (S-1-5-21-844095808-1650209266-980683291-501 - Limited - Disabled) Seb (S-1-5-21-844095808-1650209266-980683291-1000 - Administrator - Enabled) => C:\Users\Seb ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) @BIOS B16.0608.1 (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) @BIOS B16.0608.1 (x32 Version: 3.00.0000 - GIGABYTE) Hidden Active Directory Authentication Library für SQL Server (Version: 13.0.1601.5 - Microsoft Corporation) Hidden Active Directory Authentication Library für SQL Server (x86) (x32 Version: 13.0.1601.5 - Microsoft Corporation) Hidden Ambient LED (HKLM-x32\...\InstallShield_{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.2501 - GIGABYTE) Ambient LED (x32 Version: 1.00.1605.2501 - GIGABYTE) Hidden Ansel (Version: 378.92 - NVIDIA Corporation) Hidden APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1703.2301 - GIGABYTE) APP Center (x32 Version: 1.00.1703.2301 - GIGABYTE) Hidden Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation) Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.26.1 - Asmedia Technology) Audacity 1.2.6 (HKLM-x32\...\Audacity_is1) (Version: - ) Audacity Recovery Utility (HKLM-x32\...\AURC_is1) (Version: - Markus Meyer) Autobahn Police Simulator (HKLM\...\Steam App 348510) (Version: - Z-Software) Avast Internet Security (HKLM-x32\...\Avast Antivirus) (Version: 17.2.2288 - AVAST Software) Azure AD Authentication Connected Service (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.7.2.45672 - Electronic Arts) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.47.30570 - Electronic Arts) Battlefield™ Hardline (HKLM-x32\...\{CB4AC3DA-8CC1-4516-86DA-4078B57DB229}) (Version: 1.4.0.10 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50716.0 - Microsoft Corporation) Hidden Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.51210.80 - Microsoft Corporation) Hidden BIOS Setup (HKLM-x32\...\InstallShield_{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) BIOS Setup (x32 Version: 1.00.0000 - GIGABYTE) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation) Build Tools - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Build Tools Language Resources - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Buildtools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Bus Simulator 16 (HKLM\...\Steam App 324310) (Version: - stillalive studios) Call of Duty: Infinite Warfare (HKLM\...\Steam App 292730) (Version: - Infinity Ward) CodedUITestUAP (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Color Temperature (HKLM-x32\...\InstallShield_{68BFE28B-3F55-4E00-90A4-5179B91A3BD0}) (Version: 16.05.0601 - GIGABYTE) Color Temperature (x32 Version: 16.05.0601 - GIGABYTE) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0196 - Disc Soft Ltd) Demolish & Build 2017 (HKLM\...\Steam App 470740) (Version: - Noble Muffins) Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden DLL-Files.com Client (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_DLL-Files.c~79141F26_is1) (Version: 2.1.1000.4462 - DLL-Files.com Client) Dotfuscator and Analytics Community Edition 5.22.0 (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden Dotfuscator and Analytics Community Edition Language Pack 5.22.0 de-DE (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.0506 - GIGABYTE) EasyTune (x32 Version: 1.16.0506 - GIGABYTE) Hidden EasyTuneEngineService (HKLM-x32\...\InstallShield_{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 2.16.0603 - GIGABYTE) EasyTuneEngineService (x32 Version: 2.16.0603 - GIGABYTE) Hidden ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 18.1.22140 - Landesfinanzdirektion Thüringen) Emergency 2017 (HKLM\...\Steam App 524110) (Version: - Sixteen Tons Entertainment) Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{3FF082A7-A5DE-4BDA-B56A-1D2BEFD617A3}) (Version: 11.1.3000.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{FD639F4D-1460-42E6-B32D-FEC1745D0BDC}) (Version: 13.0.1601.5 - Microsoft Corporation) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) F1 2016 (HKLM\...\Steam App 391040) (Version: - Codemasters) Farming Simulator 17 (HKLM\...\Steam App 447020) (Version: - Giants Software) Fast Boot (HKLM-x32\...\InstallShield_{FA8FB4F2-F524-48E1-A06C-45602FBF26CD}) (Version: 1.16.0406 - GIGABYTE) Fast Boot (x32 Version: 1.16.0406 - GIGABYTE) Hidden Fernbus Simulator (HKLM\...\Steam App 427100) (Version: - TML-Studios) FileZilla Client 3.24.1 (HKLM-x32\...\FileZilla Client) (Version: 3.24.1 - Tim Kosse) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2013 Sprachpaket (DEU) - v1.6 (x32 Version: 1.6.30930.3 - Microsoft Corporation) Hidden Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket – DEU - v1.8 (x32 Version: 1.8.40521.1 - Microsoft Corporation) Hidden GIANTS Editor 7.0.0 64-bit (HKLM-x32\...\giants_editor_7.0.0_win64_is1) (Version: 7.0.0 - GIANTS Software GmbH) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North) Greenshot 1.2.8.14 (HKLM\...\Greenshot_is1) (Version: 1.2.8.14 - Greenshot) Helicopter 2015: Natural Disasters (HKLM\...\Steam App 350540) (Version: - Si7) IDE Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IDE-Tools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.1.40 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel® USB 3.1 Device Driver (HKLM\...\{7DFE2F7E-3154-45D6-A468-4725DE033AC8}) (Version: 15.2.30.250 - Intel Corporation) Intellisense Lang Pack Mobile Extension SDK 10.0.10586.0 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Killer Bandwidth Control Filter Driver (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer E240x Drivers (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Network Manager (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{009DF489-4590-4579-BAB2-0136BB829E4A}) (Version: 1.1.57.1346 - Rivet Networks) Kinect for Windows Speech Recognition Language Pack (de-DE) (HKLM-x32\...\{898AA67F-99B8-4C7F-9611-B11F98EF6E78}) (Version: 11.0.7413.611 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-AU) (HKLM-x32\...\{48CEC0A3-AE10-4EE3-AC62-76D3D58792E5}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-CA) (HKLM-x32\...\{9C5505DA-F9C1-46CB-9F8F-AC38F8EA518A}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-GB) (HKLM-x32\...\{A0186231-0A8B-455A-8A25-B64AABCC11A6}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-US) (HKLM-x32\...\{8AAA44BB-487E-4D01-AF76-484ACB90DBFE}) (Version: 11.0.7400.336 - Microsoft Corporation) Kits Configuration Installer (x32 Version: 10.0.26624 - Microsoft) Hidden KRISTAL Audio Engine (HKLM-x32\...\KRISTAL Audio Engine) (Version: - ) Leadwerks Game Engine (HKLM\...\Steam App 251810) (Version: - Leadwerks Software) MAGIX Common Components 1 (x64) (HKLM\...\{05799CB2-47FA-4322-9776-C0D15991EE7E}) (Version: 1.6.1.0 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\MX.{410B406D-6A35-41FF-B458-ADB0D3563487}) (Version: 2.0.1.145 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\Steam App 330130) (Version: - MAGIX Software GmbH) MAGIX Fastcut (Version: 2.0.1.145 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.4.235 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.5.273 - MAGIX Software GmbH) Hidden MAGIX Fonts Package 1 (x32 Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Screenshare (HKLM-x32\...\{20C81F73-2600-464A-BA60-401739102479}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{AB8304F0-383F-4F80-8988-87727C415BF7}) (Version: 7.0.2.6 - MAGIX Software GmbH) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX Software GmbH) Hidden MAGIX Video deluxe 2015 (HKLM\...\MX.{FFDC29E6-5C7C-4AA8-AF5A-99E015165382}) (Version: 14.0.0.159 - MAGIX Software GmbH) MAGIX Video deluxe 2015 (Version: 14.0.0.159 - MAGIX Software GmbH) Hidden MAGIX Videoton Cleaning Lab (HKLM-x32\...\MAGIX_MSI_Videoton_Cleaning_Lab) (Version: 1.0.0.0 - MAGIX AG) MAGIX Videoton Cleaning Lab (x32 Version: 1.0.0.0 - MAGIX AG) Hidden Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (HKLM-x32\...\{21B0F482-5EF9-45DA-8840-340AFE705A6C}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (Deutsch) (HKLM-x32\...\{529EFF09-750D-48B9-A47A-34A3B6248C3F}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Build Tools 2015 (HKLM-x32\...\{d21da0dd-4ba4-4838-ba58-64cf7a77131a}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.1 Sprachpaket - DEU) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.7766.2060 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft Server Speech Platform Runtime (x64) (HKLM\...\{3B433087-E62E-4BF5-97F9-4AF6E1C2409C}) (Version: 11.0.7400.345 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50905.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (HKLM-x32\...\{F351AA2C-723C-4CFE-A7CB-8E43AB164F7F}) (Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{D4E30517-FE6F-491E-942F-AE10E1B18F38}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{B4EDAE03-DB34-4DD0-BA7E-2ED80DEA50B1}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{269A8DF6-BBDA-441F-932B-233F9B746D72}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{EC75BD20-F9CA-4E77-825F-ABD77E95BE91}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{0BF65908-D137-4A9E-B7C9-78F32F74F6FD}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{93945D16-4C3D-433E-B7E4-3D0D86B284C8}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{6F173435-3F19-4043-BA3D-A46AA8472859}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL-Sprachdienst (HKLM-x32\...\{1D812D86-D8EF-41AC-A518-BA12E1913747}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2016 LocalDB (HKLM\...\{1765D93F-97E4-44D3-951D-0DA09B89EE17}) (Version: 13.0.2151.0 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (x64) (HKLM\...\{264B070C-82D7-4C9C-B1CE-A0B124BCC787}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM\...\{619537F4-1E39-4047-AA4F-D2D98A1DA743}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM-x32\...\{4EFF12AE-599C-42A2-ACFA-0D95C3B11A19}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL ScriptDom (HKLM\...\{E8F3D249-7DE6-4422-AC86-1CE7D5CCFA0F}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (12.0.61021.0) (HKLM-x32\...\{A8689DE4-28A2-4F57-9A5F-A4851A8FD849}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (14.0.60519.0) (HKLM-x32\...\{9F367648-EC0C-4F97-B351-D12A51E38F96}) (Version: 14.0.60519.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - Visual Studio 2013 (HKLM-x32\...\{1d259390-0778-4f41-8024-8c826a8ead96}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (12.0.30919.1) (HKLM-x32\...\{BCB8A870-2B3D-4CC0-87D6-F931E065AC0C}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server*2014 Express LocalDB (HKLM\...\{CA191120-4CB1-4E3D-89B8-79FDB9017A2E}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Transact-SQL ScriptDom (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 T-SQL Language Service (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2016 Management Objects (HKLM-x32\...\{35A7B00B-4F9C-4B4D-919C-86FFFEE46AD6}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{9634d50a-0c4d-4f52-8a9f-894a2baae370}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{307a22b8-8353-4c5e-b67b-2404c5734558}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio Community 2015 mit Updates (HKLM-x32\...\{ec2556f3-08aa-4829-8017-07d7ea9e125d}) (Version: 14.0.25420.1 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (HKLM-x32\...\{43341417-7882-4F34-8390-53DFD00F6C0F}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (HKLM\...\{24440413-490E-41CA-BD33-0B30FD3EBE3A}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{7F6DCED8-6A2B-4436-AF20-8F659D04E388}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{48BF289B-F3FA-4023-9251-80ABF7B726F9}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM\...\{FEC926D4-785B-4ED7-B35D-3FA37DD29F8B}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM-x32\...\{A37BE9D7-EAAE-4C6B-9D7E-DBD8B8D88681}) (Version: 13.0.1601.5 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden Motorsport Manager (HKLM\...\Steam App 415200) (Version: - Playsport Games) Mozilla Firefox 52.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 52.0.1 (x86 de)) (Version: 52.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.1.6284 - Mozilla) Mozilla Thunderbird 45.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 45.2.0 (x86 de)) (Version: 45.2.0 - Mozilla) Mozilla Thunderbird 45.8.0 (x86 de) (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Mozilla Thunderbird 45.8.0 (x86 de)) (Version: 45.8.0 - Mozilla) MSBuild/NuGet Integration 14.0 (x86) (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Napster (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\5d01cae694a4998b) (Version: 6.17.42.0 - Rhapsody International Inc.) Need for Speed™ The Run (HKLM-x32\...\{0EDC9BA0-016E-406a-86DA-04FC1BE00C21}) (Version: 1.1.0.0 - Electronic Arts) Notruf 112 (HKLM\...\Steam App 491530) (Version: - Crenetic GmbH Studios) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation) NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation) NVIDIA Grafiktreiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.16.2 - OBS Project) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) ON_OFF Charge 2 B15.0709.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden OpenIV (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OpenIV) (Version: 2.8.703 - .black/OpenIV Team) Origin (HKLM-x32\...\Origin) (Version: 10.4.2.12697 - Electronic Arts, Inc.) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{FACF2669-E25A-428A-9167-5EEDE741F3B9}) (Version: 4.6.00127 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM-x32\...\{4860C1E5-CE58-4D32-89DE-37951333B4C9}) (Version: 4.6.01055 - Microsoft Corporation) PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.26.25466 - pdfforge GmbH) PDF Architect 4 Asian Fonts Pack (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Convert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Forms Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Insert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 OCR Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Review Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Secure Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Projekt- und Elementvorlagen für Visual Studio Express 2015 für Windows 10 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Projekt- und Elementvorlagen für Visual Studio Professional 2015 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.994 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7727 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.4 - Rockstar Games) Roslyn Language Services - x86 (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden SIV (HKLM-x32\...\InstallShield_{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.16.0525 - GIGABYTE) SIV (x32 Version: 1.16.0525 - GIGABYTE) Hidden SketchUp 2017 (HKLM\...\{5A8C61BD-0912-4B76-805E-4EDE5E13298C}) (Version: 17.1.174 - Trimble Navigation Limited) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Hidden SmartKeyboard (HKLM-x32\...\InstallShield_{75B74C36-A9C6-4912-B4BB-C461AA36D01E}) (Version: 1.00.0000 - GIGABYTE) SmartKeyboard (x32 Version: 1.00.0000 - GIGABYTE) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (x32 Version: 14.102.25619 - Microsoft) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) TeamViewer 12 Host (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer) Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios) Thin2000 USB Display Adapter (HKLM\...\{CB5F5631-515F-4C70-ACA5-3FAAFA1866BC}) (Version: 1.1.323.0 - Fresco Logic) Thunderbolt(TM) Software (HKLM-x32\...\{B0E8A8CA-5A40-49C3-BE5E-9076664DB9AA}) (Version: 15.3.39.250 - Intel Corporation) TypeScript Power Tool (x32 Version: 1.8.34.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.36.0 - Microsoft Corporation) Hidden UE4 Prerequisites (x64) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (x32 Version: 1.0.13.0 - Epic Games, Inc.) Hidden Universal CRT Extension SDK (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Redistributable (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x64 (Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x86 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation) VLC media player (HKLM\...\VLC media player) (Version: 2.2.5 - VideoLAN) VLC Updater (HKLM-x32\...\VLC Updater) (Version: 1.0 - VLC Updater) <==== ACHTUNG VS Update core components (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden vs_update3notification (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Watch_Dogs 2 (HKLM\...\Steam App 447040) (Version: - Ubisoft) WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation) WinAppDeploy (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Windows SDK AddOn (HKLM-x32\...\{75C39BA6-1D02-4BEA-844F-0EA6C4B7FA1B}) (Version: 10.1.0.0 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.10586.212 (HKLM-x32\...\{43d9f43d-c90b-4fdf-9dfe-ecf9990bfa2a}) (Version: 10.1.10586.212 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.26624 (HKLM-x32\...\{e7a0c8b6-b0e9-41e2-8a0a-a6784f88d1d4}) (Version: 10.0.26624 - Microsoft Corporation) Windows-Treiberpaket - Graphics Tablet (WinUsb) USBDevice (04/10/2014 8.33.30.0) (HKLM\...\142118DF51345EA02D2B1583E102C8FB95FD6D52) (Version: 04/10/2014 8.33.30.0 - Graphics Tablet) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) WinRT Intellisense Desktop - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Desktop - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinSweeper 2.1 (HKLM-x32\...\{96E8A815-3053-4616-AAC2-865E6B1792F5}_is1) (Version: - Solvusoft Corporation) WinThruster (HKLM-x32\...\WinThruster) (Version: 1.16.8 - Solvusoft Corporation) <==== ACHTUNG WinThruster (Version: 1.16.8 - Solvusoft Corporation) Hidden <==== ACHTUNG World of Tanks Blitz (HKLM\...\Steam App 444200) (Version: - Wargaming Group Limited) XAMPP (HKLM-x32\...\xampp) (Version: 5.6.8-0 - Bitnami) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-844095808-1650209266-980683291-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Seb\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {191E8CED-5BA5-4EE3-8DC0-C8257FE2CFAA} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation) Task: {1DEFEEA4-B4A7-4654-BBD7-43AF718B4AC6} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => P:\Programme (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation) Task: {2EC4D652-1888-44F7-9811-C4959B854A6F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {3F31AB12-2BE3-4DFF-937D-C2512794E784} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {3F38DCD8-DF1E-490D-8D5D-E035AE143565} - System32\Tasks\WinThruster64-Seb-Notification => C:\Program Files\Solvusoft\WinThruster\Sync.exe [2015-10-11] (Solvusoft Corporation) <==== ACHTUNG Task: {441E0E52-EAB6-48E5-A1DA-174B77491E51} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) Task: {488F73BD-5AF1-494C-A38B-D7E98D4D25DB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {4B5F255F-761D-4D0E-8736-291C9C1BDEAF} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => Thunderbolt.exe Task: {5DE984B7-D648-47FD-873D-9E1AD1CD6116} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => Thunderbolt.exe Task: {6170758E-2D8B-46D3-80DD-B9DF43C95A4F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-02-19] (Microsoft Corporation) Task: {78C9ACF9-706C-4945-98D0-9025D9328ADA} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-03-18] (AVAST Software) Task: {7CE3E841-D7F1-4A12-B12E-E509E3A66685} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {7DF9EEC8-4310-4833-AA36-B112995760F5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-28] (AVAST Software) Task: {854BE4ED-D2D2-482F-9BD7-F54256C7F6E0} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService Task: {AE37F061-38D4-41F4-A0B6-3973F5FB378C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation) Task: {B7DDC233-D4A7-4663-9683-ECCC0A4402EF} - System32\Tasks\WinThruster64-Seb-Startup => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe [2015-10-11] (Solvusoft Corporation) <==== ACHTUNG Task: {B8021389-D6F2-4922-A95C-1A7D067E1A29} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {B9EA1437-FF91-46FB-B4BA-48F6D8B4211F} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation) Task: {C7E9D51D-8274-4306-AF9B-A94762348F9F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => tbtsvc.exe Task: {D8693F66-18EA-41CA-AD97-43AE1B96716B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {F672F9E7-4540-4C1E-A3FB-C403F543FE5F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\WinThruster64-Seb-Notification.job => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ACHTUNG Task: C:\Windows\Tasks\WinThruster64-Seb-Startup.job => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ACHTUNG ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-02-17 05:07 - 2016-12-15 12:37 - 00020208 _____ () C:\Windows\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll 2015-06-25 10:45 - 2015-06-25 10:45 - 00017920 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe 2016-10-29 09:20 - 2017-02-23 20:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-20 15:47 - 2017-03-17 01:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-02-21 23:09 - 2017-02-21 23:09 - 00052392 _____ () P:\Programme\FileZilla FTP Client\fzshellext_64.dll 2016-10-22 14:16 - 2016-11-06 03:45 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2017-03-18 17:45 - 2017-03-18 17:45 - 00162600 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00792656 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll 2017-03-23 11:40 - 2017-03-23 11:40 - 01850800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe 2015-05-14 03:30 - 2015-05-14 03:30 - 00419328 _____ () C:\Windows\System32\flvga_tray.exe 2017-03-18 17:45 - 2017-03-18 17:45 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-03-24 20:38 - 2017-03-24 20:38 - 05993232 _____ () C:\Program Files\AVAST Software\Avast\defs\17032400\algo.dll 2017-03-26 14:29 - 2017-03-26 14:29 - 05889024 _____ () C:\Program Files\AVAST Software\Avast\defs\17032500\algo.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00655056 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2015-02-17 01:47 - 2015-02-17 01:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\ycc.dll 2016-08-09 20:49 - 2016-08-09 20:49 - 01804800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\BDR_info.dll 2015-02-16 11:47 - 2015-02-16 11:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ycc.dll 2016-10-20 15:54 - 2017-03-10 02:13 - 00674592 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2016-10-20 15:54 - 2016-09-01 03:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2016-10-20 15:54 - 2016-09-01 03:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2016-10-20 15:54 - 2016-09-01 03:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2016-10-20 15:54 - 2017-03-23 02:52 - 02465056 _____ () C:\Program Files (x86)\Steam\video.dll 2016-10-20 15:54 - 2016-01-27 09:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2016-10-20 15:54 - 2016-01-27 09:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2016-10-20 15:54 - 2016-01-27 09:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2016-10-20 15:54 - 2016-01-27 09:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2016-10-20 15:54 - 2016-01-27 09:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2016-10-20 15:54 - 2017-03-23 02:52 - 00839456 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-01-03 00:52 - 2017-01-03 00:52 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00290352 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2016-12-13 01:51 - 2017-01-30 23:41 - 68875552 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2016-10-29 09:20 - 2017-02-23 16:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-10-29 09:20 - 2017-02-23 16:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-844095808-1650209266-980683291-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupfolder: C:^Users^Seb^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\Windows\pss\An OneNote senden.lnk.Startup MSCONFIG\startupreg: DAEMON Tools Lite Automount => "P:\Programme\DAEMON Tools Lite\DTAgent.exe" -autorun MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: Greenshot => P:\Programme\Greenshot\Greenshot.exe MSCONFIG\startupreg: OneDrive => "C:\Users\Seb\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background MSCONFIG\startupreg: Overwolf => "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent MSCONFIG\startupreg: PreRun => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe MSCONFIG\startupreg: TabletDriver => C:\PenTabletDriver\TabletDriver.exe -hide MSCONFIG\startupreg: VLC Updater => C:\Program Files (x86)\VLC Updater\vlc-updater.exe /silent /wait 120 ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{A10CC7B3-A9B5-4F11-82FC-EA049879F599}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3B00F960-5ECB-43CC-A3A2-A36319F1411A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{30D7E49E-0F69-4098-A6C2-5DE8C3E36D2F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{DF0C0933-6097-42DE-92C3-634C66053C8D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{025309DB-4622-48FD-8690-259B73868FA4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{49EB47F7-2720-486D-BCFE-B652E35E2CEB}P:\programme\xampp\mysql\bin\mysqld.exe] => (Allow) P:\programme\xampp\mysql\bin\mysqld.exe FirewallRules: [UDP Query User{A80F13D1-0DDD-4F2A-B2F5-3596883237D6}P:\programme\xampp\mysql\bin\mysqld.exe] => (Allow) P:\programme\xampp\mysql\bin\mysqld.exe FirewallRules: [TCP Query User{58E9547B-4248-41FC-AF92-A799505E3BF2}P:\programme\xampp\apache\bin\httpd.exe] => (Allow) P:\programme\xampp\apache\bin\httpd.exe FirewallRules: [UDP Query User{D58CCF67-AA2C-4394-A488-5929AF75125D}P:\programme\xampp\apache\bin\httpd.exe] => (Allow) P:\programme\xampp\apache\bin\httpd.exe FirewallRules: [{A9C76A59-4600-471F-A8F3-5142104993B2}] => (Allow) P:\Spiele\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{29865776-81A9-4671-9C8C-0492D6540215}] => (Allow) P:\Spiele\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{1E7893A6-0A1C-43A8-855B-E5203BD6D1F7}] => (Allow) P:\Spiele\steamapps\common\Fernbus Simulator\Fernbus\Binaries\Win64\Fernbus-Win64-Shipping.exe FirewallRules: [{A0D1C368-01E5-481F-88DC-51FA2AF6F56C}] => (Allow) P:\Spiele\steamapps\common\Fernbus Simulator\Fernbus\Binaries\Win64\Fernbus-Win64-Shipping.exe FirewallRules: [{137FB8DE-19D2-40F1-8109-5405D4D44676}] => (Allow) P:\Spiele\steamapps\common\Notruf 112\notruf112.exe FirewallRules: [{B2E82D54-FCE3-42C2-8B2B-EE3FD8509634}] => (Allow) P:\Spiele\steamapps\common\Notruf 112\notruf112.exe FirewallRules: [{2AF8C29B-BAFD-4D7A-B05C-613668D592C4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Leadwerks\Leadwerks.exe FirewallRules: [{EE2992BB-4C22-4A61-9DBF-71FF141D88CD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Leadwerks\Leadwerks.exe FirewallRules: [{284937F6-7548-4A08-B227-F09B85493C62}] => (Allow) P:\Spiele\steamapps\common\Bus Simulator 16\BusSimulator16.exe FirewallRules: [{60BA69DE-367E-4B3A-B80B-B7CD3C158409}] => (Allow) P:\Spiele\steamapps\common\Bus Simulator 16\BusSimulator16.exe FirewallRules: [{99E0B30A-D029-41C0-894B-1C90738A1E4C}] => (Allow) P:\Spiele\steamapps\common\Call of Duty - Infinite Warfare\iw7_ship.exe FirewallRules: [{9E08E97C-74CB-448C-8406-23840EF1481B}] => (Allow) P:\Spiele\steamapps\common\Call of Duty - Infinite Warfare\iw7_ship.exe FirewallRules: [{D7A9B9FB-C196-4830-9260-1BE2564B7030}] => (Allow) P:\Spiele\steamapps\common\Watch_Dogs2\bin\WatchDogs2.exe FirewallRules: [{48344851-6585-4A1C-B824-B0954BE5F7F8}] => (Allow) P:\Spiele\steamapps\common\Watch_Dogs2\bin\WatchDogs2.exe FirewallRules: [{65FA4CAF-880B-4683-ABFB-063410E18161}] => (Allow) LPort=5983 FirewallRules: [{CC64D449-FAAF-4853-A14B-5FC938CAB578}] => (Allow) LPort=5983 FirewallRules: [{9B8630F3-A76D-42E0-97AC-F386F6D9CDDC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{AE922F9C-CA26-49CB-9990-4B7C1285E9CB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{FDA63F36-A81E-4136-941E-3E853DB8996E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{9EE1D1E9-C08F-490E-9BB7-D4161012BB1A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [TCP Query User{8088952A-333C-4E86-BFC5-B76FFD7E3BD8}P:\spiele\steamapps\common\grand theft auto v\gta5.exe] => (Allow) P:\spiele\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [UDP Query User{C9D34529-4586-497C-BEC2-33AF6BF9500D}P:\spiele\steamapps\common\grand theft auto v\gta5.exe] => (Allow) P:\spiele\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [{76FEF2AC-B6D2-4D43-9602-FACE120CAA61}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\World of Tanks Blitz\wotblitz.exe FirewallRules: [{EE12DF65-2824-4A5B-8C01-387E12ADE0B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\World of Tanks Blitz\wotblitz.exe FirewallRules: [{05DA7D7D-90EB-495C-A04D-36F7663727C7}] => (Allow) P:\Spiele\steamapps\common\Demolish & Build Company\demolish.exe FirewallRules: [{93B96F0B-EBF7-4429-AF88-C6E1BCCB7F09}] => (Allow) P:\Spiele\steamapps\common\Demolish & Build Company\demolish.exe FirewallRules: [{6AA1A45C-474E-4401-AC82-4503903F9126}] => (Allow) P:\Spiele\steamapps\common\Farming Simulator 17\x64\FarmingSimulator2017Game.exe FirewallRules: [{813D99E5-70FE-48AE-81CE-C179DEEB3824}] => (Allow) P:\Spiele\steamapps\common\Farming Simulator 17\x64\FarmingSimulator2017Game.exe FirewallRules: [{1AE806AF-81A1-4AEE-9E61-AC13287BB230}] => (Allow) P:\Spiele\steamapps\common\Helicopter 2015 Natural Disasters\HelicopterND.exe FirewallRules: [{A8A1423B-03E0-4737-AA12-546995A2D9B4}] => (Allow) P:\Spiele\steamapps\common\Helicopter 2015 Natural Disasters\HelicopterND.exe FirewallRules: [{B45DD250-D70F-44F9-B872-14FD349E051A}] => (Allow) P:\Spiele\steamapps\common\Emergency 2017\bin\em5_launcher.exe FirewallRules: [{5116168F-CB5E-4007-A928-3A8AA3C82561}] => (Allow) P:\Spiele\steamapps\common\Emergency 2017\bin\em5_launcher.exe FirewallRules: [{9B77E314-4140-4384-85D0-4F111AB1B6A2}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{829CB733-76E5-4B65-9CA0-FBBAEADFB915}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{EE87FFB9-8862-45AB-9D35-390B355980D4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{33FA0CDD-A565-4691-867A-CD8C0B3665DF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{40178D82-D3A6-47DA-B37D-B77A862695B5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{C45C5AF7-3517-45C6-B889-EE795A230098}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{90ED472B-886B-40F5-A22C-4B5A8652D14F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{688A1FBA-BF9E-4AD0-A6B8-AB21A98B0988}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{D89BCCE2-7F0A-40A4-85BA-767CD48CBF43}] => (Allow) P:\Spiele\steamapps\common\F1 2016\F1_2016.exe FirewallRules: [{D137355A-7750-416C-A140-96B2C6D9DCF0}] => (Allow) P:\Spiele\steamapps\common\F1 2016\F1_2016.exe FirewallRules: [{F1105446-2D7A-457D-8EC8-47ED3C21F5F7}] => (Allow) P:\Spiele\steamapps\common\Motorsport Manager\MM.exe FirewallRules: [{82EA725A-9299-4BF3-B454-C2A692478DC3}] => (Allow) P:\Spiele\steamapps\common\Motorsport Manager\MM.exe FirewallRules: [{55A24567-54DC-4A64-B450-4261E8A5E7C2}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe FirewallRules: [{5706C27E-B721-46B6-820D-AC47B8FFBBD7}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe ==================== Wiederherstellungspunkte ========================= 21-03-2017 23:17:44 Installed Microsoft Server Speech Platform Runtime (x64) 21-03-2017 23:18:01 Installed Kinect for Windows Speech Recognition Language Pack (en-US) 21-03-2017 23:18:06 Installed Kinect for Windows Speech Recognition Language Pack (en-GB) 21-03-2017 23:18:15 Installed Kinect for Windows Speech Recognition Language Pack (en-CA) 21-03-2017 23:18:23 Installed Kinect for Windows Speech Recognition Language Pack (en-AU) 21-03-2017 23:18:30 Installed Kinect for Windows Speech Recognition Language Pack (de-DE) 21-03-2017 23:22:41 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 21-03-2017 23:42:54 WinThruster (64-bit) Backup 21-03-2017 23:44:58 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 21-03-2017 23:49:32 Windows Update 24-03-2017 11:12:01 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:33:29 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:43:10 WinThruster (64-bit) Backup 24-03-2017 20:43:57 Removed APP Center 24-03-2017 20:44:11 Installed APP Center 24-03-2017 20:44:44 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 21:07:32 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Netzwerkcontroller Description: Netzwerkcontroller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (03/26/2017 02:29:00 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/24/2017 09:15:21 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: KillerService.exe, Version: 1.1.57.1346, Zeitstempel: 0x56be4771 Name des fehlerhaften Moduls: KillerService.exe, Version: 1.1.57.1346, Zeitstempel: 0x56be4771 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000002d735 ID des fehlerhaften Prozesses: 0x8c8 Startzeit der fehlerhaften Anwendung: 0x01d2a4d258c2f1c5 Pfad der fehlerhaften Anwendung: C:\Program Files\Killer Networking\Network Manager\KillerService.exe Pfad des fehlerhaften Moduls: C:\Program Files\Killer Networking\Network Manager\KillerService.exe Berichtskennung: 39406cfa-10c6-11e7-ad5c-1c1b0d0b4a21 Error: (03/24/2017 09:11:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/24/2017 08:48:35 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/24/2017 08:43:08 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {6dd0f361-3b12-4fea-a45f-43eba28b96d1} Error: (03/24/2017 08:37:54 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/24/2017 11:21:30 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x86\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/24/2017 11:21:29 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x64\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/24/2017 11:19:57 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm\signtool.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Appx.AppxSip.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/24/2017 11:19:57 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\inspect.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\inspect.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Systemfehler: ============= Error: (03/26/2017 02:29:19 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/26/2017 02:29:00 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UsbCharger Error: (03/26/2017 02:28:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (03/26/2017 02:28:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht. Error: (03/24/2017 10:46:00 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/24/2017 10:44:36 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-19) für Benutzer NT-AUTORITÄT\LOKALER DIENST von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/24/2017 10:36:00 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/24/2017 10:34:36 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-19) für Benutzer NT-AUTORITÄT\LOKALER DIENST von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/24/2017 10:26:00 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/24/2017 10:24:36 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-19) für Benutzer NT-AUTORITÄT\LOKALER DIENST von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. CodeIntegrity: =================================== Date: 2016-12-02 18:49:24.791 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.766 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.741 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.716 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.691 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.665 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.639 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.614 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.589 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.553 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz Prozentuale Nutzung des RAM: 19% Installierter physikalischer RAM: 16333.03 MB Verfügbarer physikalischer RAM: 13123 MB Summe virtueller Speicher: 32664.25 MB Verfügbarer virtueller Speicher: 29149.32 MB ==================== Laufwerke ================================ Drive b: (Bilder) (Fixed) (Total:151.37 GB) (Free:65.28 GB) NTFS Drive c: (Windows) (Fixed) (Total:447.03 GB) (Free:130.11 GB) NTFS Drive e: (Filme) (Fixed) (Total:465.76 GB) (Free:344.71 GB) NTFS Drive m: (Musik) (Fixed) (Total:151.37 GB) (Free:145.56 GB) NTFS Drive p: (Programme) (Fixed) (Total:850 GB) (Free:139.57 GB) NTFS Drive v: (Videos) (Fixed) (Total:163.02 GB) (Free:138.82 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 447.1 GB) (Disk ID: 94D2A2C1) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=447 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0009AF56) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7BA18A71) Partition 1: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=163 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
26.03.2017, 14:04 | #5 |
| Windows 7: Malware blockiert Internetverbindungen TDSSkiller: Code:
ATTFilter 14:38:22.0606 0x134c TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01 14:38:25.0445 0x134c ============================================================ 14:38:25.0445 0x134c Current date / time: 2017/03/26 14:38:25.0445 14:38:25.0445 0x134c SystemInfo: 14:38:25.0445 0x134c 14:38:25.0445 0x134c OS Version: 6.1.7601 ServicePack: 1.0 14:38:25.0445 0x134c Product type: Workstation 14:38:25.0445 0x134c ComputerName: GAMING-PC 14:38:25.0445 0x134c UserName: Seb 14:38:25.0445 0x134c Windows directory: C:\Windows 14:38:25.0445 0x134c System windows directory: C:\Windows 14:38:25.0445 0x134c Running under WOW64 14:38:25.0445 0x134c Processor architecture: Intel x64 14:38:25.0445 0x134c Number of processors: 8 14:38:25.0445 0x134c Page size: 0x1000 14:38:25.0445 0x134c Boot type: Normal boot 14:38:25.0445 0x134c CodeIntegrityOptions = 0x00000001 14:38:25.0445 0x134c ============================================================ 14:38:25.0710 0x134c KLMD registered as C:\Windows\system32\drivers\90409892.sys 14:38:25.0710 0x134c KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.23677, osProperties = 0x1 14:38:25.0819 0x134c System UUID: {7E9EBB63-2490-1DBE-7EE2-DFEA7521A253} 14:38:26.0038 0x134c Drive \Device\Harddisk0\DR0 - Size: 0x6FC86D6000 ( 447.13 Gb ), SectorSize: 0x200, Cylinders: 0xE401, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:38:26.0069 0x134c Drive \Device\Harddisk1\DR1 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:38:26.0069 0x134c Drive \Device\Harddisk2\DR2 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:38:26.0085 0x134c Drive \Device\Harddisk3\DR3 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:38:26.0085 0x134c ============================================================ 14:38:26.0085 0x134c \Device\Harddisk0\DR0: 14:38:26.0085 0x134c MBR partitions: 14:38:26.0085 0x134c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 14:38:26.0085 0x134c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x37E10000 14:38:26.0085 0x134c \Device\Harddisk1\DR1: 14:38:26.0085 0x134c GPT partitions: 14:38:26.0085 0x134c \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {6F1E0242-97C4-11E6-8530-1C1B0D0B4A21}, Name: Microsoft reserved partition, StartLBA 0x22, BlocksNum 0x40000 14:38:26.0085 0x134c \Device\Harddisk1\DR1\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {4171C510-1217-42FC-A2EC-0E31EF3287E7}, Name: Basic data partition, StartLBA 0x40800, BlocksNum 0x6A400000 14:38:26.0085 0x134c MBR partitions: 14:38:26.0085 0x134c \Device\Harddisk2\DR2: 14:38:26.0085 0x134c MBR partitions: 14:38:26.0085 0x134c \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A384800 14:38:26.0085 0x134c \Device\Harddisk3\DR3: 14:38:26.0085 0x134c MBR partitions: 14:38:26.0085 0x134c \Device\Harddisk3\DR3\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12EBC000 14:38:26.0085 0x134c \Device\Harddisk3\DR3\Partition2: MBR, Type 0x7, StartLBA 0x12EBC800, BlocksNum 0x12EBC000 14:38:26.0085 0x134c \Device\Harddisk3\DR3\Partition3: MBR, Type 0x7, StartLBA 0x25D78800, BlocksNum 0x1460C800 14:38:26.0085 0x134c ============================================================ 14:38:26.0085 0x134c C: <-> \Device\Harddisk0\DR0\Partition2 14:38:30.0250 0x134c B: <-> \Device\Harddisk3\DR3\Partition1 14:38:33.0900 0x134c M: <-> \Device\Harddisk3\DR3\Partition2 14:38:35.0850 0x134c V: <-> \Device\Harddisk3\DR3\Partition3 14:38:35.0881 0x134c P: <-> \Device\Harddisk1\DR1\Partition2 14:38:35.0897 0x134c E: <-> \Device\Harddisk2\DR2\Partition1 14:38:35.0897 0x134c ============================================================ 14:38:35.0897 0x134c Initialize success 14:38:35.0897 0x134c ============================================================ 14:38:41.0778 0x13d8 ============================================================ 14:38:41.0778 0x13d8 Scan started 14:38:41.0778 0x13d8 Mode: Manual; SigCheck; TDLFS; 14:38:41.0778 0x13d8 ============================================================ 14:38:41.0778 0x13d8 KSN ping started 14:38:41.0903 0x13d8 KSN ping finished: true 14:38:51.0450 0x13d8 ================ Scan system memory ======================== 14:38:51.0450 0x13d8 System memory - ok 14:38:51.0450 0x13d8 ================ Scan services ============================= 14:38:51.0466 0x13d8 [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 14:38:51.0513 0x13d8 1394ohci - ok 14:38:51.0528 0x13d8 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys 14:38:51.0544 0x13d8 ACPI - ok 14:38:51.0544 0x13d8 [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 14:38:51.0559 0x13d8 AcpiPmi - ok 14:38:51.0575 0x13d8 [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 14:38:51.0591 0x13d8 adp94xx - ok 14:38:51.0606 0x13d8 [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\drivers\adpahci.sys 14:38:51.0622 0x13d8 adpahci - ok 14:38:51.0622 0x13d8 [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 14:38:51.0637 0x13d8 adpu320 - ok 14:38:51.0653 0x13d8 [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 14:38:51.0653 0x13d8 AeLookupSvc - ok 14:38:51.0669 0x13d8 [ 9A4A1EEE802BF2F878EE8EAB407B21B7, 177EB7DF4B35FE4C0E45E775A0FD5D48D39B410052E3EE18BDEEC809E152D9D8 ] AFD C:\Windows\system32\drivers\afd.sys 14:38:51.0684 0x13d8 AFD - ok 14:38:51.0700 0x13d8 [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys 14:38:51.0715 0x13d8 agp440 - ok 14:38:51.0715 0x13d8 [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe 14:38:51.0731 0x13d8 ALG - ok 14:38:51.0731 0x13d8 [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys 14:38:51.0747 0x13d8 aliide - ok 14:38:51.0747 0x13d8 [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys 14:38:51.0747 0x13d8 amdide - ok 14:38:51.0762 0x13d8 [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 14:38:51.0778 0x13d8 AmdK8 - ok 14:38:51.0778 0x13d8 [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 14:38:51.0793 0x13d8 AmdPPM - ok 14:38:51.0793 0x13d8 [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys 14:38:51.0809 0x13d8 amdsata - ok 14:38:51.0809 0x13d8 [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 14:38:51.0840 0x13d8 amdsbs - ok 14:38:51.0840 0x13d8 [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys 14:38:51.0856 0x13d8 amdxata - ok 14:38:51.0856 0x13d8 [ B84DDCCB03A9CEDC1E90A88EDA5306DB, 1E51A7336C7E3F6402ED90AB0B3E98FD3827E2DC51B133E7F8BB37140B315192 ] AppID C:\Windows\system32\drivers\appid.sys 14:38:51.0871 0x13d8 AppID - ok 14:38:51.0871 0x13d8 [ 02B60F8FA4BAB8DC3B14782A7E60564B, D7EB27CB202573734D7A4EB4667B9BCEC1598AA9EBD154F2C9266AF230F51A52 ] AppIDSvc C:\Windows\System32\appidsvc.dll 14:38:51.0871 0x13d8 AppIDSvc - ok 14:38:51.0887 0x13d8 [ DE23E052E557580674785CDF45B613F3, A955ADC6CC7D816BA7CE1065F911E7A3295A1908C22BE0A3C506C38CFEE8DE0D ] Appinfo C:\Windows\System32\appinfo.dll 14:38:51.0887 0x13d8 Appinfo - ok 14:38:51.0887 0x13d8 [ E4D0F0D5EB374D8BACF40E30E9771D60, 56C4E820485D100DACD4EF076E0B2607274B236CCC45E0CCD527C737645A1ACB ] AppleCharger C:\Windows\system32\DRIVERS\AppleCharger.sys 14:38:51.0903 0x13d8 AppleCharger - ok 14:38:51.0918 0x13d8 [ 95EF7247C50C7241FDAE39A9B3AFF4AE, 6E08FB095C04B2E217B139D6431336C0F24C128A2A83082A3085DC8C44AA247D ] AppleChargerSrv C:\Windows\system32\AppleChargerSrv.exe 14:38:51.0918 0x13d8 AppleChargerSrv - ok 14:38:51.0918 0x13d8 [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll 14:38:51.0934 0x13d8 AppMgmt - ok 14:38:51.0934 0x13d8 [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\drivers\arc.sys 14:38:51.0949 0x13d8 arc - ok 14:38:51.0949 0x13d8 [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\drivers\arcsas.sys 14:38:51.0965 0x13d8 arcsas - ok 14:38:51.0981 0x13d8 [ 070633D013447B4DA8D66B23B7BA1C3A, BD2AAFAB01551473729FA23FF5155798B0983FEBC0A64D1C7C30112FACA27988 ] asmthub3 C:\Windows\system32\DRIVERS\asmthub3.sys 14:38:51.0996 0x13d8 asmthub3 - ok 14:38:51.0996 0x13d8 [ AD0476BF351586C2B82509FBD4890A59, 409782A9263B33E0615A5CA7904424ACAB9BCB7EC883CDB873224E147119CA15 ] asmtxhci C:\Windows\system32\DRIVERS\asmtxhci.sys 14:38:52.0027 0x13d8 asmtxhci - ok 14:38:52.0027 0x13d8 [ EE424A5CE56E3923D59BB7DE2E15036D, 8B8196870EFE74D43EDA72674021A46846D370E97A6A058134D84A721AECD091 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 14:38:52.0043 0x13d8 aspnet_state - ok 14:38:52.0137 0x13d8 [ 57846C1D03BAF2F67848125339A7CEB6, 73FFD9B09641AE0506BBF5B8FEFE10C94E941CF1F101F6AAA8B7015CA4124C87 ] aswbIDSAgent C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe 14:38:52.0230 0x13d8 aswbIDSAgent - ok 14:38:52.0246 0x13d8 [ 1E6E1DA4A13081B54908E04B4BDBA55B, 9DFF229FB9B622DA90D7D6DEA12AB04ADAD1484C9A2C86225B77EEE6532A4CA8 ] aswbidsdriver C:\Windows\system32\drivers\aswbidsdrivera.sys 14:38:52.0261 0x13d8 aswbidsdriver - ok 14:38:52.0261 0x13d8 [ A90FA5233DF055BBD5154E09DDACC5A3, ECF7DD9D919A821AFFE4BEC372A1F2528180D3D327A737A93310EE48B6EBA6B1 ] aswbidsh C:\Windows\system32\drivers\aswbidsha.sys 14:38:52.0277 0x13d8 aswbidsh - ok 14:38:52.0293 0x13d8 [ 750DDA2A28B1886492527F2D864FDE72, 4E6E2D9AEF36C32CA2A2EB90857BD33BD9E63E44D343E4F43F93C40CA47AEDAF ] aswblog C:\Windows\system32\drivers\aswbloga.sys 14:38:52.0308 0x13d8 aswblog - ok 14:38:52.0308 0x13d8 [ ED1492AFADFE425CB31FA789F3B5159F, 2630D29C9D90166C9A8A2E683E7154A6E311FE4F3BFF072B7EE2D65842CA3C65 ] aswbuniv C:\Windows\system32\drivers\aswbuniva.sys 14:38:52.0308 0x13d8 aswbuniv - ok 14:38:52.0324 0x13d8 [ 6633C8097F993B47D2464A634F87F8F4, 1FCE4BFB2C1A9F86B5E407C9D33F486F8DD96AD3A7D0C201F23D83D05C41207D ] aswHwid C:\Windows\system32\drivers\aswHwid.sys 14:38:52.0339 0x13d8 aswHwid - ok 14:38:52.0339 0x13d8 [ 0ACB1ED63E538AB0CF3E85FF9FE2E957, 50C7B383CA4F2E18EAD53F29B681EB9222DAF16915EF6997B31AC5C47889C267 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys 14:38:52.0355 0x13d8 aswMonFlt - ok 14:38:52.0355 0x13d8 [ 4815CA800288A3C1CC35F4FDF8FDB2C1, CC12BC09437102F33D7A1FEE0B4446347FBAF166BB9ECD32716B122F8CE48781 ] aswRdr C:\Windows\system32\drivers\aswRdr2.sys 14:38:52.0371 0x13d8 aswRdr - ok 14:38:52.0371 0x13d8 [ FF4B137482DC270AF9DC406B4A1010C7, 2AF0DE4D07A0E8A45F71E048668FE93CABE2B861DBDE9C13668C1F7664D061CF ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys 14:38:52.0386 0x13d8 aswRvrt - ok 14:38:52.0402 0x13d8 [ 298827113E361F2EE68E7824BF59876F, B6B8216EF43BC5F5F65265CB41C4C094335C4ACE7C786F345AC3C141448F7441 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys 14:38:52.0433 0x13d8 aswSnx - ok 14:38:52.0449 0x13d8 [ CE3E83DD3C90F0679C43EC8CEB6AC326, C34180996BAD650E39F5FCF3D90DF5B87561A2A41468631C1DD6FA23B996F1E3 ] aswSP C:\Windows\system32\drivers\aswSP.sys 14:38:52.0480 0x13d8 aswSP - ok 14:38:52.0480 0x13d8 [ C4DF85748415EC924321616A0F48F62C, 5ED37AEA539EBF0D2D0E2E2EE1500454A38017CDD660038AEBE7D388ADAE2D94 ] aswStm C:\Windows\system32\drivers\aswStm.sys 14:38:52.0495 0x13d8 aswStm - ok 14:38:52.0495 0x13d8 [ 04817CE38098FBC16D3A925FCD3FE4A6, 9050932D439889B1A044CCCF5941A4175F8E7B36C0B5724753FDB27E3F101BDE ] aswVmm C:\Windows\system32\drivers\aswVmm.sys 14:38:52.0527 0x13d8 aswVmm - ok 14:38:52.0527 0x13d8 [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 14:38:52.0542 0x13d8 AsyncMac - ok 14:38:52.0558 0x13d8 [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys 14:38:52.0558 0x13d8 atapi - ok 14:38:52.0573 0x13d8 [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 14:38:52.0589 0x13d8 AudioEndpointBuilder - ok 14:38:52.0605 0x13d8 [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioSrv C:\Windows\System32\Audiosrv.dll 14:38:52.0620 0x13d8 AudioSrv - ok 14:38:52.0636 0x13d8 [ A554C77C38A97D230830AAAD0A202BB7, E17B4921E84BE4F37F2E5C93869C628102FC471DF2CE12BF0B60EF951D52E14E ] ausb3hub C:\Windows\system32\DRIVERS\ausb3hub.sys 14:38:52.0651 0x13d8 ausb3hub - ok 14:38:52.0667 0x13d8 [ 4AD52D3D2FB2BC73E2611ACECAAEC07B, B39EFB576EBC1CC1F334A7A3B21F66BCBE0D2F3CDD738E2EE8A91E6537ED83ED ] ausb3xhc C:\Windows\system32\DRIVERS\ausb3xhc.sys 14:38:52.0698 0x13d8 ausb3xhc - ok 14:38:52.0714 0x13d8 [ 5258A3572C59D8CAA4D5FDD9EF13674E, 454C26709EFF8ECEE2587CEAB5B5246064E40FAC984460B8B886D46745CAEA97 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 14:38:52.0714 0x13d8 avast! Antivirus - ok 14:38:52.0729 0x13d8 [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll 14:38:52.0729 0x13d8 AxInstSV - ok 14:38:52.0745 0x13d8 [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 14:38:52.0776 0x13d8 b06bdrv - ok 14:38:52.0776 0x13d8 [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 14:38:52.0792 0x13d8 b57nd60a - ok 14:38:52.0901 0x13d8 [ 1D4F8EE6DDCE14FF9A9B85D1EAE55336, CA6BB38B9F0AD94F99942D670E605385D1E9BCC7AB94CA131A83007617FD9FF6 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys 14:38:53.0041 0x13d8 BCM43XX - ok 14:38:53.0057 0x13d8 [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll 14:38:53.0057 0x13d8 BDESVC - ok 14:38:53.0057 0x13d8 [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys 14:38:53.0088 0x13d8 Beep - ok 14:38:53.0104 0x13d8 [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll 14:38:53.0119 0x13d8 BFE - ok 14:38:53.0119 0x13d8 [ 4CA7F8901C0BAB4BE8AB6C78D243E374, 20ED556E5E0B1108ED991300C70C7C487F276FF560C5D7ABA7AF281E36841DA5 ] BfLwf C:\Windows\system32\DRIVERS\bflwfx64.sys 14:38:53.0135 0x13d8 BfLwf - ok 14:38:53.0151 0x13d8 [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll 14:38:53.0182 0x13d8 BITS - ok 14:38:53.0182 0x13d8 [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 14:38:53.0197 0x13d8 blbdrive - ok 14:38:53.0213 0x13d8 [ ABA3984C822E4D3F889699912D85D6C5, 2251FA135CC290DA13DAE4743F393C7CC9E6A737C054707CB8D72C369D1FFACB ] bowser C:\Windows\system32\DRIVERS\bowser.sys 14:38:53.0229 0x13d8 bowser - ok 14:38:53.0229 0x13d8 [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 14:38:53.0244 0x13d8 BrFiltLo - ok 14:38:53.0244 0x13d8 [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 14:38:53.0260 0x13d8 BrFiltUp - ok 14:38:53.0260 0x13d8 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll 14:38:53.0275 0x13d8 Browser - ok 14:38:53.0275 0x13d8 [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys 14:38:53.0307 0x13d8 Brserid - ok 14:38:53.0307 0x13d8 [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 14:38:53.0322 0x13d8 BrSerWdm - ok 14:38:53.0322 0x13d8 [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 14:38:53.0338 0x13d8 BrUsbMdm - ok 14:38:53.0338 0x13d8 [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 14:38:53.0353 0x13d8 BrUsbSer - ok 14:38:53.0369 0x13d8 [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 14:38:53.0385 0x13d8 BTHMODEM - ok 14:38:53.0385 0x13d8 [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll 14:38:53.0400 0x13d8 bthserv - ok 14:38:53.0400 0x13d8 [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 14:38:53.0431 0x13d8 cdfs - ok 14:38:53.0431 0x13d8 [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 14:38:53.0447 0x13d8 cdrom - ok 14:38:53.0463 0x13d8 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll 14:38:53.0478 0x13d8 CertPropSvc - ok 14:38:53.0478 0x13d8 [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\drivers\circlass.sys 14:38:53.0494 0x13d8 circlass - ok 14:38:53.0509 0x13d8 [ 3D67C27DD17B254D7915FA16A5AE3573, 5B3A6C6A7F940C06362775DAF13CEADA37C7AA84A509458A57C23B4369970A90 ] CLFS C:\Windows\system32\CLFS.sys 14:38:53.0525 0x13d8 CLFS - ok 14:38:53.0587 0x13d8 [ CB6AC02C92BBA30187EA4591D771660E, B3BB15DC814F131672D864CAAD1537933EE83C9029DF143E5E105077EA4D7F30 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe 14:38:53.0650 0x13d8 ClickToRunSvc - ok 14:38:53.0650 0x13d8 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 14:38:53.0665 0x13d8 clr_optimization_v2.0.50727_32 - ok 14:38:53.0665 0x13d8 [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 14:38:53.0665 0x13d8 clr_optimization_v2.0.50727_64 - ok 14:38:53.0681 0x13d8 [ 5BAF4F1296D4D91FC28560CDB4C37C4B, ACA4BC57ED1F8432F18F0F215EC7FF956BAEF6E02760779E264E4008A979E9DD ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 14:38:53.0681 0x13d8 clr_optimization_v4.0.30319_32 - ok 14:38:53.0697 0x13d8 [ 569B54004A7E85A74FD92841DE6058E2, 58949313D0F6B1C06359B2F3C68E29940B1655A17E93FFC3718F6D2EAE1633E4 ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 14:38:53.0697 0x13d8 clr_optimization_v4.0.30319_64 - ok 14:38:53.0697 0x13d8 [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 14:38:53.0712 0x13d8 CmBatt - ok 14:38:53.0728 0x13d8 [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys 14:38:53.0728 0x13d8 cmdide - ok 14:38:53.0743 0x13d8 [ A98CED39AD91B445E2E442A9BD67E8B4, B4189DEEF1C0EE22AE983119047B1A40FFDD8F3E163DFFABD7C2706231B0B1B0 ] CNG C:\Windows\system32\Drivers\cng.sys 14:38:53.0759 0x13d8 CNG - ok 14:38:53.0759 0x13d8 [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 14:38:53.0775 0x13d8 Compbatt - ok 14:38:53.0775 0x13d8 [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 14:38:53.0790 0x13d8 CompositeBus - ok 14:38:53.0806 0x13d8 COMSysApp - ok 14:38:53.0806 0x13d8 [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 14:38:53.0821 0x13d8 crcdisk - ok 14:38:53.0821 0x13d8 [ 2C6632CECFDBBE793FDA8AF9CA55A9CC, 335188515F798483660E529204A13012E4D21B0ECA489224A11C26F91A5B3CCE ] CryptSvc C:\Windows\system32\cryptsvc.dll 14:38:53.0837 0x13d8 CryptSvc - ok 14:38:53.0837 0x13d8 [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys 14:38:53.0868 0x13d8 CSC - ok 14:38:53.0884 0x13d8 [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll 14:38:53.0899 0x13d8 CscService - ok 14:38:53.0899 0x13d8 [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] DcomLaunch C:\Windows\system32\rpcss.dll 14:38:53.0915 0x13d8 DcomLaunch - ok 14:38:53.0931 0x13d8 [ A57E787455A72E3087AFF1B175A023F9, 9AD3B50B170E2BE8389744C97F621DAC7EB1B17C3ABC722B5A842FC5C50C75B0 ] ddkmd C:\Windows\system32\drivers\ddkmd.sys 14:38:53.0946 0x13d8 ddkmd - detected UnsignedFile.Multi.Generic ( 1 ) 14:38:54.0960 0x13d8 Detect skipped due to KSN trusted 14:38:54.0960 0x13d8 ddkmd - ok 14:38:54.0960 0x13d8 [ 00D06397CBDAD9044980A79487CED015, 2BA4F76BBBE2DEAE85BE225CE773592C039C5C63ECD4EF483EB67547D2AAD27F ] ddkmdldr C:\Windows\system32\drivers\ddkmdldr.sys 14:38:54.0976 0x13d8 ddkmdldr - detected UnsignedFile.Multi.Generic ( 1 ) 14:38:56.0005 0x13d8 Detect skipped due to KSN trusted 14:38:56.0005 0x13d8 ddkmdldr - ok 14:38:56.0068 0x13d8 [ AF4CB84DCCF1C5F01E51308D46071F83, EECB016464CFF7B218CA1A8CD11E108D7F3EA3759F64C9AF085DEBBEF9FA25D3 ] ddmgr C:\Windows\system32\ddmgr.exe 14:38:56.0099 0x13d8 ddmgr - ok 14:38:56.0115 0x13d8 [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll 14:38:56.0130 0x13d8 defragsvc - ok 14:38:56.0146 0x13d8 [ 9B38580063D281A99E68EF5813022A5F, D91676B0E0A8E2A090E3E5DD340ABCFC20AE0F55B4C82869D6CFB34239BD27DA ] DfsC C:\Windows\system32\Drivers\dfsc.sys 14:38:56.0161 0x13d8 DfsC - ok 14:38:56.0161 0x13d8 [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys 14:38:56.0177 0x13d8 dg_ssudbus - ok 14:38:56.0193 0x13d8 [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll 14:38:56.0193 0x13d8 Dhcp - ok 14:38:56.0224 0x13d8 [ EE9954237F15BE4DD9304D12E4D305ED, F295C9BAF20F0E669B673AFCC16B4969EE31B6A3808980DAB93D9B0F167DA3C0 ] DiagTrack C:\Windows\system32\diagtrack.dll 14:38:56.0239 0x13d8 DiagTrack - ok 14:38:56.0364 0x13d8 [ B8BE3CE91E2E47AF54BAC4B2D2AAA4DD, AF64EE4F8B6CB49A9CADC6D0F3DECB2973F3A187DC9B57C2FF43FA68A5CBBA18 ] Disc Soft Lite Bus Service P:\Programme\DAEMON Tools Lite\DiscSoftBusServiceLite.exe 14:38:56.0395 0x13d8 Disc Soft Lite Bus Service - ok 14:38:56.0395 0x13d8 [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys 14:38:56.0427 0x13d8 discache - ok 14:38:56.0427 0x13d8 [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk C:\Windows\system32\drivers\disk.sys 14:38:56.0442 0x13d8 Disk - ok 14:38:56.0442 0x13d8 [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys 14:38:56.0489 0x13d8 dmvsc - ok 14:38:56.0489 0x13d8 [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll 14:38:56.0505 0x13d8 Dnscache - ok 14:38:56.0505 0x13d8 [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll 14:38:56.0520 0x13d8 dot3svc - ok 14:38:56.0536 0x13d8 [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll 14:38:56.0551 0x13d8 DPS - ok 14:38:56.0551 0x13d8 [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 14:38:56.0567 0x13d8 drmkaud - ok 14:38:56.0567 0x13d8 [ 679FF716052109392D870F6A6C4A3535, BEF1784448CCA4AF1D67ED68BD0C7CFE01A7719E98CACF92C2DCBFAA916DC57E ] dtlitescsibus C:\Windows\system32\DRIVERS\dtlitescsibus.sys 14:38:56.0583 0x13d8 dtlitescsibus - ok 14:38:56.0583 0x13d8 [ E23FDD696839A4790682CA66C48D3F2F, F5F0721BDA751968224E52E75D0C309A3E084C430CD98E85A55AF622D16B9A44 ] dtliteusbbus C:\Windows\system32\DRIVERS\dtliteusbbus.sys 14:38:56.0598 0x13d8 dtliteusbbus - ok 14:38:56.0614 0x13d8 [ 3A9D7D464BDB3B70D7ECF689ADABBD4D, B4F5B23705EA1BA453FE30791CA245E1A5F7FBEABAD026E4A8A15A9FC44E8C9C ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 14:38:56.0645 0x13d8 DXGKrnl - ok 14:38:56.0645 0x13d8 [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll 14:38:56.0661 0x13d8 EapHost - ok 14:38:56.0676 0x13d8 EasyAntiCheat - ok 14:38:56.0676 0x13d8 [ E1F3D009D191031E4E3A762B2A19FCDB, 8B8DB4223026BA6D8A06798CB3E26DC26F89C69F94749F30AB013CA9A3A7F0F8 ] EasyTuneEngineService C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe 14:38:56.0676 0x13d8 EasyTuneEngineService - ok 14:38:56.0739 0x13d8 [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\drivers\evbda.sys 14:38:56.0770 0x13d8 ebdrv - ok 14:38:56.0785 0x13d8 [ CA69E856332E2D85294665F6B7E97254, A9693F836907FB0154DC1090D9476F1E9242ABE922D932D74D0385772D2EAB65 ] EFS C:\Windows\System32\lsass.exe 14:38:56.0785 0x13d8 EFS - ok 14:38:56.0801 0x13d8 [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 14:38:56.0817 0x13d8 ehRecvr - ok 14:38:56.0817 0x13d8 [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe 14:38:56.0832 0x13d8 ehSched - ok 14:38:56.0910 0x13d8 [ 9DF468D8CCE3B3BD200CFB31E9EA17BB, D2700E2ACB034E8698E81526E7470E265E1F791503ED528E66ED0BB574CA6FFA ] ElfoService P:\Programme\ElsterFormular Update Service\bin\ElfoService.exe 14:38:56.0941 0x13d8 ElfoService - ok 14:38:56.0957 0x13d8 [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\drivers\elxstor.sys 14:38:56.0973 0x13d8 elxstor - ok 14:38:56.0973 0x13d8 [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys 14:38:56.0988 0x13d8 ErrDev - ok 14:38:57.0004 0x13d8 [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll 14:38:57.0019 0x13d8 EventSystem - ok 14:38:57.0035 0x13d8 [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys 14:38:57.0066 0x13d8 exfat - ok 14:38:57.0066 0x13d8 [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys 14:38:57.0097 0x13d8 fastfat - ok 14:38:57.0097 0x13d8 [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\drivers\fdc.sys 14:38:57.0113 0x13d8 fdc - ok 14:38:57.0113 0x13d8 [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll 14:38:57.0129 0x13d8 fdPHost - ok 14:38:57.0144 0x13d8 [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll 14:38:57.0160 0x13d8 FDResPub - ok 14:38:57.0160 0x13d8 [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 14:38:57.0175 0x13d8 FileInfo - ok 14:38:57.0175 0x13d8 [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 14:38:57.0207 0x13d8 Filetrace - ok 14:38:57.0207 0x13d8 [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 14:38:57.0222 0x13d8 flpydisk - ok 14:38:57.0222 0x13d8 [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 14:38:57.0238 0x13d8 FltMgr - ok 14:38:57.0238 0x13d8 [ 02078FE34845A8C69BA10408C21473A2, 5C8135034B3376ADC6187E8069712335BD8D9FF8DE5CF948207CDC479C72649B ] FLxHCIv C:\Windows\system32\Drivers\FLxHCIv.sys 14:38:57.0253 0x13d8 FLxHCIv - ok 14:38:57.0269 0x13d8 [ CF0108CBA6D1860563BA20E3D74C6646, 737B5E89A858D7E3AEC8BF660AA4FCC56501A69468EA143531286016AF7C0B33 ] FontCache C:\Windows\system32\FntCache.dll 14:38:57.0285 0x13d8 FontCache - ok 14:38:57.0300 0x13d8 [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 14:38:57.0300 0x13d8 FontCache3.0.0.0 - ok 14:38:57.0300 0x13d8 [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 14:38:57.0316 0x13d8 FsDepends - ok 14:38:57.0316 0x13d8 [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 14:38:57.0331 0x13d8 Fs_Rec - ok 14:38:57.0331 0x13d8 [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 14:38:57.0347 0x13d8 fvevol - ok 14:38:57.0363 0x13d8 [ 9777CE1847281E82CD4B03EAB528803B, EDDF98A41D0125FE8CD78B231A31E4182A1F11C24E0E9958FF715EBEBEEE6B9E ] gadjservice C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe 14:38:57.0363 0x13d8 gadjservice - detected UnsignedFile.Multi.Generic ( 1 ) 14:38:57.0784 0x13d8 Detect skipped due to KSN trusted 14:38:57.0784 0x13d8 gadjservice - ok 14:38:57.0799 0x13d8 [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 14:38:57.0815 0x13d8 gagp30kx - ok 14:38:57.0815 0x13d8 [ 9AB9F3B75A2EB87FAFB1B7361BE9DFB3, 31F4CFB4C71DA44120752721103A16512444C13C2AC2D857A7E6F13CB679B427 ] gdrv C:\Windows\gdrv.sys 14:38:57.0831 0x13d8 gdrv - ok 14:38:57.0846 0x13d8 [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc C:\Windows\System32\gpsvc.dll 14:38:57.0862 0x13d8 gpsvc - ok 14:38:57.0862 0x13d8 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 14:38:57.0877 0x13d8 gupdate - ok 14:38:57.0877 0x13d8 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 14:38:57.0893 0x13d8 gupdatem - ok 14:38:57.0893 0x13d8 [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 14:38:57.0909 0x13d8 hcw85cir - ok 14:38:57.0909 0x13d8 [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 14:38:57.0940 0x13d8 HdAudAddService - ok 14:38:57.0940 0x13d8 [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 14:38:57.0955 0x13d8 HDAudBus - ok 14:38:57.0955 0x13d8 [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 14:38:57.0971 0x13d8 HidBatt - ok 14:38:57.0971 0x13d8 [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\drivers\hidbth.sys 14:38:57.0987 0x13d8 HidBth - ok 14:38:57.0987 0x13d8 [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\drivers\hidir.sys 14:38:58.0002 0x13d8 HidIr - ok 14:38:58.0018 0x13d8 [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll 14:38:58.0033 0x13d8 hidserv - ok 14:38:58.0033 0x13d8 [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 14:38:58.0049 0x13d8 HidUsb - ok 14:38:58.0049 0x13d8 [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll 14:38:58.0065 0x13d8 hkmsvc - ok 14:38:58.0065 0x13d8 [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 14:38:58.0080 0x13d8 HomeGroupListener - ok 14:38:58.0080 0x13d8 [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 14:38:58.0096 0x13d8 HomeGroupProvider - ok 14:38:58.0096 0x13d8 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 14:38:58.0111 0x13d8 HpSAMD - ok 14:38:58.0127 0x13d8 [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP C:\Windows\system32\drivers\HTTP.sys 14:38:58.0158 0x13d8 HTTP - ok 14:38:58.0158 0x13d8 [ D03F34DB640F5282B3698E7BCB878EC7, ACFE2F97D3FC01091F34831AF66F3135091053CA30660EF7C6ADC187A823F8BE ] HwmRecordService C:\Program Files (x86)\GIGABYTE\SIV\HwmRecordService.exe 14:38:58.0174 0x13d8 HwmRecordService - ok 14:38:58.0174 0x13d8 [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 14:38:58.0174 0x13d8 hwpolicy - ok 14:38:58.0189 0x13d8 [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 14:38:58.0205 0x13d8 i8042prt - ok 14:38:58.0221 0x13d8 [ 5C9AAE902452EF47D8C9EA5838E666B9, 9171558EE78B555312FD8D99EDF85849A4CDE87142EB91DB9E8AF92A1DDF664E ] iaStorA C:\Windows\system32\DRIVERS\iaStorA.sys 14:38:58.0252 0x13d8 iaStorA - ok 14:38:58.0252 0x13d8 [ 31BD488EE7F6ED608A7418F6A7C6948D, BB7DC889C0F73FDE089FC0E52D321F29CBB5A65A3D9F90B0B3A730EF938B6178 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 14:38:58.0252 0x13d8 IAStorDataMgrSvc - ok 14:38:58.0267 0x13d8 [ 1B15BCA5D82C0A928936EAC536ECA719, ACAD9D46929E6D0B520B7691FA2A3939134A00DFDB6AB8ABC09C619B75322ED7 ] iaStorF C:\Windows\system32\DRIVERS\iaStorF.sys 14:38:58.0267 0x13d8 iaStorF - ok 14:38:58.0283 0x13d8 [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 14:38:58.0299 0x13d8 iaStorV - ok 14:38:58.0314 0x13d8 [ E54BFAB1679CCFBE2C28AD18BE9D0E5F, DAFFCFEBDADEE43FE657FFFFCFADA2F7AE62FCB29915540F620FDC0041A99CD1 ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe 14:38:58.0314 0x13d8 ICCS - ok 14:38:58.0330 0x13d8 [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 14:38:58.0345 0x13d8 idsvc - ok 14:38:58.0345 0x13d8 IEEtwCollectorService - ok 14:38:58.0361 0x13d8 [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\drivers\iirsp.sys 14:38:58.0361 0x13d8 iirsp - ok 14:38:58.0377 0x13d8 [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll 14:38:58.0392 0x13d8 IKEEXT - ok 14:38:58.0486 0x13d8 [ 0D378E0EC4009E954FB1A358514CE99E, 05B36FCFFBCB01DBD01096B3E72F2AEBCEF91C99EF2AA4DB17EBECC33A1CA0B7 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 14:38:58.0548 0x13d8 IntcAzAudAddService - ok 14:38:58.0548 0x13d8 [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys 14:38:58.0564 0x13d8 intelide - ok 14:38:58.0564 0x13d8 [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 14:38:58.0579 0x13d8 intelppm - ok 14:38:58.0595 0x13d8 [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll 14:38:58.0611 0x13d8 IPBusEnum - ok 14:38:58.0611 0x13d8 [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 14:38:58.0642 0x13d8 IpFilterDriver - ok 14:38:58.0642 0x13d8 [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 14:38:58.0657 0x13d8 iphlpsvc - ok 14:38:58.0657 0x13d8 [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 14:38:58.0673 0x13d8 IPMIDRV - ok 14:38:58.0689 0x13d8 [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys 14:38:58.0704 0x13d8 IPNAT - ok 14:38:58.0720 0x13d8 [ 45F14ACEA013C63A070AC5DB19677620, F60D48E7456800E311B2B7FABB3C03919D47971230C743A118982FDE07E04847 ] IpOverUsbSvc C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe 14:38:58.0720 0x13d8 IpOverUsbSvc - ok 14:38:58.0720 0x13d8 [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys 14:38:58.0735 0x13d8 IRENUM - ok 14:38:58.0735 0x13d8 [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys 14:38:58.0751 0x13d8 isapnp - ok 14:38:58.0767 0x13d8 [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 14:38:58.0782 0x13d8 iScsiPrt - ok 14:38:58.0782 0x13d8 [ 08D6B150D817A16D78A7F24CBE96639B, 1ED41F98908B01A0B4971BA0A3F56562CBB0D7068243A2959581694F6AD64F56 ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys 14:38:58.0813 0x13d8 iusb3hub - ok 14:38:58.0829 0x13d8 [ A747E5F7B68E92D1C356903C9A2C34CE, 486FB46DAAECBDB9C136F5E23679153198DFCDB2EC80F7284100CA83D066BC4C ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys 14:38:58.0860 0x13d8 iusb3xhc - ok 14:38:58.0860 0x13d8 [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 14:38:58.0876 0x13d8 kbdclass - ok 14:38:58.0876 0x13d8 [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 14:38:58.0891 0x13d8 kbdhid - ok 14:38:58.0891 0x13d8 [ CA69E856332E2D85294665F6B7E97254, A9693F836907FB0154DC1090D9476F1E9242ABE922D932D74D0385772D2EAB65 ] KeyIso C:\Windows\system32\lsass.exe 14:38:58.0907 0x13d8 KeyIso - ok 14:38:58.0907 0x13d8 [ EFCD2E046C53F0F2F0838C576E2E1399, E340B6CE96E033E516607CCF2C0B137F4A6D8ABBD55D4A388DF12C46E77406D4 ] Killer Service V2 C:\Program Files\Killer Networking\Network Manager\KillerService.exe 14:38:58.0923 0x13d8 Killer Service V2 - ok 14:38:58.0923 0x13d8 [ 54C215C39E5735E6F7B7975143FC7D14, E2007654C30401A00D9349E99483A23A5A767A5BA0C0A5944609F7F172B52A6F ] KillerEth C:\Windows\system32\DRIVERS\e2xw7x64.sys 14:38:58.0938 0x13d8 KillerEth - ok 14:38:58.0938 0x13d8 [ 3AAA10BAF3F194F7CD34F4C78F8222EE, 25AE0B764748B13C7F093966E228D506072E270379A5E751F1ED619DEFB40814 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 14:38:58.0954 0x13d8 KSecDD - ok 14:38:58.0954 0x13d8 [ 7B7C28D4E71E4A4365F2B7528DA619F8, 0A507468C6A49870F794F28FF274643FE8FD238A3A9BE86C8656882F237DE77B ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 14:38:58.0969 0x13d8 KSecPkg - ok 14:38:58.0969 0x13d8 [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 14:38:59.0001 0x13d8 ksthunk - ok 14:38:59.0001 0x13d8 [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll 14:38:59.0032 0x13d8 KtmRm - ok 14:38:59.0032 0x13d8 [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll 14:38:59.0063 0x13d8 LanmanServer - ok 14:38:59.0063 0x13d8 [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 14:38:59.0079 0x13d8 LanmanWorkstation - ok 14:38:59.0079 0x13d8 [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 14:38:59.0110 0x13d8 lltdio - ok 14:38:59.0110 0x13d8 [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll 14:38:59.0141 0x13d8 lltdsvc - ok 14:38:59.0141 0x13d8 [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll 14:38:59.0157 0x13d8 lmhosts - ok 14:38:59.0157 0x13d8 [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 14:38:59.0172 0x13d8 LSI_FC - ok 14:38:59.0172 0x13d8 [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 14:38:59.0188 0x13d8 LSI_SAS - ok 14:38:59.0203 0x13d8 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 14:38:59.0203 0x13d8 LSI_SAS2 - ok 14:38:59.0219 0x13d8 [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 14:38:59.0235 0x13d8 LSI_SCSI - ok 14:38:59.0235 0x13d8 [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys 14:38:59.0250 0x13d8 luafv - ok 14:38:59.0266 0x13d8 [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 14:38:59.0266 0x13d8 Mcx2Svc - ok 14:38:59.0266 0x13d8 [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\drivers\megasas.sys 14:38:59.0281 0x13d8 megasas - ok 14:38:59.0297 0x13d8 [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 14:38:59.0313 0x13d8 MegaSR - ok 14:38:59.0313 0x13d8 [ 124B5296DF58E1F0ED3E9122431B136D, 4158BE66A9DED8555FD62844EDE908B7B5C64DEDA55B32BFC8BDE3534B0ABA91 ] MEIx64 C:\Windows\system32\DRIVERS\TeeDriverx64.sys 14:38:59.0328 0x13d8 MEIx64 - ok 14:38:59.0328 0x13d8 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll 14:38:59.0344 0x13d8 MMCSS - ok 14:38:59.0344 0x13d8 [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys 14:38:59.0375 0x13d8 Modem - ok 14:38:59.0375 0x13d8 [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 14:38:59.0391 0x13d8 monitor - ok 14:38:59.0391 0x13d8 [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 14:38:59.0406 0x13d8 mouclass - ok 14:38:59.0406 0x13d8 [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 14:38:59.0422 0x13d8 mouhid - ok 14:38:59.0422 0x13d8 [ 8ADB5445B29941CB41AF2846FD5C93C7, 689582430FE29EC0845B1DB841D3CC49D5D09DE264586E3999EEFE616986D12B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 14:38:59.0437 0x13d8 mountmgr - ok 14:38:59.0453 0x13d8 [ 40134FB7F20C2591A3C7FC9541980E3A, B42D542D9008078DDDCFF8ED0A88E2EAB46C01E270F04C9569D630670D734879 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 14:38:59.0453 0x13d8 MozillaMaintenance - ok 14:38:59.0453 0x13d8 [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys 14:38:59.0469 0x13d8 mpio - ok 14:38:59.0484 0x13d8 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 14:38:59.0500 0x13d8 mpsdrv - ok 14:38:59.0515 0x13d8 [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll 14:38:59.0547 0x13d8 MpsSvc - ok 14:38:59.0547 0x13d8 [ 98DB1790F0A584E0A2528B92B052417F, 9AA04CA73AFE599810CD233B9CEC212E16D44DCEDF5C7D0181C7257F498068B5 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 14:38:59.0562 0x13d8 MRxDAV - ok 14:38:59.0578 0x13d8 [ 819426D736BCBD31CC7CA27221954E04, 0C4AADEFE282D89EA4A523BDA7B6BB948247F50253D7D0B90C8FC46C4DEEF835 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 14:38:59.0593 0x13d8 mrxsmb - ok 14:38:59.0593 0x13d8 [ 85CB449B319AF69A3538BB1B97EEA2E5, DB75D56A7E631F57D31957105422811C738E96E5B84480C3346B827ACF280E12 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 14:38:59.0609 0x13d8 mrxsmb10 - ok 14:38:59.0625 0x13d8 [ C0B2DC34587FE163997055AA38EB883A, A0BFD0CF873CCEF266606ADE1A4DA69DF757A67D8AD28330272AFEABD7F481D5 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 14:38:59.0640 0x13d8 mrxsmb20 - ok 14:38:59.0640 0x13d8 [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys 14:38:59.0656 0x13d8 msahci - ok 14:38:59.0656 0x13d8 [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys 14:38:59.0671 0x13d8 msdsm - ok 14:38:59.0671 0x13d8 [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe 14:38:59.0687 0x13d8 MSDTC - ok 14:38:59.0687 0x13d8 [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys 14:38:59.0718 0x13d8 Msfs - ok 14:38:59.0718 0x13d8 [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 14:38:59.0749 0x13d8 mshidkmdf - ok 14:38:59.0749 0x13d8 [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 14:38:59.0765 0x13d8 msisadrv - ok 14:38:59.0765 0x13d8 [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 14:38:59.0781 0x13d8 MSiSCSI - ok 14:38:59.0781 0x13d8 msiserver - ok 14:38:59.0781 0x13d8 [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 14:38:59.0812 0x13d8 MSKSSRV - ok 14:38:59.0812 0x13d8 [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 14:38:59.0843 0x13d8 MSPCLOCK - ok 14:38:59.0843 0x13d8 [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 14:38:59.0874 0x13d8 MSPQM - ok 14:38:59.0874 0x13d8 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 14:38:59.0890 0x13d8 MsRPC - ok 14:38:59.0890 0x13d8 [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 14:38:59.0905 0x13d8 mssmbios - ok 14:38:59.0905 0x13d8 [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 14:38:59.0937 0x13d8 MSTEE - ok 14:38:59.0937 0x13d8 [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 14:38:59.0952 0x13d8 MTConfig - ok 14:38:59.0952 0x13d8 [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys 14:38:59.0968 0x13d8 Mup - ok 14:38:59.0983 0x13d8 [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll 14:38:59.0999 0x13d8 napagent - ok 14:39:00.0015 0x13d8 [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 14:39:00.0030 0x13d8 NativeWifiP - ok 14:39:00.0046 0x13d8 [ F7309F42555F8AAB7144A51A1F2585B0, 065277A8AFAEE3888C997A76D2F751070F92DF4C3354D16B194860B4BDAFF937 ] NDIS C:\Windows\system32\drivers\ndis.sys 14:39:00.0093 0x13d8 NDIS - ok 14:39:00.0093 0x13d8 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 14:39:00.0124 0x13d8 NdisCap - ok 14:39:00.0124 0x13d8 [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 14:39:00.0139 0x13d8 NdisTapi - ok 14:39:00.0155 0x13d8 [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 14:39:00.0171 0x13d8 Ndisuio - ok 14:39:00.0171 0x13d8 [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 14:39:00.0202 0x13d8 NdisWan - ok 14:39:00.0217 0x13d8 [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 14:39:00.0233 0x13d8 NDProxy - ok 14:39:00.0233 0x13d8 [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 14:39:00.0264 0x13d8 NetBIOS - ok 14:39:00.0264 0x13d8 [ E47D571FEC2C76E867935109AB2A770C, F349D25890B6F476B106FD75BFB081DB737CA9B224D95E44927942FFF2DF82CD ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 14:39:00.0295 0x13d8 NetBT - ok 14:39:00.0295 0x13d8 [ CA69E856332E2D85294665F6B7E97254, A9693F836907FB0154DC1090D9476F1E9242ABE922D932D74D0385772D2EAB65 ] Netlogon C:\Windows\system32\lsass.exe 14:39:00.0295 0x13d8 Netlogon - ok 14:39:00.0311 0x13d8 [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll 14:39:00.0327 0x13d8 Netman - ok 14:39:00.0342 0x13d8 [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 14:39:00.0342 0x13d8 NetMsmqActivator - ok 14:39:00.0342 0x13d8 [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 14:39:00.0358 0x13d8 NetPipeActivator - ok 14:39:00.0373 0x13d8 [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll 14:39:00.0389 0x13d8 netprofm - ok 14:39:00.0389 0x13d8 [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 14:39:00.0405 0x13d8 NetTcpActivator - ok 14:39:00.0405 0x13d8 [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 14:39:00.0420 0x13d8 NetTcpPortSharing - ok 14:39:00.0420 0x13d8 [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 14:39:00.0436 0x13d8 nfrd960 - ok 14:39:00.0436 0x13d8 [ 1AC002B670A471FC5214BE45237D88B0, B0E08809E706EC067E4535E04244B8975CDC3E6723D64A1CEEDEEDA8DBE9DE94 ] nhi C:\Windows\system32\DRIVERS\tbt70x.sys 14:39:00.0451 0x13d8 nhi - ok 14:39:00.0451 0x13d8 [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc C:\Windows\System32\nlasvc.dll 14:39:00.0467 0x13d8 NlaSvc - ok 14:39:00.0467 0x13d8 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys 14:39:00.0498 0x13d8 Npfs - ok 14:39:00.0498 0x13d8 [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll 14:39:00.0514 0x13d8 nsi - ok 14:39:00.0514 0x13d8 [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 14:39:00.0545 0x13d8 nsiproxy - ok 14:39:00.0576 0x13d8 [ 47B2D0B31BDC3EBE6090228E2BA3764D, 984A4B38300954164BCBF57EC1A09C18B53779E60A26E9618B50E26016735787 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 14:39:00.0639 0x13d8 Ntfs - ok 14:39:00.0639 0x13d8 [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys 14:39:00.0654 0x13d8 Null - ok 14:39:00.0670 0x13d8 [ CEF487606A4D64DC9A5F4D76EEE996AA, 0534E3EE033B0E821597328AAA62C818593D537BDCA54625CB3C1B99912ACC21 ] NvContainerLocalSystem C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe 14:39:00.0685 0x13d8 NvContainerLocalSystem - ok 14:39:00.0701 0x13d8 [ CEF487606A4D64DC9A5F4D76EEE996AA, 0534E3EE033B0E821597328AAA62C818593D537BDCA54625CB3C1B99912ACC21 ] NvContainerNetworkService C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe 14:39:00.0701 0x13d8 NvContainerNetworkService - ok 14:39:00.0717 0x13d8 [ A138890751D328A9ADEAFCB4CC0B6370, BD42BAFD4243861A2DF9FA0170DB03D01DD3AB6A3047322878FD636576414C63 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 14:39:00.0717 0x13d8 NVHDA - ok 14:39:00.0904 0x13d8 [ A51409C8043504A6DB5C97FB8BD6FABA, 079B3C3E533F5A452B3B08963207F6481FFFB99A8A3419D15FC32763A3C93D07 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 14:39:01.0091 0x13d8 nvlddmkm - ok 14:39:01.0091 0x13d8 [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys 14:39:01.0107 0x13d8 nvraid - ok 14:39:01.0122 0x13d8 [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys 14:39:01.0138 0x13d8 nvstor - ok 14:39:01.0138 0x13d8 [ 05FECCB901276013D16A42AD4CFCE24B, 281E2F23E5C820FA670E908EA1798F3FA062C4DD37B16DF73CE13E58B6F3C56E ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys 14:39:01.0153 0x13d8 NvStreamKms - ok 14:39:01.0153 0x13d8 [ 40B216E2D52371BC377C892FE83E63E9, AFD5466C86F0B0B54BE9AE6EF172D1B8F1F828C867FDA91CDD4E0A805D6EF71E ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe 14:39:01.0169 0x13d8 NvTelemetryContainer - ok 14:39:01.0169 0x13d8 [ 47E9348591CAACC64E41C9FD88D17A5B, 5B7AECFD5D35F55BDA8E6137D80B72166EA7AA0DF075BF4615D8EE50656CDDAF ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys 14:39:01.0185 0x13d8 nvvad_WaveExtensible - ok 14:39:01.0200 0x13d8 [ 61BD2E2560FD1C5E0A8B8738816A0B93, 1057A6C4F7D04E81BFFD5B806295B3A5D12DE4D13F66E8542426D83D97E68C97 ] nvvhci C:\Windows\system32\DRIVERS\nvvhci.sys 14:39:01.0200 0x13d8 nvvhci - ok 14:39:01.0200 0x13d8 [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 14:39:01.0216 0x13d8 nv_agp - ok 14:39:01.0231 0x13d8 [ 68DFD9322418999C13C6E64F1394FD2D, 5D9046375CD31CD60AD0599213D57E3851526C6C810409A20789E5EAB9205507 ] OcButtonService C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe 14:39:01.0231 0x13d8 OcButtonService - ok 14:39:01.0231 0x13d8 [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 14:39:01.0247 0x13d8 ohci1394 - ok 14:39:01.0294 0x13d8 [ 7E39C76DD4A21D7F81910EC36B8B8734, 52471C9C18F3866CB8D46FD2BDCFDE202140B0F1271D02A0EC96F5025BC26166 ] Origin Client Service C:\Program Files (x86)\Origin\OriginClientService.exe 14:39:01.0325 0x13d8 Origin Client Service - ok 14:39:01.0356 0x13d8 [ FF0ABC191051923E62BEC38F039A48F4, 8138F032F131E5F81F3FB26E2985D5ACA0CD5801D04698BFB3B73DB2DA593B88 ] Origin Web Helper Service C:\Program Files (x86)\Origin\OriginWebHelperService.exe 14:39:01.0387 0x13d8 Origin Web Helper Service - ok 14:39:01.0387 0x13d8 [ 5C12E1436BD6CC9ED022CA5335D4F1A0, CE323DE98A4328B348193B10867E16C840224559F391213590629360EFB5F33D ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 14:39:01.0403 0x13d8 ose - ok 14:39:01.0497 0x13d8 [ FE9C0029E1AF26350D9985D00520E5C8, 967079CCF7B2CBD4B48C9F076675C26AF93A1CEC26C96811F279414E34004EE6 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 14:39:01.0559 0x13d8 osppsvc - ok 14:39:01.0559 0x13d8 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 14:39:01.0575 0x13d8 p2pimsvc - ok 14:39:01.0590 0x13d8 [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll 14:39:01.0606 0x13d8 p2psvc - ok 14:39:01.0606 0x13d8 [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\drivers\parport.sys 14:39:01.0621 0x13d8 Parport - ok 14:39:01.0621 0x13d8 [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\Windows\system32\drivers\partmgr.sys 14:39:01.0637 0x13d8 partmgr - ok 14:39:01.0653 0x13d8 [ 3CD83692C43D87088E85E3C916146FFB, 9E812535E8FBA045FDA30F68E9EB2031132C37721D542A2DC9D4C33E2B137FCF ] PcaSvc C:\Windows\System32\pcasvc.dll 14:39:01.0653 0x13d8 PcaSvc - ok 14:39:01.0668 0x13d8 [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\Windows\system32\drivers\pci.sys 14:39:01.0684 0x13d8 pci - ok 14:39:01.0684 0x13d8 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys 14:39:01.0699 0x13d8 pciide - ok 14:39:01.0699 0x13d8 [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 14:39:01.0715 0x13d8 pcmcia - ok 14:39:01.0715 0x13d8 [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys 14:39:01.0731 0x13d8 pcw - ok 14:39:01.0824 0x13d8 [ 87B3DE5B911F767C388D5A56A73D9E93, 7C845A6E9D706BC7CDFD32F9BDEA52BF2FD3D90D45BCF2D48CE704D58F00D23D ] PDF Architect 4 P:\Programme\PDF Architect 4\ws.exe 14:39:01.0855 0x13d8 PDF Architect 4 - ok 14:39:01.0887 0x13d8 [ 9049B0504C1CB438C0154F72FD7ABC28, 882141B00074CB2EDD3CB7DA745DF4347DA62A90A7E104719DBC13A8BA56B253 ] PDF Architect 4 CrashHandler P:\Programme\PDF Architect 4\crash-handler-ws.exe 14:39:01.0902 0x13d8 PDF Architect 4 CrashHandler - ok 14:39:01.0918 0x13d8 [ 5F83EDC4A22BC7CC9507E43335C3524E, E349816313DA261C1787159085D920CE975B122DB9FEEBAA132D6593B6DD03EC ] PDF Architect 4 Creator P:\Programme\PDF Architect 4\creator-ws.exe 14:39:01.0933 0x13d8 PDF Architect 4 Creator - ok 14:39:01.0949 0x13d8 [ 06B2368D9B342AE8E02C929B72E07804, 4EBCFCE5FFE934369ADD035A804BC24160BF94A796A42592B328A35A26DAB79E ] PDF Architect 4 Manager C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe 14:39:01.0980 0x13d8 PDF Architect 4 Manager - ok 14:39:01.0980 0x13d8 [ EA4D67448BE493D543F1730D6CD04694, 24717C5E41B7CA522F3330EF2228B6685E710A5259396E9887A1C1E7A413F8CA ] PEAUTH C:\Windows\system32\drivers\peauth.sys 14:39:02.0011 0x13d8 PEAUTH - ok 14:39:02.0027 0x13d8 [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 14:39:02.0058 0x13d8 PeerDistSvc - ok 14:39:02.0058 0x13d8 [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe 14:39:02.0074 0x13d8 PerfHost - ok 14:39:02.0105 0x13d8 [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll 14:39:02.0136 0x13d8 pla - ok 14:39:02.0152 0x13d8 [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 14:39:02.0152 0x13d8 PlugPlay - ok 14:39:02.0152 0x13d8 PnkBstrA - ok 14:39:02.0167 0x13d8 [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 14:39:02.0167 0x13d8 PNRPAutoReg - ok 14:39:02.0183 0x13d8 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 14:39:02.0183 0x13d8 PNRPsvc - ok 14:39:02.0199 0x13d8 [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 14:39:02.0214 0x13d8 PolicyAgent - ok 14:39:02.0214 0x13d8 [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\Windows\system32\umpo.dll 14:39:02.0245 0x13d8 Power - ok 14:39:02.0245 0x13d8 [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 14:39:02.0277 0x13d8 PptpMiniport - ok 14:39:02.0277 0x13d8 [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\drivers\processr.sys 14:39:02.0292 0x13d8 Processor - ok 14:39:02.0292 0x13d8 [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc C:\Windows\system32\profsvc.dll 14:39:02.0308 0x13d8 ProfSvc - ok 14:39:02.0308 0x13d8 [ CA69E856332E2D85294665F6B7E97254, A9693F836907FB0154DC1090D9476F1E9242ABE922D932D74D0385772D2EAB65 ] ProtectedStorage C:\Windows\system32\lsass.exe 14:39:02.0323 0x13d8 ProtectedStorage - ok 14:39:02.0323 0x13d8 [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys 14:39:02.0355 0x13d8 Psched - ok 14:39:02.0386 0x13d8 [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 14:39:02.0417 0x13d8 ql2300 - ok 14:39:02.0433 0x13d8 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 14:39:02.0448 0x13d8 ql40xx - ok 14:39:02.0448 0x13d8 [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll 14:39:02.0464 0x13d8 QWAVE - ok 14:39:02.0464 0x13d8 [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 14:39:02.0479 0x13d8 QWAVEdrv - ok 14:39:02.0479 0x13d8 [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 14:39:02.0511 0x13d8 RasAcd - ok 14:39:02.0511 0x13d8 [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 14:39:02.0542 0x13d8 RasAgileVpn - ok 14:39:02.0542 0x13d8 [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll 14:39:02.0557 0x13d8 RasAuto - ok 14:39:02.0573 0x13d8 [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 14:39:02.0589 0x13d8 Rasl2tp - ok 14:39:02.0604 0x13d8 [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll 14:39:02.0620 0x13d8 RasMan - ok 14:39:02.0620 0x13d8 [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 14:39:02.0651 0x13d8 RasPppoe - ok 14:39:02.0651 0x13d8 [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 14:39:02.0682 0x13d8 RasSstp - ok 14:39:02.0682 0x13d8 [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 14:39:02.0713 0x13d8 rdbss - ok 14:39:02.0729 0x13d8 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 14:39:02.0745 0x13d8 rdpbus - ok 14:39:02.0745 0x13d8 [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 14:39:02.0760 0x13d8 RDPCDD - ok 14:39:02.0776 0x13d8 [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 14:39:02.0791 0x13d8 RDPDR - ok 14:39:02.0791 0x13d8 [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 14:39:02.0807 0x13d8 RDPENCDD - ok 14:39:02.0823 0x13d8 [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 14:39:02.0838 0x13d8 RDPREFMP - ok 14:39:02.0838 0x13d8 [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 14:39:02.0854 0x13d8 RdpVideoMiniport - ok 14:39:02.0869 0x13d8 [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 14:39:02.0885 0x13d8 RDPWD - ok 14:39:02.0885 0x13d8 [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 14:39:02.0901 0x13d8 rdyboost - ok 14:39:02.0901 0x13d8 [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll 14:39:02.0932 0x13d8 RemoteAccess - ok 14:39:02.0932 0x13d8 [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll 14:39:02.0947 0x13d8 RemoteRegistry - ok 14:39:02.0963 0x13d8 [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 14:39:02.0979 0x13d8 RpcEptMapper - ok 14:39:02.0979 0x13d8 [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe 14:39:02.0994 0x13d8 RpcLocator - ok 14:39:02.0994 0x13d8 [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] RpcSs C:\Windows\system32\rpcss.dll 14:39:03.0010 0x13d8 RpcSs - ok 14:39:03.0010 0x13d8 [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 14:39:03.0041 0x13d8 rspndr - ok 14:39:03.0041 0x13d8 [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap C:\Windows\system32\drivers\vms3cap.sys 14:39:03.0057 0x13d8 s3cap - ok 14:39:03.0057 0x13d8 [ CA69E856332E2D85294665F6B7E97254, A9693F836907FB0154DC1090D9476F1E9242ABE922D932D74D0385772D2EAB65 ] SamSs C:\Windows\system32\lsass.exe 14:39:03.0072 0x13d8 SamSs - ok 14:39:03.0072 0x13d8 [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 14:39:03.0088 0x13d8 sbp2port - ok 14:39:03.0088 0x13d8 [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll 14:39:03.0119 0x13d8 SCardSvr - ok 14:39:03.0119 0x13d8 [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 14:39:03.0135 0x13d8 scfilter - ok 14:39:03.0150 0x13d8 [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule C:\Windows\system32\schedsvc.dll 14:39:03.0181 0x13d8 Schedule - ok 14:39:03.0181 0x13d8 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll 14:39:03.0197 0x13d8 SCPolicySvc - ok 14:39:03.0213 0x13d8 [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll 14:39:03.0213 0x13d8 SDRSVC - ok 14:39:03.0213 0x13d8 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys 14:39:03.0244 0x13d8 secdrv - ok 14:39:03.0244 0x13d8 [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon C:\Windows\system32\seclogon.dll 14:39:03.0244 0x13d8 seclogon - ok 14:39:03.0259 0x13d8 [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\System32\sens.dll 14:39:03.0275 0x13d8 SENS - ok 14:39:03.0275 0x13d8 [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll 14:39:03.0291 0x13d8 SensrSvc - ok 14:39:03.0291 0x13d8 [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 14:39:03.0306 0x13d8 Serenum - ok 14:39:03.0306 0x13d8 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\DRIVERS\serial.sys 14:39:03.0322 0x13d8 Serial - ok 14:39:03.0322 0x13d8 [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\drivers\sermouse.sys 14:39:03.0337 0x13d8 sermouse - ok 14:39:03.0337 0x13d8 [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll 14:39:03.0369 0x13d8 SessionEnv - ok 14:39:03.0369 0x13d8 [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 14:39:03.0384 0x13d8 sffdisk - ok 14:39:03.0384 0x13d8 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 14:39:03.0400 0x13d8 sffp_mmc - ok 14:39:03.0400 0x13d8 [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 14:39:03.0415 0x13d8 sffp_sd - ok 14:39:03.0415 0x13d8 [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 14:39:03.0431 0x13d8 sfloppy - ok 14:39:03.0447 0x13d8 [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll 14:39:03.0462 0x13d8 SharedAccess - ok 14:39:03.0478 0x13d8 [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 14:39:03.0493 0x13d8 ShellHWDetection - ok 14:39:03.0493 0x13d8 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 14:39:03.0509 0x13d8 SiSRaid2 - ok 14:39:03.0509 0x13d8 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 14:39:03.0525 0x13d8 SiSRaid4 - ok 14:39:03.0540 0x13d8 [ B72B80E6FF423C5011E745CB76DA9A08, 18A6B9D46E91AD4D463EB5CB832702392D2E162577F90C328B515FCE69FABD15 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 14:39:03.0556 0x13d8 SkypeUpdate - ok 14:39:03.0556 0x13d8 [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys 14:39:03.0587 0x13d8 Smb - ok 14:39:03.0587 0x13d8 [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 14:39:03.0603 0x13d8 SNMPTRAP - ok 14:39:03.0603 0x13d8 [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys 14:39:03.0618 0x13d8 spldr - ok 14:39:03.0618 0x13d8 [ B96C17B5DC1424D56EEA3A99E97428CD, AF0A85066A7983878DC1C663811CE61C6CA1912DC956184F878B7B82DB93C651 ] Spooler C:\Windows\System32\spoolsv.exe 14:39:03.0649 0x13d8 Spooler - ok 14:39:03.0696 0x13d8 [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe 14:39:03.0759 0x13d8 sppsvc - ok 14:39:03.0759 0x13d8 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll 14:39:03.0774 0x13d8 sppuinotify - ok 14:39:03.0790 0x13d8 [ E8276BE984738AA44070CFDE6EFC9300, F0B09D3E08BDB1B8AEBA97A700271E97AB2506793B42D96415B23DB68DA99FA8 ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 14:39:03.0790 0x13d8 SQLWriter - ok 14:39:03.0805 0x13d8 [ EB15C46477EB84B6B520871ED5936CCF, 7366FD2E1315109B9A2F47DA08959CF0CBEEB1F20B2E2DEF449D39B508107D29 ] srv C:\Windows\system32\DRIVERS\srv.sys 14:39:03.0821 0x13d8 srv - ok 14:39:03.0837 0x13d8 [ 7F4FDC9528BCE6FB919615B6A77D5724, C4843381504E0F50D4B8E4F8886C83112018CE5F64467B875F2809508EA2B182 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 14:39:03.0852 0x13d8 srv2 - ok 14:39:03.0852 0x13d8 [ 3F20CD2A11872284BD667DAD6D4801CC, 917EAA680CD10D3EA59EEF4B77BB3813D5718E7D1CB0846431255EE73035D834 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 14:39:03.0868 0x13d8 srvnet - ok 14:39:03.0883 0x13d8 [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 14:39:03.0899 0x13d8 SSDPSRV - ok 14:39:03.0899 0x13d8 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll 14:39:03.0930 0x13d8 SstpSvc - ok 14:39:03.0930 0x13d8 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys 14:39:03.0946 0x13d8 ssudmdm - ok 14:39:04.0071 0x13d8 [ 7DB9E612A2742ACEAB080B882E83141C, FFD1FA36E732F55223F3F4B5F845331DBB3073B023C2C5BF51A0E7680DEE7FA7 ] ss_conn_service P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe 14:39:04.0102 0x13d8 ss_conn_service - ok 14:39:04.0133 0x13d8 [ DF8D486ADBBC6ACA0901CF3C1A09EF05, 734477E23E1C8578517B187CE26FC0F5646BB557F871D6C69D78D12AEB20D287 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe 14:39:04.0164 0x13d8 Steam Client Service - ok 14:39:04.0180 0x13d8 [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\drivers\stexstor.sys 14:39:04.0180 0x13d8 stexstor - ok 14:39:04.0195 0x13d8 [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll 14:39:04.0211 0x13d8 stisvc - ok 14:39:04.0227 0x13d8 [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt C:\Windows\system32\drivers\vmstorfl.sys 14:39:04.0242 0x13d8 storflt - ok 14:39:04.0242 0x13d8 [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc C:\Windows\system32\storsvc.dll 14:39:04.0242 0x13d8 StorSvc - ok 14:39:04.0258 0x13d8 [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc C:\Windows\system32\drivers\storvsc.sys 14:39:04.0258 0x13d8 storvsc - ok 14:39:04.0273 0x13d8 [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 14:39:04.0289 0x13d8 swenum - ok 14:39:04.0289 0x13d8 [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll 14:39:04.0320 0x13d8 swprv - ok 14:39:04.0351 0x13d8 [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain C:\Windows\system32\sysmain.dll 14:39:04.0383 0x13d8 SysMain - ok 14:39:04.0383 0x13d8 [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll 14:39:04.0398 0x13d8 TabletInputService - ok 14:39:04.0398 0x13d8 [ D765F43CBEA72D14C04AF3D2B9C8E54B, 89C5CA1440DF186497CE158EB71C0C6BF570A75B6BC1880EAC7C87A0250201C0 ] tap0901 C:\Windows\system32\DRIVERS\tap0901.sys 14:39:04.0414 0x13d8 tap0901 - detected UnsignedFile.Multi.Generic ( 1 ) 14:39:05.0412 0x13d8 Detect skipped due to KSN trusted 14:39:05.0412 0x13d8 tap0901 - ok 14:39:05.0428 0x13d8 [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll 14:39:05.0475 0x13d8 TapiSrv - ok 14:39:05.0506 0x13d8 [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] Tcpip C:\Windows\system32\drivers\tcpip.sys 14:39:05.0568 0x13d8 Tcpip - ok 14:39:05.0599 0x13d8 [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 14:39:05.0646 0x13d8 TCPIP6 - ok 14:39:05.0646 0x13d8 [ 7FE5586314EE7D6AA8483264A089E5AF, 4E3EA68713A45C22F1B9A1AA125E15D06D0C5E637B815537431ADFB6D7563879 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 14:39:05.0662 0x13d8 tcpipreg - ok 14:39:05.0662 0x13d8 [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 14:39:05.0677 0x13d8 TDPIPE - ok 14:39:05.0677 0x13d8 [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 14:39:05.0693 0x13d8 TDTCP - ok 14:39:05.0709 0x13d8 [ AA77EB517D2F07A947294F260E3ACA83, B7A5DF3066830C0C2302B059778A67419792058A0D300C471DE40AB245EA7E58 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 14:39:05.0724 0x13d8 tdx - ok 14:39:05.0724 0x13d8 [ 2625DD0C44FEB294E4096E129938C618, 50CD1F8618C46911A1A5DF62797AC16BD88E1915288D62B09BF2BDB44472C68B ] Te.Service C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe 14:39:05.0740 0x13d8 Te.Service - detected UnsignedFile.Multi.Generic ( 1 ) 14:39:06.0145 0x13d8 Detect skipped due to KSN trusted 14:39:06.0145 0x13d8 Te.Service - ok 14:39:06.0348 0x13d8 [ C24C2FFBFEBA45AE980E8CB77E70A9BD, AB605A4B68B2461CC326CC853C390A86FB9E6C566BD61052A637B45C059B829A ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe 14:39:06.0489 0x13d8 TeamViewer - ok 14:39:06.0489 0x13d8 [ F5520DBB47C60EE83024B38720ABDA24, B8E555D92440BF93E3B55A66E27CEF936477EF7528F870D3B78BD3B294A05CC0 ] teamviewervpn C:\Windows\system32\DRIVERS\teamviewervpn.sys 14:39:06.0504 0x13d8 teamviewervpn - ok 14:39:06.0504 0x13d8 [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 14:39:06.0520 0x13d8 TermDD - ok 14:39:06.0535 0x13d8 [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService C:\Windows\System32\termsrv.dll 14:39:06.0551 0x13d8 TermService - ok 14:39:06.0551 0x13d8 [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll 14:39:06.0567 0x13d8 Themes - ok 14:39:06.0567 0x13d8 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll 14:39:06.0598 0x13d8 THREADORDER - ok 14:39:06.0629 0x13d8 [ 5835A845C5991E502C10F92D23EA08AB, 7EB166A43AD748544852C2E2673A6E7F6D883302FD4EF3F7F45414CB848FF767 ] ThunderboltService C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe 14:39:06.0645 0x13d8 ThunderboltService - ok 14:39:06.0660 0x13d8 [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll 14:39:06.0676 0x13d8 TrkWks - ok 14:39:06.0691 0x13d8 [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 14:39:06.0707 0x13d8 TrustedInstaller - ok 14:39:06.0707 0x13d8 [ 19BEDA57F3E0A06B8D5EB6D619BD5624, 952D5FAFD662C93628C12A6F7EB8E240A44216C0A15CBD2F5016BC357CBFE821 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 14:39:06.0723 0x13d8 tssecsrv - ok 14:39:06.0723 0x13d8 [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 14:39:06.0738 0x13d8 TsUsbFlt - ok 14:39:06.0738 0x13d8 [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 14:39:06.0754 0x13d8 TsUsbGD - ok 14:39:06.0769 0x13d8 [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 14:39:06.0785 0x13d8 tunnel - ok 14:39:06.0801 0x13d8 [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 14:39:06.0801 0x13d8 uagp35 - ok 14:39:06.0816 0x13d8 [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 14:39:06.0847 0x13d8 udfs - ok 14:39:06.0847 0x13d8 [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe 14:39:06.0863 0x13d8 UI0Detect - ok 14:39:06.0863 0x13d8 [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 14:39:06.0879 0x13d8 uliagpkx - ok 14:39:06.0879 0x13d8 [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\DRIVERS\umbus.sys 14:39:06.0894 0x13d8 umbus - ok 14:39:06.0910 0x13d8 [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\drivers\umpass.sys 14:39:06.0910 0x13d8 UmPass - ok 14:39:06.0925 0x13d8 [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService C:\Windows\System32\umrdp.dll 14:39:06.0941 0x13d8 UmRdpService - ok 14:39:06.0941 0x13d8 [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll 14:39:06.0972 0x13d8 upnphost - ok 14:39:06.0972 0x13d8 [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 14:39:06.0988 0x13d8 usbaudio - ok 14:39:06.0988 0x13d8 [ 28B81917A195B67617AF7DCF4DFE5736, 40A4D2AAE1BDE5ABA8708ED150396E913C566ECD5CDA40D6C6DB256F1B9FD4A9 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 14:39:07.0003 0x13d8 usbccgp - ok 14:39:07.0003 0x13d8 [ 84A8E67E6CB15B070A2A7A0B3A9F1609, 08AB5691024A5B69A23DEF4E69696EC46D5BAD01A24861CFE612FBD649D87BDB ] UsbCharger C:\Windows\system32\DRIVERS\UsbCharger.sys 14:39:07.0019 0x13d8 UsbCharger - ok 14:39:07.0019 0x13d8 [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir C:\Windows\system32\drivers\usbcir.sys 14:39:07.0035 0x13d8 usbcir - ok 14:39:07.0050 0x13d8 [ B626F048318DAE65A3317F0592BE592C, 284D8FFE1D35F852EFDA182A72288AC3A10D6ED825FE2CC5812497D3FE291AF1 ] usbehci C:\Windows\system32\drivers\usbehci.sys 14:39:07.0066 0x13d8 usbehci - ok 14:39:07.0066 0x13d8 [ 390109E8E05BA00375DCB1ED64DC60AF, B8628502590B423BEFB6F7C8C69FAD0667AD0746FF6B444EE02016E8E1052B78 ] usbhub C:\Windows\system32\drivers\usbhub.sys 14:39:07.0081 0x13d8 usbhub - ok 14:39:07.0097 0x13d8 [ B4DF0F4C1D9D25DFE1DAD1D8670F1D4F, 4317C2DEDC639527B53864BAEC46CBE022D298C0503E29E1072DD1C851D92BFC ] usbohci C:\Windows\system32\drivers\usbohci.sys 14:39:07.0113 0x13d8 usbohci - ok 14:39:07.0113 0x13d8 [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 14:39:07.0128 0x13d8 usbprint - ok 14:39:07.0128 0x13d8 [ D029DD09E22EB24318A8FC3D8138BA43, C95805E8BF75ECB939520AE86420B16467B0771C161C51C9F1A37649ADFADCD0 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 14:39:07.0144 0x13d8 USBSTOR - ok 14:39:07.0144 0x13d8 [ CFEAAF96E666E3DCBD8F6DFF516784AE, 006218A3DB5851790CC0A7F3DCD7B3AF82F624DA679296DE507AFD36C5468317 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 14:39:07.0159 0x13d8 usbuhci - ok 14:39:07.0159 0x13d8 [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 14:39:07.0191 0x13d8 usbvideo - ok 14:39:07.0191 0x13d8 [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll 14:39:07.0206 0x13d8 UxSms - ok 14:39:07.0206 0x13d8 [ CA69E856332E2D85294665F6B7E97254, A9693F836907FB0154DC1090D9476F1E9242ABE922D932D74D0385772D2EAB65 ] VaultSvc C:\Windows\system32\lsass.exe 14:39:07.0222 0x13d8 VaultSvc - ok 14:39:07.0222 0x13d8 [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 14:39:07.0237 0x13d8 vdrvroot - ok 14:39:07.0253 0x13d8 [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe 14:39:07.0269 0x13d8 vds - ok 14:39:07.0284 0x13d8 [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 14:39:07.0300 0x13d8 vga - ok 14:39:07.0300 0x13d8 [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys 14:39:07.0315 0x13d8 VgaSave - ok 14:39:07.0331 0x13d8 [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 14:39:07.0347 0x13d8 vhdmp - ok 14:39:07.0347 0x13d8 [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys 14:39:07.0362 0x13d8 viaide - ok 14:39:07.0362 0x13d8 [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus C:\Windows\system32\drivers\vmbus.sys 14:39:07.0378 0x13d8 vmbus - ok 14:39:07.0378 0x13d8 [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 14:39:07.0393 0x13d8 VMBusHID - ok 14:39:07.0409 0x13d8 [ 39CCC7F3F7F8BA7895B51B447127B2D5, 2670DC54D9B6A3ED6EF64E54854A12B4C9EA98F4707C1C0D8D569BBAFCDA61ED ] vmulti C:\Windows\system32\DRIVERS\vmulti.sys 14:39:07.0425 0x13d8 vmulti - ok 14:39:07.0425 0x13d8 [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\Windows\system32\drivers\volmgr.sys 14:39:07.0440 0x13d8 volmgr - ok 14:39:07.0440 0x13d8 [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 14:39:07.0456 0x13d8 volmgrx - ok 14:39:07.0471 0x13d8 [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap C:\Windows\system32\drivers\volsnap.sys 14:39:07.0487 0x13d8 volsnap - ok 14:39:07.0487 0x13d8 [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 14:39:07.0503 0x13d8 vsmraid - ok 14:39:07.0534 0x13d8 [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe 14:39:07.0565 0x13d8 VSS - ok 14:39:07.0659 0x13d8 [ BE6C456AE7620B86A7273CBD11A3D450, DEBBB12CB9771722D8258FDF9ECC4ED035BD7090371A975928D11F6B9EDC0C59 ] VSStandardCollectorService140 P:\Programme (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe 14:39:07.0690 0x13d8 VSStandardCollectorService140 - ok 14:39:07.0690 0x13d8 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 14:39:07.0721 0x13d8 vwifibus - ok 14:39:07.0721 0x13d8 [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 14:39:07.0737 0x13d8 vwififlt - ok 14:39:07.0737 0x13d8 [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 14:39:07.0768 0x13d8 vwifimp - ok 14:39:07.0768 0x13d8 [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll 14:39:07.0799 0x13d8 W32Time - ok 14:39:07.0799 0x13d8 [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 14:39:07.0815 0x13d8 WacomPen - ok 14:39:07.0815 0x13d8 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 14:39:07.0846 0x13d8 WANARP - ok 14:39:07.0846 0x13d8 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 14:39:07.0877 0x13d8 Wanarpv6 - ok 14:39:07.0893 0x13d8 [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe 14:39:07.0924 0x13d8 wbengine - ok 14:39:07.0924 0x13d8 [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 14:39:07.0939 0x13d8 WbioSrvc - ok 14:39:07.0955 0x13d8 [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll 14:39:07.0971 0x13d8 wcncsvc - ok 14:39:07.0971 0x13d8 [ BC00873272B3771CCDA38336AF2B4D4B, 3E412DEC5F172B4C5FD5C227CD790EE56B90A00A8B538704E8F973D230BE2289 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 14:39:07.0971 0x13d8 WcsPlugInService - ok 14:39:07.0986 0x13d8 [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\drivers\wd.sys 14:39:07.0986 0x13d8 Wd - ok 14:39:08.0002 0x13d8 [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 14:39:08.0033 0x13d8 Wdf01000 - ok 14:39:08.0033 0x13d8 [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost C:\Windows\system32\wdi.dll 14:39:08.0049 0x13d8 WdiServiceHost - ok 14:39:08.0049 0x13d8 [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost C:\Windows\system32\wdi.dll 14:39:08.0064 0x13d8 WdiSystemHost - ok 14:39:08.0064 0x13d8 [ EE841B6D1F2B9508D3ABAE52AC05A94F, F1AE981FCDBFC4672A4EABABD41382E93762EFC2EDAD96E75530E7ACA5AF1FD8 ] WebClient C:\Windows\System32\webclnt.dll 14:39:08.0080 0x13d8 WebClient - ok 14:39:08.0095 0x13d8 [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\Windows\system32\wecsvc.dll 14:39:08.0111 0x13d8 Wecsvc - ok 14:39:08.0111 0x13d8 [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll 14:39:08.0142 0x13d8 wercplsupport - ok 14:39:08.0142 0x13d8 [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll 14:39:08.0158 0x13d8 WerSvc - ok 14:39:08.0173 0x13d8 [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 14:39:08.0189 0x13d8 WfpLwf - ok 14:39:08.0205 0x13d8 [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys 14:39:08.0205 0x13d8 WIMMount - ok 14:39:08.0220 0x13d8 WinDefend - ok 14:39:08.0220 0x13d8 WinHttpAutoProxySvc - ok 14:39:08.0220 0x13d8 [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 14:39:08.0251 0x13d8 Winmgmt - ok 14:39:08.0283 0x13d8 [ EBDA1B0F15CB9B2CBCC6C94824E4E054, C51314F7D611E4903DA00EFA8EB99365414436324D256083CE0B5A8E055E8E06 ] WinRM C:\Windows\system32\WsmSvc.dll 14:39:08.0314 0x13d8 WinRM - ok 14:39:08.0314 0x13d8 [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 14:39:08.0345 0x13d8 WinUsb - ok 14:39:08.0361 0x13d8 [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll 14:39:08.0376 0x13d8 Wlansvc - ok 14:39:08.0376 0x13d8 [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 14:39:08.0392 0x13d8 WmiAcpi - ok 14:39:08.0407 0x13d8 [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 14:39:08.0407 0x13d8 wmiApSrv - ok 14:39:08.0407 0x13d8 WMPNetworkSvc - ok 14:39:08.0423 0x13d8 [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll 14:39:08.0423 0x13d8 WPCSvc - ok 14:39:08.0439 0x13d8 [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 14:39:08.0439 0x13d8 WPDBusEnum - ok 14:39:08.0439 0x13d8 [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 14:39:08.0470 0x13d8 ws2ifsl - ok 14:39:08.0470 0x13d8 [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\System32\wscsvc.dll 14:39:08.0485 0x13d8 wscsvc - ok 14:39:08.0485 0x13d8 [ 8D918B1DB190A4D9B1753A66FA8C96E8, DB7D2714DC04D2D6999A207D7399A5647C8653E5A1AD80856A65C5B6065AEDFE ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 14:39:08.0501 0x13d8 WSDPrintDevice - ok 14:39:08.0517 0x13d8 [ 4A2A5C50DD1A63577D3ACA94269FBC7F, F75C1906D431CF871AD954218DF32A0F206E45FF49332DEF9F13C0A36A407047 ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys 14:39:08.0532 0x13d8 WSDScan - ok 14:39:08.0532 0x13d8 WSearch - ok 14:39:08.0563 0x13d8 [ 1749AE2670F51F704A9335C22DEDD819, 8E1EE86DF991C665383C29D237677FA3F1C15AE4FB5B0E9521518A791047F0FD ] wuauserv C:\Windows\system32\wuaueng.dll 14:39:08.0610 0x13d8 wuauserv - ok 14:39:08.0610 0x13d8 [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 14:39:08.0626 0x13d8 WudfPf - ok 14:39:08.0641 0x13d8 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 14:39:08.0657 0x13d8 WUDFRd - ok 14:39:08.0657 0x13d8 [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 14:39:08.0673 0x13d8 wudfsvc - ok 14:39:08.0673 0x13d8 [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc C:\Windows\System32\wwansvc.dll 14:39:08.0688 0x13d8 WwanSvc - ok 14:39:08.0688 0x13d8 [ 16B6B5B4CAFEA003B4ADA9FF16A6299A, 413A47C745CC1C98D16F403767EAA5E2F4DA587CFE3B0D8F20CA3D69C9E6731B ] XtuAcpiDriver C:\Windows\system32\DRIVERS\XtuAcpiDriver.sys 14:39:08.0704 0x13d8 XtuAcpiDriver - ok 14:39:08.0704 0x13d8 ================ Scan global =============================== 14:39:08.0704 0x13d8 [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\Windows\system32\basesrv.dll 14:39:08.0719 0x13d8 [ B68AD91370FA58C1296DE9086BB4BA0A, 3B6B8170990B3B3B321752539A54D8EAB6E6241A25092682FDEE1A46BD39DBF6 ] C:\Windows\system32\winsrv.dll 14:39:08.0719 0x13d8 [ B68AD91370FA58C1296DE9086BB4BA0A, 3B6B8170990B3B3B321752539A54D8EAB6E6241A25092682FDEE1A46BD39DBF6 ] C:\Windows\system32\winsrv.dll 14:39:08.0735 0x13d8 [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll 14:39:08.0735 0x13d8 [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\Windows\system32\services.exe 14:39:08.0751 0x13d8 [ Global ] - ok 14:39:08.0751 0x13d8 ================ Scan MBR ================================== 14:39:08.0751 0x13d8 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 14:39:08.0782 0x13d8 \Device\Harddisk0\DR0 - ok 14:39:08.0813 0x13d8 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1 14:39:09.0141 0x13d8 \Device\Harddisk1\DR1 - ok 14:39:09.0141 0x13d8 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2 14:39:09.0219 0x13d8 \Device\Harddisk2\DR2 - ok 14:39:09.0219 0x13d8 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk3\DR3 14:40:27.0128 0x13d8 \Device\Harddisk3\DR3 - ok 14:40:27.0129 0x13d8 ================ Scan VBR ================================== 14:40:27.0144 0x13d8 [ DC68099DE893DC91BED4475CD4BF500A ] \Device\Harddisk0\DR0\Partition1 14:40:27.0147 0x13d8 \Device\Harddisk0\DR0\Partition1 - ok 14:40:27.0152 0x13d8 [ 1323F607C1677370A6C5C7C32FABD057 ] \Device\Harddisk0\DR0\Partition2 14:40:27.0155 0x13d8 \Device\Harddisk0\DR0\Partition2 - ok 14:40:27.0202 0x13d8 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk1\DR1\Partition1 14:40:27.0202 0x13d8 \Device\Harddisk1\DR1\Partition1 - ok 14:40:27.0206 0x13d8 [ BEC6C90F2103EF18355C83CAC1EF65BF ] \Device\Harddisk1\DR1\Partition2 14:40:27.0208 0x13d8 \Device\Harddisk1\DR1\Partition2 - ok 14:40:27.0210 0x13d8 [ EFD19048A7F1ECD344DAD2518F715E7A ] \Device\Harddisk2\DR2\Partition1 14:40:27.0211 0x13d8 \Device\Harddisk2\DR2\Partition1 - ok 14:40:27.0213 0x13d8 [ 02E6AB162254EF21FDFD4A1077C20303 ] \Device\Harddisk3\DR3\Partition1 14:40:27.0215 0x13d8 \Device\Harddisk3\DR3\Partition1 - ok 14:40:27.0221 0x13d8 [ ED63275AD5225B429CB27DFBCEA3172E ] \Device\Harddisk3\DR3\Partition2 14:40:27.0222 0x13d8 \Device\Harddisk3\DR3\Partition2 - ok 14:40:27.0224 0x13d8 [ B0F15733DA26BB7B3D59D9515395B3C8 ] \Device\Harddisk3\DR3\Partition3 14:40:27.0230 0x13d8 \Device\Harddisk3\DR3\Partition3 - ok 14:40:27.0230 0x13d8 ================ Scan generic autorun ====================== 14:40:27.0363 0x13d8 [ C137F3B93557075F8CC6232F0E2D9EC3, 54E89108F3EC9009036C8BF9053E76534D8F8911CCF83AEA0C45B9EACFBB1EF5 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe 14:40:27.0476 0x13d8 RTHDVCPL - ok 14:40:27.0484 0x13d8 [ A8012BE61DC9CEFA5C41C2DA995812BD, 63D64926B700AD5378C7A719CD71906382EAAA1BE3CB2EE22D9A63D13E12C272 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe 14:40:27.0489 0x13d8 IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 ) 14:40:28.0479 0x13d8 Detect skipped due to KSN trusted 14:40:28.0479 0x13d8 IAStorIcon - ok 14:40:28.0484 0x13d8 [ DD81D91FF3B0763C392422865C9AC12E, F5691B8F200E3196E6808E932630E862F8F26F31CD949981373F23C9D87DB8B9 ] C:\Windows\system32\rundll32.exe 14:40:28.0515 0x13d8 ShadowPlay - ok 14:40:28.0548 0x13d8 [ 6219A6387F46488BE13CF68AEE49CE50, BE01B62B0F747041F3B97F7B405A8CD25022006E14F986A282003F5A8E26C8EB ] C:\Program Files (x86)\Solvusoft\Tray\SolvusoftTray.exe 14:40:28.0576 0x13d8 CommonToolkitTray_Solvusoft - ok 14:40:28.0585 0x13d8 [ 9602CE3F53844065AD38CC5F355E19DF, EA3109B8C733462E2F097C8582E299864ADC9904EF17CBA417006006E8E1D14E ] C:\Windows\system32\flvga_tray.exe 14:40:28.0596 0x13d8 flvga_tray64 - detected UnsignedFile.Multi.Generic ( 1 ) 14:40:29.0591 0x13d8 Detect skipped due to KSN trusted 14:40:29.0591 0x13d8 flvga_tray64 - ok 14:40:29.0618 0x13d8 [ 8AD65052ED4FCDAFB2F90D4070462F3F, 754344248F9873929EAD93B89066A6CF21ADCB3FBC5BF55A51E4591E7DC78053 ] C:\Program Files\AVAST Software\Avast\AvLaunch.exe 14:40:29.0658 0x13d8 AvastUI.exe - ok 14:40:29.0676 0x13d8 [ 395CB6E8C67BFB1063AD86987909C184, 15F3BA6DF6D0C5C8FB9FF0AB661A5A652F26BAB7A0FB0DB47874069522400B16 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 14:40:29.0696 0x13d8 SunJavaUpdateSched - ok 14:40:29.0699 0x13d8 [ ABA0DD35566DA94BFF6CC988CE3910A8, BD33B0036B96EEFA87E29CDFD9D91C03D646F503B5CFA6491ACD6F703761D7E2 ] C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EngineRunOnce.exe 14:40:29.0707 0x13d8 EasyTuneEngineService - ok 14:40:29.0709 0x13d8 [ 998DC432AD3FD5414FFFCDB5E593F910, 087EAD4DACA1758597B9E030F3FA550BEA2AF78BB2CF7F42CCD947C79215D6A9 ] C:\Program Files (x86)\GIGABYTE\EasyTune\etro.exe 14:40:29.0715 0x13d8 EasyTune - detected UnsignedFile.Multi.Generic ( 1 ) 14:40:30.0713 0x13d8 Detect skipped due to KSN trusted 14:40:30.0713 0x13d8 EasyTune - ok 14:40:30.0728 0x13d8 [ 0AD2CC7B7EBD32708B189E360B30699E, 20413B0FE869E9498A5B81052E283D8FCFBE48C8272194E9BF570BF5273B9B2D ] C:\Program Files (x86)\GIGABYTE\SIV\sivro.exe 14:40:30.0744 0x13d8 SIV - detected UnsignedFile.Multi.Generic ( 1 ) 14:40:31.0179 0x13d8 Detect skipped due to KSN trusted 14:40:31.0179 0x13d8 SIV - ok 14:40:31.0194 0x13d8 [ 12AC70C6353054F56D72E2EDD6F39CC6, 22BC16080877A98E78A956F58379154AE76BDC90E1A5015932BF855EDA0D05CE ] C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe 14:40:31.0223 0x13d8 PreRun - ok 14:40:31.0275 0x13d8 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 14:40:31.0317 0x13d8 Sidebar - ok 14:40:31.0321 0x13d8 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 14:40:31.0338 0x13d8 mctadmin - ok 14:40:31.0354 0x13d8 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 14:40:31.0378 0x13d8 Sidebar - ok 14:40:31.0381 0x13d8 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 14:40:31.0395 0x13d8 mctadmin - ok 14:40:31.0438 0x13d8 [ 2F3E5E6834D1171B2CCF756729AD38BD, 86A95957B3E27A314C1BDEEC327401B5E0789D75ACAEE10F4711AECF2A9142F5 ] C:\Program Files (x86)\Steam\steam.exe 14:40:31.0479 0x13d8 Steam - ok 14:40:31.0481 0x13d8 Waiting for KSN requests completion. In queue: 12 14:40:32.0504 0x13d8 AV detected via SS2: Avast Antivirus, C:\Program Files\AVAST Software\Avast\wsc_proxy.exe ( 17.2.3419.0 ), 0x41000 ( enabled : updated ) 14:40:32.0511 0x13d8 Win FW state via NFP2: enabled ( trusted ) 14:40:32.0612 0x13d8 ============================================================ 14:40:32.0612 0x13d8 Scan finished 14:40:32.0612 0x13d8 ============================================================ 14:40:32.0626 0x1cd0 Detected object count: 0 14:40:32.0627 0x1cd0 Actual detected object count: 0 14:42:09.0839 0x1cf0 Deinitialize success |
27.03.2017, 19:40 | #6 |
/// TB-Ausbilder | Windows 7: Malware blockiert Internetverbindungen Servus, Lesestoff: Warnung vor vlc.de Den Logdateien ist zu entnehmen, dass du den bekannten VLC Player fälschlicherweise von vlc.de heruntergeladen hast. Auf dieser Seite gibt es den VLC Player nur in Kombination mit unerwünschter Software wie "Startfenster" oder "VLC Updater". Diese Software kann die Startseiten deiner Internetbrowser manipulieren und hat keinerlei Nutzen oder Mehrwert. Ich möchte dich in deinem eigenen Interesse dringend darum bitten, den VLC Player nur noch von der offiziellen Homepage videolan.org herunterzuladen. Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware 3
Schritt 3
Bitte poste mit deiner nächsten Antwort
|
28.03.2017, 18:52 | #7 |
| Windows 7: Malware blockiert Internetverbindungen AdwCleaner: Code:
ATTFilter # AdwCleaner v6.044 - Bericht erstellt am 28/03/2017 um 19:45:56 # Aktualisiert am 28/02/2017 von Malwarebytes # Datenbank : 2017-03-23.2 [Server] # Betriebssystem : Windows 7 Professional Service Pack 1 (X64) # Benutzername : Seb - GAMING-PC # Gestartet von : C:\Users\Seb\Desktop\AdwCleaner_6.044.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner gelöscht: C:\Users\Seb\AppData\Local\YSearchUtil [-] Ordner gelöscht: C:\Users\Seb\AppData\Roaming\Solvusoft [-] Ordner gelöscht: C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC UPDATER [-] Ordner gelöscht: C:\Program Files\Solvusoft [-] Ordner gelöscht: C:\ProgramData\Solvusoft [-] Ordner gelöscht: C:\ProgramData\{B96EB44A-7860-4F13-BC9A-0A73CA5F11C2} [#] Ordner mit Neustart gelöscht: C:\ProgramData\Application Data\Solvusoft [#] Ordner mit Neustart gelöscht: C:\ProgramData\Application Data\{B96EB44A-7860-4F13-BC9A-0A73CA5F11C2} [-] Ordner gelöscht: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft [-] Ordner gelöscht: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster Symbol [-] Ordner gelöscht: C:\Program Files (x86)\Solvusoft [-] Ordner gelöscht: C:\Program Files (x86)\Startfenster Symbol [-] Ordner gelöscht: C:\Program Files (x86)\VLC UPDATER [-] Ordner gelöscht: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil [-] Ordner gelöscht: C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\djhangopedggnlnicpbjklghlckmndge ***** [ Dateien ] ***** [-] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk [#] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\startfenster.lnk [-] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Startfenster Symbol.lnk [-] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\GOODGAME.LNK [-] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster Symbol.lnk [-] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\GOODGAME.LNK [-] Datei gelöscht: C:\END [-] Datei gelöscht: C:\Users\Public\Desktop\WinThruster.lnk [-] Datei gelöscht: C:\ProgramData\Microsoft\Windows\Start Menu\Startfenster.lnk [#] Datei gelöscht: C:\ProgramData\Microsoft\Windows\Start Menu\startfenster.lnk [-] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Mozilla\Extensions\startfensterde-0.0.1-an+fx-linux.xpi [-] Datei gelöscht: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\extensions\jid1-16aeif9OQIRKxA@jetpack.xpi ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht: HKU\S-1-5-21-844095808-1650209266-980683291-1000\Software\Solvusoft [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Solvusoft [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinThruster [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{80107F16-CB2E-42AB-AB9D-6C11540D5A8B} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VLC Updater [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Solvusoft [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Solvusoft [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinThruster [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{80107F16-CB2E-42AB-AB9D-6C11540D5A8B} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Installer\Features\61F70108E2BCBA24BAD9C61145D0A5B8 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Installer\Products\61F70108E2BCBA24BAD9C61145D0A5B8 [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\61F70108E2BCBA24BAD9C61145D0A5B8 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\61F70108E2BCBA24BAD9C61145D0A5B8 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Installer\Features\61F70108E2BCBA24BAD9C61145D0A5B8 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Installer\Products\61F70108E2BCBA24BAD9C61145D0A5B8 [-] Schlüssel gelöscht: HKU\S-1-5-21-844095808-1650209266-980683291-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} [-] Wert gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [CommonToolkitTray_Solvusoft] [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\VLC Updater [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Applications\Setup_WinThruster_2016.exe [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinThruster.exe [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Applications\WinThrusterSetup.exe [-] Schlüssel gelöscht: HKLM\SOFTWARE\CLASSES\APPLICATIONS\SolvusoftTray.exe [-] Schlüssel gelöscht: HKLM\SOFTWARE\Google\Chrome\Extensions\djhangopedggnlnicpbjklghlckmndge ***** [ Browser ] ***** [-] [C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default] [extension] Gelöscht: djhangopedggnlnicpbjklghlckmndge ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: "Prefetch" Dateien gelöscht :: Proxy Einstellungen zurückgesetzt :: Firewall Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [6192 Bytes] - [28/03/2017 19:45:56] C:\AdwCleaner\AdwCleaner[S0].txt - [6001 Bytes] - [28/03/2017 19:44:39] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [6338 Bytes] ########## Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 28.03.17 Scan-Zeit: 19:52 Protokolldatei: MalwareBytes.txt Administrator: Ja -Softwaredaten- Version: 3.0.6.1469 Komponentenversion: 1.0.75 Version des Aktualisierungspakets: 1.0.1600 Lizenz: Testversion -Systemdaten- Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Gaming-PC\Seb -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Ergebnis: Abgeschlossen Gescannte Objekte: 455409 Abgelaufene Zeit: 2 Min., 34 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 2 PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3F38DCD8-DF1E-490D-8D5D-E035AE143565}, In Quarantäne, [448], [345403],1.0.1600 PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B7DDC233-D4A7-4663-9683-ECCC0A4402EF}, In Quarantäne, [448], [345403],1.0.1600 Registrierungswert: 2 PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3F38DCD8-DF1E-490D-8D5D-E035AE143565}|PATH, In Quarantäne, [448], [345403],1.0.1600 PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B7DDC233-D4A7-4663-9683-ECCC0A4402EF}|PATH, In Quarantäne, [448], [345403],1.0.1600 Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Datei: 4 PUP.Optional.Solvusoft, C:\WINDOWS\TASKS\WINTHRUSTER64-SEB-STARTUP.JOB, In Quarantäne, [448], [335181],1.0.1600 PUP.Optional.Solvusoft, C:\WINDOWS\SYSTEM32\TASKS\WinThruster64-Seb-Notification, In Quarantäne, [448], [335180],1.0.1600 PUP.Optional.Solvusoft, C:\WINDOWS\SYSTEM32\TASKS\WinThruster64-Seb-Startup, In Quarantäne, [448], [335180],1.0.1600 PUP.Optional.Solvusoft, C:\WINDOWS\TASKS\WINTHRUSTER64-SEB-NOTIFICATION.JOB, In Quarantäne, [448], [335181],1.0.1600 Physischer Sektor: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017 durchgeführt von Seb (Administrator) auf GAMING-PC (28-03-2017 20:12:31) Gestartet von C:\Users\Seb\Desktop Geladene Profile: Seb (Verfügbare Profile: Seb) Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe (OSBASE) C:\Windows\System32\ddmgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (pdfforge GmbH) P:\Programme\PDF Architect 4\creator-ws.exe (© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (DEVGURU Co., LTD.) P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngine.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe () C:\Windows\System32\flvga_tray.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\SIV\thermald.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) P:\Programme\Mozilla Thunderbird\thunderbird.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-27] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [flvga_tray64] => C:\Windows\system32\flvga_tray.exe [419328 2015-05-14] () HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-18] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM-x32\...\RunOnce: [EasyTuneEngineService] => C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EngineRunOnce.exe [14632 2016-05-03] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [EasyTune] => C:\Program Files (x86)\GIGABYTE\EasyTune\etro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [SIV] => C:\Program Files (x86)\GIGABYTE\SIV\sivro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe [14632 2016-02-26] () HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-03-23] (Valve Corporation) HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\MountPoints2: {d30ece49-96c7-11e6-bcff-806e6f6e6963} - D:\ZToolBar.exe ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-18] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-18] (AVAST Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-10-20] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{EE112510-05F2-423F-9B82-4CF134C99522}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== SearchScopes: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> {DA6F9CB8-5F1C-45FC-AB8D-6C4B3457583F} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-01-29] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-01-29] (Microsoft Corporation) BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-29] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-29] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2016-08-05] (pdfforge GmbH) Toolbar: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: 8i010wxq.default FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default [2017-03-26] FF NetworkProxy: Mozilla\Firefox\Profiles\8i010wxq.default -> type", 0 FF Extension: (Flash Video Downloader - YouTube HD Download [4K]) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\artur.dubovoy@gmail.com [2017-02-20] FF Extension: (ColorZilla) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-03-09] FF Extension: (Site Deployment Checker) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\features\{07233581-9539-488f-93b7-c5fc51995368}\deployment-checker@mozilla.org.xpi [2017-03-26] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\jgc1n486.Standard-Benutzer [2016-12-27] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\xs280j99.Standard-Benutzer1 [2016-12-27] FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension FF Extension: (PDF Architect 4 Creator) - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension [2017-01-08] [ist nicht signiert] FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-11-10] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-11-10] (VideoLAN) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-01-29] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH) Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default CHR DefaultSearchKeyword: Default -> Yahoo CHR DefaultSuggestURL: Default -> hxxps://de.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Profile: C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default [2017-02-02] CHR Extension: (Google Präsentationen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-20] CHR Extension: (Google Docs) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-20] CHR Extension: (Google Drive) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-20] CHR Extension: (YouTube) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-20] CHR Extension: (Google-Suche) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-10-20] CHR Extension: (Yahoo Partner) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabhkdeopjkcpkmofliimbjckmocfiom [2016-12-28] CHR Extension: (Google Tabellen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-20] CHR Extension: (Google Docs Offline) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-01] CHR Extension: (Avast Online Security) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-28] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-20] CHR Extension: (Google Mail) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-20] CHR Extension: (Chrome Media Router) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-28] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fabhkdeopjkcpkmofliimbjckmocfiom] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-18] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-18] (AVAST Software) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3704520 2017-02-18] (Microsoft Corporation) R2 ddmgr; C:\Windows\system32\ddmgr.exe [1659040 2016-01-04] (OSBASE) S3 Disc Soft Lite Bus Service; P:\Programme\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1468608 2016-10-06] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-25] (EasyAntiCheat Ltd) R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [142656 2016-06-01] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 ElfoService; P:\Programme\ElsterFormular Update Service\bin\ElfoService.exe [1283376 2017-02-13] () R2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [Datei ist nicht signiert] S3 HwmRecordService; C:\Program Files (x86)\GIGABYTE\SIV\HwmRecordService.exe [118568 2016-05-24] (GIGA-BYTE TECHNOLOGY CO., LTD.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21184 2016-03-29] (Microsoft Corporation) R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-02-12] (Rivet Networks) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440 2017-03-17] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-02-23] (NVIDIA Corporation) S2 OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [127272 2016-05-20] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2121736 2017-01-24] (Electronic Arts) S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2183696 2017-01-24] (Electronic Arts) S3 PDF Architect 4; P:\Programme\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH) S3 PDF Architect 4 CrashHandler; P:\Programme\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Creator; P:\Programme\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-11-06] () R2 ss_conn_service; P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.) S3 Te.Service; C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [137216 2016-03-29] (Microsoft Corporation) [Datei ist nicht signiert] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10362608 2016-12-15] (TeamViewer GmbH) S3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [1831064 2015-11-04] (Intel Corporation) S3 VSStandardCollectorService140; P:\Programme (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] () R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [309272 2017-03-18] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-18] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334600 2017-03-18] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-18] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-18] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [126600 2017-03-18] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [100640 2017-03-18] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-18] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [993608 2017-03-18] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [548928 2017-03-21] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162528 2017-03-18] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [337592 2017-03-18] (AVAST Software) R3 ausb3hub; C:\Windows\System32\DRIVERS\ausb3hub.sys [404480 2016-10-20] (Intel Corporation) R3 ausb3xhc; C:\Windows\System32\DRIVERS\ausb3xhc.sys [817664 2016-10-20] (Intel Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-02-12] (Rivet Networks, LLC.) R4 ddkmd; C:\Windows\system32\drivers\ddkmd.sys [254968 2016-01-04] (OSBASE) [Datei ist nicht signiert] R0 ddkmdldr; C:\Windows\System32\drivers\ddkmdldr.sys [16888 2016-01-04] (OSBASE) [Datei ist nicht signiert] S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-10-22] (Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-10-22] (Disc Soft Ltd) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77408 2017-02-24] () R3 FLxHCIv; C:\Windows\System32\Drivers\FLxHCIv.sys [199304 2016-01-08] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31728 2015-11-12] (Intel Corporation) R3 KillerEth; C:\Windows\System32\DRIVERS\e2xw7x64.sys [134296 2016-02-12] (Qualcomm Atheros, Inc.) R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-03-26] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-03-26] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-03-26] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251840 2017-03-26] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82208 2017-03-26] (Malwarebytes) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation) S3 nhi; C:\Windows\System32\DRIVERS\tbt70x.sys [126464 2015-11-10] (Intel Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-02-23] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2017-01-20] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (The OpenVPN Project) [Datei ist nicht signiert] S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] () S3 vmulti; C:\Windows\System32\DRIVERS\vmulti.sys [19504 2016-01-13] (Windows (R) Win 7 DDK provider) R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-26 15:12 - 2017-03-26 15:12 - 00025255 _____ C:\Users\Seb\Desktop\FRST.txt 2017-03-26 15:12 - 2017-03-26 15:12 - 00002351 _____ C:\Users\Seb\Desktop\MalwareBytes.txt 2017-03-26 14:59 - 2017-03-26 14:59 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-03-26 14:53 - 2017-03-26 14:54 - 93433704 _____ C:\Users\Seb\Downloads\UT_PCE_AC68_2115.zip 2017-03-26 14:52 - 2017-03-26 14:59 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-03-26 14:52 - 2017-03-26 14:59 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-03-26 14:52 - 2017-03-26 14:59 - 00082208 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-03-26 14:52 - 2017-03-26 14:58 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-03-26 14:51 - 2017-03-26 14:58 - 00251840 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-03-26 14:51 - 2017-03-26 14:51 - 00001874 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\Program Files\Malwarebytes 2017-03-26 14:51 - 2017-02-24 06:23 - 00077408 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-03-26 14:50 - 2017-03-26 14:50 - 57131432 _____ (Malwarebytes ) C:\Users\Seb\Desktop\mb3-setup-consumer-3.0.6.1469-1075.exe 2017-03-26 14:45 - 2017-03-26 14:45 - 00006461 _____ C:\Users\Seb\Desktop\AdwCleaner[C0].txt 2017-03-26 14:43 - 2017-03-26 15:10 - 00000000 ____D C:\AdwCleaner 2017-03-26 14:42 - 2017-03-26 14:42 - 04031440 _____ C:\Users\Seb\Desktop\AdwCleaner_6.044.exe 2017-03-26 14:38 - 2017-03-26 14:42 - 00233058 _____ C:\Users\Seb\Desktop\TDSSKiller.3.1.0.12_26.03.2017_14.38.22_log.txt 2017-03-26 14:31 - 2017-03-26 15:12 - 00000000 ____D C:\FRST 2017-03-26 14:31 - 2017-03-26 14:32 - 00081292 _____ C:\Users\Seb\Desktop\FRST1.txt 2017-03-26 14:31 - 2017-03-26 14:32 - 00073700 _____ C:\Users\Seb\Desktop\Addition1.txt 2017-03-26 14:31 - 2017-03-26 14:31 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Seb\Desktop\tdsskiller.exe 2017-03-26 14:30 - 2017-03-26 14:30 - 02424832 _____ (Farbar) C:\Users\Seb\Desktop\FRST64.exe 2017-03-24 20:49 - 2017-03-26 14:59 - 00196286 _____ C:\Windows\SysWOW64\bios.ini 2017-03-24 20:44 - 2017-03-24 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE 2017-03-24 12:54 - 2017-03-24 12:54 - 00038955 _____ C:\Users\Seb\Downloads\Augenaerztlicher_Vorabbefund.pdf 2017-03-22 02:10 - 2017-03-22 02:10 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Playsport Games 2017-03-22 00:24 - 2017-03-22 00:24 - 00000222 _____ C:\Users\Seb\Desktop\Motorsport Manager.url 2017-03-22 00:02 - 2017-03-22 00:02 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-03-22 00:02 - 2017-03-17 00:56 - 00134592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-03-22 00:02 - 2017-01-26 02:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-03-22 00:02 - 2017-01-26 02:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe 2017-03-22 00:00 - 2017-03-17 02:59 - 40190400 _____ C:\Windows\system32\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 34952760 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 28223544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 17282648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 16400616 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14674712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14434360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 11122912 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 04064088 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03627064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03187256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 01053240 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00989120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00912440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00504104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00492560 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00425104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00408272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 00170360 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00153368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:31 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-03-21 23:49 - 2017-03-08 06:22 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:18 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-03-21 23:49 - 2017-03-08 06:07 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:06 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-03-21 23:49 - 2017-03-04 19:24 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 18:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 10:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-03-21 23:49 - 2017-03-04 10:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-03-21 23:49 - 2017-03-04 10:02 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-03-21 23:49 - 2017-03-04 10:01 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-04 09:59 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-03-21 23:49 - 2017-03-04 09:52 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-03-21 23:49 - 2017-03-04 09:51 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-03-21 23:49 - 2017-03-04 09:48 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-03-21 23:49 - 2017-03-04 09:46 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-03-21 23:49 - 2017-03-04 09:45 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-03-21 23:49 - 2017-03-04 09:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-03-21 23:49 - 2017-03-04 09:36 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-03-21 23:49 - 2017-03-04 09:32 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-03-21 23:49 - 2017-03-04 09:31 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-03-21 23:49 - 2017-03-04 09:23 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-04 09:21 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-03-21 23:49 - 2017-03-04 09:13 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-03-21 23:49 - 2017-03-04 09:11 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-03-21 23:49 - 2017-03-04 08:57 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-03-21 23:49 - 2017-03-04 08:55 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-03-21 23:49 - 2017-03-04 08:54 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-03-21 23:49 - 2017-03-04 08:52 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-03-21 23:49 - 2017-03-04 08:52 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-04 08:26 - 15259648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-03-21 23:49 - 2017-03-04 08:25 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-03-21 23:49 - 2017-03-04 08:12 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-03-21 23:49 - 2017-03-04 08:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-03-21 23:49 - 2017-03-04 06:18 - 20281856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-03-21 23:49 - 2017-03-02 20:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-03-21 23:49 - 2017-03-02 20:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-03-21 23:49 - 2017-03-02 20:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-02 20:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-02 19:55 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-03-21 23:49 - 2017-03-02 19:54 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-03-21 23:49 - 2017-03-02 19:53 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-03-21 23:49 - 2017-03-02 19:51 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-03-21 23:49 - 2017-03-02 19:50 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-03-21 23:49 - 2017-03-02 19:49 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-03-21 23:49 - 2017-03-02 19:49 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-03-21 23:49 - 2017-03-02 19:41 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-03-21 23:49 - 2017-03-02 19:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-02 19:35 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-03-21 23:49 - 2017-03-02 19:32 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-03-21 23:49 - 2017-03-02 19:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-03-21 23:49 - 2017-03-02 19:29 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-03-21 23:49 - 2017-03-02 19:28 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-03-21 23:49 - 2017-03-02 19:22 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-03-21 23:49 - 2017-03-02 19:21 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-03-21 23:49 - 2017-03-02 19:19 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-03-21 23:49 - 2017-03-02 19:17 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-03-21 23:49 - 2017-03-02 19:17 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-02 19:11 - 13654528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-03-21 23:49 - 2017-03-02 18:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 01312768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-03-21 23:49 - 2017-02-14 18:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-03-21 23:49 - 2017-02-14 18:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-03-21 23:49 - 2017-02-11 18:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-03-21 23:49 - 2017-02-11 18:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-03-21 23:49 - 2017-02-11 17:58 - 00462848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-03-21 23:49 - 2017-02-10 18:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:32 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-03-21 23:49 - 2017-02-10 16:33 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-03-21 23:49 - 2017-02-09 18:36 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:35 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-03-21 23:49 - 2017-02-09 18:35 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-03-21 23:49 - 2017-02-09 18:33 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:19 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-03-21 23:49 - 2017-02-09 18:19 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:16 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-03-21 23:49 - 2017-02-09 18:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-03-21 23:49 - 2017-02-09 18:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-03-21 23:49 - 2017-02-09 18:02 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-03-21 23:49 - 2017-02-09 18:00 - 03220480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-03-21 23:49 - 2017-02-09 17:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-03-21 23:49 - 2017-02-09 17:58 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-03-21 23:49 - 2017-02-09 17:55 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-03-21 23:49 - 2017-02-09 17:54 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-03-21 23:49 - 2017-02-09 17:54 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-03-21 23:49 - 2017-02-09 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-03-21 23:49 - 2017-02-09 17:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-03-21 23:49 - 2017-02-09 17:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-03-21 23:49 - 2017-02-06 18:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-03-21 23:49 - 2017-01-18 17:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-03-21 23:49 - 2017-01-06 20:00 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-03-21 23:49 - 2017-01-06 19:44 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437892.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437892.dll 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-03-21 23:27 - 2017-03-21 23:27 - 00000000 ____D C:\ProgramData\Codemasters 2017-03-21 19:23 - 2017-02-23 01:42 - 00084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-03-21 19:23 - 2017-02-23 01:37 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 01609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00398408 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-03-03 19:42 - 2017-03-03 19:42 - 00001416 _____ C:\Users\Seb\Desktop\RAGEPluginHook.exe - Verknüpfung (2).lnk 2017-02-27 00:37 - 2017-02-27 00:58 - 00000000 ____D C:\Users\Seb\Downloads\GTA 5 Mods 2017-02-26 21:04 - 2017-02-27 00:37 - 00000000 ____D C:\Users\Seb\Downloads\GTA 5 mods - installed 2017-02-25 21:43 - 2017-02-25 21:43 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Promotion Software GmbH 2017-02-25 20:47 - 2017-02-26 21:09 - 00000000 ____D C:\Users\Seb\Downloads\Neuer Ordner (2) 2017-02-25 20:02 - 2017-02-25 20:02 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2017-02-25 20:01 - 2017-02-25 20:01 - 00001132 _____ C:\Users\Public\Desktop\DLL-Files.com Client.lnk 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\Users\Seb\AppData\Roaming\DLL-files.com 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\Users\Seb\AppData\Roaming\DFXCT 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DLL-Files.com Client 2017-02-25 20:01 - 2017-02-25 20:01 - 00000000 ____D C:\Program Files (x86)\DLL-Files.com Client 2017-02-25 19:15 - 2017-02-25 19:15 - 00000222 _____ C:\Users\Seb\Desktop\Emergency 2017.url ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-26 15:06 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-26 15:06 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-26 15:04 - 2010-11-21 08:50 - 00700130 _____ C:\Windows\system32\perfh007.dat 2017-03-26 15:04 - 2010-11-21 08:50 - 00149768 _____ C:\Windows\system32\perfc007.dat 2017-03-26 15:04 - 2009-07-14 07:13 - 01622706 _____ C:\Windows\system32\PerfStringBackup.INI 2017-03-26 15:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2017-03-26 15:00 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\NVIDIA 2017-03-26 14:59 - 2016-11-25 19:53 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Mozilla 2017-03-26 14:59 - 2016-10-29 09:31 - 00026192 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2017-03-26 14:59 - 2016-10-20 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2017-03-26 14:58 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-26 14:55 - 2016-10-20 18:58 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-03-24 21:01 - 2016-10-21 20:20 - 00000000 ____D C:\Users\Seb\AppData\Roaming\FileZilla 2017-03-24 20:44 - 2016-10-29 09:29 - 00000000 ____D C:\Program Files (x86)\GIGABYTE 2017-03-24 19:37 - 2017-02-17 05:06 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2017-03-24 15:34 - 2016-10-20 18:43 - 00000000 ____D C:\Users\Seb\AppData\Roaming\vlc 2017-03-24 12:55 - 2016-03-30 09:16 - 00000000 ____D C:\Users\Seb\Documents\Bewerbungen 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-03-22 00:19 - 2009-07-14 06:45 - 00556104 _____ C:\Windows\system32\FNTCACHE.DAT 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ___SD C:\Windows\system32\CompatTel 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ____D C:\Windows\system32\appraiser 2017-03-22 00:03 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-03-22 00:03 - 2016-10-20 15:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-03-21 23:53 - 2016-10-29 07:22 - 00000000 ____D C:\Windows\system32\MRT 2017-03-21 23:51 - 2016-10-29 07:22 - 138634176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-03-21 23:50 - 2017-02-13 03:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-03-21 23:45 - 2016-11-08 20:50 - 00000000 ____D C:\ProgramData\Skype 2017-03-21 23:27 - 2016-10-25 17:51 - 00000000 ____D C:\Users\Seb\Documents\My Games 2017-03-21 23:24 - 2016-11-30 16:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-21 23:24 - 2016-10-20 15:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-21 23:18 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-03-21 23:06 - 2017-02-02 21:35 - 00004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2017-02-02 21:35 - 00001419 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2017-03-21 23:06 - 2016-10-29 09:20 - 00003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-20 15:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-03-21 23:06 - 2016-10-20 15:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-03-21 19:25 - 2017-01-03 00:52 - 00548928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2017-03-18 17:46 - 2017-01-03 00:52 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00334600 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00309272 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-03-18 17:45 - 2017-02-07 22:10 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-03-18 17:45 - 2017-01-03 00:52 - 00993608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00547904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.148985196613904 2017-03-18 17:45 - 2017-01-03 00:52 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.148985196721606 2017-03-18 17:45 - 2017-01-03 00:52 - 00162528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00126600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00100640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2017-03-18 17:45 - 2017-01-03 00:52 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2017-03-17 02:59 - 2017-02-15 02:55 - 19883600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 13378096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 03583744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2017-03-17 02:59 - 2016-10-20 15:47 - 00042686 _____ C:\Windows\system32\nvinfo.pb 2017-03-17 02:59 - 2015-11-06 12:23 - 01600056 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2017-03-17 01:31 - 2016-10-29 09:20 - 00001951 _____ C:\Windows\NvContainerRecovery.bat 2017-03-17 01:16 - 2016-10-29 09:32 - 00549944 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2017-03-17 01:16 - 2016-10-29 09:32 - 00081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 02477504 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2017-03-16 11:39 - 2016-10-20 15:47 - 07813427 _____ C:\Windows\system32\nvcoproc.bin 2017-03-09 20:52 - 2016-12-10 12:46 - 00000000 ____D C:\Users\Seb\Desktop\Steuer 2017-03-03 20:14 - 2016-10-21 15:41 - 00000000 ____D C:\Fraps 2017-03-03 18:28 - 2016-10-26 18:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-03-03 18:27 - 2016-10-20 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-03-02 22:42 - 2016-12-19 01:43 - 00000000 ____D C:\Users\Seb\Documents\Visual Studio 2015 2017-02-28 19:44 - 2016-10-22 11:21 - 00000000 ____D C:\Users\Seb\AppData\Local\Deployment 2017-02-27 01:22 - 2016-10-25 17:56 - 00000000 ____D C:\Users\Seb\AppData\Local\CrashDumps 2017-02-26 21:05 - 2017-02-18 20:20 - 00000000 ____D C:\Users\Seb\AppData\Local\Albo1125 2017-02-26 13:13 - 2016-10-22 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2017-02-25 19:56 - 2016-08-10 15:38 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2017-02-25 19:52 - 2016-10-20 15:49 - 00000000 ____D C:\Users\Seb\AppData\Local\NVIDIA Corporation ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-10-26 18:41 - 2016-11-11 20:08 - 0000104 _____ () C:\Users\Seb\AppData\Roaming\Camdata.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamLayout.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamShapes.ini 2016-10-26 18:41 - 2016-11-11 17:06 - 0004535 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.cfg 2016-11-11 17:06 - 2016-11-11 17:06 - 0000000 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.Data.ini 2016-11-11 17:06 - 2016-11-11 17:06 - 0001206 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.ini 2016-10-26 18:41 - 2016-11-11 18:13 - 0000096 _____ () C:\Users\Seb\AppData\Roaming\version2.xml 2016-11-25 20:37 - 2017-01-06 22:17 - 0007602 _____ () C:\Users\Seb\AppData\Local\resmon.resmoncfg 2016-10-20 15:26 - 2016-10-20 15:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2016-10-22 11:23 - 2016-10-22 11:23 - 0000185 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2016-02-28 19:58 - 2016-02-28 19:58 - 0010218 _____ () C:\ProgramData\regid.2015-05.exe.textpad_83F5EF12-C2F9-4C11-A5C5-57A7B2D7AD25.swidtag Einige Dateien in TEMP: ==================== 2016-11-20 15:25 - 2017-02-10 00:39 - 0754168 _____ (NVIDIA Corporation) C:\Users\Seb\AppData\Local\Temp\nvSCPAPI.dll 2017-03-21 23:49 - 2017-02-10 00:39 - 0352704 _____ (NVIDIA Corporation) C:\Users\Seb\AppData\Local\Temp\nvStInst.exe 2017-03-21 23:44 - 2017-03-21 23:44 - 14456872 _____ (Microsoft Corporation) C:\Users\Seb\AppData\Local\Temp\vc_redist.x86.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-03-18 18:59 ==================== Ende von FRST.txt ============================ |
28.03.2017, 18:54 | #8 |
| Windows 7: Malware blockiert Internetverbindungen Addition: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017 durchgeführt von Seb (28-03-2017 20:12:49) Gestartet von C:\Users\Seb\Desktop Windows 7 Professional Service Pack 1 (X64) (2016-10-19 19:46:39) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-844095808-1650209266-980683291-500 - Administrator - Disabled) Gast (S-1-5-21-844095808-1650209266-980683291-501 - Limited - Disabled) Seb (S-1-5-21-844095808-1650209266-980683291-1000 - Administrator - Enabled) => C:\Users\Seb ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) @BIOS B16.0608.1 (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) @BIOS B16.0608.1 (x32 Version: 3.00.0000 - GIGABYTE) Hidden Active Directory Authentication Library für SQL Server (Version: 13.0.1601.5 - Microsoft Corporation) Hidden Active Directory Authentication Library für SQL Server (x86) (x32 Version: 13.0.1601.5 - Microsoft Corporation) Hidden Ambient LED (HKLM-x32\...\InstallShield_{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.2501 - GIGABYTE) Ambient LED (x32 Version: 1.00.1605.2501 - GIGABYTE) Hidden Ansel (Version: 378.92 - NVIDIA Corporation) Hidden APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1703.2301 - GIGABYTE) APP Center (x32 Version: 1.00.1703.2301 - GIGABYTE) Hidden Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation) Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.26.1 - Asmedia Technology) Audacity 1.2.6 (HKLM-x32\...\Audacity_is1) (Version: - ) Audacity Recovery Utility (HKLM-x32\...\AURC_is1) (Version: - Markus Meyer) Autobahn Police Simulator (HKLM\...\Steam App 348510) (Version: - Z-Software) Avast Internet Security (HKLM-x32\...\Avast Antivirus) (Version: 17.2.2288 - AVAST Software) Azure AD Authentication Connected Service (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.7.2.45672 - Electronic Arts) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.47.30570 - Electronic Arts) Battlefield™ Hardline (HKLM-x32\...\{CB4AC3DA-8CC1-4516-86DA-4078B57DB229}) (Version: 1.4.0.10 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50716.0 - Microsoft Corporation) Hidden Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.51210.80 - Microsoft Corporation) Hidden BIOS Setup (HKLM-x32\...\InstallShield_{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) BIOS Setup (x32 Version: 1.00.0000 - GIGABYTE) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation) Build Tools - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Build Tools Language Resources - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Buildtools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Bus Simulator 16 (HKLM\...\Steam App 324310) (Version: - stillalive studios) Call of Duty: Infinite Warfare (HKLM\...\Steam App 292730) (Version: - Infinity Ward) CodedUITestUAP (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Color Temperature (HKLM-x32\...\InstallShield_{68BFE28B-3F55-4E00-90A4-5179B91A3BD0}) (Version: 16.05.0601 - GIGABYTE) Color Temperature (x32 Version: 16.05.0601 - GIGABYTE) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0196 - Disc Soft Ltd) Demolish & Build 2017 (HKLM\...\Steam App 470740) (Version: - Noble Muffins) Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden DLL-Files.com Client (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_DLL-Files.c~79141F26_is1) (Version: 2.1.1000.4462 - DLL-Files.com Client) Dotfuscator and Analytics Community Edition 5.22.0 (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden Dotfuscator and Analytics Community Edition Language Pack 5.22.0 de-DE (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.0506 - GIGABYTE) EasyTune (x32 Version: 1.16.0506 - GIGABYTE) Hidden EasyTuneEngineService (HKLM-x32\...\InstallShield_{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 2.16.0603 - GIGABYTE) EasyTuneEngineService (x32 Version: 2.16.0603 - GIGABYTE) Hidden ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 18.1.22140 - Landesfinanzdirektion Thüringen) Emergency 2017 (HKLM\...\Steam App 524110) (Version: - Sixteen Tons Entertainment) Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{3FF082A7-A5DE-4BDA-B56A-1D2BEFD617A3}) (Version: 11.1.3000.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{FD639F4D-1460-42E6-B32D-FEC1745D0BDC}) (Version: 13.0.1601.5 - Microsoft Corporation) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) F1 2016 (HKLM\...\Steam App 391040) (Version: - Codemasters) Farming Simulator 17 (HKLM\...\Steam App 447020) (Version: - Giants Software) Fast Boot (HKLM-x32\...\InstallShield_{FA8FB4F2-F524-48E1-A06C-45602FBF26CD}) (Version: 1.16.0406 - GIGABYTE) Fast Boot (x32 Version: 1.16.0406 - GIGABYTE) Hidden Fernbus Simulator (HKLM\...\Steam App 427100) (Version: - TML-Studios) FileZilla Client 3.24.1 (HKLM-x32\...\FileZilla Client) (Version: 3.24.1 - Tim Kosse) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2013 Sprachpaket (DEU) - v1.6 (x32 Version: 1.6.30930.3 - Microsoft Corporation) Hidden Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket – DEU - v1.8 (x32 Version: 1.8.40521.1 - Microsoft Corporation) Hidden GIANTS Editor 7.0.0 64-bit (HKLM-x32\...\giants_editor_7.0.0_win64_is1) (Version: 7.0.0 - GIANTS Software GmbH) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North) Greenshot 1.2.8.14 (HKLM\...\Greenshot_is1) (Version: 1.2.8.14 - Greenshot) IDE Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IDE-Tools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.1.40 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel® USB 3.1 Device Driver (HKLM\...\{7DFE2F7E-3154-45D6-A468-4725DE033AC8}) (Version: 15.2.30.250 - Intel Corporation) Intellisense Lang Pack Mobile Extension SDK 10.0.10586.0 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Killer Bandwidth Control Filter Driver (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer E240x Drivers (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Network Manager (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{009DF489-4590-4579-BAB2-0136BB829E4A}) (Version: 1.1.57.1346 - Rivet Networks) Kinect for Windows Speech Recognition Language Pack (de-DE) (HKLM-x32\...\{898AA67F-99B8-4C7F-9611-B11F98EF6E78}) (Version: 11.0.7413.611 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-AU) (HKLM-x32\...\{48CEC0A3-AE10-4EE3-AC62-76D3D58792E5}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-CA) (HKLM-x32\...\{9C5505DA-F9C1-46CB-9F8F-AC38F8EA518A}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-GB) (HKLM-x32\...\{A0186231-0A8B-455A-8A25-B64AABCC11A6}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-US) (HKLM-x32\...\{8AAA44BB-487E-4D01-AF76-484ACB90DBFE}) (Version: 11.0.7400.336 - Microsoft Corporation) Kits Configuration Installer (x32 Version: 10.0.26624 - Microsoft) Hidden KRISTAL Audio Engine (HKLM-x32\...\KRISTAL Audio Engine) (Version: - ) Leadwerks Game Engine (HKLM\...\Steam App 251810) (Version: - Leadwerks Software) MAGIX Common Components 1 (x64) (HKLM\...\{05799CB2-47FA-4322-9776-C0D15991EE7E}) (Version: 1.6.1.0 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\MX.{410B406D-6A35-41FF-B458-ADB0D3563487}) (Version: 2.0.1.145 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\Steam App 330130) (Version: - MAGIX Software GmbH) MAGIX Fastcut (Version: 2.0.1.145 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.4.235 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.5.273 - MAGIX Software GmbH) Hidden MAGIX Fonts Package 1 (x32 Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Screenshare (HKLM-x32\...\{20C81F73-2600-464A-BA60-401739102479}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{AB8304F0-383F-4F80-8988-87727C415BF7}) (Version: 7.0.2.6 - MAGIX Software GmbH) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX Software GmbH) Hidden MAGIX Video deluxe 2015 (HKLM\...\MX.{FFDC29E6-5C7C-4AA8-AF5A-99E015165382}) (Version: 14.0.0.159 - MAGIX Software GmbH) MAGIX Video deluxe 2015 (Version: 14.0.0.159 - MAGIX Software GmbH) Hidden MAGIX Videoton Cleaning Lab (HKLM-x32\...\MAGIX_MSI_Videoton_Cleaning_Lab) (Version: 1.0.0.0 - MAGIX AG) MAGIX Videoton Cleaning Lab (x32 Version: 1.0.0.0 - MAGIX AG) Hidden Malwarebytes Version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (HKLM-x32\...\{21B0F482-5EF9-45DA-8840-340AFE705A6C}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (Deutsch) (HKLM-x32\...\{529EFF09-750D-48B9-A47A-34A3B6248C3F}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Build Tools 2015 (HKLM-x32\...\{d21da0dd-4ba4-4838-ba58-64cf7a77131a}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.1 Sprachpaket - DEU) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.7766.2060 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft Server Speech Platform Runtime (x64) (HKLM\...\{3B433087-E62E-4BF5-97F9-4AF6E1C2409C}) (Version: 11.0.7400.345 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50905.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (HKLM-x32\...\{F351AA2C-723C-4CFE-A7CB-8E43AB164F7F}) (Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{D4E30517-FE6F-491E-942F-AE10E1B18F38}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{B4EDAE03-DB34-4DD0-BA7E-2ED80DEA50B1}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{269A8DF6-BBDA-441F-932B-233F9B746D72}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{EC75BD20-F9CA-4E77-825F-ABD77E95BE91}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{0BF65908-D137-4A9E-B7C9-78F32F74F6FD}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{93945D16-4C3D-433E-B7E4-3D0D86B284C8}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{6F173435-3F19-4043-BA3D-A46AA8472859}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL-Sprachdienst (HKLM-x32\...\{1D812D86-D8EF-41AC-A518-BA12E1913747}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2016 LocalDB (HKLM\...\{1765D93F-97E4-44D3-951D-0DA09B89EE17}) (Version: 13.0.2151.0 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (x64) (HKLM\...\{264B070C-82D7-4C9C-B1CE-A0B124BCC787}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM\...\{619537F4-1E39-4047-AA4F-D2D98A1DA743}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM-x32\...\{4EFF12AE-599C-42A2-ACFA-0D95C3B11A19}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL ScriptDom (HKLM\...\{E8F3D249-7DE6-4422-AC86-1CE7D5CCFA0F}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (12.0.61021.0) (HKLM-x32\...\{A8689DE4-28A2-4F57-9A5F-A4851A8FD849}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (14.0.60519.0) (HKLM-x32\...\{9F367648-EC0C-4F97-B351-D12A51E38F96}) (Version: 14.0.60519.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - Visual Studio 2013 (HKLM-x32\...\{1d259390-0778-4f41-8024-8c826a8ead96}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (12.0.30919.1) (HKLM-x32\...\{BCB8A870-2B3D-4CC0-87D6-F931E065AC0C}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server*2014 Express LocalDB (HKLM\...\{CA191120-4CB1-4E3D-89B8-79FDB9017A2E}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Transact-SQL ScriptDom (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 T-SQL Language Service (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2016 Management Objects (HKLM-x32\...\{35A7B00B-4F9C-4B4D-919C-86FFFEE46AD6}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{9634d50a-0c4d-4f52-8a9f-894a2baae370}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{307a22b8-8353-4c5e-b67b-2404c5734558}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio Community 2015 mit Updates (HKLM-x32\...\{ec2556f3-08aa-4829-8017-07d7ea9e125d}) (Version: 14.0.25420.1 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (HKLM-x32\...\{43341417-7882-4F34-8390-53DFD00F6C0F}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (HKLM\...\{24440413-490E-41CA-BD33-0B30FD3EBE3A}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{7F6DCED8-6A2B-4436-AF20-8F659D04E388}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{48BF289B-F3FA-4023-9251-80ABF7B726F9}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM\...\{FEC926D4-785B-4ED7-B35D-3FA37DD29F8B}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM-x32\...\{A37BE9D7-EAAE-4C6B-9D7E-DBD8B8D88681}) (Version: 13.0.1601.5 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden Motorsport Manager (HKLM\...\Steam App 415200) (Version: - Playsport Games) Mozilla Firefox 52.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 52.0.1 (x86 de)) (Version: 52.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.1.6284 - Mozilla) Mozilla Thunderbird 45.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 45.2.0 (x86 de)) (Version: 45.2.0 - Mozilla) Mozilla Thunderbird 45.8.0 (x86 de) (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Mozilla Thunderbird 45.8.0 (x86 de)) (Version: 45.8.0 - Mozilla) MSBuild/NuGet Integration 14.0 (x86) (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Napster (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\5d01cae694a4998b) (Version: 6.17.42.0 - Rhapsody International Inc.) Need for Speed™ The Run (HKLM-x32\...\{0EDC9BA0-016E-406a-86DA-04FC1BE00C21}) (Version: 1.1.0.0 - Electronic Arts) Notruf 112 (HKLM\...\Steam App 491530) (Version: - Crenetic GmbH Studios) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation) NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation) NVIDIA Grafiktreiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.16.2 - OBS Project) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) ON_OFF Charge 2 B15.0709.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden OpenIV (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OpenIV) (Version: 2.8.703 - .black/OpenIV Team) Origin (HKLM-x32\...\Origin) (Version: 10.4.2.12697 - Electronic Arts, Inc.) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{FACF2669-E25A-428A-9167-5EEDE741F3B9}) (Version: 4.6.00127 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM-x32\...\{4860C1E5-CE58-4D32-89DE-37951333B4C9}) (Version: 4.6.01055 - Microsoft Corporation) PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.26.25466 - pdfforge GmbH) PDF Architect 4 Asian Fonts Pack (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Convert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Forms Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Insert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 OCR Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Review Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Secure Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Projekt- und Elementvorlagen für Visual Studio Express 2015 für Windows 10 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Projekt- und Elementvorlagen für Visual Studio Professional 2015 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.994 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7727 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.4 - Rockstar Games) Roslyn Language Services - x86 (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden SIV (HKLM-x32\...\InstallShield_{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.16.0525 - GIGABYTE) SIV (x32 Version: 1.16.0525 - GIGABYTE) Hidden SketchUp 2017 (HKLM\...\{5A8C61BD-0912-4B76-805E-4EDE5E13298C}) (Version: 17.1.174 - Trimble Navigation Limited) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Hidden SmartKeyboard (HKLM-x32\...\InstallShield_{75B74C36-A9C6-4912-B4BB-C461AA36D01E}) (Version: 1.00.0000 - GIGABYTE) SmartKeyboard (x32 Version: 1.00.0000 - GIGABYTE) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (x32 Version: 14.102.25619 - Microsoft) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) TeamViewer 12 Host (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer) Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios) Thin2000 USB Display Adapter (HKLM\...\{CB5F5631-515F-4C70-ACA5-3FAAFA1866BC}) (Version: 1.1.323.0 - Fresco Logic) Thunderbolt(TM) Software (HKLM-x32\...\{B0E8A8CA-5A40-49C3-BE5E-9076664DB9AA}) (Version: 15.3.39.250 - Intel Corporation) TypeScript Power Tool (x32 Version: 1.8.34.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.36.0 - Microsoft Corporation) Hidden UE4 Prerequisites (x64) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (x32 Version: 1.0.13.0 - Epic Games, Inc.) Hidden Universal CRT Extension SDK (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Redistributable (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x64 (Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x86 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation) VLC media player (HKLM\...\VLC media player) (Version: 2.2.5 - VideoLAN) VS Update core components (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden vs_update3notification (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Watch_Dogs 2 (HKLM\...\Steam App 447040) (Version: - Ubisoft) WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation) WinAppDeploy (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Windows SDK AddOn (HKLM-x32\...\{75C39BA6-1D02-4BEA-844F-0EA6C4B7FA1B}) (Version: 10.1.0.0 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.10586.212 (HKLM-x32\...\{43d9f43d-c90b-4fdf-9dfe-ecf9990bfa2a}) (Version: 10.1.10586.212 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.26624 (HKLM-x32\...\{e7a0c8b6-b0e9-41e2-8a0a-a6784f88d1d4}) (Version: 10.0.26624 - Microsoft Corporation) Windows-Treiberpaket - Graphics Tablet (WinUsb) USBDevice (04/10/2014 8.33.30.0) (HKLM\...\142118DF51345EA02D2B1583E102C8FB95FD6D52) (Version: 04/10/2014 8.33.30.0 - Graphics Tablet) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) WinRT Intellisense Desktop - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Desktop - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinSweeper 2.1 (HKLM-x32\...\{96E8A815-3053-4616-AAC2-865E6B1792F5}_is1) (Version: - Solvusoft Corporation) World of Tanks Blitz (HKLM\...\Steam App 444200) (Version: - Wargaming Group Limited) XAMPP (HKLM-x32\...\xampp) (Version: 5.6.8-0 - Bitnami) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-844095808-1650209266-980683291-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Seb\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {191E8CED-5BA5-4EE3-8DC0-C8257FE2CFAA} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation) Task: {1DEFEEA4-B4A7-4654-BBD7-43AF718B4AC6} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => P:\Programme (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation) Task: {2EC4D652-1888-44F7-9811-C4959B854A6F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {3F31AB12-2BE3-4DFF-937D-C2512794E784} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {441E0E52-EAB6-48E5-A1DA-174B77491E51} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) Task: {488F73BD-5AF1-494C-A38B-D7E98D4D25DB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {4B5F255F-761D-4D0E-8736-291C9C1BDEAF} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => Thunderbolt.exe Task: {5DE984B7-D648-47FD-873D-9E1AD1CD6116} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => Thunderbolt.exe Task: {6170758E-2D8B-46D3-80DD-B9DF43C95A4F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-02-19] (Microsoft Corporation) Task: {78C9ACF9-706C-4945-98D0-9025D9328ADA} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-03-18] (AVAST Software) Task: {7CE3E841-D7F1-4A12-B12E-E509E3A66685} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {7DF9EEC8-4310-4833-AA36-B112995760F5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-28] (AVAST Software) Task: {854BE4ED-D2D2-482F-9BD7-F54256C7F6E0} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService Task: {AE37F061-38D4-41F4-A0B6-3973F5FB378C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation) Task: {B8021389-D6F2-4922-A95C-1A7D067E1A29} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {B9EA1437-FF91-46FB-B4BA-48F6D8B4211F} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation) Task: {C7E9D51D-8274-4306-AF9B-A94762348F9F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => tbtsvc.exe Task: {D8693F66-18EA-41CA-AD97-43AE1B96716B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {F672F9E7-4540-4C1E-A3FB-C403F543FE5F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-02-17 05:07 - 2016-12-15 12:37 - 00020208 _____ () C:\Windows\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll 2015-06-25 10:45 - 2015-06-25 10:45 - 00017920 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe 2016-10-29 09:20 - 2017-02-23 20:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-20 15:47 - 2017-03-17 01:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-02-21 23:09 - 2017-02-21 23:09 - 00052392 _____ () P:\Programme\FileZilla FTP Client\fzshellext_64.dll 2016-10-22 14:16 - 2016-11-06 03:45 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2017-03-26 14:51 - 2017-02-24 06:23 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-03-26 14:51 - 2017-02-24 06:23 - 02264528 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00162600 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll 2017-03-23 11:40 - 2017-03-23 11:40 - 01850800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe 2015-05-14 03:30 - 2015-05-14 03:30 - 00419328 _____ () C:\Windows\System32\flvga_tray.exe 2017-03-18 17:45 - 2017-03-18 17:45 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-03-26 14:29 - 2017-03-26 14:29 - 05889024 _____ () C:\Program Files\AVAST Software\Avast\defs\17032500\algo.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00655056 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2015-02-17 01:47 - 2015-02-17 01:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\ycc.dll 2016-08-09 20:49 - 2016-08-09 20:49 - 01804800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\BDR_info.dll 2015-02-16 11:47 - 2015-02-16 11:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ycc.dll 2017-01-03 00:52 - 2017-01-03 00:52 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-03-18 17:45 - 2017-03-18 17:45 - 00290352 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2016-10-29 09:20 - 2017-02-23 16:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-10-29 09:20 - 2017-02-23 16:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-844095808-1650209266-980683291-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupfolder: C:^Users^Seb^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\Windows\pss\An OneNote senden.lnk.Startup MSCONFIG\startupreg: DAEMON Tools Lite Automount => "P:\Programme\DAEMON Tools Lite\DTAgent.exe" -autorun MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: Greenshot => P:\Programme\Greenshot\Greenshot.exe MSCONFIG\startupreg: OneDrive => "C:\Users\Seb\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background MSCONFIG\startupreg: Overwolf => "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent MSCONFIG\startupreg: PreRun => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe MSCONFIG\startupreg: TabletDriver => C:\PenTabletDriver\TabletDriver.exe -hide ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{D5A10B96-019A-463B-93FA-E793E9FD99AD}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{B4866065-6535-4F02-A6ED-1135D0AF6369}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{FC34C004-8D8E-471F-8472-EC7E5A07A944}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{34220BE5-470C-49B1-988C-6A766AE041E4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{57203B3F-273A-4BCD-A084-20CFB95B4F33}C:\program files (x86)\gigabyte\appcenter\gcupd.exe] => (Allow) C:\program files (x86)\gigabyte\appcenter\gcupd.exe FirewallRules: [UDP Query User{7DF7F82C-B3FA-40D3-AAFB-093E66B97C8A}C:\program files (x86)\gigabyte\appcenter\gcupd.exe] => (Allow) C:\program files (x86)\gigabyte\appcenter\gcupd.exe ==================== Wiederherstellungspunkte ========================= 21-03-2017 23:17:44 Installed Microsoft Server Speech Platform Runtime (x64) 21-03-2017 23:18:01 Installed Kinect for Windows Speech Recognition Language Pack (en-US) 21-03-2017 23:18:06 Installed Kinect for Windows Speech Recognition Language Pack (en-GB) 21-03-2017 23:18:15 Installed Kinect for Windows Speech Recognition Language Pack (en-CA) 21-03-2017 23:18:23 Installed Kinect for Windows Speech Recognition Language Pack (en-AU) 21-03-2017 23:18:30 Installed Kinect for Windows Speech Recognition Language Pack (de-DE) 21-03-2017 23:22:41 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 21-03-2017 23:42:54 WinThruster (64-bit) Backup 21-03-2017 23:44:58 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 21-03-2017 23:49:32 Windows Update 24-03-2017 11:12:01 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:33:29 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:43:10 WinThruster (64-bit) Backup 24-03-2017 20:43:57 Removed APP Center 24-03-2017 20:44:11 Installed APP Center 24-03-2017 20:44:44 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 21:07:32 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Netzwerkcontroller Description: Netzwerkcontroller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (03/26/2017 02:58:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/26/2017 02:47:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/26/2017 02:39:48 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x86\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/26/2017 02:39:48 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x64\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/26/2017 02:37:52 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm\signtool.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Appx.AppxSip.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/26/2017 02:37:52 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\inspect.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\inspect.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/26/2017 02:37:52 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\accevent.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\accevent.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/26/2017 02:37:52 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AccScope\accscope.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AccScope\accscope.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/26/2017 02:37:52 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AppPerfAnalyzer\appperfanalyzer_js.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AppPerfAnalyzer\appperfanalyzer_js.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/26/2017 02:37:52 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\signtool.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Appx.AppxSip.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Systemfehler: ============= Error: (03/26/2017 02:59:13 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/26/2017 02:58:57 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UsbCharger Error: (03/26/2017 02:58:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (03/26/2017 02:58:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht. Error: (03/26/2017 02:48:00 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/26/2017 02:47:42 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UsbCharger Error: (03/26/2017 02:47:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (03/26/2017 02:47:27 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht. Error: (03/26/2017 02:46:04 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: Es wird bereits eine Instanz des Dienstes ausgeführt. Error: (03/26/2017 02:45:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Office Software Protection Platform" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. CodeIntegrity: =================================== Date: 2016-12-02 18:49:24.791 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.766 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.741 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.716 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.691 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.665 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.639 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.614 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.589 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.553 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz Prozentuale Nutzung des RAM: 22% Installierter physikalischer RAM: 16333.03 MB Verfügbarer physikalischer RAM: 12717.42 MB Summe virtueller Speicher: 32664.25 MB Verfügbarer virtueller Speicher: 28639.72 MB ==================== Laufwerke ================================ Drive b: (Bilder) (Fixed) (Total:151.37 GB) (Free:65.28 GB) NTFS Drive c: (Windows) (Fixed) (Total:447.03 GB) (Free:129.76 GB) NTFS Drive e: (Filme) (Fixed) (Total:465.76 GB) (Free:344.71 GB) NTFS Drive m: (Musik) (Fixed) (Total:151.37 GB) (Free:145.56 GB) NTFS Drive p: (Programme) (Fixed) (Total:850 GB) (Free:140.63 GB) NTFS Drive v: (Videos) (Fixed) (Total:163.02 GB) (Free:138.82 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 447.1 GB) (Disk ID: 94D2A2C1) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=447 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0009AF56) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7BA18A71) Partition 1: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=163 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ EditNote: -> VLC wurde deinstalliert. Beim versuch VLC von Videolan.org herunterzuladen, tauchte der Fehler "Die Verbindung wurde zurückgesetzt, während die Seite geladen wurde" erneut auf. EditNote2: Ich habe die Vermutung, dass der Killer Service V2 meine Internetverbindungen kappt. Ich habe in letzter Zeit immer wieder versucht in meinen Augen unnötige Dienste zu beenden und das immer wieder mit Erfolg. Heute habe ich genauer getestet, Service für Service und dann geschaut obs wieder geht. Zuerst Punkbuster, ohne Erfolg, dann die Automatische WLan Konfiguration, o.E., dann Killer Service V2, und alles ging wieder. Ich habe ein Mainboard mit dem Killer E2400 Gigabit Ethernet Controller. Kann ich den Treiber installieren, ohne den Killer Network Manager und somit ohne den Killer Service V2? "Killer Service V2: Controls the Killer NIC functionality. This service must be started in order for the features presented in the Network Manager to be active." -> C:\Program Files\Killer Networking\Network Manager\KillerService.exe Geändert von Schlesse (28.03.2017 um 19:07 Uhr) |
28.03.2017, 20:59 | #9 | |
/// TB-Ausbilder | Windows 7: Malware blockiert Internetverbindungen Servus, Zitat:
Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start CloseProcesses: Toolbar: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei RemoveProxy: CMD: ipconfig /flushdns CMD: netsh winsock reset EmptyTemp: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Schritt 3
Bitte poste mit deiner nächsten Antwort
|
29.03.2017, 08:08 | #10 |
| Windows 7: Malware blockiert Internetverbindungen Fixlog: Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017 durchgeführt von Seb (29-03-2017 08:53:14) Run:1 Gestartet von C:\Users\Seb\Desktop Geladene Profile: Seb (Verfügbare Profile: Seb) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** start CloseProcesses: Toolbar: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei RemoveProxy: CMD: ipconfig /flushdns CMD: netsh winsock reset EmptyTemp: end ***************** Prozesse erfolgreich geschlossen. HKU\S-1-5-21-844095808-1650209266-980683291-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wert erfolgreich entfernt HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Schlüssel nicht gefunden. ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt HKU\S-1-5-21-844095808-1650209266-980683291-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt HKU\S-1-5-21-844095808-1650209266-980683291-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt ========= Ende von RemoveProxy: ========= ========= ipconfig /flushdns ========= Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. ========= Ende von CMD: ========= ========= netsh winsock reset ========= Der Winsock-Katalog wurde zurckgesetzt. Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen. ========= Ende von CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 141188731 B Java, Flash, Steam htmlcache => 548407596 B Windows/system/drivers => 86476360 B Edge => 0 B Chrome => 13768676 B Firefox => 380603226 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 66228 B Public => 0 B ProgramData => 0 B systemprofile => 58558412 B systemprofile32 => 73805 B LocalService => 66228 B NetworkService => 66228 B Seb => 409188525 B RecycleBin => 0 B EmptyTemp: => 1.5 GB temporäre Dateien entfernt. ================================ Das System musste neu gestartet werden. ==== Ende von Fixlog 08:53:29 ==== Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 08:58 on 29/03/2017 by Seb Administrator - Elevation successful ========== filefind ========== Searching for "*YSearchUtil*" No files found. Searching for "*Solvusoft*" C:\AdwCleaner\quarantine\files\fdzlftexctnkxwwprlsduuontriryfdz\Tray\SolvusoftTray.exe --a---- 1686088 bytes [12:45 26/03/2017] [21:06 23/09/2015] 6219A6387F46488BE13CF68AEE49CE50 C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\program files\Solvusoft\Tray\SolvusoftTray.exe --a---- 1686088 bytes [12:45 26/03/2017] [21:06 23/09/2015] 6219A6387F46488BE13CF68AEE49CE50 Searching for "*VLC UPDATER*" No files found. Searching for "*VLCUPDATER*" No files found. Searching for "*Startfenster*" C:\AdwCleaner\quarantine\files\kxokndevcsqswnwpbyrrgjomvktixfyb\Startfenster.lnk --a---- 1272 bytes [12:45 26/03/2017] [12:14 12/11/2016] D84379A5BF94040ACFDBCA21C0DFC03E Searching for "*WinThruster*" C:\AdwCleaner\quarantine\files\dqshvtgrlzfvjfwerharicnuubakzhdn\WinThruster\WinThruster.lnk --a---- 2080 bytes [12:45 26/03/2017] [17:55 05/02/2017] AE20E1ABB90875A944CC7BB1C85A1603 C:\AdwCleaner\quarantine\files\qewhbobcthirhtsxdmexzsslfyozmdby\WinThruster\WinThruster64.exe --a---- 13707712 bytes [12:45 26/03/2017] [19:32 11/10/2015] 972F6A923DA037D8A2FC06D924AAB6A2 C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\WinThrusterSetup.dat --a---- 296 bytes [12:45 26/03/2017] [17:58 05/02/2017] DB59B126FF689DCA916CDEA09A4F8078 C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\WinThrusterSetup.exe --a---- 5467365 bytes [12:45 26/03/2017] [19:32 11/10/2015] DCC4E757BB46FDCC2F6F749CEBF1B2B0 C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\WinThrusterSetup.lan --a---- 8 bytes [12:45 26/03/2017] [17:55 05/02/2017] EA3DDDFE0F8E07978450C94C5C9057B4 C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\WinThrusterSetup.lnk --a---- 3 bytes [12:45 26/03/2017] [17:55 05/02/2017] ECAA88F7FA0BF610A5A26CF545DCD3AA C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\WinThrusterSetup.msi --a---- 2588672 bytes [12:45 26/03/2017] [19:32 11/10/2015] F8878F5828454237DCDC4AA97E1058BC C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\WinThrusterSetup.par --a---- 4513 bytes [12:45 26/03/2017] [17:55 05/02/2017] 4350BF3A8ACA89BFCB7D89457C460A7F C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\WinThrusterSetup.res --a---- 11227901 bytes [12:45 26/03/2017] [19:32 11/10/2015] 781E2FC820E9A056CB82DCD00E4D5243 C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\OFFLINE\56EA7D95\9A1BC107\WinThruster64.exe --a---- 13707712 bytes [12:45 26/03/2017] [19:32 11/10/2015] 972F6A923DA037D8A2FC06D924AAB6A2 C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\OFFLINE\68385B83\A7CBC777\WinThruster.exe --a---- 12244928 bytes [12:45 26/03/2017] [19:32 11/10/2015] 1B18E32ACBA4F436831DA1BCB4CD9B6D C:\Users\Seb\Downloads\Neuer Ordner (2)\Setup_WinThruster_2016.exe --a---- 8932000 bytes [17:53 05/02/2017] [17:54 05/02/2017] FF705FCACBC099BDBFA7A3B916A8822F ========== folderfind ========== Searching for "*YSearchUtil*" No folders found. Searching for "*Solvusoft*" C:\AdwCleaner\quarantine\files\anfxzysjjqzbqqqmsngwrqwxssquiawa\Solvusoft Suite d------ [12:45 26/03/2017] C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\Common Application Data\Solvusoft d------ [12:45 26/03/2017] C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\program files\Solvusoft d------ [12:45 26/03/2017] C:\AdwCleaner\quarantine\files\txmxeqmmecwsanxbefzeeqehcizfmkbg\Solvusoft Suite d------ [12:45 26/03/2017] Searching for "*VLC UPDATER*" No folders found. Searching for "*VLCUPDATER*" No folders found. Searching for "*Startfenster*" No folders found. Searching for "*WinThruster*" C:\AdwCleaner\quarantine\files\dqshvtgrlzfvjfwerharicnuubakzhdn\WinThruster d------ [12:45 26/03/2017] C:\AdwCleaner\quarantine\files\qewhbobcthirhtsxdmexzsslfyozmdby\WinThruster d------ [12:45 26/03/2017] C:\AdwCleaner\quarantine\files\txmxeqmmecwsanxbefzeeqehcizfmkbg\WinThruster d------ [12:45 26/03/2017] C:\AdwCleaner\quarantine\files\txmxeqmmecwsanxbefzeeqehcizfmkbg\WinThruster64 d------ [12:45 26/03/2017] ========== regfind ========== Searching for "YSearchUtil" No data found. Searching for "Solvusoft" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe"="WinThruster for Registry Cleaner" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files\Solvusoft\WinThruster\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files\Solvusoft\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files\Solvusoft\WinThruster\Languages\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files\Solvusoft\WinThruster\Documents\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Solvusoft\WinThruster64\LOGS\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Solvusoft\WinThruster64\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\HTML\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Solvusoft\Tray\Configurations\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\FAQ und Lizenzbedingungen\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\notification\gfx\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\notification\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\scrollbar\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\icons\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\arrows\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Solvusoft\Tray\Translations\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Solvusoft\Tray\Menu\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02AD40ADC378E90409702FA67B6979E5] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04F13554A61855C42A5E5357B092AD7F] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0621E6E1B6B52EF44B62539982EA7B3D] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\OEMData.pkt" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07B51C13962E8BF49BAFEA042FB2D4A6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C?\Program Files (x86)\Solvusoft\Tray\SuiteClient.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07B51C13962E8BF49BAFEA042FB2D4A6] "00000000000000000000000000000000"="C?\Program Files (x86)\Solvusoft\Tray\SuiteClient.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\185CAFD6D4F47E24497B21FC90E0350A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_RO.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1B60DDC9BF81C064A82AF0385C9D2567] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_JA.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D5048D884F3B6C409215B8CB2693BAB] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E7AF89BAA26CA647916E34F22FDF8A7] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_RU.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\313612321C03DA94BB835A99167F910E] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\FAQ und Lizenzbedingungen\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\387E6FC02E9831343B4AC2A39C0A0F7B] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_FI.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B023CDE6CF3E7332F36D1EBC07A537E] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\scrollbar\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3BAAF2C977324DC4CB4357E67C585C6B] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\notification\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DF8E189BC38EE64BB45811045118DA2] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_DA.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E1083A730542024193B2C9A46A7058F] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Solvusoft\Tray\Configurations\RCPRO.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\406329CF9623A0D4B9F8A2F719BF47CF] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_BG.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44966E5926BB1CE41BC437EA51951395] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FE56A821F941EA4482E15588DC6B5D3] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_EN-US.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5192B2CDA7ABA684F9A2BE824D71954A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_SV.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51E12932F39770041B4EF2A97ABD91DF] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_DE.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\573538BED6AF5194BA01E6DC495137F0] "61F70108E2BCBA24BAD9C61145D0A5B8"="C?\Program Files (x86)\Solvusoft\Tray\Translations\Language_EN.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\576EAF7FE321ABD48B0E1CC0F0B022C9] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_EL.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\58063D014BB5589EEC87B802189A0F17] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\arrows\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\58501F584E038684F82F2776E5899CC3] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\MsgSys.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\59843717A95D4694DAB85FFDCD959614] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\LogFilesCollector.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D037D8A7226A644AACB2374996436C6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\FAQ und Lizenzbedingungen\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D202BE31CE72864C93964B7753A0FF5] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_ZH.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5DF26C905827B9B4BB6AF3B9A980C37D] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\CommonToolkitSuite.cts" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60427098C7667644F8EDF8DE123521E6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_HR.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\607619A9F409DBF409D2A1C5EE52FEF4] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_PL.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\618428E3619CB7647A2AF889C0579048] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_TW.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\62BCA6CE3556502EBEF535F967AB024D] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\663A4B12A55E10D459BD10818BD6BD05] "61F70108E2BCBA24BAD9C61145D0A5B8"="22:\Software\Solvusoft\Tray\Language" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6CE0ED9933AA13541BA59BBFB178220D] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_HU.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6FBCA5620C4C5684481F40E424F92406] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_IT.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72B9B8B8742542D4CB055A236DBBEA18] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\sfhtml.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78107A1660B21BE4A98DF907109C6C30] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_TR.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B61CCA13AE59EA46B6BFCD7E5D5F050] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_PT.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CED801F5F8896A46A99671A76944D69] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\CommonToolkitSuiteLight_x64.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8630FB65C7A3C744DB6226EBAA657D13] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_CS.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8E64601C02B9B8A49B2094D918AAB059] "61F70108E2BCBA24BAD9C61145D0A5B8"="C?\Program Files (x86)\Solvusoft\Tray\SolvusoftTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8E64601C02B9B8A49B2094D918AAB059] "00000000000000000000000000000000"="C?\Program Files (x86)\Solvusoft\Tray\SolvusoftTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\989BF290AEF71F747A45C129752F1208] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\997F95DDCAA04B243B1B961E5D4DF0CE] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\HTML\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9AEE1837AE189074980C35BEC077774A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\MachineId.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C1F1C6E78B15D147AD91785D5AB689A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_ID.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A01064ABB42DBE44EBFBD389518AB1C6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_NO.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A139670AC5F063A409103EC6C72644F6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C?\Program Files (x86)\Solvusoft\Tray\MsgSys.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A139670AC5F063A409103EC6C72644F6] "00000000000000000000000000000000"="C?\Program Files (x86)\Solvusoft\Tray\MsgSys.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF70C113ECEA42B46B60F3B0F849D237] "61F70108E2BCBA24BAD9C61145D0A5B8"="C?\Program Files (x86)\Solvusoft\Tray\sfhtml.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF70C113ECEA42B46B60F3B0F849D237] "00000000000000000000000000000000"="C?\Program Files (x86)\Solvusoft\Tray\sfhtml.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1DF4301F6A767A4EA9AAC7A2CC83C02] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_EN.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B340DF4BCD2621449B84006B1411B131] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_KO.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4BD36D3F00FCD54EA410EE863EB4A4F] "61F70108E2BCBA24BAD9C61145D0A5B8"="20:\Applications\SolvusoftTray.exe\NoStartPage" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B6B145DFA7D688147AE6AE8CA0B13541] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\MachineIdGatewayx64.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B8893EA43E1F40D45AC545630A2B25B4] "61F70108E2BCBA24BAD9C61145D0A5B8"="C?\ProgramData\Solvusoft\Tray\Menu\products_list.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA90E738CAFC1B344AC33A24A00AA1DC] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB9B007BCB8535B4C899BD1B6B5E5413] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBDBC04C7EE185E40860F8FE41C24EA3] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Documents\LicenseEN.rtf" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C18F140306B90004EB1E34CA2D3EC4C8] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_TH.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C5364CB0CE867A74681565F7FB259285] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_FR.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CAF8DF216BFEA7243B84FAAD3CC44593] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_ES.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D357670DFF3638841AE824797DA6948F] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Sync.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D7D76AE42E6D299DDC5E04D002EEA4E4] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\icons\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E724A0DC8B0CCAB4D80406BF582F82CB] "61F70108E2BCBA24BAD9C61145D0A5B8"="21:\Software\Solvusoft\RCPRO\Misc\Lang" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E962B13BE1C14CA499F22E6440A52DCF] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_NL.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE4C830CF908B9F4AA3F71349C5E1147] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\UpDates.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F26646641DFFFCB458166067EF1B4274] "61F70108E2BCBA24BAD9C61145D0A5B8"="C?\ProgramData\Solvusoft\Tray\Configurations\TKTRAY.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F443D8303C4FBCB448836C6865F454F6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\HTML\gfx\Icon_TKTRAY-UPD-RCPRO.png" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F5D1AEF540FF49FA7062CCA03F7243BA] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files (x86)\Solvusoft\Tray\notification\gfx\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FC678684CE97E584D881210B7DAFB1D1] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Solvusoft\WinThruster64\LOGS\" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{96E8A815-3053-4616-AAC2-865E6B1792F5}_is1] "Publisher"="Solvusoft Corporation" [HKEY_USERS\S-1-5-21-844095808-1650209266-980683291-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe"="WinThruster for Registry Cleaner" [HKEY_USERS\S-1-5-21-844095808-1650209266-980683291-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe"="WinThruster for Registry Cleaner" Searching for "VLC UPDATER" No data found. Searching for "VLCUPDATER" No data found. Searching for "Startfenster" No data found. Searching for "WinThruster" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe"="WinThruster for Registry Cleaner" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\Seb\Downloads\Setup_WinThruster_2016.exe"="WinThruster Installation " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files\Solvusoft\WinThruster\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files\Solvusoft\WinThruster\Languages\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files\Solvusoft\WinThruster\Documents\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Solvusoft\WinThruster64\LOGS\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Solvusoft\WinThruster64\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\FAQ und Lizenzbedingungen\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02AD40ADC378E90409702FA67B6979E5] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04F13554A61855C42A5E5357B092AD7F] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0621E6E1B6B52EF44B62539982EA7B3D] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\OEMData.pkt" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\185CAFD6D4F47E24497B21FC90E0350A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_RO.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1B60DDC9BF81C064A82AF0385C9D2567] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_JA.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D5048D884F3B6C409215B8CB2693BAB] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E7AF89BAA26CA647916E34F22FDF8A7] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_RU.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\313612321C03DA94BB835A99167F910E] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\FAQ und Lizenzbedingungen\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\387E6FC02E9831343B4AC2A39C0A0F7B] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_FI.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DF8E189BC38EE64BB45811045118DA2] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_DA.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\406329CF9623A0D4B9F8A2F719BF47CF] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_BG.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44966E5926BB1CE41BC437EA51951395] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FE56A821F941EA4482E15588DC6B5D3] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_EN-US.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5192B2CDA7ABA684F9A2BE824D71954A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_SV.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51E12932F39770041B4EF2A97ABD91DF] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_DE.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\576EAF7FE321ABD48B0E1CC0F0B022C9] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_EL.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\58501F584E038684F82F2776E5899CC3] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\MsgSys.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\59843717A95D4694DAB85FFDCD959614] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\LogFilesCollector.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D037D8A7226A644AACB2374996436C6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\FAQ und Lizenzbedingungen\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D202BE31CE72864C93964B7753A0FF5] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_ZH.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5DF26C905827B9B4BB6AF3B9A980C37D] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\CommonToolkitSuite.cts" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60427098C7667644F8EDF8DE123521E6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_HR.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\607619A9F409DBF409D2A1C5EE52FEF4] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_PL.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\618428E3619CB7647A2AF889C0579048] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_TW.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6CE0ED9933AA13541BA59BBFB178220D] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_HU.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6FBCA5620C4C5684481F40E424F92406] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_IT.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72B9B8B8742542D4CB055A236DBBEA18] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\sfhtml.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78107A1660B21BE4A98DF907109C6C30] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_TR.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B61CCA13AE59EA46B6BFCD7E5D5F050] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_PT.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CED801F5F8896A46A99671A76944D69] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\CommonToolkitSuiteLight_x64.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8630FB65C7A3C744DB6226EBAA657D13] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_CS.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9AEE1837AE189074980C35BEC077774A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\MachineId.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C1F1C6E78B15D147AD91785D5AB689A] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_ID.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A01064ABB42DBE44EBFBD389518AB1C6] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_NO.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1DF4301F6A767A4EA9AAC7A2CC83C02] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_EN.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B340DF4BCD2621449B84006B1411B131] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_KO.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B6B145DFA7D688147AE6AE8CA0B13541] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\MachineIdGatewayx64.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA90E738CAFC1B344AC33A24A00AA1DC] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\Supportwerkzeuge\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB9B007BCB8535B4C899BD1B6B5E5413] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft\WinThruster\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBDBC04C7EE185E40860F8FE41C24EA3] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Documents\LicenseEN.rtf" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C18F140306B90004EB1E34CA2D3EC4C8] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_TH.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C5364CB0CE867A74681565F7FB259285] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_FR.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CAF8DF216BFEA7243B84FAAD3CC44593] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_ES.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D357670DFF3638841AE824797DA6948F] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Sync.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E962B13BE1C14CA499F22E6440A52DCF] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\Languages\Language_NL.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE4C830CF908B9F4AA3F71349C5E1147] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\Program Files\Solvusoft\WinThruster\UpDates.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FC678684CE97E584D881210B7DAFB1D1] "61F70108E2BCBA24BAD9C61145D0A5B8"="C:\ProgramData\Solvusoft\WinThruster64\LOGS\" [HKEY_USERS\S-1-5-21-844095808-1650209266-980683291-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe"="WinThruster for Registry Cleaner" [HKEY_USERS\S-1-5-21-844095808-1650209266-980683291-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\Seb\Downloads\Setup_WinThruster_2016.exe"="WinThruster Installation " [HKEY_USERS\S-1-5-21-844095808-1650209266-980683291-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe"="WinThruster for Registry Cleaner" [HKEY_USERS\S-1-5-21-844095808-1650209266-980683291-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\Seb\Downloads\Setup_WinThruster_2016.exe"="WinThruster Installation " -= EOF =- PS: Vor ausführen des Programms wurde eine Änderung in der Registery mit RegEdit durchgeführt: -> Die Automatische Konsistenzprüfung wurde so eingestellt, dass die Festplatte B (Bilder) nicht mehr überprüft wird, das dies bei jedem Start gefordert wurde und immer Fehlerhaft endete und somit ein Neustart über den Resetknopf nötig war. Siehe nächste FRST Log: ALT: "BootExecute: autocheck autochk *" NEU: "BootExecute: autocheck autochk:b" Geändert von Schlesse (29.03.2017 um 08:14 Uhr) |
29.03.2017, 08:09 | #11 |
| Windows 7: Malware blockiert Internetverbindungen FRST: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017 durchgeführt von Seb (Administrator) auf GAMING-PC (29-03-2017 09:08:32) Gestartet von C:\Users\Seb\Desktop Geladene Profile: Seb (Verfügbare Profile: Seb) Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe (OSBASE) C:\Windows\System32\ddmgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (pdfforge GmbH) P:\Programme\PDF Architect 4\creator-ws.exe (© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (DEVGURU Co., LTD.) P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngine.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe () C:\Windows\System32\flvga_tray.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\SIV\thermald.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Mozilla Corporation) P:\Programme\Mozilla Thunderbird\thunderbird.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-27] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [flvga_tray64] => C:\Windows\system32\flvga_tray.exe [419328 2015-05-14] () HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-03-28] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM-x32\...\RunOnce: [EasyTuneEngineService] => C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EngineRunOnce.exe [14632 2016-05-03] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [EasyTune] => C:\Program Files (x86)\GIGABYTE\EasyTune\etro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [SIV] => C:\Program Files (x86)\GIGABYTE\SIV\sivro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe [14632 2016-02-26] () HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-03-23] (Valve Corporation) HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3044816 2017-03-26] (Electronic Arts) HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\MountPoints2: {d30ece49-96c7-11e6-bcff-806e6f6e6963} - D:\ZToolBar.exe ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-28] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-28] (AVAST Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-10-20] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) BootExecute: autocheck autochk:b ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{CEBDFDF5-5314-417B-8F65-948D370BAC2B}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{EE112510-05F2-423F-9B82-4CF134C99522}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== SearchScopes: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> {DA6F9CB8-5F1C-45FC-AB8D-6C4B3457583F} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-01-29] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-01-29] (Microsoft Corporation) BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-29] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-29] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2016-08-05] (pdfforge GmbH) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: 8i010wxq.default FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default [2017-03-29] FF NetworkProxy: Mozilla\Firefox\Profiles\8i010wxq.default -> type", 0 FF Extension: (Flash Video Downloader - YouTube HD Download [4K]) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\artur.dubovoy@gmail.com [2017-02-20] FF Extension: (ColorZilla) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-03-09] FF Extension: (Site Deployment Checker) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\features\{07233581-9539-488f-93b7-c5fc51995368}\deployment-checker@mozilla.org.xpi [2017-03-26] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\jgc1n486.Standard-Benutzer [2017-03-29] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\xs280j99.Standard-Benutzer1 [2017-03-29] FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension FF Extension: (PDF Architect 4 Creator) - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension [2017-01-08] [ist nicht signiert] FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Keine Datei] FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-01-29] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH) Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default CHR DefaultSearchKeyword: Default -> Yahoo CHR DefaultSuggestURL: Default -> hxxps://de.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Profile: C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default [2017-03-29] CHR Extension: (Google Präsentationen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-20] CHR Extension: (Google Docs) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-20] CHR Extension: (Google Drive) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-20] CHR Extension: (YouTube) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-20] CHR Extension: (Google-Suche) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-10-20] CHR Extension: (Yahoo Partner) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabhkdeopjkcpkmofliimbjckmocfiom [2016-12-28] CHR Extension: (Google Tabellen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-20] CHR Extension: (Google Docs Offline) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-01] CHR Extension: (Avast Online Security) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-28] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-20] CHR Extension: (Google Mail) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-20] CHR Extension: (Chrome Media Router) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-28] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fabhkdeopjkcpkmofliimbjckmocfiom] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-03-28] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-03-28] (AVAST Software) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3704520 2017-02-18] (Microsoft Corporation) R2 ddmgr; C:\Windows\system32\ddmgr.exe [1659040 2016-01-04] (OSBASE) S3 Disc Soft Lite Bus Service; P:\Programme\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1468608 2016-10-06] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-25] (EasyAntiCheat Ltd) R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [142656 2016-06-01] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 ElfoService; P:\Programme\ElsterFormular Update Service\bin\ElfoService.exe [1283376 2017-02-13] () R2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [Datei ist nicht signiert] S3 HwmRecordService; C:\Program Files (x86)\GIGABYTE\SIV\HwmRecordService.exe [118568 2016-05-24] (GIGA-BYTE TECHNOLOGY CO., LTD.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21184 2016-03-29] (Microsoft Corporation) S4 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-02-12] (Rivet Networks) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440 2017-03-17] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-02-23] (NVIDIA Corporation) S2 OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [127272 2016-05-20] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123240 2017-03-26] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2184688 2017-03-26] (Electronic Arts) S3 PDF Architect 4; P:\Programme\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH) S3 PDF Architect 4 CrashHandler; P:\Programme\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Creator; P:\Programme\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-11-06] () R2 ss_conn_service; P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.) S3 Te.Service; C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [137216 2016-03-29] (Microsoft Corporation) [Datei ist nicht signiert] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10362608 2016-12-15] (TeamViewer GmbH) S3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [1831064 2015-11-04] (Intel Corporation) S3 VSStandardCollectorService140; P:\Programme (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] () R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-03-28] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-28] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-03-28] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-28] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-28] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-03-28] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-03-28] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-28] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-03-28] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-03-28] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-03-28] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-03-28] (AVAST Software) R3 ausb3hub; C:\Windows\System32\DRIVERS\ausb3hub.sys [404480 2016-10-20] (Intel Corporation) R3 ausb3xhc; C:\Windows\System32\DRIVERS\ausb3xhc.sys [817664 2016-10-20] (Intel Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-02-12] (Rivet Networks, LLC.) R4 ddkmd; C:\Windows\system32\drivers\ddkmd.sys [254968 2016-01-04] (OSBASE) [Datei ist nicht signiert] R0 ddkmdldr; C:\Windows\System32\drivers\ddkmdldr.sys [16888 2016-01-04] (OSBASE) [Datei ist nicht signiert] S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-10-22] (Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-10-22] (Disc Soft Ltd) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77408 2017-02-24] () R3 FLxHCIv; C:\Windows\System32\Drivers\FLxHCIv.sys [199304 2016-01-08] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31728 2015-11-12] (Intel Corporation) R3 KillerEth; C:\Windows\System32\DRIVERS\e2xw7x64.sys [134296 2016-02-12] (Qualcomm Atheros, Inc.) R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-03-29] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-03-29] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-03-29] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251840 2017-03-29] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82208 2017-03-29] (Malwarebytes) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation) S3 nhi; C:\Windows\System32\DRIVERS\tbt70x.sys [126464 2015-11-10] (Intel Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-02-23] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2017-01-20] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (The OpenVPN Project) [Datei ist nicht signiert] S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] () S3 vmulti; C:\Windows\System32\DRIVERS\vmulti.sys [19504 2016-01-13] (Windows (R) Win 7 DDK provider) R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-29 09:08 - 2017-03-29 09:08 - 00025618 _____ C:\Users\Seb\Desktop\FRST.txt 2017-03-29 08:58 - 2017-03-29 09:06 - 00079360 _____ C:\Users\Seb\Desktop\SystemLook.txt 2017-03-29 08:57 - 2017-03-29 08:57 - 00165376 _____ C:\Users\Seb\Desktop\SystemLook_x64.exe 2017-03-29 08:57 - 2017-03-29 08:57 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-03-29 08:53 - 2017-03-29 08:53 - 00002683 _____ C:\Users\Seb\Desktop\Fixlog.txt 2017-03-28 20:26 - 2017-03-28 20:26 - 00001073 _____ C:\Users\Public\Desktop\VLC media player.lnk 2017-03-28 20:26 - 2017-03-28 20:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-03-28 20:26 - 2017-03-28 20:26 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-03-28 19:58 - 2017-03-28 19:59 - 30533688 _____ C:\Users\Seb\Downloads\vlc-2.2.4-win32.exe 2017-03-28 19:22 - 2017-03-28 19:22 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-03-27 00:06 - 2017-03-27 00:06 - 00000000 ___HD C:\Program Files\Common FilesEAInstaller 2017-03-26 15:37 - 2017-03-26 15:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Utility 2017-03-26 15:37 - 2017-03-26 15:37 - 00000000 ____D C:\Program Files (x86)\ASUS 2017-03-26 15:37 - 2014-12-15 21:47 - 04401152 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll 2017-03-26 15:37 - 2014-12-15 21:47 - 03667968 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll 2017-03-26 15:36 - 2017-03-26 15:36 - 00000000 ____D C:\Users\Seb\Downloads\UT_PCE-AC68_2115 2017-03-26 15:12 - 2017-03-26 15:13 - 00082772 _____ C:\Users\Seb\Desktop\FRST2.txt 2017-03-26 15:12 - 2017-03-26 15:13 - 00063437 _____ C:\Users\Seb\Desktop\Addition2.txt 2017-03-26 15:12 - 2017-03-26 15:12 - 00002351 _____ C:\Users\Seb\Desktop\MalwareBytes.txt 2017-03-26 14:53 - 2017-03-26 14:54 - 93433704 _____ C:\Users\Seb\Downloads\UT_PCE_AC68_2115.zip 2017-03-26 14:52 - 2017-03-29 09:07 - 00082208 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-03-26 14:52 - 2017-03-29 08:55 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-03-26 14:52 - 2017-03-29 08:55 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-03-26 14:52 - 2017-03-29 08:55 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-03-26 14:51 - 2017-03-29 08:54 - 00251840 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-03-26 14:51 - 2017-03-26 14:51 - 00001874 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\Program Files\Malwarebytes 2017-03-26 14:51 - 2017-02-24 06:23 - 00077408 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-03-26 14:50 - 2017-03-26 14:50 - 57131432 _____ (Malwarebytes ) C:\Users\Seb\Desktop\mb3-setup-consumer-3.0.6.1469-1075.exe 2017-03-26 14:45 - 2017-03-26 14:45 - 00006461 _____ C:\Users\Seb\Desktop\AdwCleaner[C0].txt 2017-03-26 14:43 - 2017-03-26 15:10 - 00000000 ____D C:\AdwCleaner 2017-03-26 14:42 - 2017-03-26 14:42 - 04031440 _____ C:\Users\Seb\Desktop\AdwCleaner_6.044.exe 2017-03-26 14:38 - 2017-03-26 14:42 - 00233058 _____ C:\Users\Seb\Desktop\TDSSKiller.3.1.0.12_26.03.2017_14.38.22_log.txt 2017-03-26 14:31 - 2017-03-29 09:08 - 00000000 ____D C:\FRST 2017-03-26 14:31 - 2017-03-26 14:32 - 00081292 _____ C:\Users\Seb\Desktop\FRST1.txt 2017-03-26 14:31 - 2017-03-26 14:32 - 00073700 _____ C:\Users\Seb\Desktop\Addition1.txt 2017-03-26 14:31 - 2017-03-26 14:31 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Seb\Desktop\tdsskiller.exe 2017-03-26 14:30 - 2017-03-26 14:30 - 02424832 _____ (Farbar) C:\Users\Seb\Desktop\FRST64.exe 2017-03-24 20:49 - 2017-03-29 08:55 - 00196286 _____ C:\Windows\SysWOW64\bios.ini 2017-03-24 20:44 - 2017-03-24 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE 2017-03-24 12:54 - 2017-03-24 12:54 - 00038955 _____ C:\Users\Seb\Downloads\Augenaerztlicher_Vorabbefund.pdf 2017-03-22 02:10 - 2017-03-22 02:10 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Playsport Games 2017-03-22 00:24 - 2017-03-22 00:24 - 00000222 _____ C:\Users\Seb\Desktop\Motorsport Manager.url 2017-03-22 00:02 - 2017-03-22 00:02 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-03-22 00:02 - 2017-03-17 00:56 - 00134592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-03-22 00:02 - 2017-01-26 02:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-03-22 00:02 - 2017-01-26 02:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe 2017-03-22 00:00 - 2017-03-17 02:59 - 40190400 _____ C:\Windows\system32\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 34952760 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 28223544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 17282648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 16400616 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14674712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14434360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 11122912 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 04064088 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03627064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03187256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 01053240 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00989120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00912440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00504104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00492560 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00425104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00408272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 00170360 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00153368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:31 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-03-21 23:49 - 2017-03-08 06:22 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:18 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-03-21 23:49 - 2017-03-08 06:07 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:06 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-03-21 23:49 - 2017-03-04 19:24 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 18:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 10:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-03-21 23:49 - 2017-03-04 10:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-03-21 23:49 - 2017-03-04 10:02 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-03-21 23:49 - 2017-03-04 10:01 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-04 09:59 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-03-21 23:49 - 2017-03-04 09:52 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-03-21 23:49 - 2017-03-04 09:51 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-03-21 23:49 - 2017-03-04 09:48 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-03-21 23:49 - 2017-03-04 09:46 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-03-21 23:49 - 2017-03-04 09:45 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-03-21 23:49 - 2017-03-04 09:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-03-21 23:49 - 2017-03-04 09:36 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-03-21 23:49 - 2017-03-04 09:32 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-03-21 23:49 - 2017-03-04 09:31 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-03-21 23:49 - 2017-03-04 09:23 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-04 09:21 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-03-21 23:49 - 2017-03-04 09:13 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-03-21 23:49 - 2017-03-04 09:11 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-03-21 23:49 - 2017-03-04 08:57 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-03-21 23:49 - 2017-03-04 08:55 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-03-21 23:49 - 2017-03-04 08:54 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-03-21 23:49 - 2017-03-04 08:52 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-03-21 23:49 - 2017-03-04 08:52 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-04 08:26 - 15259648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-03-21 23:49 - 2017-03-04 08:25 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-03-21 23:49 - 2017-03-04 08:12 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-03-21 23:49 - 2017-03-04 08:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-03-21 23:49 - 2017-03-04 06:18 - 20281856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-03-21 23:49 - 2017-03-02 20:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-03-21 23:49 - 2017-03-02 20:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-03-21 23:49 - 2017-03-02 20:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-02 20:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-02 19:55 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-03-21 23:49 - 2017-03-02 19:54 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-03-21 23:49 - 2017-03-02 19:53 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-03-21 23:49 - 2017-03-02 19:51 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-03-21 23:49 - 2017-03-02 19:50 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-03-21 23:49 - 2017-03-02 19:49 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-03-21 23:49 - 2017-03-02 19:49 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-03-21 23:49 - 2017-03-02 19:41 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-03-21 23:49 - 2017-03-02 19:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-02 19:35 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-03-21 23:49 - 2017-03-02 19:32 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-03-21 23:49 - 2017-03-02 19:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-03-21 23:49 - 2017-03-02 19:29 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-03-21 23:49 - 2017-03-02 19:28 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-03-21 23:49 - 2017-03-02 19:22 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-03-21 23:49 - 2017-03-02 19:21 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-03-21 23:49 - 2017-03-02 19:19 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-03-21 23:49 - 2017-03-02 19:17 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-03-21 23:49 - 2017-03-02 19:17 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-02 19:11 - 13654528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-03-21 23:49 - 2017-03-02 18:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 01312768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-03-21 23:49 - 2017-02-14 18:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-03-21 23:49 - 2017-02-14 18:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-03-21 23:49 - 2017-02-11 18:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-03-21 23:49 - 2017-02-11 18:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-03-21 23:49 - 2017-02-11 17:58 - 00462848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-03-21 23:49 - 2017-02-10 18:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:32 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-03-21 23:49 - 2017-02-10 16:33 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-03-21 23:49 - 2017-02-09 18:36 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:35 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-03-21 23:49 - 2017-02-09 18:35 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-03-21 23:49 - 2017-02-09 18:33 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:19 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-03-21 23:49 - 2017-02-09 18:19 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:16 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-03-21 23:49 - 2017-02-09 18:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-03-21 23:49 - 2017-02-09 18:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-03-21 23:49 - 2017-02-09 18:02 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-03-21 23:49 - 2017-02-09 18:00 - 03220480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-03-21 23:49 - 2017-02-09 17:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-03-21 23:49 - 2017-02-09 17:58 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-03-21 23:49 - 2017-02-09 17:55 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-03-21 23:49 - 2017-02-09 17:54 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-03-21 23:49 - 2017-02-09 17:54 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-03-21 23:49 - 2017-02-09 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-03-21 23:49 - 2017-02-09 17:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-03-21 23:49 - 2017-02-09 17:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-03-21 23:49 - 2017-02-06 18:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-03-21 23:49 - 2017-01-18 17:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-03-21 23:49 - 2017-01-06 20:00 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-03-21 23:49 - 2017-01-06 19:44 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437892.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437892.dll 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-03-21 23:27 - 2017-03-21 23:27 - 00000000 ____D C:\ProgramData\Codemasters 2017-03-21 19:23 - 2017-02-23 01:42 - 00084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-03-21 19:23 - 2017-02-23 01:37 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 01609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-03-03 19:42 - 2017-03-03 19:42 - 00001416 _____ C:\Users\Seb\Desktop\RAGEPluginHook.exe - Verknüpfung (2).lnk 2017-02-27 00:37 - 2017-02-27 00:58 - 00000000 ____D C:\Users\Seb\Downloads\GTA 5 Mods ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-29 09:08 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-29 09:08 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-29 09:00 - 2010-11-21 08:50 - 00700130 _____ C:\Windows\system32\perfh007.dat 2017-03-29 09:00 - 2010-11-21 08:50 - 00149768 _____ C:\Windows\system32\perfc007.dat 2017-03-29 09:00 - 2009-07-14 07:13 - 01622706 _____ C:\Windows\system32\PerfStringBackup.INI 2017-03-29 09:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2017-03-29 08:59 - 2016-11-30 16:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-29 08:57 - 2016-11-25 19:53 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Mozilla 2017-03-29 08:57 - 2016-10-20 18:58 - 00000000 ____D C:\ProgramData\Origin 2017-03-29 08:57 - 2016-10-20 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2017-03-29 08:56 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\NVIDIA 2017-03-29 08:55 - 2016-10-29 09:31 - 00026192 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2017-03-29 08:54 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-29 08:53 - 2016-12-19 18:56 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Temp 2017-03-28 19:55 - 2016-10-20 18:33 - 00000000 ____D C:\Program Files\VideoLAN 2017-03-28 19:22 - 2017-02-07 22:10 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-03-28 19:22 - 2017-01-03 00:52 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2017-03-28 19:22 - 2017-01-03 00:52 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2017-03-28 19:22 - 2017-01-03 00:52 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2017-03-28 19:22 - 2017-01-03 00:52 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2017-03-28 19:22 - 2017-01-03 00:52 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2017-03-28 19:22 - 2017-01-03 00:52 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2017-03-28 19:22 - 2017-01-03 00:52 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2017-03-28 19:22 - 2017-01-03 00:52 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2017-03-27 01:10 - 2016-10-20 19:07 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Origin 2017-03-27 01:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2017-03-27 00:37 - 2016-10-22 14:17 - 00001238 _____ C:\Users\Public\Desktop\Battlefield 4.lnk 2017-03-27 00:37 - 2016-10-20 15:24 - 00000000 ____D C:\ProgramData\Package Cache 2017-03-27 00:06 - 2016-12-31 18:56 - 00000658 _____ C:\Users\Public\Desktop\Battlefield 1.lnk 2017-03-26 22:44 - 2017-02-17 05:06 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2017-03-26 15:37 - 2016-10-20 15:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-03-26 15:32 - 2016-10-20 19:06 - 00000000 ____D C:\Program Files (x86)\Origin 2017-03-26 15:29 - 2016-10-22 11:21 - 00000000 ____D C:\Users\Seb\AppData\Local\Deployment 2017-03-26 14:55 - 2016-10-20 18:58 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-03-24 21:01 - 2016-10-21 20:20 - 00000000 ____D C:\Users\Seb\AppData\Roaming\FileZilla 2017-03-24 20:44 - 2016-10-29 09:29 - 00000000 ____D C:\Program Files (x86)\GIGABYTE 2017-03-24 12:55 - 2016-03-30 09:16 - 00000000 ____D C:\Users\Seb\Documents\Bewerbungen 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-03-22 00:19 - 2009-07-14 06:45 - 00556104 _____ C:\Windows\system32\FNTCACHE.DAT 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ___SD C:\Windows\system32\CompatTel 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ____D C:\Windows\system32\appraiser 2017-03-22 00:03 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-03-22 00:03 - 2016-10-20 15:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-03-21 23:53 - 2016-10-29 07:22 - 00000000 ____D C:\Windows\system32\MRT 2017-03-21 23:51 - 2016-10-29 07:22 - 138634176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-03-21 23:50 - 2017-02-13 03:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-03-21 23:45 - 2016-11-08 20:50 - 00000000 ____D C:\ProgramData\Skype 2017-03-21 23:27 - 2016-10-25 17:51 - 00000000 ____D C:\Users\Seb\Documents\My Games 2017-03-21 23:24 - 2016-10-20 15:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-21 23:18 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-03-21 23:06 - 2017-02-02 21:35 - 00004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2017-02-02 21:35 - 00001419 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2017-03-21 23:06 - 2016-10-29 09:20 - 00003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-20 15:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-03-21 23:06 - 2016-10-20 15:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-03-18 17:45 - 2017-01-03 00:52 - 00547904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.148985196613904 2017-03-18 17:45 - 2017-01-03 00:52 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.148985196721606 2017-03-17 02:59 - 2017-02-15 02:55 - 19883600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 13378096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 03583744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2017-03-17 02:59 - 2016-10-20 15:47 - 00042686 _____ C:\Windows\system32\nvinfo.pb 2017-03-17 02:59 - 2015-11-06 12:23 - 01600056 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2017-03-17 01:31 - 2016-10-29 09:20 - 00001951 _____ C:\Windows\NvContainerRecovery.bat 2017-03-17 01:16 - 2016-10-29 09:32 - 00549944 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2017-03-17 01:16 - 2016-10-29 09:32 - 00081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 02477504 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2017-03-16 11:39 - 2016-10-20 15:47 - 07813427 _____ C:\Windows\system32\nvcoproc.bin 2017-03-09 20:52 - 2016-12-10 12:46 - 00000000 ____D C:\Users\Seb\Desktop\Steuer 2017-03-03 20:14 - 2016-10-21 15:41 - 00000000 ____D C:\Fraps 2017-03-03 18:28 - 2016-10-26 18:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-03-03 18:27 - 2016-10-20 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-03-02 22:42 - 2016-12-19 01:43 - 00000000 ____D C:\Users\Seb\Documents\Visual Studio 2015 2017-02-27 01:22 - 2016-10-25 17:56 - 00000000 ____D C:\Users\Seb\AppData\Local\CrashDumps 2017-02-27 00:37 - 2017-02-26 21:04 - 00000000 ____D C:\Users\Seb\Downloads\GTA 5 mods - installed ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-10-26 18:41 - 2016-11-11 20:08 - 0000104 _____ () C:\Users\Seb\AppData\Roaming\Camdata.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamLayout.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamShapes.ini 2016-10-26 18:41 - 2016-11-11 17:06 - 0004535 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.cfg 2016-11-11 17:06 - 2016-11-11 17:06 - 0000000 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.Data.ini 2016-11-11 17:06 - 2016-11-11 17:06 - 0001206 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.ini 2016-10-26 18:41 - 2016-11-11 18:13 - 0000096 _____ () C:\Users\Seb\AppData\Roaming\version2.xml 2016-11-25 20:37 - 2017-01-06 22:17 - 0007602 _____ () C:\Users\Seb\AppData\Local\resmon.resmoncfg 2016-10-20 15:26 - 2016-10-20 15:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2016-10-22 11:23 - 2016-10-22 11:23 - 0000185 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2016-02-28 19:58 - 2016-02-28 19:58 - 0010218 _____ () C:\ProgramData\regid.2015-05.exe.textpad_83F5EF12-C2F9-4C11-A5C5-57A7B2D7AD25.swidtag ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-03-27 00:55 ==================== Ende von FRST.txt ============================ |
29.03.2017, 08:10 | #12 |
| Windows 7: Malware blockiert Internetverbindungen Addition: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017 durchgeführt von Seb (29-03-2017 09:08:49) Gestartet von C:\Users\Seb\Desktop Windows 7 Professional Service Pack 1 (X64) (2016-10-19 19:46:39) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-844095808-1650209266-980683291-500 - Administrator - Disabled) Gast (S-1-5-21-844095808-1650209266-980683291-501 - Limited - Disabled) Seb (S-1-5-21-844095808-1650209266-980683291-1000 - Administrator - Enabled) => C:\Users\Seb ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) @BIOS B16.0608.1 (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) @BIOS B16.0608.1 (x32 Version: 3.00.0000 - GIGABYTE) Hidden Active Directory Authentication Library für SQL Server (Version: 13.0.1601.5 - Microsoft Corporation) Hidden Active Directory Authentication Library für SQL Server (x86) (x32 Version: 13.0.1601.5 - Microsoft Corporation) Hidden Ambient LED (HKLM-x32\...\InstallShield_{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.2501 - GIGABYTE) Ambient LED (x32 Version: 1.00.1605.2501 - GIGABYTE) Hidden Ansel (Version: 378.92 - NVIDIA Corporation) Hidden APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1703.2301 - GIGABYTE) APP Center (x32 Version: 1.00.1703.2301 - GIGABYTE) Hidden Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation) Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.26.1 - Asmedia Technology) ASUS PCE-AC68 WLAN Card Driver (HKLM-x32\...\{39BD9681-D3B1-435C-A0C1-F87C68513401}) (Version: 2.1.1.5 - ASUS) Audacity 1.2.6 (HKLM-x32\...\Audacity_is1) (Version: - ) Audacity Recovery Utility (HKLM-x32\...\AURC_is1) (Version: - Markus Meyer) Autobahn Police Simulator (HKLM\...\Steam App 348510) (Version: - Z-Software) Avast Internet Security (HKLM-x32\...\Avast Antivirus) (Version: 17.3.2290 - AVAST Software) Azure AD Authentication Connected Service (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.49.28890 - Electronic Arts) Battlefield™ Hardline (HKLM-x32\...\{CB4AC3DA-8CC1-4516-86DA-4078B57DB229}) (Version: 1.4.0.10 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50716.0 - Microsoft Corporation) Hidden Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.51210.80 - Microsoft Corporation) Hidden BIOS Setup (HKLM-x32\...\InstallShield_{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) BIOS Setup (x32 Version: 1.00.0000 - GIGABYTE) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation) Build Tools - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Build Tools Language Resources - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Buildtools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Bus Simulator 16 (HKLM\...\Steam App 324310) (Version: - stillalive studios) Call of Duty: Infinite Warfare (HKLM\...\Steam App 292730) (Version: - Infinity Ward) CodedUITestUAP (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Color Temperature (HKLM-x32\...\InstallShield_{68BFE28B-3F55-4E00-90A4-5179B91A3BD0}) (Version: 16.05.0601 - GIGABYTE) Color Temperature (x32 Version: 16.05.0601 - GIGABYTE) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0196 - Disc Soft Ltd) Demolish & Build 2017 (HKLM\...\Steam App 470740) (Version: - Noble Muffins) Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden DLL-Files.com Client (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_DLL-Files.c~79141F26_is1) (Version: 2.1.1000.4462 - DLL-Files.com Client) Dotfuscator and Analytics Community Edition 5.22.0 (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden Dotfuscator and Analytics Community Edition Language Pack 5.22.0 de-DE (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.0506 - GIGABYTE) EasyTune (x32 Version: 1.16.0506 - GIGABYTE) Hidden EasyTuneEngineService (HKLM-x32\...\InstallShield_{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 2.16.0603 - GIGABYTE) EasyTuneEngineService (x32 Version: 2.16.0603 - GIGABYTE) Hidden ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 18.1.22140 - Landesfinanzdirektion Thüringen) Emergency 2017 (HKLM\...\Steam App 524110) (Version: - Sixteen Tons Entertainment) Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{3FF082A7-A5DE-4BDA-B56A-1D2BEFD617A3}) (Version: 11.1.3000.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{FD639F4D-1460-42E6-B32D-FEC1745D0BDC}) (Version: 13.0.1601.5 - Microsoft Corporation) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) F1 2016 (HKLM\...\Steam App 391040) (Version: - Codemasters) Farming Simulator 17 (HKLM\...\Steam App 447020) (Version: - Giants Software) Fast Boot (HKLM-x32\...\InstallShield_{FA8FB4F2-F524-48E1-A06C-45602FBF26CD}) (Version: 1.16.0406 - GIGABYTE) Fast Boot (x32 Version: 1.16.0406 - GIGABYTE) Hidden Fernbus Simulator (HKLM\...\Steam App 427100) (Version: - TML-Studios) FileZilla Client 3.24.1 (HKLM-x32\...\FileZilla Client) (Version: 3.24.1 - Tim Kosse) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2013 Sprachpaket (DEU) - v1.6 (x32 Version: 1.6.30930.3 - Microsoft Corporation) Hidden Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket – DEU - v1.8 (x32 Version: 1.8.40521.1 - Microsoft Corporation) Hidden GIANTS Editor 7.0.0 64-bit (HKLM-x32\...\giants_editor_7.0.0_win64_is1) (Version: 7.0.0 - GIANTS Software GmbH) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North) Greenshot 1.2.8.14 (HKLM\...\Greenshot_is1) (Version: 1.2.8.14 - Greenshot) IDE Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IDE-Tools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.1.40 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel® USB 3.1 Device Driver (HKLM\...\{7DFE2F7E-3154-45D6-A468-4725DE033AC8}) (Version: 15.2.30.250 - Intel Corporation) Intellisense Lang Pack Mobile Extension SDK 10.0.10586.0 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Killer Bandwidth Control Filter Driver (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer E240x Drivers (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Network Manager (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{009DF489-4590-4579-BAB2-0136BB829E4A}) (Version: 1.1.57.1346 - Rivet Networks) Kinect for Windows Speech Recognition Language Pack (de-DE) (HKLM-x32\...\{898AA67F-99B8-4C7F-9611-B11F98EF6E78}) (Version: 11.0.7413.611 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-AU) (HKLM-x32\...\{48CEC0A3-AE10-4EE3-AC62-76D3D58792E5}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-CA) (HKLM-x32\...\{9C5505DA-F9C1-46CB-9F8F-AC38F8EA518A}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-GB) (HKLM-x32\...\{A0186231-0A8B-455A-8A25-B64AABCC11A6}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-US) (HKLM-x32\...\{8AAA44BB-487E-4D01-AF76-484ACB90DBFE}) (Version: 11.0.7400.336 - Microsoft Corporation) Kits Configuration Installer (x32 Version: 10.0.26624 - Microsoft) Hidden KRISTAL Audio Engine (HKLM-x32\...\KRISTAL Audio Engine) (Version: - ) Leadwerks Game Engine (HKLM\...\Steam App 251810) (Version: - Leadwerks Software) MAGIX Common Components 1 (x64) (HKLM\...\{05799CB2-47FA-4322-9776-C0D15991EE7E}) (Version: 1.6.1.0 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\MX.{410B406D-6A35-41FF-B458-ADB0D3563487}) (Version: 2.0.1.145 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\Steam App 330130) (Version: - MAGIX Software GmbH) MAGIX Fastcut (Version: 2.0.1.145 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.4.235 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.5.273 - MAGIX Software GmbH) Hidden MAGIX Fonts Package 1 (x32 Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Screenshare (HKLM-x32\...\{20C81F73-2600-464A-BA60-401739102479}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{AB8304F0-383F-4F80-8988-87727C415BF7}) (Version: 7.0.2.6 - MAGIX Software GmbH) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX Software GmbH) Hidden MAGIX Video deluxe 2015 (HKLM\...\MX.{FFDC29E6-5C7C-4AA8-AF5A-99E015165382}) (Version: 14.0.0.159 - MAGIX Software GmbH) MAGIX Video deluxe 2015 (Version: 14.0.0.159 - MAGIX Software GmbH) Hidden MAGIX Videoton Cleaning Lab (HKLM-x32\...\MAGIX_MSI_Videoton_Cleaning_Lab) (Version: 1.0.0.0 - MAGIX AG) MAGIX Videoton Cleaning Lab (x32 Version: 1.0.0.0 - MAGIX AG) Hidden Malwarebytes Version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (HKLM-x32\...\{21B0F482-5EF9-45DA-8840-340AFE705A6C}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (Deutsch) (HKLM-x32\...\{529EFF09-750D-48B9-A47A-34A3B6248C3F}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Build Tools 2015 (HKLM-x32\...\{d21da0dd-4ba4-4838-ba58-64cf7a77131a}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.1 Sprachpaket - DEU) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.7766.2060 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft Server Speech Platform Runtime (x64) (HKLM\...\{3B433087-E62E-4BF5-97F9-4AF6E1C2409C}) (Version: 11.0.7400.345 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50905.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (HKLM-x32\...\{F351AA2C-723C-4CFE-A7CB-8E43AB164F7F}) (Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{D4E30517-FE6F-491E-942F-AE10E1B18F38}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{B4EDAE03-DB34-4DD0-BA7E-2ED80DEA50B1}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{269A8DF6-BBDA-441F-932B-233F9B746D72}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{EC75BD20-F9CA-4E77-825F-ABD77E95BE91}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{0BF65908-D137-4A9E-B7C9-78F32F74F6FD}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{93945D16-4C3D-433E-B7E4-3D0D86B284C8}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{6F173435-3F19-4043-BA3D-A46AA8472859}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL-Sprachdienst (HKLM-x32\...\{1D812D86-D8EF-41AC-A518-BA12E1913747}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2016 LocalDB (HKLM\...\{1765D93F-97E4-44D3-951D-0DA09B89EE17}) (Version: 13.0.2151.0 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (x64) (HKLM\...\{264B070C-82D7-4C9C-B1CE-A0B124BCC787}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM\...\{619537F4-1E39-4047-AA4F-D2D98A1DA743}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM-x32\...\{4EFF12AE-599C-42A2-ACFA-0D95C3B11A19}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL ScriptDom (HKLM\...\{E8F3D249-7DE6-4422-AC86-1CE7D5CCFA0F}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (12.0.61021.0) (HKLM-x32\...\{A8689DE4-28A2-4F57-9A5F-A4851A8FD849}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (14.0.60519.0) (HKLM-x32\...\{9F367648-EC0C-4F97-B351-D12A51E38F96}) (Version: 14.0.60519.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - Visual Studio 2013 (HKLM-x32\...\{1d259390-0778-4f41-8024-8c826a8ead96}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (12.0.30919.1) (HKLM-x32\...\{BCB8A870-2B3D-4CC0-87D6-F931E065AC0C}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server*2014 Express LocalDB (HKLM\...\{CA191120-4CB1-4E3D-89B8-79FDB9017A2E}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Transact-SQL ScriptDom (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 T-SQL Language Service (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2016 Management Objects (HKLM-x32\...\{35A7B00B-4F9C-4B4D-919C-86FFFEE46AD6}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{9634d50a-0c4d-4f52-8a9f-894a2baae370}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{307a22b8-8353-4c5e-b67b-2404c5734558}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio Community 2015 mit Updates (HKLM-x32\...\{ec2556f3-08aa-4829-8017-07d7ea9e125d}) (Version: 14.0.25420.1 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (HKLM-x32\...\{43341417-7882-4F34-8390-53DFD00F6C0F}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (HKLM\...\{24440413-490E-41CA-BD33-0B30FD3EBE3A}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{7F6DCED8-6A2B-4436-AF20-8F659D04E388}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{48BF289B-F3FA-4023-9251-80ABF7B726F9}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM\...\{FEC926D4-785B-4ED7-B35D-3FA37DD29F8B}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM-x32\...\{A37BE9D7-EAAE-4C6B-9D7E-DBD8B8D88681}) (Version: 13.0.1601.5 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden Motorsport Manager (HKLM\...\Steam App 415200) (Version: - Playsport Games) Mozilla Firefox 52.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 52.0.1 (x86 de)) (Version: 52.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.1.6284 - Mozilla) Mozilla Thunderbird 45.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 45.2.0 (x86 de)) (Version: 45.2.0 - Mozilla) Mozilla Thunderbird 45.8.0 (x86 de) (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Mozilla Thunderbird 45.8.0 (x86 de)) (Version: 45.8.0 - Mozilla) MSBuild/NuGet Integration 14.0 (x86) (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Napster (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\5d01cae694a4998b) (Version: 6.17.50.0 - Rhapsody International Inc.) Need for Speed™ The Run (HKLM-x32\...\{0EDC9BA0-016E-406a-86DA-04FC1BE00C21}) (Version: 1.1.0.0 - Electronic Arts) Notruf 112 (HKLM\...\Steam App 491530) (Version: - Crenetic GmbH Studios) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation) NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation) NVIDIA Grafiktreiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.16.2 - OBS Project) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) ON_OFF Charge 2 B15.0709.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden OpenIV (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OpenIV) (Version: 2.8.703 - .black/OpenIV Team) Origin (HKLM-x32\...\Origin) (Version: 10.4.5.30491 - Electronic Arts, Inc.) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{FACF2669-E25A-428A-9167-5EEDE741F3B9}) (Version: 4.6.00127 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM-x32\...\{4860C1E5-CE58-4D32-89DE-37951333B4C9}) (Version: 4.6.01055 - Microsoft Corporation) PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.26.25466 - pdfforge GmbH) PDF Architect 4 Asian Fonts Pack (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Convert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Forms Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Insert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 OCR Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Review Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Secure Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Projekt- und Elementvorlagen für Visual Studio Express 2015 für Windows 10 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Projekt- und Elementvorlagen für Visual Studio Professional 2015 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.994 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7727 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.4 - Rockstar Games) Roslyn Language Services - x86 (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden SIV (HKLM-x32\...\InstallShield_{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.16.0525 - GIGABYTE) SIV (x32 Version: 1.16.0525 - GIGABYTE) Hidden SketchUp 2017 (HKLM\...\{5A8C61BD-0912-4B76-805E-4EDE5E13298C}) (Version: 17.1.174 - Trimble Navigation Limited) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Hidden SmartKeyboard (HKLM-x32\...\InstallShield_{75B74C36-A9C6-4912-B4BB-C461AA36D01E}) (Version: 1.00.0000 - GIGABYTE) SmartKeyboard (x32 Version: 1.00.0000 - GIGABYTE) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (x32 Version: 14.102.25619 - Microsoft) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) TeamViewer 12 Host (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer) Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios) Thin2000 USB Display Adapter (HKLM\...\{CB5F5631-515F-4C70-ACA5-3FAAFA1866BC}) (Version: 1.1.323.0 - Fresco Logic) Thunderbolt(TM) Software (HKLM-x32\...\{B0E8A8CA-5A40-49C3-BE5E-9076664DB9AA}) (Version: 15.3.39.250 - Intel Corporation) TypeScript Power Tool (x32 Version: 1.8.34.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.36.0 - Microsoft Corporation) Hidden UE4 Prerequisites (x64) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (x32 Version: 1.0.13.0 - Epic Games, Inc.) Hidden Universal CRT Extension SDK (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Redistributable (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x64 (Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x86 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) VS Update core components (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden vs_update3notification (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Watch_Dogs 2 (HKLM\...\Steam App 447040) (Version: - Ubisoft) WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation) WinAppDeploy (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Windows SDK AddOn (HKLM-x32\...\{75C39BA6-1D02-4BEA-844F-0EA6C4B7FA1B}) (Version: 10.1.0.0 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.10586.212 (HKLM-x32\...\{43d9f43d-c90b-4fdf-9dfe-ecf9990bfa2a}) (Version: 10.1.10586.212 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.26624 (HKLM-x32\...\{e7a0c8b6-b0e9-41e2-8a0a-a6784f88d1d4}) (Version: 10.0.26624 - Microsoft Corporation) Windows-Treiberpaket - Graphics Tablet (WinUsb) USBDevice (04/10/2014 8.33.30.0) (HKLM\...\142118DF51345EA02D2B1583E102C8FB95FD6D52) (Version: 04/10/2014 8.33.30.0 - Graphics Tablet) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) WinRT Intellisense Desktop - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Desktop - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinSweeper 2.1 (HKLM-x32\...\{96E8A815-3053-4616-AAC2-865E6B1792F5}_is1) (Version: - Solvusoft Corporation) World of Tanks Blitz (HKLM\...\Steam App 444200) (Version: - Wargaming Group Limited) XAMPP (HKLM-x32\...\xampp) (Version: 5.6.8-0 - Bitnami) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-844095808-1650209266-980683291-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Seb\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {191E8CED-5BA5-4EE3-8DC0-C8257FE2CFAA} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation) Task: {1DEFEEA4-B4A7-4654-BBD7-43AF718B4AC6} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => P:\Programme (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation) Task: {2EC4D652-1888-44F7-9811-C4959B854A6F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {3F31AB12-2BE3-4DFF-937D-C2512794E784} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {41D1D541-4206-4C63-BEC7-327098990ABA} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-03-28] (AVAST Software) Task: {441E0E52-EAB6-48E5-A1DA-174B77491E51} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) Task: {488F73BD-5AF1-494C-A38B-D7E98D4D25DB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {4B5F255F-761D-4D0E-8736-291C9C1BDEAF} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => Thunderbolt.exe Task: {5DE984B7-D648-47FD-873D-9E1AD1CD6116} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => Thunderbolt.exe Task: {6170758E-2D8B-46D3-80DD-B9DF43C95A4F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-02-19] (Microsoft Corporation) Task: {7CE3E841-D7F1-4A12-B12E-E509E3A66685} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {7DF9EEC8-4310-4833-AA36-B112995760F5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-28] (AVAST Software) Task: {854BE4ED-D2D2-482F-9BD7-F54256C7F6E0} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService Task: {AE37F061-38D4-41F4-A0B6-3973F5FB378C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation) Task: {B8021389-D6F2-4922-A95C-1A7D067E1A29} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {B9EA1437-FF91-46FB-B4BA-48F6D8B4211F} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation) Task: {C7E9D51D-8274-4306-AF9B-A94762348F9F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => tbtsvc.exe Task: {D8693F66-18EA-41CA-AD97-43AE1B96716B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {F672F9E7-4540-4C1E-A3FB-C403F543FE5F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-02-17 05:07 - 2016-12-15 12:37 - 00020208 _____ () C:\Windows\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll 2015-06-25 10:45 - 2015-06-25 10:45 - 00017920 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe 2016-10-29 09:20 - 2017-02-23 20:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-20 15:47 - 2017-03-17 01:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-10-22 14:16 - 2016-11-06 03:45 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2017-03-26 14:51 - 2017-02-24 06:23 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-03-26 14:51 - 2017-02-24 06:23 - 02264528 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00162024 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00790544 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00275776 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll 2017-03-23 11:40 - 2017-03-23 11:40 - 01850800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe 2015-05-14 03:30 - 2015-05-14 03:30 - 00419328 _____ () C:\Windows\System32\flvga_tray.exe 2017-03-28 19:22 - 2017-03-28 19:22 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00176480 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-03-28 19:21 - 2017-03-28 19:21 - 05889024 _____ () C:\Program Files\AVAST Software\Avast\defs\17032801\algo.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00653520 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00230632 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2015-02-17 01:47 - 2015-02-17 01:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\ycc.dll 2016-08-09 20:49 - 2016-08-09 20:49 - 01804800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\BDR_info.dll 2015-02-16 11:47 - 2015-02-16 11:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ycc.dll 2017-01-03 00:52 - 2017-01-03 00:52 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00293936 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2016-10-20 19:06 - 2017-03-26 15:32 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2016-10-29 09:20 - 2017-02-23 16:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-10-29 09:20 - 2017-02-23 16:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-844095808-1650209266-980683291-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupfolder: C:^Users^Seb^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\Windows\pss\An OneNote senden.lnk.Startup MSCONFIG\startupreg: DAEMON Tools Lite Automount => "P:\Programme\DAEMON Tools Lite\DTAgent.exe" -autorun MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: Greenshot => P:\Programme\Greenshot\Greenshot.exe MSCONFIG\startupreg: OneDrive => "C:\Users\Seb\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background MSCONFIG\startupreg: Overwolf => "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent MSCONFIG\startupreg: PreRun => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe MSCONFIG\startupreg: TabletDriver => C:\PenTabletDriver\TabletDriver.exe -hide ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{D5A10B96-019A-463B-93FA-E793E9FD99AD}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{B4866065-6535-4F02-A6ED-1135D0AF6369}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{FC34C004-8D8E-471F-8472-EC7E5A07A944}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{34220BE5-470C-49B1-988C-6A766AE041E4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{57203B3F-273A-4BCD-A084-20CFB95B4F33}C:\program files (x86)\gigabyte\appcenter\gcupd.exe] => (Allow) C:\program files (x86)\gigabyte\appcenter\gcupd.exe FirewallRules: [UDP Query User{7DF7F82C-B3FA-40D3-AAFB-093E66B97C8A}C:\program files (x86)\gigabyte\appcenter\gcupd.exe] => (Allow) C:\program files (x86)\gigabyte\appcenter\gcupd.exe FirewallRules: [TCP Query User{83CBCA05-0092-4624-A2EE-AEA87720796F}P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe] => (Allow) P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe FirewallRules: [UDP Query User{23E2BD2C-46F9-49F5-AE2F-9CB8AC2747BF}P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe] => (Allow) P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe FirewallRules: [{DE88D321-F128-4B12-BAB3-19EFE8F881E8}] => (Allow) P:\Spiele\Battlefield 1\bf1Trial.exe FirewallRules: [{50AD9EBA-9C32-4DE2-A3AF-A51B0680B7CA}] => (Allow) P:\Spiele\Battlefield 1\bf1Trial.exe FirewallRules: [{50073B1D-8DEA-4008-BFCE-1D2CA15E8474}] => (Allow) P:\Spiele\Battlefield 1\bf1.exe FirewallRules: [{422BB53F-5B92-4A4A-A239-6F05AACB8AC5}] => (Allow) P:\Spiele\Battlefield 1\bf1.exe FirewallRules: [{1004E635-633A-425B-94A0-21735B3731D6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe FirewallRules: [{FD154E03-263B-41DB-97FB-BB94F20D4B00}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe FirewallRules: [{4CFF971B-E5B3-47A1-8D5F-847BB8A9B3F3}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe FirewallRules: [{D08C05D6-B42B-461A-99C8-95D2700B733E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe ==================== Wiederherstellungspunkte ========================= 21-03-2017 23:49:32 Windows Update 24-03-2017 11:12:01 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:33:29 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:43:10 WinThruster (64-bit) Backup 24-03-2017 20:43:57 Removed APP Center 24-03-2017 20:44:11 Installed APP Center 24-03-2017 20:44:44 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 21:07:32 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 26-03-2017 15:32:32 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 26-03-2017 15:32:42 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 26-03-2017 15:37:19 Installiert ASUS PCE-AC68 WLAN Card Driver 27-03-2017 00:05:49 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 27-03-2017 00:05:56 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 27-03-2017 00:37:04 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 27-03-2017 00:37:20 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (03/29/2017 09:07:54 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x86\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/29/2017 09:07:53 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x64\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm\signtool.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Appx.AppxSip.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\inspect.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\inspect.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\accevent.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\accevent.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AccScope\accscope.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AccScope\accscope.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AppPerfAnalyzer\appperfanalyzer_js.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\AppPerfAnalyzer\appperfanalyzer_js.exe" in Zeile 8. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\signtool.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Appx.AppxSip.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\makecert.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\makecert.exe" in Zeile 9. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm64\certmgr.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Kits\10\bin\arm64\certmgr.exe" in Zeile 9. Der Wert "arm64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Systemfehler: ============= Error: (03/29/2017 08:55:23 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} und APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden. Error: (03/29/2017 08:55:07 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UsbCharger Error: (03/29/2017 08:54:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (03/29/2017 08:54:51 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht. Error: (03/29/2017 08:53:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden. Error: (03/29/2017 08:53:46 AM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: Die Anforderung wird nicht unterstützt. Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (03/29/2017 08:53:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden. Error: (03/29/2017 08:53:46 AM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "WMPNetworkSvc" konnte sich nicht als "NT AUTHORITY\NetworkService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: Die Anforderung wird nicht unterstützt. Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (03/29/2017 08:53:44 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\Windows\System32\bcmihvsrv64.dll Error: (03/29/2017 08:53:44 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\Windows\System32\bcmihvsrv64.dll CodeIntegrity: =================================== Date: 2016-12-02 18:49:24.791 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.766 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.741 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.716 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.691 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.665 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.639 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.614 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.589 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.553 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz Prozentuale Nutzung des RAM: 29% Installierter physikalischer RAM: 16333.03 MB Verfügbarer physikalischer RAM: 11573.68 MB Summe virtueller Speicher: 32664.25 MB Verfügbarer virtueller Speicher: 27741.7 MB ==================== Laufwerke ================================ Drive b: (Bilder) (Fixed) (Total:151.37 GB) (Free:65.28 GB) NTFS Drive c: (Windows) (Fixed) (Total:447.03 GB) (Free:126.44 GB) NTFS Drive e: (Filme) (Fixed) (Total:465.76 GB) (Free:344.71 GB) NTFS Drive m: (Musik) (Fixed) (Total:151.37 GB) (Free:145.56 GB) NTFS Drive p: (Programme) (Fixed) (Total:850 GB) (Free:135.09 GB) NTFS Drive v: (Videos) (Fixed) (Total:163.02 GB) (Free:138.82 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 447.1 GB) (Disk ID: 94D2A2C1) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=447 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0009AF56) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7BA18A71) Partition 1: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=163 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
29.03.2017, 20:29 | #13 |
/// TB-Ausbilder | Windows 7: Malware blockiert Internetverbindungen Servus, Wir kontrollieren nochmal alles. Hinweis: Der Suchlauf mit ESET kann länger dauern. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start CloseProcesses: C:\Users\Seb\Downloads\Neuer Ordner (2)\Setup_WinThruster_2016.exe end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 3 ESET Online Scanner
Schritt 4
Gibt es jetzt noch Probleme mit dem PC oder mit deinen Internet Browsern? Wenn ja, welche? Bitte poste mit deiner nächsten Antwort
|
30.03.2017, 19:47 | #14 |
| Windows 7: Malware blockiert Internetverbindungen FixLog: Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017 durchgeführt von Seb (30-03-2017 07:41:18) Run:2 Gestartet von C:\Users\Seb\Desktop Geladene Profile: Seb (Verfügbare Profile: Seb) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** start CloseProcesses: C:\Users\Seb\Downloads\Neuer Ordner (2)\Setup_WinThruster_2016.exe end ***************** Prozesse erfolgreich geschlossen. C:\Users\Seb\Downloads\Neuer Ordner (2)\Setup_WinThruster_2016.exe => erfolgreich verschoben Das System musste neu gestartet werden. ==== Ende von Fixlog 07:41:19 ==== Code:
ATTFilter HitmanPro 3.7.15.281 www.hitmanpro.com Computer name . . . . : GAMING-PC Windows . . . . . . . : 6.1.1.7601.X64/8 User name . . . . . . : Gaming-PC\Seb UAC . . . . . . . . . : Enabled License . . . . . . . : Free Scan date . . . . . . : 2017-03-30 07:45:54 Scan mode . . . . . . : Normal Scan duration . . . . : 6m 15s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 1 Traces . . . . . . . : 3 Objects scanned . . . : 2.463.019 Files scanned . . . . : 53.296 Remnants scanned . . : 524.465 files / 1.885.258 keys Malware _____________________________________________________________________ C:\Users\Seb\Downloads\Neuer Ordner (2)\CamStudio 2.7\CamStudio - CHIP-Installer.exe Size . . . . . . . : 1.101.648 bytes Age . . . . . . . : 154.5 days (2016-10-26 18:46:02) Entropy . . . . . : 7.0 SHA-256 . . . . . : 860DAA63A99A51F1D7569B4144DC31CD4487AA5AFCC6C5C742DA99FEF3279585 Needs elevation . : Yes RSA Key Size . . . : 2048 Authenticode . . . : Valid > Kaspersky . . . . : not-a-virus:RiskTool.Win32.Ocna.gen Fuzzy . . . . . . : 103.0 Suspicious files ____________________________________________________________ C:\Users\Seb\Desktop\FRST64.exe Size . . . . . . . : 2.424.832 bytes Age . . . . . . . : 3.7 days (2017-03-26 14:30:40) Entropy . . . . . : 7.6 SHA-256 . . . . . : 3A3DCD0D3C9C1FE10C45AF795DC9452DA192246BB67D896AB7F16151A53C1B5F Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. References HKU\S-1-5-21-844095808-1650209266-980683291-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\Seb\Desktop\FRST64.exe Forensic Cluster 0.0s C:\Users\Seb\Desktop\FRST64.exe 22.7s C:\Users\Seb\Desktop\tdsskiller.exe ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=f7c4e2e75bad364cb037b21aa5e3260d # end=init # utc_time=2017-03-30 05:54:17 # local_time=2017-03-30 07:54:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 32891 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=f7c4e2e75bad364cb037b21aa5e3260d # end=updated # utc_time=2017-03-30 05:56:16 # local_time=2017-03-30 07:56:16 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=f7c4e2e75bad364cb037b21aa5e3260d # engine=32891 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2017-03-30 07:28:33 # local_time=2017-03-30 09:28:33 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avast Antivirus' # compatibility_mode=799 16777213 66 82 88676 7464985 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 13435332 242488763 0 0 # scanned=452338 # found=10 # cleaned=0 # scan_time=5536 sh=06AEEE97A8E40D82E97A0945E61C9EF1C0E7DDE7 ft=1 fh=8c61c410b53542e1 vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\anfxzysjjqzbqqqmsngwrqwxssquiawa\Tray\AutoInstall\DM.exe" sh=06AEEE97A8E40D82E97A0945E61C9EF1C0E7DDE7 ft=1 fh=8c61c410b53542e1 vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\anfxzysjjqzbqqqmsngwrqwxssquiawa\Tray\Updates\TKTRAY-DM\DM.exe" sh=1B16CBB33328B6423D94BE7870EBA8A1FC6878F4 ft=1 fh=03ced33df6e35ece vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\qewhbobcthirhtsxdmexzsslfyozmdby\WinThruster\MsgSys.exe" sh=87A898FD79D4D3417465A0E154964960B000C90E ft=1 fh=5f866aa4a1845b8b vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\qewhbobcthirhtsxdmexzsslfyozmdby\WinThruster\sfhtml.dll" sh=87A898FD79D4D3417465A0E154964960B000C90E ft=1 fh=5f866aa4a1845b8b vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\OFFLINE\2E0FC2A8\97827A85\sfhtml.dll" sh=1B16CBB33328B6423D94BE7870EBA8A1FC6878F4 ft=1 fh=03ced33df6e35ece vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\OFFLINE\55B400A5\97827A85\MsgSys.exe" sh=B60CB64C277732C393A92847F7751CDF3025C213 ft=1 fh=a9876a88dffe9128 vn="Variante von Win32/SlowPCfighter eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\OFFLINE\68385B83\A7CBC777\WinThruster.exe" sh=28974CEFB478DEEA416C96B771A6849BEF54E4B9 ft=1 fh=b20f1b1415d1df3c vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\rfavnvdjakfgdaiwnxuvjvsjvpiqdtjb\OFFLINE\AEED362E\97827A85\CommonToolkitSuiteLight.dll" sh=8194BB2B9553B5EDA3CF74B13444B60977CBDCC3 ft=1 fh=29befc07afba20fa vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\Seb\Downloads\Neuer Ordner (2)\Setup_WinThruster_2016.exe.xBAD" sh=80949B171B4054C1233FCFECE2DAD4376529C9DD ft=1 fh=84739757af3b2fb9 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Seb\Downloads\Neuer Ordner (2)\CamStudio 2.7\CamStudio - CHIP-Installer.exe" Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017 durchgeführt von Seb (Administrator) auf GAMING-PC (30-03-2017 20:45:53) Gestartet von C:\Users\Seb\Desktop Geladene Profile: Seb (Verfügbare Profile: Seb) Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe (OSBASE) C:\Windows\System32\ddmgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (pdfforge GmbH) P:\Programme\PDF Architect 4\creator-ws.exe (© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (DEVGURU Co., LTD.) P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngine.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\SIV\thermald.exe () C:\Windows\System32\flvga_tray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-27] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [flvga_tray64] => C:\Windows\system32\flvga_tray.exe [419328 2015-05-14] () HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-03-28] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM-x32\...\RunOnce: [EasyTuneEngineService] => C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EngineRunOnce.exe [14632 2016-05-03] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [EasyTune] => C:\Program Files (x86)\GIGABYTE\EasyTune\etro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [SIV] => C:\Program Files (x86)\GIGABYTE\SIV\sivro.exe [5632 2016-04-26] (GIGA-BYTE TECHNOLOGY CO., LTD.) HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe [14632 2016-02-26] () HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-03-23] (Valve Corporation) HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3044816 2017-03-26] (Electronic Arts) HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\MountPoints2: {d30ece49-96c7-11e6-bcff-806e6f6e6963} - D:\ZToolBar.exe ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-28] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-28] (AVAST Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-10-20] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) BootExecute: autocheck autochk:b ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{CEBDFDF5-5314-417B-8F65-948D370BAC2B}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{EE112510-05F2-423F-9B82-4CF134C99522}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== SearchScopes: HKU\S-1-5-21-844095808-1650209266-980683291-1000 -> {DA6F9CB8-5F1C-45FC-AB8D-6C4B3457583F} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-01-29] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-01-29] (Microsoft Corporation) BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-29] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-02-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-29] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2016-08-05] (pdfforge GmbH) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: 8i010wxq.default FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default [2017-03-30] FF NetworkProxy: Mozilla\Firefox\Profiles\8i010wxq.default -> type", 0 FF Extension: (Flash Video Downloader - YouTube HD Download [4K]) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\artur.dubovoy@gmail.com [2017-02-20] FF Extension: (ColorZilla) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-03-09] FF Extension: (Site Deployment Checker) - C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\8i010wxq.default\features\{07233581-9539-488f-93b7-c5fc51995368}\deployment-checker@mozilla.org.xpi [2017-03-26] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\jgc1n486.Standard-Benutzer [2017-03-29] FF ProfilePath: C:\Users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\xs280j99.Standard-Benutzer1 [2017-03-29] FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-29] [ist nicht signiert] FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension FF Extension: (PDF Architect 4 Creator) - P:\Programme\PDF Architect 4\resources\pdfarchitect4firefoxextension [2017-01-08] [ist nicht signiert] FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Keine Datei] FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-01-29] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-03-17] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH) Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default CHR DefaultSearchKeyword: Default -> Yahoo CHR DefaultSuggestURL: Default -> hxxps://de.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Profile: C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default [2017-03-29] CHR Extension: (Google Präsentationen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-20] CHR Extension: (Google Docs) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-20] CHR Extension: (Google Drive) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-20] CHR Extension: (YouTube) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-20] CHR Extension: (Google-Suche) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-10-20] CHR Extension: (Yahoo Partner) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabhkdeopjkcpkmofliimbjckmocfiom [2016-12-28] CHR Extension: (Google Tabellen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-20] CHR Extension: (Google Docs Offline) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-01] CHR Extension: (Avast Online Security) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-28] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-20] CHR Extension: (Google Mail) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-20] CHR Extension: (Chrome Media Router) - C:\Users\Seb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-28] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fabhkdeopjkcpkmofliimbjckmocfiom] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-03-28] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-03-28] (AVAST Software) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3704520 2017-02-18] (Microsoft Corporation) R2 ddmgr; C:\Windows\system32\ddmgr.exe [1659040 2016-01-04] (OSBASE) S3 Disc Soft Lite Bus Service; P:\Programme\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1468608 2016-10-06] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-25] (EasyAntiCheat Ltd) R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [142656 2016-06-01] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 ElfoService; P:\Programme\ElsterFormular Update Service\bin\ElfoService.exe [1283376 2017-02-13] () R2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [Datei ist nicht signiert] S3 HwmRecordService; C:\Program Files (x86)\GIGABYTE\SIV\HwmRecordService.exe [118568 2016-05-24] (GIGA-BYTE TECHNOLOGY CO., LTD.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21184 2016-03-29] (Microsoft Corporation) S4 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-02-12] (Rivet Networks) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440 2017-03-17] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-02-23] (NVIDIA Corporation) S2 OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [127272 2016-05-20] (GIGA-BYTE TECHNOLOGY CO., LTD.) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123240 2017-03-26] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2184688 2017-03-26] (Electronic Arts) S3 PDF Architect 4; P:\Programme\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH) S3 PDF Architect 4 CrashHandler; P:\Programme\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Creator; P:\Programme\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH) R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-11-06] () R2 ss_conn_service; P:\Programme\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.) S3 Te.Service; C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [137216 2016-03-29] (Microsoft Corporation) [Datei ist nicht signiert] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10362608 2016-12-15] (TeamViewer GmbH) S3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [1831064 2015-11-04] (Intel Corporation) S3 VSStandardCollectorService140; P:\Programme (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] () R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-03-28] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-28] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-03-28] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-28] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-03-30] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-03-30] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-30] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-03-30] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-03-30] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-03-30] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-03-30] (AVAST Software) R3 ausb3hub; C:\Windows\System32\DRIVERS\ausb3hub.sys [404480 2016-10-20] (Intel Corporation) R3 ausb3xhc; C:\Windows\System32\DRIVERS\ausb3xhc.sys [817664 2016-10-20] (Intel Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-02-12] (Rivet Networks, LLC.) R4 ddkmd; C:\Windows\system32\drivers\ddkmd.sys [254968 2016-01-04] (OSBASE) [Datei ist nicht signiert] R0 ddkmdldr; C:\Windows\System32\drivers\ddkmdldr.sys [16888 2016-01-04] (OSBASE) [Datei ist nicht signiert] S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-10-22] (Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-10-22] (Disc Soft Ltd) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77408 2017-02-24] () R3 FLxHCIv; C:\Windows\System32\Drivers\FLxHCIv.sys [199304 2016-01-08] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31728 2015-11-12] (Intel Corporation) R3 KillerEth; C:\Windows\System32\DRIVERS\e2xw7x64.sys [134296 2016-02-12] (Qualcomm Atheros, Inc.) R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-03-30] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-03-30] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-03-30] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251840 2017-03-30] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82208 2017-03-30] (Malwarebytes) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation) S3 nhi; C:\Windows\System32\DRIVERS\tbt70x.sys [126464 2015-11-10] (Intel Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-02-23] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2017-01-20] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (The OpenVPN Project) [Datei ist nicht signiert] S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] () S3 vmulti; C:\Windows\System32\DRIVERS\vmulti.sys [19504 2016-01-13] (Windows (R) Win 7 DDK provider) R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-30 20:45 - 2017-03-30 20:46 - 00025710 _____ C:\Users\Seb\Desktop\FRST.txt 2017-03-30 20:05 - 2017-03-30 20:05 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-03-30 07:57 - 2017-03-30 09:01 - 00000000 ____D C:\Users\Seb\AppData\Roaming\vlc 2017-03-30 07:54 - 2017-03-30 09:28 - 00003931 _____ C:\Users\Seb\Desktop\EsetLog1.txt 2017-03-30 07:54 - 2017-03-30 07:54 - 00000000 ____D C:\Program Files (x86)\ESET 2017-03-30 07:53 - 2017-03-30 07:53 - 02870984 _____ (ESET) C:\Users\Seb\Desktop\esetsmartinstaller_deu.exe 2017-03-30 07:47 - 2017-03-30 07:47 - 00000098 _____ C:\Users\Seb\Desktop\Fixlist2.txt 2017-03-30 07:46 - 2017-03-30 07:47 - 00000235 _____ C:\Users\Seb\Desktop\Fixlist1.txt 2017-03-30 07:45 - 2017-03-30 07:53 - 00000000 ____D C:\ProgramData\HitmanPro 2017-03-30 07:45 - 2017-03-30 07:45 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-03-30 07:44 - 2017-03-30 07:44 - 11581544 _____ (SurfRight B.V.) C:\Users\Seb\Desktop\HitmanPro_x64.exe 2017-03-30 07:44 - 2017-03-30 07:41 - 00000648 _____ C:\Users\Seb\Desktop\Fixlog2.txt 2017-03-29 09:08 - 2017-03-29 09:09 - 00083571 _____ C:\Users\Seb\Desktop\FRST3.txt 2017-03-29 09:08 - 2017-03-29 09:09 - 00066311 _____ C:\Users\Seb\Desktop\Addition3.txt 2017-03-29 08:58 - 2017-03-29 09:06 - 00079360 _____ C:\Users\Seb\Desktop\SystemLook.txt 2017-03-29 08:57 - 2017-03-29 08:57 - 00165376 _____ C:\Users\Seb\Desktop\SystemLook_x64.exe 2017-03-29 08:53 - 2017-03-30 07:46 - 00002686 _____ C:\Users\Seb\Desktop\Fixlog1.txt 2017-03-28 20:26 - 2017-03-28 20:26 - 00001073 _____ C:\Users\Public\Desktop\VLC media player.lnk 2017-03-28 20:26 - 2017-03-28 20:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-03-28 20:26 - 2017-03-28 20:26 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-03-28 19:58 - 2017-03-28 19:59 - 30533688 _____ C:\Users\Seb\Downloads\vlc-2.2.4-win32.exe 2017-03-27 00:06 - 2017-03-27 00:06 - 00000000 ___HD C:\Program Files\Common FilesEAInstaller 2017-03-26 15:37 - 2017-03-26 15:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Utility 2017-03-26 15:37 - 2017-03-26 15:37 - 00000000 ____D C:\Program Files (x86)\ASUS 2017-03-26 15:37 - 2014-12-15 21:47 - 04401152 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll 2017-03-26 15:37 - 2014-12-15 21:47 - 03667968 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll 2017-03-26 15:36 - 2017-03-26 15:36 - 00000000 ____D C:\Users\Seb\Downloads\UT_PCE-AC68_2115 2017-03-26 15:12 - 2017-03-26 15:13 - 00082772 _____ C:\Users\Seb\Desktop\FRST2.txt 2017-03-26 15:12 - 2017-03-26 15:13 - 00063437 _____ C:\Users\Seb\Desktop\Addition2.txt 2017-03-26 15:12 - 2017-03-26 15:12 - 00002351 _____ C:\Users\Seb\Desktop\MalwareBytes.txt 2017-03-26 14:53 - 2017-03-26 14:54 - 93433704 _____ C:\Users\Seb\Downloads\UT_PCE_AC68_2115.zip 2017-03-26 14:52 - 2017-03-30 20:37 - 00082208 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-03-26 14:52 - 2017-03-30 07:43 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-03-26 14:52 - 2017-03-30 07:43 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-03-26 14:52 - 2017-03-30 07:43 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-03-26 14:51 - 2017-03-30 07:42 - 00251840 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-03-26 14:51 - 2017-03-26 14:51 - 00001874 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-26 14:51 - 2017-03-26 14:51 - 00000000 ____D C:\Program Files\Malwarebytes 2017-03-26 14:51 - 2017-02-24 06:23 - 00077408 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-03-26 14:50 - 2017-03-26 14:50 - 57131432 _____ (Malwarebytes ) C:\Users\Seb\Desktop\mb3-setup-consumer-3.0.6.1469-1075.exe 2017-03-26 14:45 - 2017-03-26 14:45 - 00006461 _____ C:\Users\Seb\Desktop\AdwCleaner[C0].txt 2017-03-26 14:43 - 2017-03-26 15:10 - 00000000 ____D C:\AdwCleaner 2017-03-26 14:42 - 2017-03-26 14:42 - 04031440 _____ C:\Users\Seb\Desktop\AdwCleaner_6.044.exe 2017-03-26 14:38 - 2017-03-26 14:42 - 00233058 _____ C:\Users\Seb\Desktop\TDSSKiller.3.1.0.12_26.03.2017_14.38.22_log.txt 2017-03-26 14:31 - 2017-03-30 20:45 - 00000000 ____D C:\FRST 2017-03-26 14:31 - 2017-03-26 14:32 - 00081292 _____ C:\Users\Seb\Desktop\FRST1.txt 2017-03-26 14:31 - 2017-03-26 14:32 - 00073700 _____ C:\Users\Seb\Desktop\Addition1.txt 2017-03-26 14:31 - 2017-03-26 14:31 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Seb\Desktop\tdsskiller.exe 2017-03-26 14:30 - 2017-03-26 14:30 - 02424832 _____ (Farbar) C:\Users\Seb\Desktop\FRST64.exe 2017-03-24 20:49 - 2017-03-30 07:43 - 00196286 _____ C:\Windows\SysWOW64\bios.ini 2017-03-24 20:44 - 2017-03-24 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE 2017-03-24 12:54 - 2017-03-24 12:54 - 00038955 _____ C:\Users\Seb\Downloads\Augenaerztlicher_Vorabbefund.pdf 2017-03-22 02:10 - 2017-03-22 02:10 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Playsport Games 2017-03-22 00:24 - 2017-03-22 00:24 - 00000222 _____ C:\Users\Seb\Desktop\Motorsport Manager.url 2017-03-22 00:02 - 2017-03-22 00:02 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-03-22 00:02 - 2017-03-17 00:56 - 00134592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-03-22 00:02 - 2017-01-26 02:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-03-22 00:02 - 2017-01-26 02:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll 2017-03-22 00:02 - 2017-01-26 02:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe 2017-03-22 00:00 - 2017-03-17 02:59 - 40190400 _____ C:\Windows\system32\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 34952760 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 28223544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 17282648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 16400616 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14674712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 14434360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 11122912 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 04064088 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03627064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 03187256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 01053240 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00989120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00912440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00504104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00492560 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00425104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00408272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2017-03-22 00:00 - 2017-03-17 02:59 - 00170360 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00153368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-03-22 00:00 - 2017-03-17 02:59 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:33 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:31 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-03-21 23:49 - 2017-03-08 06:22 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-03-21 23:49 - 2017-03-08 06:18 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:16 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-03-21 23:49 - 2017-03-08 06:16 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-03-21 23:49 - 2017-03-08 06:07 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-03-21 23:49 - 2017-03-08 06:06 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-03-21 23:49 - 2017-03-08 06:06 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-03-21 23:49 - 2017-03-04 19:24 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 18:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-03-21 23:49 - 2017-03-04 10:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-03-21 23:49 - 2017-03-04 10:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-03-21 23:49 - 2017-03-04 10:02 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-03-21 23:49 - 2017-03-04 10:01 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-04 10:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-04 09:59 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-03-21 23:49 - 2017-03-04 09:52 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-03-21 23:49 - 2017-03-04 09:51 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-03-21 23:49 - 2017-03-04 09:48 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-03-21 23:49 - 2017-03-04 09:46 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-03-21 23:49 - 2017-03-04 09:45 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-03-21 23:49 - 2017-03-04 09:45 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-03-21 23:49 - 2017-03-04 09:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-03-21 23:49 - 2017-03-04 09:36 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-03-21 23:49 - 2017-03-04 09:32 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-03-21 23:49 - 2017-03-04 09:31 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-03-21 23:49 - 2017-03-04 09:23 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-04 09:21 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-03-21 23:49 - 2017-03-04 09:16 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-03-21 23:49 - 2017-03-04 09:13 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-03-21 23:49 - 2017-03-04 09:11 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-03-21 23:49 - 2017-03-04 08:57 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-03-21 23:49 - 2017-03-04 08:55 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-03-21 23:49 - 2017-03-04 08:54 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-03-21 23:49 - 2017-03-04 08:52 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-03-21 23:49 - 2017-03-04 08:52 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-04 08:26 - 15259648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-03-21 23:49 - 2017-03-04 08:25 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-03-21 23:49 - 2017-03-04 08:12 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-03-21 23:49 - 2017-03-04 08:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-03-21 23:49 - 2017-03-04 06:18 - 20281856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-03-21 23:49 - 2017-03-02 20:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-03-21 23:49 - 2017-03-02 20:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-03-21 23:49 - 2017-03-02 20:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-03-21 23:49 - 2017-03-02 20:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-03-21 23:49 - 2017-03-02 20:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-03-21 23:49 - 2017-03-02 19:55 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-03-21 23:49 - 2017-03-02 19:54 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-03-21 23:49 - 2017-03-02 19:53 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-03-21 23:49 - 2017-03-02 19:51 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-03-21 23:49 - 2017-03-02 19:50 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-03-21 23:49 - 2017-03-02 19:49 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-03-21 23:49 - 2017-03-02 19:49 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-03-21 23:49 - 2017-03-02 19:41 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-03-21 23:49 - 2017-03-02 19:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-03-21 23:49 - 2017-03-02 19:35 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-03-21 23:49 - 2017-03-02 19:32 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-03-21 23:49 - 2017-03-02 19:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-03-21 23:49 - 2017-03-02 19:29 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-03-21 23:49 - 2017-03-02 19:28 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-03-21 23:49 - 2017-03-02 19:22 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-03-21 23:49 - 2017-03-02 19:21 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-03-21 23:49 - 2017-03-02 19:19 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-03-21 23:49 - 2017-03-02 19:17 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-03-21 23:49 - 2017-03-02 19:17 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-03-21 23:49 - 2017-03-02 19:11 - 13654528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-03-21 23:49 - 2017-03-02 18:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 01312768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-03-21 23:49 - 2017-03-02 18:50 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-03-21 23:49 - 2017-02-14 18:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-03-21 23:49 - 2017-02-14 18:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-03-21 23:49 - 2017-02-11 18:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-03-21 23:49 - 2017-02-11 18:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-03-21 23:49 - 2017-02-11 17:58 - 00462848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-03-21 23:49 - 2017-02-11 17:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-03-21 23:49 - 2017-02-10 18:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:32 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-03-21 23:49 - 2017-02-10 18:17 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-03-21 23:49 - 2017-02-10 16:33 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-03-21 23:49 - 2017-02-09 18:36 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:35 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-03-21 23:49 - 2017-02-09 18:35 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-03-21 23:49 - 2017-02-09 18:35 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-03-21 23:49 - 2017-02-09 18:33 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 18:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:19 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-03-21 23:49 - 2017-02-09 18:19 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-03-21 23:49 - 2017-02-09 18:16 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 18:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-03-21 23:49 - 2017-02-09 18:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-03-21 23:49 - 2017-02-09 18:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-03-21 23:49 - 2017-02-09 18:02 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-03-21 23:49 - 2017-02-09 18:00 - 03220480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-03-21 23:49 - 2017-02-09 17:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-03-21 23:49 - 2017-02-09 17:58 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-03-21 23:49 - 2017-02-09 17:55 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-03-21 23:49 - 2017-02-09 17:55 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-03-21 23:49 - 2017-02-09 17:54 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-03-21 23:49 - 2017-02-09 17:54 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-03-21 23:49 - 2017-02-09 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-03-21 23:49 - 2017-02-09 17:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-03-21 23:49 - 2017-02-09 17:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-03-21 23:49 - 2017-02-09 17:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-03-21 23:49 - 2017-02-09 17:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 17:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-03-21 23:49 - 2017-02-09 16:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-03-21 23:49 - 2017-02-06 18:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-03-21 23:49 - 2017-01-18 17:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-03-21 23:49 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 20:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-03-21 23:49 - 2017-01-13 19:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-03-21 23:49 - 2017-01-11 20:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-03-21 23:49 - 2017-01-11 19:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-03-21 23:49 - 2017-01-06 20:00 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-03-21 23:49 - 2017-01-06 19:44 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437892.dll 2017-03-21 23:48 - 2017-03-17 02:59 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437892.dll 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-03-21 23:45 - 2017-03-21 23:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-03-21 23:27 - 2017-03-21 23:27 - 00000000 ____D C:\ProgramData\Codemasters 2017-03-21 19:23 - 2017-02-23 01:42 - 00084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-03-21 19:23 - 2017-02-23 01:37 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 01609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-03-21 19:23 - 2017-02-18 16:05 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-03-21 19:23 - 2016-12-31 17:36 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-03-03 19:42 - 2017-03-03 19:42 - 00001416 _____ C:\Users\Seb\Desktop\RAGEPluginHook.exe - Verknüpfung (2).lnk ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-30 20:05 - 2017-02-07 22:10 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-03-30 20:05 - 2017-01-03 00:52 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2017-03-30 20:05 - 2017-01-03 00:52 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2017-03-30 20:05 - 2017-01-03 00:52 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2017-03-30 20:05 - 2017-01-03 00:52 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2017-03-30 20:05 - 2017-01-03 00:52 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2017-03-30 20:05 - 2017-01-03 00:52 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2017-03-30 20:05 - 2017-01-03 00:52 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2017-03-30 20:05 - 2017-01-03 00:52 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2017-03-30 13:09 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\NVIDIA 2017-03-30 09:50 - 2016-12-27 13:22 - 00000000 ____D C:\Users\Seb\AppData\Local\ElevatedDiagnostics 2017-03-30 07:50 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-30 07:50 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-30 07:48 - 2010-11-21 08:50 - 00700130 _____ C:\Windows\system32\perfh007.dat 2017-03-30 07:48 - 2010-11-21 08:50 - 00149768 _____ C:\Windows\system32\perfc007.dat 2017-03-30 07:48 - 2009-07-14 07:13 - 01622706 _____ C:\Windows\system32\PerfStringBackup.INI 2017-03-30 07:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2017-03-30 07:43 - 2016-11-25 19:53 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Mozilla 2017-03-30 07:43 - 2016-10-29 09:31 - 00026192 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2017-03-30 07:43 - 2016-10-20 18:58 - 00000000 ____D C:\ProgramData\Origin 2017-03-30 07:43 - 2016-10-20 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2017-03-30 07:42 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-30 07:41 - 2017-02-25 20:47 - 00000000 ____D C:\Users\Seb\Downloads\Neuer Ordner (2) 2017-03-30 07:36 - 2016-11-30 16:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-30 07:36 - 2016-10-20 15:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-29 08:53 - 2016-12-19 18:56 - 00000000 ____D C:\Users\Seb\AppData\LocalLow\Temp 2017-03-28 19:55 - 2016-10-20 18:33 - 00000000 ____D C:\Program Files\VideoLAN 2017-03-28 19:22 - 2017-02-07 22:10 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\asw7128.tmp 2017-03-28 19:22 - 2017-02-07 22:10 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\asw7107.tmp 2017-03-28 19:22 - 2017-02-07 22:10 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\asw7117.tmp 2017-03-28 19:22 - 2017-02-07 22:10 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-03-28 19:22 - 2017-02-07 22:10 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\asw7139.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\asw713A.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\asw716D.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\asw717E.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\asw718F.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\asw715C.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\asw714A.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\asw716C.tmp 2017-03-28 19:22 - 2017-01-03 00:52 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\asw714B.tmp 2017-03-27 01:10 - 2016-10-20 19:07 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Origin 2017-03-27 01:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2017-03-27 00:37 - 2016-10-22 14:17 - 00001238 _____ C:\Users\Public\Desktop\Battlefield 4.lnk 2017-03-27 00:37 - 2016-10-20 15:24 - 00000000 ____D C:\ProgramData\Package Cache 2017-03-27 00:06 - 2016-12-31 18:56 - 00000658 _____ C:\Users\Public\Desktop\Battlefield 1.lnk 2017-03-26 22:44 - 2017-02-17 05:06 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2017-03-26 15:37 - 2016-10-20 15:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-03-26 15:32 - 2016-10-20 19:06 - 00000000 ____D C:\Program Files (x86)\Origin 2017-03-26 15:29 - 2016-10-22 11:21 - 00000000 ____D C:\Users\Seb\AppData\Local\Deployment 2017-03-26 14:55 - 2016-10-20 18:58 - 00000000 ____D C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-03-24 21:01 - 2016-10-21 20:20 - 00000000 ____D C:\Users\Seb\AppData\Roaming\FileZilla 2017-03-24 20:44 - 2016-10-29 09:29 - 00000000 ____D C:\Program Files (x86)\GIGABYTE 2017-03-24 12:55 - 2016-03-30 09:16 - 00000000 ____D C:\Users\Seb\Documents\Bewerbungen 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-03-22 00:19 - 2017-02-13 03:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-03-22 00:19 - 2009-07-14 06:45 - 00556104 _____ C:\Windows\system32\FNTCACHE.DAT 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ___SD C:\Windows\system32\CompatTel 2017-03-22 00:16 - 2016-10-25 21:19 - 00000000 ____D C:\Windows\system32\appraiser 2017-03-22 00:03 - 2016-10-20 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-03-22 00:03 - 2016-10-20 15:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-03-21 23:53 - 2016-10-29 07:22 - 00000000 ____D C:\Windows\system32\MRT 2017-03-21 23:51 - 2016-10-29 07:22 - 138634176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-03-21 23:50 - 2017-02-13 03:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-03-21 23:45 - 2016-11-08 20:50 - 00000000 ____D C:\ProgramData\Skype 2017-03-21 23:27 - 2016-10-25 17:51 - 00000000 ____D C:\Users\Seb\Documents\My Games 2017-03-21 23:18 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-03-21 23:06 - 2017-02-02 21:35 - 00004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2017-02-02 21:35 - 00001419 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2017-03-21 23:06 - 2016-10-29 09:20 - 00003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-29 09:20 - 00003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-03-21 23:06 - 2016-10-20 15:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-03-21 23:06 - 2016-10-20 15:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-03-18 17:45 - 2017-01-03 00:52 - 00547904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.148985196613904 2017-03-18 17:45 - 2017-01-03 00:52 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.148985196721606 2017-03-17 02:59 - 2017-02-15 02:55 - 19883600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 13378096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2017-03-17 02:59 - 2017-02-15 02:55 - 03583744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2017-03-17 02:59 - 2016-10-20 15:47 - 00042686 _____ C:\Windows\system32\nvinfo.pb 2017-03-17 02:59 - 2015-11-06 12:23 - 01600056 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2017-03-17 01:31 - 2016-10-29 09:20 - 00001951 _____ C:\Windows\NvContainerRecovery.bat 2017-03-17 01:16 - 2016-10-29 09:32 - 00549944 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2017-03-17 01:16 - 2016-10-29 09:32 - 00081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 02477504 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2017-03-17 01:16 - 2016-10-20 15:47 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2017-03-16 11:39 - 2016-10-20 15:47 - 07813427 _____ C:\Windows\system32\nvcoproc.bin 2017-03-09 20:52 - 2016-12-10 12:46 - 00000000 ____D C:\Users\Seb\Desktop\Steuer 2017-03-03 20:14 - 2016-10-21 15:41 - 00000000 ____D C:\Fraps 2017-03-03 18:28 - 2016-10-26 18:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-03-03 18:27 - 2016-10-20 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-03-02 22:42 - 2016-12-19 01:43 - 00000000 ____D C:\Users\Seb\Documents\Visual Studio 2015 ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-10-26 18:41 - 2016-11-11 20:08 - 0000104 _____ () C:\Users\Seb\AppData\Roaming\Camdata.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamLayout.ini 2016-10-26 18:41 - 2016-11-11 20:08 - 0000408 _____ () C:\Users\Seb\AppData\Roaming\CamShapes.ini 2016-10-26 18:41 - 2016-11-11 17:06 - 0004535 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.cfg 2016-11-11 17:06 - 2016-11-11 17:06 - 0000000 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.Data.ini 2016-11-11 17:06 - 2016-11-11 17:06 - 0001206 _____ () C:\Users\Seb\AppData\Roaming\CamStudio.Producer.ini 2016-10-26 18:41 - 2016-11-11 18:13 - 0000096 _____ () C:\Users\Seb\AppData\Roaming\version2.xml 2016-11-25 20:37 - 2017-01-06 22:17 - 0007602 _____ () C:\Users\Seb\AppData\Local\resmon.resmoncfg 2016-10-20 15:26 - 2016-10-20 15:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2016-10-22 11:23 - 2016-10-22 11:23 - 0000185 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2016-02-28 19:58 - 2016-02-28 19:58 - 0010218 _____ () C:\ProgramData\regid.2015-05.exe.textpad_83F5EF12-C2F9-4C11-A5C5-57A7B2D7AD25.swidtag ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-03-27 00:55 ==================== Ende von FRST.txt ============================ |
30.03.2017, 19:48 | #15 |
| Windows 7: Malware blockiert Internetverbindungen Addition: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017 durchgeführt von Seb (30-03-2017 20:46:11) Gestartet von C:\Users\Seb\Desktop Windows 7 Professional Service Pack 1 (X64) (2016-10-19 19:46:39) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-844095808-1650209266-980683291-500 - Administrator - Disabled) Gast (S-1-5-21-844095808-1650209266-980683291-501 - Limited - Disabled) Seb (S-1-5-21-844095808-1650209266-980683291-1000 - Administrator - Enabled) => C:\Users\Seb ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) @BIOS B16.0608.1 (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) @BIOS B16.0608.1 (x32 Version: 3.00.0000 - GIGABYTE) Hidden Active Directory Authentication Library für SQL Server (Version: 13.0.1601.5 - Microsoft Corporation) Hidden Active Directory Authentication Library für SQL Server (x86) (x32 Version: 13.0.1601.5 - Microsoft Corporation) Hidden Ambient LED (HKLM-x32\...\InstallShield_{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.2501 - GIGABYTE) Ambient LED (x32 Version: 1.00.1605.2501 - GIGABYTE) Hidden Ansel (Version: 378.92 - NVIDIA Corporation) Hidden APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1703.2301 - GIGABYTE) APP Center (x32 Version: 1.00.1703.2301 - GIGABYTE) Hidden Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation) Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.26.1 - Asmedia Technology) ASUS PCE-AC68 WLAN Card Driver (HKLM-x32\...\{39BD9681-D3B1-435C-A0C1-F87C68513401}) (Version: 2.1.1.5 - ASUS) Audacity 1.2.6 (HKLM-x32\...\Audacity_is1) (Version: - ) Audacity Recovery Utility (HKLM-x32\...\AURC_is1) (Version: - Markus Meyer) Autobahn Police Simulator (HKLM\...\Steam App 348510) (Version: - Z-Software) Avast Internet Security (HKLM-x32\...\Avast Antivirus) (Version: 17.3.2291 - AVAST Software) Azure AD Authentication Connected Service (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.49.28890 - Electronic Arts) Battlefield™ Hardline (HKLM-x32\...\{CB4AC3DA-8CC1-4516-86DA-4078B57DB229}) (Version: 1.4.0.10 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50716.0 - Microsoft Corporation) Hidden Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.51210.80 - Microsoft Corporation) Hidden BIOS Setup (HKLM-x32\...\InstallShield_{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) BIOS Setup (x32 Version: 1.00.0000 - GIGABYTE) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation) Build Tools - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Build Tools Language Resources - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Buildtools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Bus Simulator 16 (HKLM\...\Steam App 324310) (Version: - stillalive studios) Call of Duty: Infinite Warfare (HKLM\...\Steam App 292730) (Version: - Infinity Ward) CodedUITestUAP (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Color Temperature (HKLM-x32\...\InstallShield_{68BFE28B-3F55-4E00-90A4-5179B91A3BD0}) (Version: 16.05.0601 - GIGABYTE) Color Temperature (x32 Version: 16.05.0601 - GIGABYTE) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0196 - Disc Soft Ltd) Demolish & Build 2017 (HKLM\...\Steam App 470740) (Version: - Noble Muffins) Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden DLL-Files.com Client (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_DLL-Files.c~79141F26_is1) (Version: 2.1.1000.4462 - DLL-Files.com Client) Dotfuscator and Analytics Community Edition 5.22.0 (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden Dotfuscator and Analytics Community Edition Language Pack 5.22.0 de-DE (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.0506 - GIGABYTE) EasyTune (x32 Version: 1.16.0506 - GIGABYTE) Hidden EasyTuneEngineService (HKLM-x32\...\InstallShield_{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 2.16.0603 - GIGABYTE) EasyTuneEngineService (x32 Version: 2.16.0603 - GIGABYTE) Hidden ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 18.1.22140 - Landesfinanzdirektion Thüringen) Emergency 2017 (HKLM\...\Steam App 524110) (Version: - Sixteen Tons Entertainment) Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{3FF082A7-A5DE-4BDA-B56A-1D2BEFD617A3}) (Version: 11.1.3000.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (HKLM-x32\...\{FD639F4D-1460-42E6-B32D-FEC1745D0BDC}) (Version: 13.0.1601.5 - Microsoft Corporation) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) F1 2016 (HKLM\...\Steam App 391040) (Version: - Codemasters) Farming Simulator 17 (HKLM\...\Steam App 447020) (Version: - Giants Software) Fast Boot (HKLM-x32\...\InstallShield_{FA8FB4F2-F524-48E1-A06C-45602FBF26CD}) (Version: 1.16.0406 - GIGABYTE) Fast Boot (x32 Version: 1.16.0406 - GIGABYTE) Hidden Fernbus Simulator (HKLM\...\Steam App 427100) (Version: - TML-Studios) FileZilla Client 3.24.1 (HKLM-x32\...\FileZilla Client) (Version: 3.24.1 - Tim Kosse) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2013 Sprachpaket (DEU) - v1.6 (x32 Version: 1.6.30930.3 - Microsoft Corporation) Hidden Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket – DEU - v1.8 (x32 Version: 1.8.40521.1 - Microsoft Corporation) Hidden GIANTS Editor 7.0.0 64-bit (HKLM-x32\...\giants_editor_7.0.0_win64_is1) (Version: 7.0.0 - GIANTS Software GmbH) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North) Greenshot 1.2.8.14 (HKLM\...\Greenshot_is1) (Version: 1.2.8.14 - Greenshot) IDE Tools for Windows 10 (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IDE-Tools für Windows 10 - DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.1.40 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel® USB 3.1 Device Driver (HKLM\...\{7DFE2F7E-3154-45D6-A468-4725DE033AC8}) (Version: 15.2.30.250 - Intel Corporation) Intellisense Lang Pack Mobile Extension SDK 10.0.10586.0 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Killer Bandwidth Control Filter Driver (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer E240x Drivers (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Network Manager (Version: 1.1.57.1346 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{009DF489-4590-4579-BAB2-0136BB829E4A}) (Version: 1.1.57.1346 - Rivet Networks) Kinect for Windows Speech Recognition Language Pack (de-DE) (HKLM-x32\...\{898AA67F-99B8-4C7F-9611-B11F98EF6E78}) (Version: 11.0.7413.611 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-AU) (HKLM-x32\...\{48CEC0A3-AE10-4EE3-AC62-76D3D58792E5}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-CA) (HKLM-x32\...\{9C5505DA-F9C1-46CB-9F8F-AC38F8EA518A}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-GB) (HKLM-x32\...\{A0186231-0A8B-455A-8A25-B64AABCC11A6}) (Version: 11.0.7400.336 - Microsoft Corporation) Kinect for Windows Speech Recognition Language Pack (en-US) (HKLM-x32\...\{8AAA44BB-487E-4D01-AF76-484ACB90DBFE}) (Version: 11.0.7400.336 - Microsoft Corporation) Kits Configuration Installer (x32 Version: 10.0.26624 - Microsoft) Hidden KRISTAL Audio Engine (HKLM-x32\...\KRISTAL Audio Engine) (Version: - ) Leadwerks Game Engine (HKLM\...\Steam App 251810) (Version: - Leadwerks Software) MAGIX Common Components 1 (x64) (HKLM\...\{05799CB2-47FA-4322-9776-C0D15991EE7E}) (Version: 1.6.1.0 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\MX.{410B406D-6A35-41FF-B458-ADB0D3563487}) (Version: 2.0.1.145 - MAGIX Software GmbH) MAGIX Fastcut (HKLM\...\Steam App 330130) (Version: - MAGIX Software GmbH) MAGIX Fastcut (Version: 2.0.1.145 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.4.235 - MAGIX Software GmbH) Hidden MAGIX Fastcut Update (Version: 2.0.5.273 - MAGIX Software GmbH) Hidden MAGIX Fonts Package 1 (x32 Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Screenshare (HKLM-x32\...\{20C81F73-2600-464A-BA60-401739102479}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{AB8304F0-383F-4F80-8988-87727C415BF7}) (Version: 7.0.2.6 - MAGIX Software GmbH) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX Software GmbH) Hidden MAGIX Video deluxe 2015 (HKLM\...\MX.{FFDC29E6-5C7C-4AA8-AF5A-99E015165382}) (Version: 14.0.0.159 - MAGIX Software GmbH) MAGIX Video deluxe 2015 (Version: 14.0.0.159 - MAGIX Software GmbH) Hidden MAGIX Videoton Cleaning Lab (HKLM-x32\...\MAGIX_MSI_Videoton_Cleaning_Lab) (Version: 1.0.0.0 - MAGIX AG) MAGIX Videoton Cleaning Lab (x32 Version: 1.0.0.0 - MAGIX AG) Hidden Malwarebytes Version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (HKLM-x32\...\{21B0F482-5EF9-45DA-8840-340AFE705A6C}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (Deutsch) (HKLM-x32\...\{529EFF09-750D-48B9-A47A-34A3B6248C3F}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Build Tools 2015 (HKLM-x32\...\{d21da0dd-4ba4-4838-ba58-64cf7a77131a}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.1 Sprachpaket - DEU) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.7766.2060 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft Server Speech Platform Runtime (x64) (HKLM\...\{3B433087-E62E-4BF5-97F9-4AF6E1C2409C}) (Version: 11.0.7400.345 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50905.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (HKLM-x32\...\{F351AA2C-723C-4CFE-A7CB-8E43AB164F7F}) (Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{D4E30517-FE6F-491E-942F-AE10E1B18F38}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{B4EDAE03-DB34-4DD0-BA7E-2ED80DEA50B1}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{269A8DF6-BBDA-441F-932B-233F9B746D72}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{EC75BD20-F9CA-4E77-825F-ABD77E95BE91}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{0BF65908-D137-4A9E-B7C9-78F32F74F6FD}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{93945D16-4C3D-433E-B7E4-3D0D86B284C8}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{6F173435-3F19-4043-BA3D-A46AA8472859}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL-Sprachdienst (HKLM-x32\...\{1D812D86-D8EF-41AC-A518-BA12E1913747}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2016 LocalDB (HKLM\...\{1765D93F-97E4-44D3-951D-0DA09B89EE17}) (Version: 13.0.2151.0 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (x64) (HKLM\...\{264B070C-82D7-4C9C-B1CE-A0B124BCC787}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM\...\{619537F4-1E39-4047-AA4F-D2D98A1DA743}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM-x32\...\{4EFF12AE-599C-42A2-ACFA-0D95C3B11A19}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL ScriptDom (HKLM\...\{E8F3D249-7DE6-4422-AC86-1CE7D5CCFA0F}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (12.0.61021.0) (HKLM-x32\...\{A8689DE4-28A2-4F57-9A5F-A4851A8FD849}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (14.0.60519.0) (HKLM-x32\...\{9F367648-EC0C-4F97-B351-D12A51E38F96}) (Version: 14.0.60519.0 - Microsoft Corporation) Microsoft SQL Server Data Tools - Visual Studio 2013 (HKLM-x32\...\{1d259390-0778-4f41-8024-8c826a8ead96}) (Version: 12.0.61021.0 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (12.0.30919.1) (HKLM-x32\...\{BCB8A870-2B3D-4CC0-87D6-F931E065AC0C}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server*2014 Express LocalDB (HKLM\...\{CA191120-4CB1-4E3D-89B8-79FDB9017A2E}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 Transact-SQL ScriptDom (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2014 T-SQL Language Service (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server*2016 Management Objects (HKLM-x32\...\{35A7B00B-4F9C-4B4D-919C-86FFFEE46AD6}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{9634d50a-0c4d-4f52-8a9f-894a2baae370}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{307a22b8-8353-4c5e-b67b-2404c5734558}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio Community 2015 mit Updates (HKLM-x32\...\{ec2556f3-08aa-4829-8017-07d7ea9e125d}) (Version: 14.0.25420.1 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (HKLM-x32\...\{43341417-7882-4F34-8390-53DFD00F6C0F}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (HKLM\...\{24440413-490E-41CA-BD33-0B30FD3EBE3A}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{7F6DCED8-6A2B-4436-AF20-8F659D04E388}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{48BF289B-F3FA-4023-9251-80ABF7B726F9}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM\...\{FEC926D4-785B-4ED7-B35D-3FA37DD29F8B}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server*2016 (HKLM-x32\...\{A37BE9D7-EAAE-4C6B-9D7E-DBD8B8D88681}) (Version: 13.0.1601.5 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden Motorsport Manager (HKLM\...\Steam App 415200) (Version: - Playsport Games) Mozilla Firefox 52.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 52.0.2 (x86 de)) (Version: 52.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.2.6291 - Mozilla) Mozilla Thunderbird 45.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 45.2.0 (x86 de)) (Version: 45.2.0 - Mozilla) Mozilla Thunderbird 45.8.0 (x86 de) (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\Mozilla Thunderbird 45.8.0 (x86 de)) (Version: 45.8.0 - Mozilla) MSBuild/NuGet Integration 14.0 (x86) (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Napster (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\5d01cae694a4998b) (Version: 6.17.50.0 - Rhapsody International Inc.) Need for Speed™ The Run (HKLM-x32\...\{0EDC9BA0-016E-406a-86DA-04FC1BE00C21}) (Version: 1.1.0.0 - Electronic Arts) Notruf 112 (HKLM\...\Steam App 491530) (Version: - Crenetic GmbH Studios) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation) NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation) NVIDIA Grafiktreiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.16.2 - OBS Project) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) ON_OFF Charge 2 B15.0709.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden OpenIV (HKU\S-1-5-21-844095808-1650209266-980683291-1000\...\OpenIV) (Version: 2.8.703 - .black/OpenIV Team) Origin (HKLM-x32\...\Origin) (Version: 10.4.5.30491 - Electronic Arts, Inc.) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{FACF2669-E25A-428A-9167-5EEDE741F3B9}) (Version: 4.6.00127 - Microsoft Corporation) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM-x32\...\{4860C1E5-CE58-4D32-89DE-37951333B4C9}) (Version: 4.6.01055 - Microsoft Corporation) PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.26.25466 - pdfforge GmbH) PDF Architect 4 Asian Fonts Pack (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Convert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Forms Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Insert Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 OCR Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Review Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 Secure Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Projekt- und Elementvorlagen für Visual Studio Express 2015 für Windows 10 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden Projekt- und Elementvorlagen für Visual Studio Professional 2015 – DEU (x32 Version: 14.0.25527 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.994 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7727 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.4 - Rockstar Games) Roslyn Language Services - x86 (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden SIV (HKLM-x32\...\InstallShield_{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.16.0525 - GIGABYTE) SIV (x32 Version: 1.16.0525 - GIGABYTE) Hidden SketchUp 2017 (HKLM\...\{5A8C61BD-0912-4B76-805E-4EDE5E13298C}) (Version: 17.1.174 - Trimble Navigation Limited) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16102.12 - Samsung Electronics Co., Ltd.) Hidden SmartKeyboard (HKLM-x32\...\InstallShield_{75B74C36-A9C6-4912-B4BB-C461AA36D01E}) (Version: 1.00.0000 - GIGABYTE) SmartKeyboard (x32 Version: 1.00.0000 - GIGABYTE) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (x32 Version: 14.102.25619 - Microsoft) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) TeamViewer 12 Host (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer) Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios) Thin2000 USB Display Adapter (HKLM\...\{CB5F5631-515F-4C70-ACA5-3FAAFA1866BC}) (Version: 1.1.323.0 - Fresco Logic) Thunderbolt(TM) Software (HKLM-x32\...\{B0E8A8CA-5A40-49C3-BE5E-9076664DB9AA}) (Version: 15.3.39.250 - Intel Corporation) TypeScript Power Tool (x32 Version: 1.8.34.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.36.0 - Microsoft Corporation) Hidden UE4 Prerequisites (x64) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (x32 Version: 1.0.13.0 - Epic Games, Inc.) Hidden Universal CRT Extension SDK (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Redistributable (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x64 (Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal CRT Tools x86 (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.0.26624 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) VS Update core components (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden vs_update3notification (x32 Version: 14.0.25431 - Microsoft Corporation) Hidden Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Watch_Dogs 2 (HKLM\...\Steam App 447040) (Version: - Ubisoft) WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation) WinAppDeploy (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden Windows SDK AddOn (HKLM-x32\...\{75C39BA6-1D02-4BEA-844F-0EA6C4B7FA1B}) (Version: 10.1.0.0 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.10586.212 (HKLM-x32\...\{43d9f43d-c90b-4fdf-9dfe-ecf9990bfa2a}) (Version: 10.1.10586.212 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.26624 (HKLM-x32\...\{e7a0c8b6-b0e9-41e2-8a0a-a6784f88d1d4}) (Version: 10.0.26624 - Microsoft Corporation) Windows-Treiberpaket - Graphics Tablet (WinUsb) USBDevice (04/10/2014 8.33.30.0) (HKLM\...\142118DF51345EA02D2B1583E102C8FB95FD6D52) (Version: 04/10/2014 8.33.30.0 - Graphics Tablet) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) WinRT Intellisense Desktop - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Desktop - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense IoT - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense PPI - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense UAP - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - en-us (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinRT Intellisense Xbox Live Extension SDK - Other Languages (x32 Version: 10.1.10586.212 - Microsoft Corporation) Hidden WinSweeper 2.1 (HKLM-x32\...\{96E8A815-3053-4616-AAC2-865E6B1792F5}_is1) (Version: - Solvusoft Corporation) World of Tanks Blitz (HKLM\...\Steam App 444200) (Version: - Wargaming Group Limited) XAMPP (HKLM-x32\...\xampp) (Version: 5.6.8-0 - Bitnami) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-844095808-1650209266-980683291-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Seb\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {191E8CED-5BA5-4EE3-8DC0-C8257FE2CFAA} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation) Task: {1DEFEEA4-B4A7-4654-BBD7-43AF718B4AC6} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => P:\Programme (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation) Task: {24F0CDF9-CA42-4B9F-A194-FBE2652F189D} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-03-30] (AVAST Software) Task: {2EC4D652-1888-44F7-9811-C4959B854A6F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {3F31AB12-2BE3-4DFF-937D-C2512794E784} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {441E0E52-EAB6-48E5-A1DA-174B77491E51} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) Task: {488F73BD-5AF1-494C-A38B-D7E98D4D25DB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {4B5F255F-761D-4D0E-8736-291C9C1BDEAF} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => Thunderbolt.exe Task: {5DE984B7-D648-47FD-873D-9E1AD1CD6116} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => Thunderbolt.exe Task: {6170758E-2D8B-46D3-80DD-B9DF43C95A4F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-02-19] (Microsoft Corporation) Task: {7CE3E841-D7F1-4A12-B12E-E509E3A66685} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {7DF9EEC8-4310-4833-AA36-B112995760F5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-28] (AVAST Software) Task: {854BE4ED-D2D2-482F-9BD7-F54256C7F6E0} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService Task: {AE37F061-38D4-41F4-A0B6-3973F5FB378C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation) Task: {B8021389-D6F2-4922-A95C-1A7D067E1A29} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {B9EA1437-FF91-46FB-B4BA-48F6D8B4211F} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation) Task: {C7E9D51D-8274-4306-AF9B-A94762348F9F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => tbtsvc.exe Task: {D8693F66-18EA-41CA-AD97-43AE1B96716B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.) Task: {F672F9E7-4540-4C1E-A3FB-C403F543FE5F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-02-17 05:07 - 2016-12-15 12:37 - 00020208 _____ () C:\Windows\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll 2015-06-25 10:45 - 2015-06-25 10:45 - 00017920 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe 2016-10-29 09:20 - 2017-02-23 20:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-20 15:47 - 2017-03-17 01:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-02-21 23:09 - 2017-02-21 23:09 - 00052392 _____ () P:\Programme\FileZilla FTP Client\fzshellext_64.dll 2016-10-22 14:16 - 2016-11-06 03:45 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2017-03-26 14:51 - 2017-02-24 06:23 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-03-26 14:51 - 2017-02-24 06:23 - 02264528 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00162024 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00790544 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00275776 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll 2017-03-23 11:40 - 2017-03-23 11:40 - 01850800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe 2015-05-14 03:30 - 2015-05-14 03:30 - 00419328 _____ () C:\Windows\System32\flvga_tray.exe 2017-03-28 19:22 - 2017-03-28 19:22 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00176480 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00653520 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00230632 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2017-03-30 16:51 - 2017-03-30 16:51 - 05907968 _____ () C:\Program Files\AVAST Software\Avast\defs\17033001\algo.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-10-29 09:20 - 2017-02-23 20:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2015-02-17 01:47 - 2015-02-17 01:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\ycc.dll 2016-08-09 20:49 - 2016-08-09 20:49 - 01804800 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\BDR_info.dll 2015-02-16 11:47 - 2015-02-16 11:47 - 00105472 _____ () C:\Program Files (x86)\GIGABYTE\AppCenter\ycc.dll 2017-01-03 00:52 - 2017-01-03 00:52 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-03-28 19:22 - 2017-03-28 19:22 - 00293936 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2016-10-20 19:06 - 2017-03-26 15:32 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2016-10-29 09:20 - 2017-02-23 16:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-10-29 09:20 - 2017-02-23 16:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-10-29 09:20 - 2017-02-23 16:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-844095808-1650209266-980683291-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Seb\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupfolder: C:^Users^Seb^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\Windows\pss\An OneNote senden.lnk.Startup MSCONFIG\startupreg: DAEMON Tools Lite Automount => "P:\Programme\DAEMON Tools Lite\DTAgent.exe" -autorun MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: Greenshot => P:\Programme\Greenshot\Greenshot.exe MSCONFIG\startupreg: OneDrive => "C:\Users\Seb\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background MSCONFIG\startupreg: Overwolf => "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent MSCONFIG\startupreg: PreRun => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe MSCONFIG\startupreg: TabletDriver => C:\PenTabletDriver\TabletDriver.exe -hide ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{D5A10B96-019A-463B-93FA-E793E9FD99AD}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{B4866065-6535-4F02-A6ED-1135D0AF6369}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{FC34C004-8D8E-471F-8472-EC7E5A07A944}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{34220BE5-470C-49B1-988C-6A766AE041E4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{57203B3F-273A-4BCD-A084-20CFB95B4F33}C:\program files (x86)\gigabyte\appcenter\gcupd.exe] => (Allow) C:\program files (x86)\gigabyte\appcenter\gcupd.exe FirewallRules: [UDP Query User{7DF7F82C-B3FA-40D3-AAFB-093E66B97C8A}C:\program files (x86)\gigabyte\appcenter\gcupd.exe] => (Allow) C:\program files (x86)\gigabyte\appcenter\gcupd.exe FirewallRules: [TCP Query User{83CBCA05-0092-4624-A2EE-AEA87720796F}P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe] => (Allow) P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe FirewallRules: [UDP Query User{23E2BD2C-46F9-49F5-AE2F-9CB8AC2747BF}P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe] => (Allow) P:\spiele\steamapps\common\farming simulator 17\x64\farmingsimulator2017game.exe FirewallRules: [{DE88D321-F128-4B12-BAB3-19EFE8F881E8}] => (Allow) P:\Spiele\Battlefield 1\bf1Trial.exe FirewallRules: [{50AD9EBA-9C32-4DE2-A3AF-A51B0680B7CA}] => (Allow) P:\Spiele\Battlefield 1\bf1Trial.exe FirewallRules: [{50073B1D-8DEA-4008-BFCE-1D2CA15E8474}] => (Allow) P:\Spiele\Battlefield 1\bf1.exe FirewallRules: [{422BB53F-5B92-4A4A-A239-6F05AACB8AC5}] => (Allow) P:\Spiele\Battlefield 1\bf1.exe FirewallRules: [{1004E635-633A-425B-94A0-21735B3731D6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe FirewallRules: [{FD154E03-263B-41DB-97FB-BB94F20D4B00}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe FirewallRules: [{4CFF971B-E5B3-47A1-8D5F-847BB8A9B3F3}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe FirewallRules: [{D08C05D6-B42B-461A-99C8-95D2700B733E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe FirewallRules: [{EB8611EE-61AA-4DF6-BC77-AC197F2B69FC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5D1D552B-F886-4B46-96B2-3A6B71D2C7D8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Wiederherstellungspunkte ========================= 21-03-2017 23:49:32 Windows Update 24-03-2017 11:12:01 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:33:29 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 20:43:10 WinThruster (64-bit) Backup 24-03-2017 20:43:57 Removed APP Center 24-03-2017 20:44:11 Installed APP Center 24-03-2017 20:44:44 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 24-03-2017 21:07:32 Installed Microsoft Solution - f4c2a476-3532-4511-a4be-0f5ccc5501af 26-03-2017 15:32:32 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 26-03-2017 15:32:42 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 26-03-2017 15:37:19 Installiert ASUS PCE-AC68 WLAN Card Driver 27-03-2017 00:05:49 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 27-03-2017 00:05:56 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 27-03-2017 00:37:04 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 27-03-2017 00:37:20 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (03/30/2017 08:43:47 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (03/30/2017 07:54:13 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Seb\Desktop\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (03/30/2017 07:54:04 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Seb\Desktop\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (03/30/2017 07:54:03 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Seb\Desktop\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (03/30/2017 07:53:55 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Seb\Desktop\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (03/30/2017 07:43:03 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/30/2017 07:37:11 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (03/29/2017 09:07:54 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x86\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/29/2017 09:07:53 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\8.0\bin\x64\makecat.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Signing.wintrust.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (03/29/2017 09:06:08 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Kits\10\bin\arm\signtool.exe.Manifest". Die abhängige Assemblierung "Microsoft.Windows.Build.Appx.AppxSip.dll,version="0.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Systemfehler: ============= Error: (03/30/2017 08:15:04 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:15:02 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:15:00 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:14:58 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:14:56 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:14:54 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:14:52 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:14:50 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:14:48 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 Error: (03/30/2017 08:14:46 PM) (Source: nvlddmkm) (EventID: 14) (User: ) Description: Event-ID 14 CodeIntegrity: =================================== Date: 2016-12-02 18:49:24.791 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.766 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.741 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.716 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.691 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.665 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.639 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.614 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.589 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2016-12-02 18:49:24.553 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.100.9.0\x64\OWExplorer.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz Prozentuale Nutzung des RAM: 19% Installierter physikalischer RAM: 16333.03 MB Verfügbarer physikalischer RAM: 13074.68 MB Summe virtueller Speicher: 32664.25 MB Verfügbarer virtueller Speicher: 26682.42 MB ==================== Laufwerke ================================ Drive b: (Bilder) (Fixed) (Total:151.37 GB) (Free:65.28 GB) NTFS Drive c: (Windows) (Fixed) (Total:447.03 GB) (Free:129.17 GB) NTFS Drive e: (Filme) (Fixed) (Total:465.76 GB) (Free:344.71 GB) NTFS Drive m: (Musik) (Fixed) (Total:151.37 GB) (Free:145.56 GB) NTFS Drive p: (Programme) (Fixed) (Total:850 GB) (Free:135.09 GB) NTFS Drive v: (Videos) (Fixed) (Total:163.02 GB) (Free:138.82 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 447.1 GB) (Disk ID: 94D2A2C1) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=447 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0009AF56) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7BA18A71) Partition 1: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=151.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=163 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
Themen zu Windows 7: Malware blockiert Internetverbindungen |
blockiert, explorer, firefox, firewall, fix, ftp, funktioniert, hosts-datei, internet explorer, internetseite, log, lösung, malware, microsoft, problem, probleme, programm, seite, sekunden, software, spiele, system, windows, windows firewall, winsock, zurücksetzen |