|
Plagegeister aller Art und deren Bekämpfung: New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer"Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.06.2017, 23:41 | #1 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Hallo, Ich bin mittlerweile am Verzweifeln, da ich das Problem absolut nicht behoben kriege. Es wird in unregelmäßigen Abständen per Explorer (IE, FireFox, Chrome) je nachdem welches installiert/ standard ist tabs geöffnet, die auf folgenden Link zugreifen: hxxp://hosted.ap.org/dynamic/stories/A/AF_WEST_AFRICA_EXTREMIST_ATTACKS_GLANCE?SITE=OHCIN&SECTION=HOME&TEMPLATE=DEFAULT Was ich bereits versucht habe: EEK Scan Malwarebytes Scan Avast Antivirus Scan CCleaner Scan Browserdaten gelöscht Browser deinstalliert Sobald ich den PC hochfahre wird der Browser mit 1 bis 10 Tabs von dieser Seite geöffnet. Danach in unregelmäßigen Abständen 1 - 3 Tabs. Teilweise 2-3 Stunden nix, teilweise alle paar Minuten. Im Startup konnte ich keine Einstellung finden, die das verursachen könnte. Das Einzige, was ich finden konnte waren zwei Dateien, die im Localstorage erstellt werden, sobald die Seite aufgerufen wird: https://www.file-upload.net/download-12560757/http_hosted.ap.org_0.localstorage.html https://www.file-upload.net/download-12560758/http_hosted.ap.org_0.localstorage-journal.html Ich kriege es leider auch nicht hin, per Adblock Plus oder uBlocker das Öffnen der Tabs zu verhindern, stattdessen steht dann im geöffneten Tab, dass die Seite geblockt wurde. Ich verwende Windows 10 64 Bit Google Chrome ist mein Standardbrowser Ich hoffe, ihr könnt mir helfen, das Problem zu beheben. MfG Raphael |
19.06.2017, 15:59 | #2 |
/// TB-Ausbilder | New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer"Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Um die Bereinigung möchlichst effektiv und schnell gestalten zu können, bitte ich um Beachtung der folgenden Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Schritt 2 Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Bitte poste mit deiner nächsten Antwort
|
19.06.2017, 22:06 | #3 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Hallo Matthias,
__________________ich habe deine Schritte befolgt, hier sind die Logfiles: TDSS: Code:
ATTFilter 23:00:31.0730 6136 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 23:00:33.0505 6136 ============================================================ 23:00:33.0505 6136 Current date / time: 2017/06/19 23:00:33.0505 23:00:33.0505 6136 SystemInfo: 23:00:33.0505 6136 23:00:33.0506 6136 OS Version: 6.2.9200 ServicePack: 0.0 23:00:33.0506 6136 Product type: Workstation 23:00:33.0506 6136 ComputerName: BRAINWASHED-PC 23:00:33.0506 6136 UserName: BrainWasheD 23:00:33.0506 6136 Windows directory: C:\WINDOWS 23:00:33.0506 6136 System windows directory: C:\WINDOWS 23:00:33.0506 6136 Running under WOW64 23:00:33.0506 6136 Processor architecture: Intel x64 23:00:33.0506 6136 Number of processors: 8 23:00:33.0506 6136 Page size: 0x1000 23:00:33.0506 6136 Boot type: Normal boot 23:00:33.0506 6136 ============================================================ 23:00:33.0649 6136 Drive \Device\Harddisk0\DR0 - Size: 0x37E4896000 (223.57 Gb), SectorSize: 0x200, Cylinders: 0x7201, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:00:33.0649 6136 Drive \Device\Harddisk1\DR1 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:00:33.0654 6136 Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:00:33.0677 6136 ============================================================ 23:00:33.0677 6136 \Device\Harddisk0\DR0: 23:00:33.0677 6136 MBR partitions: 23:00:33.0677 6136 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1BF23000 23:00:33.0677 6136 \Device\Harddisk1\DR1: 23:00:33.0678 6136 MBR partitions: 23:00:33.0678 6136 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 23:00:33.0678 6136 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xDE80800 23:00:33.0678 6136 \Device\Harddisk2\DR2: 23:00:33.0679 6136 GPT partitions: 23:00:33.0679 6136 \Device\Harddisk2\DR2\Partition1: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {5BC6AE9C-68CC-4EA4-9F0C-F658EB956BD4}, Name: Basic data partition, StartLBA 0x72800, BlocksNum 0x3D01E000 23:00:33.0679 6136 \Device\Harddisk2\DR2\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {F3BBD056-75F7-4982-A762-77E43B3FC4C1}, Name: Basic data partition, StartLBA 0x3D090800, BlocksNum 0x37675800 23:00:33.0679 6136 MBR partitions: 23:00:33.0679 6136 ============================================================ 23:00:33.0683 6136 C: <-> \Device\Harddisk1\DR1\Partition2 23:00:33.0704 6136 D: <-> \Device\Harddisk2\DR2\Partition1 23:00:33.0733 6136 E: <-> \Device\Harddisk2\DR2\Partition2 23:00:33.0734 6136 A: <-> \Device\Harddisk0\DR0\Partition1 23:00:33.0734 6136 ============================================================ 23:00:33.0734 6136 Initialize success 23:00:33.0734 6136 ============================================================ 23:00:38.0203 3724 ============================================================ 23:00:38.0203 3724 Scan started 23:00:38.0203 3724 Mode: Manual; SigCheck; TDLFS; 23:00:38.0203 3724 ============================================================ 23:00:38.0323 3724 ================ Scan system memory ======================== 23:00:38.0323 3724 System memory - ok 23:00:38.0323 3724 ================ Scan services ============================= 23:00:38.0384 3724 1394ohci - ok 23:00:38.0387 3724 3ware - ok 23:00:38.0390 3724 ACPI - ok 23:00:38.0392 3724 AcpiDev - ok 23:00:38.0395 3724 acpiex - ok 23:00:38.0397 3724 acpipagr - ok 23:00:38.0400 3724 AcpiPmi - ok 23:00:38.0403 3724 acpitime - ok 23:00:38.0408 3724 [ 8D6BA8E7676038A27FD4ECF12CC744B0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 23:00:38.0440 3724 AdobeARMservice - ok 23:00:38.0446 3724 ADP80XX - ok 23:00:38.0450 3724 AFD - ok 23:00:38.0454 3724 ahcache - ok 23:00:38.0456 3724 AJRouter - ok 23:00:38.0459 3724 ALG - ok 23:00:38.0461 3724 AmdK8 - ok 23:00:38.0463 3724 AmdPPM - ok 23:00:38.0466 3724 amdsata - ok 23:00:38.0470 3724 amdsbs - ok 23:00:38.0473 3724 amdxata - ok 23:00:38.0475 3724 AppID - ok 23:00:38.0477 3724 AppIDSvc - ok 23:00:38.0480 3724 Appinfo - ok 23:00:38.0483 3724 applockerfltr - ok 23:00:38.0486 3724 AppReadiness - ok 23:00:38.0488 3724 AppXSvc - ok 23:00:38.0491 3724 arcsas - ok 23:00:38.0548 3724 [ A760C2AFBA1A71E0F7310A6E900CB0E4 ] aswbIDSAgent C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe 23:00:38.0704 3724 aswbIDSAgent - ok 23:00:38.0715 3724 [ 0C19C91ED99964925FF8B05C23743AB1 ] aswbidsdriver C:\WINDOWS\system32\drivers\aswbidsdrivera.sys 23:00:38.0737 3724 aswbidsdriver - ok 23:00:38.0740 3724 [ 670839F4BA6D82F3035AADFE8274F02E ] aswbidsh C:\WINDOWS\system32\drivers\aswbidsha.sys 23:00:38.0757 3724 aswbidsh - ok 23:00:38.0766 3724 [ 5C561968CF601D76A98692DCC8CF74ED ] aswblog C:\WINDOWS\system32\drivers\aswbloga.sys 23:00:38.0786 3724 aswblog - ok 23:00:38.0790 3724 [ 335E5F19E7397A283B7ED20FE7B369EB ] aswbuniv C:\WINDOWS\system32\drivers\aswbuniva.sys 23:00:38.0803 3724 aswbuniv - ok 23:00:38.0806 3724 [ BA02CA77D989710F79FD662019C4DF94 ] aswHwid C:\WINDOWS\system32\drivers\aswHwid.sys 23:00:38.0822 3724 aswHwid - ok 23:00:38.0825 3724 [ 5E6FD2CB74138C6AF591779D2619BD6C ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys 23:00:38.0839 3724 aswKbd - ok 23:00:38.0844 3724 [ 2B1490F2F1CC76C9C9B61CE63D6E7973 ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys 23:00:38.0861 3724 aswMonFlt - ok 23:00:38.0866 3724 [ F26D1F761E14789743275FA5D258EAB8 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr2.sys 23:00:38.0882 3724 aswRdr - ok 23:00:38.0887 3724 [ C1007774450CFAB19D784D50C3410FC7 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys 23:00:38.0902 3724 aswRvrt - ok 23:00:38.0917 3724 [ EB1991686949400C51B8C21CE013621E ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys 23:00:38.0961 3724 aswSnx - ok 23:00:38.0968 3724 [ 7A17BD26C74F5329CB1DF029AE4DD357 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys 23:00:38.0999 3724 aswSP - ok 23:00:39.0003 3724 [ 2933CBC7643168E4288D443B4125941C ] aswStm C:\WINDOWS\system32\drivers\aswStm.sys 23:00:39.0014 3724 aswStm - ok 23:00:39.0023 3724 [ E76C21203E29F2DCC489EF585E0B1A38 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys 23:00:39.0046 3724 aswVmm - ok 23:00:39.0049 3724 AsyncMac - ok 23:00:39.0052 3724 atapi - ok 23:00:39.0055 3724 AudioEndpointBuilder - ok 23:00:39.0058 3724 Audiosrv - ok 23:00:39.0062 3724 [ D961A7C05A76302E782B1B0CF6546BA7 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 23:00:39.0075 3724 avast! Antivirus - ok 23:00:39.0079 3724 AxInstSV - ok 23:00:39.0081 3724 b06bdrv - ok 23:00:39.0084 3724 BasicDisplay - ok 23:00:39.0087 3724 BasicRender - ok 23:00:39.0090 3724 bcmfn2 - ok 23:00:39.0092 3724 BDESVC - ok 23:00:39.0094 3724 Suspicious service (Hidden): BEDaisy 23:00:39.0095 3724 BEDaisy ( HiddenService.Multi.Generic ) - warning 23:00:39.0095 3724 BEDaisy - detected HiddenService.Multi.Generic (1) 23:00:39.0098 3724 Beep - ok 23:00:39.0110 3724 [ 5EC0D7E4DBEB0D8CA45F01A3277D8D9B ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe 23:00:39.0148 3724 BEService - ok 23:00:39.0151 3724 BFE - ok 23:00:39.0154 3724 BitDefenderCOM - ok 23:00:39.0157 3724 BITS - ok 23:00:39.0159 3724 bowser - ok 23:00:39.0162 3724 BrokerInfrastructure - ok 23:00:39.0165 3724 Browser - ok 23:00:39.0168 3724 BthAvrcpTg - ok 23:00:39.0170 3724 BthHFEnum - ok 23:00:39.0172 3724 bthhfhid - ok 23:00:39.0175 3724 BthHFSrv - ok 23:00:39.0178 3724 BTHMODEM - ok 23:00:39.0181 3724 bthserv - ok 23:00:39.0183 3724 buttonconverter - ok 23:00:39.0187 3724 CAD - ok 23:00:39.0189 3724 CapImg - ok 23:00:39.0191 3724 cdfs - ok 23:00:39.0194 3724 CDPSvc - ok 23:00:39.0196 3724 CDPUserSvc - ok 23:00:39.0199 3724 Suspicious service (Hidden): CDPUserSvc_3f01d 23:00:39.0202 3724 cdrom - ok 23:00:39.0204 3724 CertPropSvc - ok 23:00:39.0207 3724 cht4iscsi - ok 23:00:39.0210 3724 cht4vbd - ok 23:00:39.0212 3724 circlass - ok 23:00:39.0215 3724 CldFlt - ok 23:00:39.0217 3724 CLFS - ok 23:00:39.0267 3724 [ C464783FB7BF3FF6FB620453B3B96A89 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe 23:00:39.0363 3724 ClickToRunSvc - ok 23:00:39.0368 3724 ClipSVC - ok 23:00:39.0370 3724 clreg - ok 23:00:39.0377 3724 CmBatt - ok 23:00:39.0379 3724 CNG - ok 23:00:39.0382 3724 cnghwassist - ok 23:00:39.0412 3724 CompositeBus - ok 23:00:39.0414 3724 COMSysApp - ok 23:00:39.0417 3724 condrv - ok 23:00:39.0421 3724 CoreMessagingRegistrar - ok 23:00:39.0425 3724 CryptSvc - ok 23:00:39.0428 3724 dam - ok 23:00:39.0432 3724 DcomLaunch - ok 23:00:39.0434 3724 defragsvc - ok 23:00:39.0437 3724 DeviceAssociationService - ok 23:00:39.0439 3724 DeviceInstall - ok 23:00:39.0442 3724 DevicesFlowUserSvc - ok 23:00:39.0444 3724 Suspicious service (Hidden): DevicesFlowUserSvc_3f01d 23:00:39.0447 3724 DevQueryBroker - ok 23:00:39.0449 3724 Dfsc - ok 23:00:39.0453 3724 [ 9593475FBC857A05D93BFF4FA7323C2B ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys 23:00:39.0472 3724 dg_ssudbus - ok 23:00:39.0474 3724 Dhcp - ok 23:00:39.0479 3724 diagnosticshub.standardcollector.service - ok 23:00:39.0482 3724 DiagTrack - ok 23:00:39.0484 3724 Disk - ok 23:00:39.0487 3724 DmEnrollmentSvc - ok 23:00:39.0490 3724 dmvsc - ok 23:00:39.0492 3724 dmwappushservice - ok 23:00:39.0495 3724 Dnscache - ok 23:00:39.0498 3724 dot3svc - ok 23:00:39.0500 3724 DPS - ok 23:00:39.0503 3724 drmkaud - ok 23:00:39.0505 3724 DsmSvc - ok 23:00:39.0508 3724 DsSvc - ok 23:00:39.0511 3724 DusmSvc - ok 23:00:39.0514 3724 DXGKrnl - ok 23:00:39.0516 3724 EapHost - ok 23:00:39.0518 3724 ebdrv - ok 23:00:39.0521 3724 EFS - ok 23:00:39.0523 3724 EhStorClass - ok 23:00:39.0525 3724 EhStorTcgDrv - ok 23:00:39.0528 3724 embeddedmode - ok 23:00:39.0531 3724 EntAppSvc - ok 23:00:39.0535 3724 [ 0E840AA66CAB02CBA9730C772BBE305B ] epp C:\EEK\bin64\epp.sys 23:00:39.0554 3724 epp - ok 23:00:39.0560 3724 [ D315FF43E23DF424ECEC2F6C930203E4 ] EpsonScanSvc C:\WINDOWS\system32\EscSvc64.exe 23:00:39.0574 3724 EpsonScanSvc - ok 23:00:39.0577 3724 [ 86032A47AD0105130FE7808C903E2086 ] EPSON_PM_RPCV4_06 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE 23:00:39.0588 3724 EPSON_PM_RPCV4_06 - ok 23:00:39.0591 3724 ErrDev - ok 23:00:39.0595 3724 EventSystem - ok 23:00:39.0598 3724 exfat - ok 23:00:39.0600 3724 fastfat - ok 23:00:39.0604 3724 Fax - ok 23:00:39.0607 3724 fdc - ok 23:00:39.0610 3724 fdPHost - ok 23:00:39.0612 3724 FDResPub - ok 23:00:39.0614 3724 fhsvc - ok 23:00:39.0617 3724 FileCrypt - ok 23:00:39.0619 3724 FileInfo - ok 23:00:39.0622 3724 Filetrace - ok 23:00:39.0625 3724 flpydisk - ok 23:00:39.0627 3724 FltMgr - ok 23:00:39.0630 3724 FontCache - ok 23:00:39.0634 3724 FontCache3.0.0.0 - ok 23:00:39.0638 3724 FrameServer - ok 23:00:39.0640 3724 FsDepends - ok 23:00:39.0643 3724 Fs_Rec - ok 23:00:39.0645 3724 fvevol - ok 23:00:39.0648 3724 gencounter - ok 23:00:39.0650 3724 genericusbfn - ok 23:00:39.0653 3724 GPIOClx0101 - ok 23:00:39.0657 3724 gpsvc - ok 23:00:39.0659 3724 GpuEnergyDrv - ok 23:00:39.0666 3724 [ 0545A3EB959CFA4790D267BFB8C1ACA4 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 23:00:39.0677 3724 gupdate - ok 23:00:39.0683 3724 [ 0545A3EB959CFA4790D267BFB8C1ACA4 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 23:00:39.0693 3724 gupdatem - ok 23:00:39.0696 3724 HdAudAddService - ok 23:00:39.0699 3724 HDAudBus - ok 23:00:39.0702 3724 HidBatt - ok 23:00:39.0705 3724 HidBth - ok 23:00:39.0708 3724 hidi2c - ok 23:00:39.0710 3724 hidinterrupt - ok 23:00:39.0712 3724 HidIr - ok 23:00:39.0715 3724 hidserv - ok 23:00:39.0717 3724 HidUsb - ok 23:00:39.0720 3724 HomeGroupListener - ok 23:00:39.0722 3724 HomeGroupProvider - ok 23:00:39.0725 3724 HpSAMD - ok 23:00:39.0727 3724 HTTP - ok 23:00:39.0729 3724 HvHost - ok 23:00:39.0732 3724 hvservice - ok 23:00:39.0734 3724 hwpolicy - ok 23:00:39.0737 3724 hyperkbd - ok 23:00:39.0741 3724 i8042prt - ok 23:00:39.0743 3724 iagpio - ok 23:00:39.0745 3724 iai2c - ok 23:00:39.0749 3724 iaLPSS2i_GPIO2 - ok 23:00:39.0751 3724 iaLPSS2i_GPIO2_BXT_P - ok 23:00:39.0754 3724 iaLPSS2i_I2C - ok 23:00:39.0756 3724 iaLPSS2i_I2C_BXT_P - ok 23:00:39.0760 3724 iaLPSSi_GPIO - ok 23:00:39.0762 3724 iaLPSSi_I2C - ok 23:00:39.0765 3724 iaStorAV - ok 23:00:39.0767 3724 iaStorV - ok 23:00:39.0770 3724 ibbus - ok 23:00:39.0772 3724 icssvc - ok 23:00:39.0776 3724 IKEEXT - ok 23:00:39.0778 3724 IndirectKmd - ok 23:00:39.0812 3724 [ 3A2D6740F51BE48C0FD01AD907329DEE ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys 23:00:39.0909 3724 IntcAzAudAddService - ok 23:00:39.0913 3724 intelide - ok 23:00:39.0916 3724 intelpep - ok 23:00:39.0919 3724 intelppm - ok 23:00:39.0921 3724 iorate - ok 23:00:39.0924 3724 IpFilterDriver - ok 23:00:39.0926 3724 iphlpsvc - ok 23:00:39.0929 3724 IPMIDRV - ok 23:00:39.0931 3724 IPNAT - ok 23:00:39.0934 3724 IpxlatCfgSvc - ok 23:00:39.0938 3724 irda - ok 23:00:39.0940 3724 IRENUM - ok 23:00:39.0943 3724 irmon - ok 23:00:39.0946 3724 isapnp - ok 23:00:39.0948 3724 iScsiPrt - ok 23:00:39.0951 3724 kbdclass - ok 23:00:39.0954 3724 kbdhid - ok 23:00:39.0957 3724 kdnic - ok 23:00:39.0960 3724 KeyIso - ok 23:00:39.0962 3724 KSecDD - ok 23:00:39.0964 3724 KSecPkg - ok 23:00:39.0968 3724 ksthunk - ok 23:00:39.0970 3724 KtmRm - ok 23:00:39.0974 3724 [ 89C6518926FA2E7C1800964375DB67B5 ] ladfGSS C:\WINDOWS\system32\drivers\ladfGSS.sys 23:00:39.0983 3724 ladfGSS - ok 23:00:39.0986 3724 LanmanServer - ok 23:00:39.0988 3724 LanmanWorkstation - ok 23:00:39.0992 3724 lfsvc - ok 23:00:39.0995 3724 [ A6F294B38F3DFB67D6B6E1D1E60A402A ] LGBusEnum C:\WINDOWS\system32\drivers\LGBusEnum.sys 23:00:40.0010 3724 LGBusEnum - ok 23:00:40.0015 3724 [ 2D7F1C02B94D6F0F3E10107E5EA8E141 ] LGCoreTemp C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys 23:00:40.0029 3724 LGCoreTemp - ok 23:00:40.0032 3724 [ 2A9F60E6531F42B31874618743037719 ] LGJoyXlCore C:\WINDOWS\system32\drivers\LGJoyXlCore.sys 23:00:40.0047 3724 LGJoyXlCore - ok 23:00:40.0050 3724 [ FA59A7421049F5852C1182345A4B8C4F ] LGVirHid C:\WINDOWS\system32\drivers\LGVirHid.sys 23:00:40.0064 3724 LGVirHid - ok 23:00:40.0067 3724 LicenseManager - ok 23:00:40.0070 3724 lltdio - ok 23:00:40.0073 3724 lltdsvc - ok 23:00:40.0075 3724 lmhosts - ok 23:00:40.0079 3724 [ 409BCD64FCA0147614E6B0DD14C071FA ] LogiRegistryService C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe 23:00:40.0091 3724 LogiRegistryService - ok 23:00:40.0095 3724 LSI_SAS - ok 23:00:40.0097 3724 LSI_SAS2i - ok 23:00:40.0101 3724 LSI_SAS3i - ok 23:00:40.0104 3724 LSI_SSS - ok 23:00:40.0107 3724 LSM - ok 23:00:40.0109 3724 luafv - ok 23:00:40.0112 3724 MapsBroker - ok 23:00:40.0115 3724 mausbhost - ok 23:00:40.0117 3724 mausbip - ok 23:00:40.0150 3724 [ D76E56108E6482905D3FAEA0649919E4 ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe 23:00:40.0245 3724 MBAMService - ok 23:00:40.0249 3724 megasas - ok 23:00:40.0252 3724 megasas2i - ok 23:00:40.0256 3724 megasr - ok 23:00:40.0260 3724 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys 23:00:40.0275 3724 MEIx64 - ok 23:00:40.0278 3724 MessagingService - ok 23:00:40.0279 3724 Suspicious service (Hidden): MessagingService_3f01d 23:00:40.0282 3724 mlx4_bus - ok 23:00:40.0284 3724 MMCSS - ok 23:00:40.0287 3724 Modem - ok 23:00:40.0291 3724 monitor - ok 23:00:40.0294 3724 mouclass - ok 23:00:40.0297 3724 mouhid - ok 23:00:40.0299 3724 mountmgr - ok 23:00:40.0301 3724 mpsdrv - ok 23:00:40.0305 3724 MpsSvc - ok 23:00:40.0307 3724 MRxDAV - ok 23:00:40.0309 3724 mrxsmb - ok 23:00:40.0311 3724 mrxsmb10 - ok 23:00:40.0314 3724 mrxsmb20 - ok 23:00:40.0316 3724 MsBridge - ok 23:00:40.0319 3724 MSDTC - ok 23:00:40.0323 3724 Msfs - ok 23:00:40.0326 3724 msgpiowin32 - ok 23:00:40.0328 3724 mshidkmdf - ok 23:00:40.0330 3724 mshidumdf - ok 23:00:40.0332 3724 msisadrv - ok 23:00:40.0335 3724 MSiSCSI - ok 23:00:40.0338 3724 msiserver - ok 23:00:40.0340 3724 MSKSSRV - ok 23:00:40.0342 3724 MsLldp - ok 23:00:40.0345 3724 MSPCLOCK - ok 23:00:40.0347 3724 MSPQM - ok 23:00:40.0350 3724 MsRPC - ok 23:00:40.0355 3724 mssmbios - ok 23:00:40.0357 3724 MSTEE - ok 23:00:40.0360 3724 MTConfig - ok 23:00:40.0362 3724 Mup - ok 23:00:40.0364 3724 mvumis - ok 23:00:40.0376 3724 [ 9BD90C37FF23463CEAFC465A688B1E9F ] MyEpson Portal Service C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe 23:00:40.0399 3724 MyEpson Portal Service - ok 23:00:40.0403 3724 NativeWifiP - ok 23:00:40.0406 3724 NaturalAuthentication - ok 23:00:40.0408 3724 NcaSvc - ok 23:00:40.0410 3724 NcbService - ok 23:00:40.0413 3724 NcdAutoSetup - ok 23:00:40.0415 3724 ndfltr - ok 23:00:40.0417 3724 NDIS - ok 23:00:40.0420 3724 NdisCap - ok 23:00:40.0423 3724 NdisImPlatform - ok 23:00:40.0425 3724 NdisTapi - ok 23:00:40.0427 3724 Ndisuio - ok 23:00:40.0430 3724 NdisVirtualBus - ok 23:00:40.0432 3724 NdisWan - ok 23:00:40.0435 3724 ndiswanlegacy - ok 23:00:40.0437 3724 ndproxy - ok 23:00:40.0440 3724 Ndu - ok 23:00:40.0442 3724 NetAdapterCx - ok 23:00:40.0444 3724 NetBIOS - ok 23:00:40.0448 3724 NetBT - ok 23:00:40.0451 3724 Netlogon - ok 23:00:40.0454 3724 Netman - ok 23:00:40.0456 3724 netprofm - ok 23:00:40.0459 3724 NetSetupSvc - ok 23:00:40.0470 3724 NetTcpPortSharing - ok 23:00:40.0473 3724 netvsc - ok 23:00:40.0477 3724 NgcCtnrSvc - ok 23:00:40.0479 3724 NgcSvc - ok 23:00:40.0481 3724 NlaSvc - ok 23:00:40.0484 3724 Npfs - ok 23:00:40.0487 3724 npsvctrig - ok 23:00:40.0489 3724 nsi - ok 23:00:40.0492 3724 nsiproxy - ok 23:00:40.0495 3724 NTFS - ok 23:00:40.0499 3724 Null - ok 23:00:40.0509 3724 [ 934BF1FB1BE4A5BAE408EE860D82AEF0 ] NvContainerLocalSystem C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe 23:00:40.0526 3724 NvContainerLocalSystem - ok 23:00:40.0536 3724 [ 934BF1FB1BE4A5BAE408EE860D82AEF0 ] NvContainerNetworkService C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe 23:00:40.0552 3724 NvContainerNetworkService - ok 23:00:40.0556 3724 nvdimmn - ok 23:00:40.0561 3724 [ C27427C9D79DE00A01B9987B68485F60 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys 23:00:40.0573 3724 NVHDA - ok 23:00:40.0691 3724 [ 444B969DABB3F2D2176EF0BFAB42364F ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys 23:00:40.0980 3724 nvlddmkm - ok 23:00:40.0986 3724 nvraid - ok 23:00:40.0991 3724 nvstor - ok 23:00:40.0994 3724 [ FED2C4C15F3547D0B7E83AFA96B1FBB6 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys 23:00:41.0008 3724 NvStreamKms - ok 23:00:41.0019 3724 [ 0B7BD772ED45111574E2736A5F358D79 ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe 23:00:41.0033 3724 NvTelemetryContainer - ok 23:00:41.0037 3724 [ 0DF10036D38CD3B83307984ECFE61436 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys 23:00:41.0051 3724 nvvad_WaveExtensible - ok 23:00:41.0055 3724 [ AECE653E7B9583938B1CF74B5B831CE3 ] nvvhci C:\WINDOWS\System32\drivers\nvvhci.sys 23:00:41.0065 3724 nvvhci - ok 23:00:41.0067 3724 OneSyncSvc - ok 23:00:41.0069 3724 Suspicious service (Hidden): OneSyncSvc_3f01d 23:00:41.0074 3724 [ 80D3AD0BC4300D3C3EB61C84CD2A2710 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 23:00:41.0086 3724 ose - ok 23:00:41.0105 3724 [ 1FA09B19F725F0A0EA41F99DE7A9B18B ] OverwolfUpdater C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe 23:00:41.0143 3724 OverwolfUpdater - ok 23:00:41.0146 3724 p2pimsvc - ok 23:00:41.0150 3724 p2psvc - ok 23:00:41.0152 3724 Parport - ok 23:00:41.0155 3724 partmgr - ok 23:00:41.0157 3724 PcaSvc - ok 23:00:41.0160 3724 pci - ok 23:00:41.0162 3724 pciide - ok 23:00:41.0165 3724 pcmcia - ok 23:00:41.0167 3724 pcw - ok 23:00:41.0171 3724 pdc - ok 23:00:41.0174 3724 PEAUTH - ok 23:00:41.0176 3724 percsas2i - ok 23:00:41.0180 3724 percsas3i - ok 23:00:41.0205 3724 PerfHost - ok 23:00:41.0211 3724 PhoneSvc - ok 23:00:41.0214 3724 PimIndexMaintenanceSvc - ok 23:00:41.0215 3724 Suspicious service (Hidden): PimIndexMaintenanceSvc_3f01d 23:00:41.0218 3724 pla - ok 23:00:41.0221 3724 PlugPlay - ok 23:00:41.0223 3724 pmem - ok 23:00:41.0226 3724 PNRPAutoReg - ok 23:00:41.0228 3724 PNRPsvc - ok 23:00:41.0231 3724 PolicyAgent - ok 23:00:41.0236 3724 Power - ok 23:00:41.0238 3724 PptpMiniport - ok 23:00:41.0326 3724 [ 5404E7A968A26DF03793B6F68536594D ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll 23:00:41.0387 3724 PrintNotify - ok 23:00:41.0392 3724 Processor - ok 23:00:41.0397 3724 ProfSvc - ok 23:00:41.0399 3724 Psched - ok 23:00:41.0402 3724 QWAVE - ok 23:00:41.0405 3724 QWAVEdrv - ok 23:00:41.0407 3724 RasAcd - ok 23:00:41.0410 3724 RasAgileVpn - ok 23:00:41.0413 3724 RasAuto - ok 23:00:41.0415 3724 Rasl2tp - ok 23:00:41.0420 3724 RasMan - ok 23:00:41.0422 3724 RasPppoe - ok 23:00:41.0425 3724 RasSstp - ok 23:00:41.0427 3724 rdbss - ok 23:00:41.0432 3724 rdpbus - ok 23:00:41.0434 3724 RDPDR - ok 23:00:41.0439 3724 RdpVideoMiniport - ok 23:00:41.0442 3724 rdyboost - ok 23:00:41.0445 3724 ReFS - ok 23:00:41.0447 3724 ReFSv1 - ok 23:00:41.0452 3724 RemoteAccess - ok 23:00:41.0454 3724 RemoteRegistry - ok 23:00:41.0457 3724 RetailDemo - ok 23:00:41.0461 3724 RmSvc - ok 23:00:41.0464 3724 RpcEptMapper - ok 23:00:41.0466 3724 RpcLocator - ok 23:00:41.0470 3724 RpcSs - ok 23:00:41.0473 3724 rspndr - ok 23:00:41.0487 3724 [ 5FC48CA9FFB9FB56ABA925A85BAB0272 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys 23:00:41.0525 3724 rt640x64 - ok 23:00:41.0528 3724 s3cap - ok 23:00:41.0531 3724 SamSs - ok 23:00:41.0534 3724 sbp2port - ok 23:00:41.0538 3724 SCardSvr - ok 23:00:41.0540 3724 ScDeviceEnum - ok 23:00:41.0544 3724 scfilter - ok 23:00:41.0546 3724 Schedule - ok 23:00:41.0549 3724 scmbus - ok 23:00:41.0552 3724 SCPolicySvc - ok 23:00:41.0554 3724 sdbus - ok 23:00:41.0557 3724 SDFRd - ok 23:00:41.0560 3724 SDRSVC - ok 23:00:41.0563 3724 sdstor - ok 23:00:41.0565 3724 seclogon - ok 23:00:41.0569 3724 SecurityHealthService - ok 23:00:41.0571 3724 SEMgrSvc - ok 23:00:41.0576 3724 SENS - ok 23:00:41.0578 3724 SensorDataService - ok 23:00:41.0581 3724 SensorService - ok 23:00:41.0584 3724 SensrSvc - ok 23:00:41.0588 3724 SerCx - ok 23:00:41.0591 3724 SerCx2 - ok 23:00:41.0594 3724 Serenum - ok 23:00:41.0597 3724 Serial - ok 23:00:41.0600 3724 sermouse - ok 23:00:41.0606 3724 SessionEnv - ok 23:00:41.0612 3724 sfloppy - ok 23:00:41.0615 3724 SharedAccess - ok 23:00:41.0618 3724 ShellHWDetection - ok 23:00:41.0621 3724 shpamsvc - ok 23:00:41.0623 3724 SiSRaid2 - ok 23:00:41.0626 3724 SiSRaid4 - ok 23:00:41.0629 3724 smphost - ok 23:00:41.0633 3724 SmsRouter - ok 23:00:41.0639 3724 SNMPTRAP - ok 23:00:41.0642 3724 spaceport - ok 23:00:41.0644 3724 SpatialGraphFilter - ok 23:00:41.0647 3724 SpbCx - ok 23:00:41.0650 3724 spectrum - ok 23:00:41.0653 3724 Spooler - ok 23:00:41.0657 3724 sppsvc - ok 23:00:41.0659 3724 srv - ok 23:00:41.0663 3724 srv2 - ok 23:00:41.0666 3724 srvnet - ok 23:00:41.0669 3724 SSDPSRV - ok 23:00:41.0672 3724 SstpSvc - ok 23:00:41.0678 3724 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys 23:00:41.0696 3724 ssudmdm - ok 23:00:41.0699 3724 StateRepository - ok 23:00:41.0713 3724 [ AC5DE2689B571942E08128D0EC771495 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe 23:00:41.0752 3724 Steam Client Service - ok 23:00:41.0755 3724 stexstor - ok 23:00:41.0758 3724 stisvc - ok 23:00:41.0761 3724 storahci - ok 23:00:41.0764 3724 storflt - ok 23:00:41.0766 3724 stornvme - ok 23:00:41.0770 3724 storqosflt - ok 23:00:41.0773 3724 StorSvc - ok 23:00:41.0776 3724 storufs - ok 23:00:41.0779 3724 storvsc - ok 23:00:41.0782 3724 svsvc - ok 23:00:41.0784 3724 swenum - ok 23:00:41.0788 3724 swprv - ok 23:00:41.0792 3724 Synth3dVsc - ok 23:00:41.0795 3724 SysMain - ok 23:00:41.0798 3724 SystemEventsBroker - ok 23:00:41.0800 3724 TabletInputService - ok 23:00:41.0803 3724 TapiSrv - ok 23:00:41.0806 3724 Tcpip - ok 23:00:41.0808 3724 Tcpip6 - ok 23:00:41.0812 3724 tcpipreg - ok 23:00:41.0816 3724 tdx - ok 23:00:41.0819 3724 terminpt - ok 23:00:41.0822 3724 TermService - ok 23:00:41.0825 3724 Themes - ok 23:00:41.0828 3724 TieringEngineService - ok 23:00:41.0831 3724 tiledatamodelsvc - ok 23:00:41.0834 3724 TimeBrokerSvc - ok 23:00:41.0837 3724 TokenBroker - ok 23:00:41.0839 3724 TPM - ok 23:00:41.0842 3724 TrkWks - ok 23:00:41.0852 3724 [ B9E5E3CFD096A5D60F2F7061A6FBB67B ] Trufos C:\WINDOWS\system32\DRIVERS\Trufos.sys 23:00:41.0879 3724 Trufos - ok 23:00:41.0882 3724 TrustedInstaller - ok 23:00:41.0886 3724 TsUsbFlt - ok 23:00:41.0889 3724 TsUsbGD - ok 23:00:41.0891 3724 tunnel - ok 23:00:41.0895 3724 tzautoupdate - ok 23:00:41.0897 3724 UASPStor - ok 23:00:41.0900 3724 UcmCx0101 - ok 23:00:41.0903 3724 UcmTcpciCx0101 - ok 23:00:41.0907 3724 UcmUcsi - ok 23:00:41.0909 3724 Ucx01000 - ok 23:00:41.0912 3724 UdeCx - ok 23:00:41.0915 3724 udfs - ok 23:00:41.0918 3724 UEFI - ok 23:00:41.0922 3724 Ufx01000 - ok 23:00:41.0924 3724 UfxChipidea - ok 23:00:41.0929 3724 ufxsynopsys - ok 23:00:41.0935 3724 UI0Detect - ok 23:00:41.0937 3724 umbus - ok 23:00:41.0940 3724 UmPass - ok 23:00:41.0943 3724 UmRdpService - ok 23:00:41.0947 3724 UnistoreSvc - ok 23:00:41.0949 3724 Suspicious service (Hidden): UnistoreSvc_3f01d 23:00:41.0952 3724 upnphost - ok 23:00:41.0955 3724 UrsChipidea - ok 23:00:41.0958 3724 UrsCx01000 - ok 23:00:41.0960 3724 UrsSynopsys - ok 23:00:41.0964 3724 usbaudio - ok 23:00:41.0966 3724 usbccgp - ok 23:00:41.0969 3724 usbcir - ok 23:00:41.0972 3724 usbehci - ok 23:00:41.0976 3724 usbhub - ok 23:00:41.0979 3724 USBHUB3 - ok 23:00:41.0982 3724 usbohci - ok 23:00:41.0984 3724 usbprint - ok 23:00:41.0989 3724 [ 96B48485A7CC2C0A63C196A16403C5F3 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 23:00:42.0008 3724 usbscan - ok 23:00:42.0011 3724 usbser - ok 23:00:42.0014 3724 USBSTOR - ok 23:00:42.0017 3724 usbuhci - ok 23:00:42.0021 3724 USBXHCI - ok 23:00:42.0025 3724 UserDataSvc - ok 23:00:42.0027 3724 Suspicious service (Hidden): UserDataSvc_3f01d 23:00:42.0030 3724 UserManager - ok 23:00:42.0032 3724 UsoSvc - ok 23:00:42.0035 3724 VaultSvc - ok 23:00:42.0039 3724 vdrvroot - ok 23:00:42.0041 3724 vds - ok 23:00:42.0044 3724 VerifierExt - ok 23:00:42.0047 3724 vhdmp - ok 23:00:42.0050 3724 vhf - ok 23:00:42.0055 3724 vmbus - ok 23:00:42.0057 3724 VMBusHID - ok 23:00:42.0060 3724 vmgid - ok 23:00:42.0064 3724 vmicguestinterface - ok 23:00:42.0066 3724 vmicheartbeat - ok 23:00:42.0069 3724 vmickvpexchange - ok 23:00:42.0072 3724 vmicrdv - ok 23:00:42.0075 3724 vmicshutdown - ok 23:00:42.0078 3724 vmictimesync - ok 23:00:42.0081 3724 vmicvmsession - ok 23:00:42.0083 3724 vmicvss - ok 23:00:42.0087 3724 volmgr - ok 23:00:42.0090 3724 volmgrx - ok 23:00:42.0093 3724 volsnap - ok 23:00:42.0096 3724 volume - ok 23:00:42.0099 3724 vpci - ok 23:00:42.0102 3724 vsmraid - ok 23:00:42.0105 3724 VSS - ok 23:00:42.0108 3724 VSTXRAID - ok 23:00:42.0111 3724 vwifibus - ok 23:00:42.0114 3724 vwififlt - ok 23:00:42.0117 3724 W32Time - ok 23:00:42.0121 3724 WacomPen - ok 23:00:42.0125 3724 WalletService - ok 23:00:42.0127 3724 wanarp - ok 23:00:42.0130 3724 wanarpv6 - ok 23:00:42.0133 3724 wbengine - ok 23:00:42.0136 3724 WbioSrvc - ok 23:00:42.0140 3724 wcifs - ok 23:00:42.0143 3724 Wcmsvc - ok 23:00:42.0146 3724 wcncsvc - ok 23:00:42.0149 3724 wcnfs - ok 23:00:42.0154 3724 WdBoot - ok 23:00:42.0157 3724 Wdf01000 - ok 23:00:42.0161 3724 WdFilter - ok 23:00:42.0164 3724 WdiServiceHost - ok 23:00:42.0167 3724 WdiSystemHost - ok 23:00:42.0170 3724 wdiwifi - ok 23:00:42.0173 3724 WdNisDrv - ok 23:00:42.0175 3724 WdNisSvc - ok 23:00:42.0179 3724 WebClient - ok 23:00:42.0182 3724 Wecsvc - ok 23:00:42.0186 3724 WEPHOSTSVC - ok 23:00:42.0189 3724 wercplsupport - ok 23:00:42.0192 3724 WerSvc - ok 23:00:42.0195 3724 WFDSConMgrSvc - ok 23:00:42.0198 3724 WFPLWFS - ok 23:00:42.0201 3724 WiaRpc - ok 23:00:42.0205 3724 WIMMount - ok 23:00:42.0207 3724 WinDefend - ok 23:00:42.0214 3724 WindowsTrustedRT - ok 23:00:42.0217 3724 WindowsTrustedRTProxy - ok 23:00:42.0220 3724 WinHttpAutoProxySvc - ok 23:00:42.0223 3724 WinMad - ok 23:00:42.0232 3724 Winmgmt - ok 23:00:42.0235 3724 WinNat - ok 23:00:42.0238 3724 WinRM - ok 23:00:42.0244 3724 WINUSB - ok 23:00:42.0247 3724 WinVerbs - ok 23:00:42.0250 3724 wisvc - ok 23:00:42.0253 3724 WlanSvc - ok 23:00:42.0256 3724 wlidsvc - ok 23:00:42.0259 3724 wlpasvc - ok 23:00:42.0263 3724 WmiAcpi - ok 23:00:42.0267 3724 wmiApSrv - ok 23:00:42.0270 3724 WMPNetworkSvc - ok 23:00:42.0277 3724 [ 1AE1076034392218EE89D2744EC2A071 ] Wof C:\WINDOWS\system32\drivers\Wof.sys 23:00:42.0300 3724 Wof - ok 23:00:42.0305 3724 workfolderssvc - ok 23:00:42.0310 3724 WPDBusEnum - ok 23:00:42.0313 3724 WpdUpFltr - ok 23:00:42.0316 3724 WpnService - ok 23:00:42.0319 3724 WpnUserService - ok 23:00:42.0322 3724 Suspicious service (Hidden): WpnUserService_3f01d 23:00:42.0324 3724 ws2ifsl - ok 23:00:42.0328 3724 wscsvc - ok 23:00:42.0330 3724 WSearch - ok 23:00:42.0335 3724 wuauserv - ok 23:00:42.0339 3724 WudfPf - ok 23:00:42.0342 3724 WUDFRd - ok 23:00:42.0345 3724 wudfsvc - ok 23:00:42.0348 3724 WUDFWpdFs - ok 23:00:42.0351 3724 WUDFWpdMtp - ok 23:00:42.0354 3724 WwanSvc - ok 23:00:42.0358 3724 xbgm - ok 23:00:42.0361 3724 XblAuthManager - ok 23:00:42.0364 3724 XblGameSave - ok 23:00:42.0367 3724 xboxgip - ok 23:00:42.0370 3724 XboxGipSvc - ok 23:00:42.0373 3724 XboxNetApiSvc - ok 23:00:42.0376 3724 xinputhid - ok 23:00:42.0378 3724 ================ Scan global =============================== 23:00:42.0387 3724 [Global] - ok 23:00:42.0387 3724 ================ Scan MBR ================================== 23:00:42.0389 3724 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 23:00:42.0408 3724 \Device\Harddisk0\DR0 - ok 23:00:42.0410 3724 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1 23:00:42.0472 3724 \Device\Harddisk1\DR1 - ok 23:00:42.0473 3724 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk2\DR2 23:00:42.0556 3724 \Device\Harddisk2\DR2 - ok 23:00:42.0556 3724 ================ Scan VBR ================================== 23:00:42.0558 3724 [ 1195C03E7DA255B6915431A60E4B1184 ] \Device\Harddisk0\DR0\Partition1 23:00:42.0559 3724 \Device\Harddisk0\DR0\Partition1 - ok 23:00:42.0561 3724 [ 506CBC4A9F285019A259E027A0DDF1BE ] \Device\Harddisk1\DR1\Partition1 23:00:42.0562 3724 \Device\Harddisk1\DR1\Partition1 - ok 23:00:42.0564 3724 [ 594A7BDBF1B78F87D4872DE2EA5996E9 ] \Device\Harddisk1\DR1\Partition2 23:00:42.0566 3724 \Device\Harddisk1\DR1\Partition2 - ok 23:00:42.0593 3724 [ 5BF1B60609D5BC337ADE74C6A37DF53B ] \Device\Harddisk2\DR2\Partition1 23:00:42.0594 3724 \Device\Harddisk2\DR2\Partition1 - ok 23:00:42.0614 3724 [ EE83130179050E9C0607F99DEB389C0E ] \Device\Harddisk2\DR2\Partition2 23:00:42.0615 3724 \Device\Harddisk2\DR2\Partition2 - ok 23:00:42.0615 3724 ============================================================ 23:00:42.0615 3724 Scan finished 23:00:42.0615 3724 ============================================================ 23:00:42.0621 13376 Detected object count: 1 23:00:42.0621 13376 Actual detected object count: 1 23:00:43.0820 13376 BEDaisy ( HiddenService.Multi.Generic ) - skipped by user 23:00:43.0820 13376 BEDaisy ( HiddenService.Multi.Generic ) - User select action: Skip Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (19-06-2017 22:47:32) Gestartet von C:\Users\BrainWasheD\Desktop Windows 10 Home Version 1703 (X64) (2017-05-20 17:35:03) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1290209912-1044598962-369420843-500 - Administrator - Disabled) BrainWasheD (S-1-5-21-1290209912-1044598962-369420843-1000 - Administrator - Enabled) => C:\Users\BrainWasheD DefaultAccount (S-1-5-21-1290209912-1044598962-369420843-503 - Limited - Disabled) Gast (S-1-5-21-1290209912-1044598962-369420843-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1290209912-1044598962-369420843-1002 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Ansel (Version: 382.05 - NVIDIA Corporation) Hidden Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.4.2294 - AVAST Software) Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform) Discord (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.) Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION) EPSON XP-630 Series Printer Uninstall (HKLM\...\EPSON XP-630 Series) (Version: - Seiko Epson Corporation) EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.53.0.0 - Seiko Epson Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.104 - Google Inc.) Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden Guild Wars 2 (HKLM\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games) League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden Logitech Gaming Software 8.92 (HKLM\...\Logitech Gaming Software) (Version: 8.92.67 - Logitech Inc.) Malwarebytes Version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 16.0.8229.2041 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) MyEpson Portal (x32 Version: 1.1.2.2 - SEIKO EPSON CORPORATION) Hidden Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.4.1 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation) NVIDIA GeForce Experience 3.6.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.6.0.74 - NVIDIA Corporation) NVIDIA Grafiktreiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation) NvNodejs (Version: 3.6.0.74 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.4.10.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.104.211.0 - Overwolf Ltd.) Overwolf.Setup.VC100CRTx64.Dist (HKLM\...\{EC9D5554-6852-4A55-81BB-AC02C7A8CFED}) (Version: 1.0.0 - Overwolf) Overwolf.Setup.VC100CRTx86.Dist (x32 Version: 1.0.0 - Overwolf) Hidden PLAYERUNKNOWN'S BATTLEGROUNDS (HKLM\...\Steam App 578080) (Version: - Bluehole, Inc.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.91.1119.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.) SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden SHIELD Streaming (Version: 7.1.0370 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.6.0.74 - NVIDIA Corporation) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\TeamSpeak 3 Client) (Version: 3.1.4 - TeamSpeak Systems GmbH) Twitch (HKLM-x32\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Twitch Interactive, Inc.) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0EA1CF12-4D4E-4351-94B7-84115E3AB914} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {18BD4184-9849-4FDB-9B2D-24D03803CE9D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {197019C0-A39E-4251-AA72-360935C4A061} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {1B4E6278-16D4-45A6-8BDE-8BAA2F57111A} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03] (NVIDIA Corporation) Task: {2A01F3FF-934C-4158-998B-12E9A8BA31B2} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-20] (AVAST Software) Task: {3BF8BA78-4AC9-4CB9-9335-A07B87708F74} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {420B7897-F154-4134-B3AE-149DECC6BAF7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {4D07E85B-84E3-41BF-B128-048A1B11ABD7} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {4D092839-43B2-4855-AB19-8D6325F14541} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {5832288D-E503-4966-AF8E-965743410F82} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5A7E1579-B6EB-4F42-9120-BC6031D5793C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5B4D641C-AF35-4B5B-8EDB-D191464EBBE8} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {61C6518D-C13B-4071-9836-2975C78C13FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd) Task: {6F7AC86E-5FFA-4710-9A38-0BE5F3CB4539} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {7270ECB5-AEA9-489F-BA3C-BC230228194A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {74D85C90-A46D-4914-B0DE-2B320BE872A4} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-05-03] (NVIDIA Corporation) Task: {7CA44C16-4C06-4287-B3F5-C92E3853D309} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-05-20] (AVAST Software) Task: {7E801DA2-CF04-4FED-BCA3-31CF6097C3C2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {7FB80D08-E1BE-4B3C-BDA4-6AA519217046} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {925B5788-1503-42EF-BA35-28AAED84F0DD} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {93A58816-DD3E-4BF6-9C17-F4D3BAC595AC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {95284773-EAF4-481E-B224-DB2BF54EDA8F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {957EF89D-E1CF-4C48-BEC4-14BB44D42D51} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {96F95AF5-1C8C-4718-A36B-24E45D8224B4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {9CC7B1AB-F5C2-46E8-AF00-3CA249EBFF9A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {A150F5A9-E5F0-4935-BD77-219558415C65} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A34D82D1-35D7-40D5-BFBD-1228C53033DF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A4D1A90D-EB59-4F32-94B7-FF32DB04EE43} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A664084A-B808-467F-AAE7-749AE16EAF62} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {A81ACE1F-61CB-4BC1-A7FA-8C924339B59A} - System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [2013-11-22] (SEIKO EPSON CORPORATION) Task: {B428955E-0F10-42B9-9BC2-C8E0D4A2E8CA} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {B74E1E8C-4791-48B9-AB80-C95F3E9408B5} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-06-06] (Overwolf LTD) Task: {BE535D16-1CEE-4C7F-B997-0936C38FD171} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {BFCFEED0-3A42-43DE-9DB8-3EB9C8A3436B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {C0E93ABF-6B28-43AF-9233-8C6C60788FCE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C2F94150-B72D-4E77-AF25-E4B46736A963} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {DE170156-FC9E-4655-9B93-0A1102B1FB76} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {E3B079A5-9C71-41C8-B6DF-3EF03C091D3E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-05-03] (NVIDIA Corporation) Task: {E413BE20-6FCF-4881-9CF1-2A7117D6ED3A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-17] (Microsoft Corporation) Task: {E8B61091-544C-404C-8B07-6E8782293A49} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F43B762F-7560-433A-B5B4-784D6E925E58} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-05-03] (NVIDIA Corporation) Task: {F848E963-1286-4D26-917B-4090052424C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {FCA81C28-8677-43F7-B312-4732D381BE28} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {FCC70481-09E8-4295-9EA9-2E5D1007F50D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE :/EXE:{61C1FF77-ABA5-4555-868B-77F3A3B348E5} /F:Update WORKGROUP\BRAINWASHED-PC$ ÄŠSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-05-20 19:44 - 2017-05-03 22:16 - 01267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-03-18 22:59 - 2017-03-20 06:36 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-06-08 11:14 - 2017-06-08 11:14 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2017-06-18 22:38 - 2017-06-15 09:29 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libglesv2.dll 2017-06-18 22:38 - 2017-06-15 09:29 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libegl.dll 2017-05-27 02:21 - 2017-05-27 02:21 - 01529320 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\Battle.net Helper.exe 2017-05-20 19:44 - 2017-05-03 22:16 - 01040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-05-20 18:23 - 2017-05-20 18:23 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-05-20 19:44 - 2017-05-03 22:15 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-05-20 21:01 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\SDL2.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 04969248 _____ () D:\Program Files (x86)\Steam\v8.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 02485536 _____ () D:\Program Files (x86)\Steam\video.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01563936 _____ () D:\Program Files (x86)\Steam\icui18n.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01195296 _____ () D:\Program Files (x86)\Steam\icuuc.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 02549760 _____ () D:\Program Files (x86)\Steam\libavcodec-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00491008 _____ () D:\Program Files (x86)\Steam\libavformat-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00332800 _____ () D:\Program Files (x86)\Steam\libavresample-2.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00442880 _____ () D:\Program Files (x86)\Steam\libavutil-54.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00485888 _____ () D:\Program Files (x86)\Steam\libswscale-3.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00877856 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-05-20 21:01 - 2016-07-05 00:17 - 00266560 _____ () D:\Program Files (x86)\Steam\openvr_api.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\ffmpeg.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 01082880 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node 2017-05-20 21:01 - 2017-05-20 21:01 - 03750400 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 00914432 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node 2017-05-20 21:01 - 2017-05-20 21:01 - 01127424 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node 2017-05-20 21:02 - 2017-05-08 21:45 - 69516064 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2017-06-08 14:55 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00385312 _____ () D:\Program Files (x86)\Steam\steam.dll 2017-05-27 02:21 - 2017-05-27 02:21 - 55758824 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\libcef.dll 2017-05-27 02:21 - 2017-05-27 02:21 - 00540336 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\ortp.dll 2017-05-27 02:21 - 2017-05-27 02:21 - 00133632 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\libEGL.dll 2017-05-27 02:21 - 2017-05-27 02:21 - 03384832 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\libGLESv2.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libglesv2.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libegl.dll 2017-06-19 22:41 - 2017-06-19 22:41 - 00148992 _____ () \\?\C:\Users\BrainWasheD\AppData\Local\Temp\4D6.tmp.node 2017-05-20 21:01 - 2017-05-20 21:01 - 02658296 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node 2017-05-20 21:02 - 2017-05-20 21:02 - 02665976 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\sharepoint.com -> hxxps://uniduesseldorf-files.sharepoint.com ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2017-06-18 02:58 - 00000969 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 hxxp://hosted.ap.org/dynamic/stories/L/LT_COLOMBIA_EXPLOSION?SITE=OHCIN&SECTION=HOME&TEMPLATE=DEFAULT 127.0.0.1 hxxp://hosted.ap.org ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 80.69.96.12 - 81.210.129.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{87F5FF42-E6DD-4726-95E9-16739ECC7E30}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596\SZBrowser.exe FirewallRules: [{872189C6-BFD2-4B8B-96BE-0B46B96644F3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{B8B90C3A-5B14-488C-AF0F-D1617885C3B7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{C26FC00F-49AE-4D19-99C7-600F0478DE5E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{0D761F0A-BBB2-45AC-B7A4-D482C6DEB44B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{55CDFBBC-4E2A-4AEF-B3B1-DCFC7D9BAF85}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{0E3356F7-F228-4728-9E30-BE801CEA82CF}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{1EF88E0A-7ACA-4DF1-9C90-B65F0AA1445A}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{A3092E72-F609-4569-A434-CAB23FFFD283}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{52E242B6-D440-4CAD-A20C-9C233527808A}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{C64A3D05-997F-4A86-9259-386559B19FF4}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{AFD1EF63-594B-48BA-8E9E-D023CE536350}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{8C819F29-F37B-4144-9A59-8A5F5E71EA8A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{0D25867A-6142-4002-9962-9CD7B1B7F4E4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{42229EC3-B520-47C7-83BB-FE6C632C0FCF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{CC3CEC28-C196-4CD5-81FE-F01B597B1DC5}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{963131C2-051C-40C2-9D9B-0DC305839D3A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [TCP Query User{F64ACAA9-9C9C-40A8-BB68-4A6B0368B519}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{A4F420F1-BA4B-4233-B661-6CC140C9B529}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe FirewallRules: [TCP Query User{155E7B90-091A-478A-B97D-3A7485E295DD}A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{31E9F334-B532-4C13-92D2-7D1C496B3D14}A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{51EFE651-26BE-4A31-A5A4-A2EC6E2B4CB4}A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{FF09E575-090C-458D-B310-F628B9378142}A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [{EAE34AD0-B88C-47A7-BD29-081717FA782C}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{133124C8-C45C-4ED5-BDB8-4AFC92BF3C11}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [TCP Query User{87218B48-9D2E-4248-B98B-8A9D1CBCB1E2}A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{306540A7-53FE-4C88-B647-E8EC332FF4F6}A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{2384971D-B58C-4376-908D-B785C4406E02}A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{56FAF66C-996E-4481-A4EB-6A0541C4D719}A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe FirewallRules: [{952936BB-C030-4D9E-A816-BBEE5A3F2EB7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{31C9BEE6-141A-4867-82E9-47746613D8AE}] => (Block) C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hosted.ap.org_0 FirewallRules: [{70B0E2F7-4E72-43B7-B9DA-9975BAD33385}] => (Block) C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hosted.ap.org_0.localstorage-journal ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (06/19/2017 04:43:29 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/19/2017 02:38:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000006369f2 ID des fehlerhaften Prozesses: 0x1564 Startzeit der fehlerhaften Anwendung: 0x01d2e890df61f200 Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe Berichtskennung: d9f806dd-6a32-4ab4-8c07-96a419ac4200 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 02:12:50 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: AUDIODG.EXE, Version: 10.0.15063.0, Zeitstempel: 0x4247e346 Name des fehlerhaften Moduls: RenderAPO.dll, Version: 8.90.101.0, Zeitstempel: 0x584a1932 Ausnahmecode: 0xc0000409 Fehleroffset: 0x00000000000c93e7 ID des fehlerhaften Prozesses: 0x2fec Startzeit der fehlerhaften Anwendung: 0x01d2e8838602c153 Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\AUDIODG.EXE Pfad des fehlerhaften Moduls: C:\WINDOWS\system32\RenderAPO.dll Berichtskennung: a64e6368-da15-461b-be26-1fece953fe2c Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 01:22:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TDSSKiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x37a8 Startzeit der fehlerhaften Anwendung: 0x01d2e889c899d617 Pfad der fehlerhaften Anwendung: C:\Users\BRAINW~1\AppData\Local\Temp\Rar$EXa0.094\TDSSKiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 4a7d28d3-39ab-48a6-ae36-a72fca7d377f Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 01:22:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller (1).exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x1a74 Startzeit der fehlerhaften Anwendung: 0x01d2e889b1a52f70 Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Downloads\tdsskiller (1).exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 78777bab-34d4-4f08-a8f2-70d99e9fd9d2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 01:21:36 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller (1).exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x26b0 Startzeit der fehlerhaften Anwendung: 0x01d2e889a189150a Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Downloads\tdsskiller (1).exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 447b1cbb-e56f-4c39-824c-f12ca2c57e09 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 01:18:40 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x1f94 Startzeit der fehlerhaften Anwendung: 0x01d2e88938948a87 Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Downloads\tdsskiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: ddedb9af-99dd-491f-85de-35329c0bfae1 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/18/2017 11:31:38 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/18/2017 11:22:41 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/18/2017 10:51:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000006369f2 ID des fehlerhaften Prozesses: 0x650 Startzeit der fehlerhaften Anwendung: 0x01d2e87252f161d4 Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe Berichtskennung: d7cf5a99-5bea-4dd1-bf40-a2adac4d1fb2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Systemfehler: ============= Error: (06/19/2017 12:11:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "BitDefenderCOM" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (06/19/2017 12:11:29 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "HomeGroupListener" wurde mit dem folgenden dienstspezifischen Fehler beendet: %%2147944153 = In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar. Error: (06/19/2017 12:11:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (06/18/2017 11:38:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "BitDefenderCOM" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/18/2017 11:31:23 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "HomeGroupListener" wurde mit dem folgenden dienstspezifischen Fehler beendet: %%2147944153 = In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar. Error: (06/18/2017 11:31:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (06/18/2017 11:30:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/18/2017 11:30:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/18/2017 11:30:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "NVIDIA NetworkService Container" wurde mit folgendem Fehler beendet: Für einen allgemeinen Befehl wurde ein Ergebnis zurückgegeben, das auf einen Fehler hinweist. Error: (06/18/2017 11:30:22 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2017-06-18 22:36:46.693 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.372 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.197 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.659 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.652 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.252 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.244 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.324 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.317 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:58:02.048 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz Prozentuale Nutzung des RAM: 42% Installierter physikalischer RAM: 8173.24 MB Verfügbarer physikalischer RAM: 4715.89 MB Summe virtueller Speicher: 16877.24 MB Verfügbarer virtueller Speicher: 12610.84 MB ==================== Laufwerke ================================ Drive a: (Volume) (Fixed) (Total:223.57 GB) (Free:165.94 GB) NTFS Drive c: () (Fixed) (Total:111.25 GB) (Free:70.25 GB) NTFS Drive d: () (Fixed) (Total:488.06 GB) (Free:439.63 GB) NTFS Drive e: (Volume) (Fixed) (Total:443.23 GB) (Free:403.34 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 1E55C42B) Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: DBC5041D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 2 (Size: 931.5 GB) (Disk ID: C99F686A) Partition: GPT. ==================== Ende von Addition.txt ============================ |
19.06.2017, 22:08 | #4 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" FRST Part 1: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (Administrator) auf BRAINWASHED-PC (19-06-2017 22:47:02) Gestartet von C:\Users\BrainWasheD\Desktop Geladene Profile: BrainWasheD (Verfügbare Profile: BrainWasheD) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.5676\Agent.exe (Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Blizzard Entertainment) D:\Program Files (x86)\Blizzard App\Battle.net.8839\Battle.net.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8839\Battle.net Helper.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8839\Battle.net Helper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-20] (AVAST Software) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17494136 2017-04-06] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <====== ACHTUNG HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Discord] => C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Battle.net] => D:\Program Files (x86)\Blizzard App\Battle.net Launcher.exe [3229160 2017-05-20] (Blizzard Entertainment) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9803992 2017-06-13] (Piriform Ltd) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-20] (AVAST Software) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 80.69.96.12 81.210.129.4 Tcpip\..\Interfaces\{00f4a4f9-90c8-4abb-b592-61cb1208f787}: [DhcpNameServer] 80.69.96.12 81.210.129.4 Internet Explorer: ================== BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-05-20] (AVAST Software) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-20] (AVAST Software) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: mguelu0x.default FF ProfilePath: C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default [2017-06-18] FF Homepage: Mozilla\Firefox\Profiles\mguelu0x.default -> Fa FF Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\sp@avast.com.xpi [2017-06-18] FF Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\wrc@avast.com.xpi [2017-06-18] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.de/ CHR StartupUrls: Default -> "hxxp://www.facebook.com/","hxxp://www.mmo-champion.com/content/","hxxp://www.google.de/","hxxp://www.youtube.com/" CHR Profile: C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default [2017-06-19] CHR Extension: (Google Präsentationen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-18] CHR Extension: (Google Docs) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-18] CHR Extension: (Google Drive) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-18] CHR Extension: (YouTube) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-18] CHR Extension: (Adblock Plus) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-06-19] CHR Extension: (Legacy MindMup (discontinued)) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnenaecjcgeppfpaokiifokeieopppej [2017-06-18] CHR Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-06-18] CHR Extension: (Google Tabellen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-18] CHR Extension: (Google Docs Offline) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-18] CHR Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-18] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-18] CHR Extension: (Google Mail) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-18] CHR Extension: (Chrome Media Router) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-18] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7346208 2017-05-20] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-20] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1522184 2017-05-20] () R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4412616 2017-06-09] (Microsoft Corporation) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation) R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON CORPORATION) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [225400 2017-04-06] (Logitech Inc.) S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [819672 2017-06-05] (Seiko Epson Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-05-03] (NVIDIA Corporation) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1326408 2017-06-06] (Overwolf LTD) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) S2 BitDefenderCOM; "C:\Program Files\BDServices\BitDefenderCom.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [311808 2017-05-20] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [190256 2017-05-20] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334576 2017-05-20] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [49016 2017-05-20] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-05-20] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32600 2017-05-20] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [128648 2017-05-20] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [101152 2017-05-20] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-05-20] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1007160 2017-05-20] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [569192 2017-05-20] (AVAST Software) R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [158880 2017-05-20] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [339696 2017-05-20] (AVAST Software) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd) R3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [54552 2017-04-06] (Logitech Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2017-04-06] (Logitech Inc.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys [14456944 2017-05-02] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-05-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-05-03] (NVIDIA Corporation) R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59448 2017-05-02] (NVIDIA Corporation) U5 PROCMON23; C:\Windows\System32\Drivers\PROCMON23.sys [84960 2017-05-22] (Sysinternals - www.sysinternals.com) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [898296 2016-01-13] (Realtek ) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 Trufos; C:\WINDOWS\System32\DRIVERS\Trufos.sys [442848 2017-05-05] (BitDefender S.R.L.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) U3 idsvc; kein ImagePath U3 wpcsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-19 22:47 - 2017-06-19 22:47 - 00020017 _____ C:\Users\BrainWasheD\Desktop\FRST.txt 2017-06-19 22:46 - 2017-06-19 22:47 - 00000000 ____D C:\FRST 2017-06-19 22:46 - 2017-06-19 22:46 - 02439680 _____ (Farbar) C:\Users\BrainWasheD\Desktop\FRST64.exe 2017-06-19 13:49 - 2017-06-19 13:49 - 09836385 _____ C:\Users\BrainWasheD\Downloads\01_Studi.pdf 2017-06-19 01:23 - 2017-06-19 01:23 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\85203316.sys 2017-06-19 01:23 - 2017-06-19 01:23 - 00064778 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.23.11_log.txt 2017-06-19 01:22 - 2017-06-19 01:22 - 04830473 _____ C:\Users\BrainWasheD\Downloads\tdsskiller.zip 2017-06-19 01:22 - 2017-06-19 01:22 - 00000356 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.22.26_log.txt 2017-06-19 00:31 - 2017-06-19 00:31 - 00000000 ____D C:\ProgramData\Emsisoft 2017-06-19 00:30 - 2017-06-19 00:32 - 00000000 ____D C:\EEK 2017-06-19 00:30 - 2017-06-19 00:30 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-06-18 23:28 - 2017-06-18 23:30 - 00000000 ____D C:\AdwCleaner 2017-06-18 22:39 - 2017-06-18 22:39 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Google 2017-06-18 22:38 - 2017-06-18 22:38 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-06-18 22:38 - 2017-06-18 22:38 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-06-18 22:38 - 2017-06-18 22:38 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-06-18 21:20 - 2017-06-18 22:35 - 00000000 ____D C:\Program Files\CCleaner 2017-06-18 21:20 - 2017-06-18 21:20 - 00002880 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2017-06-18 21:20 - 2017-06-18 21:20 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-06-18 21:20 - 2017-06-18 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-06-18 21:19 - 2017-06-18 22:47 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Google 2017-06-18 21:19 - 2017-06-18 22:38 - 00000000 ____D C:\Program Files (x86)\Google 2017-06-18 21:18 - 2017-06-18 21:52 - 00000000 ____D C:\Users\BrainWasheD\AppData\LocalLow\Mozilla 2017-06-18 21:18 - 2017-06-18 21:41 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Mozilla 2017-06-18 21:18 - 2017-06-18 21:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Mozilla 2017-06-18 21:03 - 2017-06-18 21:03 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\7BA52E92.sys 2017-06-18 15:45 - 2017-06-19 01:22 - 02213976 _____ (Kaspersky Lab ZAO) C:\Users\BrainWasheD\Downloads\tdsskiller.exe 2017-06-18 15:43 - 2017-06-18 15:46 - 00000000 ____D C:\ProgramData\HitmanPro 2017-06-18 13:31 - 2017-06-18 21:54 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Deployment 2017-06-18 13:31 - 2017-06-18 13:31 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Macromedia 2017-06-18 13:21 - 2017-06-18 13:21 - 00001173 _____ C:\Users\BrainWasheD\Desktop\JRT.txt 2017-06-18 12:52 - 2017-06-18 13:00 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-06-18 12:51 - 2017-06-18 13:00 - 00000000 ____D C:\Users\BrainWasheD\Desktop\mbar 2017-06-18 03:03 - 2017-06-19 22:40 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-06-18 03:03 - 2017-06-19 22:40 - 00188312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-06-18 03:03 - 2017-06-19 22:40 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-06-18 03:03 - 2017-06-19 22:40 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-06-18 03:03 - 2017-06-19 22:40 - 00044960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-06-18 03:03 - 2017-06-18 12:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\Program Files\Malwarebytes 2017-06-18 03:03 - 2017-05-25 11:58 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-06-17 23:13 - 2017-06-17 23:13 - 00000000 ____D C:\Program Files (x86)\Notepad++ 2017-06-17 21:04 - 2017-06-17 21:04 - 00000000 ____D C:\Users\BrainWasheD\Documents\League of Legends 2017-06-17 21:03 - 2017-06-17 21:04 - 00000863 _____ C:\Users\Public\Desktop\League of Legends.lnk 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Riot Games 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2017-06-17 21:03 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2017-06-17 21:02 - 2017-06-17 21:03 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Riot Games 2017-06-15 10:19 - 2017-06-15 10:19 - 00000713 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk 2017-06-15 10:19 - 2017-06-15 10:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2 2017-06-15 10:17 - 2017-06-15 10:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Guild Wars 2 2017-06-15 09:57 - 2017-06-15 09:57 - 00061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys 2017-06-14 17:08 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-06-14 17:08 - 2017-06-03 11:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-06-14 17:08 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-06-14 17:08 - 2017-06-03 11:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2017-06-14 17:08 - 2017-06-03 11:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-06-14 17:08 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2017-06-14 17:08 - 2017-06-03 11:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-06-14 17:08 - 2017-06-03 11:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-06-14 17:08 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-06-14 17:08 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-06-14 17:08 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2017-06-14 17:08 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2017-06-14 17:08 - 2017-06-03 10:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-06-14 17:08 - 2017-06-03 10:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-06-14 17:08 - 2017-06-03 10:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-06-14 17:08 - 2017-06-03 10:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2017-06-14 17:07 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2017-06-14 17:07 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2017-06-14 17:07 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2017-06-14 17:07 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2017-06-14 17:07 - 2017-06-03 11:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2017-06-14 17:07 - 2017-06-03 11:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2017-06-14 17:07 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2017-06-14 17:07 - 2017-06-03 11:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-06-14 17:07 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-06-14 17:07 - 2017-06-03 11:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-06-14 17:07 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2017-06-14 17:07 - 2017-06-03 11:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2017-06-14 17:07 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2017-06-14 17:07 - 2017-06-03 11:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-06-14 17:07 - 2017-06-03 11:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2017-06-14 17:07 - 2017-06-03 11:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-06-14 17:07 - 2017-06-03 10:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-06-14 17:07 - 2017-06-03 10:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-06-14 17:07 - 2017-06-03 10:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-06-14 17:06 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-06-14 17:06 - 2017-06-03 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-06-14 17:06 - 2017-06-03 12:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-06-14 17:06 - 2017-06-03 12:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-06-14 17:06 - 2017-06-03 12:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2017-06-14 17:06 - 2017-06-03 12:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-06-14 17:06 - 2017-06-03 12:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-06-14 17:06 - 2017-06-03 12:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-06-14 17:06 - 2017-06-03 11:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-06-14 17:06 - 2017-06-03 11:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-06-14 17:06 - 2017-06-03 11:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-06-14 17:06 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-06-14 17:06 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-06-14 17:06 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe 2017-06-14 17:06 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:06 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe 2017-06-14 17:06 - 2017-06-03 11:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-06-14 17:06 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-06-14 17:06 - 2017-06-03 11:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2017-06-14 17:06 - 2017-06-03 10:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-06-14 17:06 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe 2017-06-06 18:03 - 2017-06-18 23:30 - 00012800 ___SH C:\Users\BrainWasheD\Desktop\Thumbs.db 2017-06-03 08:08 - 2017-06-05 01:45 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000819 _____ C:\Users\BrainWasheD\Desktop\UseNeXT by Tangysoft.lnk 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\Users\BrainWasheD\Documents\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT 2017-06-03 08:05 - 2017-06-06 18:58 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-06-03 08:05 - 2017-06-03 16:08 - 00000000 ____D C:\ProgramData\Adobe 2017-06-03 08:05 - 2017-06-03 08:05 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-06-03 08:05 - 2017-06-03 08:05 - 00000000 ____D C:\Program Files (x86)\Adobe 2017-05-30 16:35 - 2017-05-30 16:35 - 00000000 ____D C:\Users\BrainWasheD\Documents\Benutzerdefinierte Office-Vorlagen 2017-05-29 12:51 - 2017-05-20 11:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-05-29 12:51 - 2017-05-20 10:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 10:48 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-05-29 12:51 - 2017-05-20 10:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 10:45 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 10:24 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2017-05-29 12:51 - 2017-05-20 10:23 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 10:20 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 10:19 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 10:18 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 10:17 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 10:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2017-05-29 12:51 - 2017-05-20 10:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-05-29 12:51 - 2017-05-20 09:07 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2017-05-29 12:51 - 2017-05-20 09:03 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 08:59 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2017-05-29 12:51 - 2017-05-20 08:58 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 04847928 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-05-29 12:51 - 2017-05-20 08:56 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-05-29 12:51 - 2017-05-20 08:55 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-05-29 12:51 - 2017-05-20 08:54 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00335808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2017-05-29 12:51 - 2017-05-20 08:53 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 06551856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01219560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 00406064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 08:48 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys 2017-05-29 12:51 - 2017-05-20 08:09 - 17365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll 2017-05-29 12:51 - 2017-05-20 08:07 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe 2017-05-29 12:51 - 2017-05-20 08:06 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 08:00 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 07:57 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-05-29 12:51 - 2017-05-20 07:56 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe 2017-05-29 12:51 - 2017-05-20 07:56 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04537344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll 2017-05-25 17:23 - 2017-05-25 17:23 - 00001150 _____ C:\Users\Public\Desktop\Overwolf.lnk 2017-05-25 17:23 - 2017-05-25 17:23 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\NVIDIA 2017-05-25 17:22 - 2017-06-13 17:22 - 00000000 ____D C:\Program Files (x86)\Overwolf 2017-05-25 17:22 - 2017-06-02 12:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\TS3Client 2017-05-25 17:22 - 2017-06-02 08:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Overwolf 2017-05-25 17:22 - 2017-05-25 17:24 - 00000000 ____D C:\ProgramData\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00004382 _____ C:\WINDOWS\System32\Tasks\Overwolf Updater Task 2017-05-25 17:22 - 2017-05-25 17:22 - 00001342 _____ C:\Users\BrainWasheD\Desktop\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00001300 _____ C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\TeamSpeak 3 Client 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.TeamSpeak 3 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.QtWebEngineProcess 2017-05-23 10:31 - 2017-06-18 22:37 - 00000000 ____D C:\WINDOWS\Minidump 2017-05-22 01:31 - 2017-06-19 22:44 - 00004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{08FEE1D4-25C0-4D3B-B4B9-6E4636D53EB8} 2017-05-22 01:25 - 2017-05-22 01:25 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Epson 2017-05-22 01:21 - 2017-05-22 12:07 - 00000949 _____ C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job 2017-05-22 01:21 - 2017-05-22 01:21 - 00004146 _____ C:\WINDOWS\System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} 2017-05-22 01:21 - 2017-05-22 01:21 - 00000000 ____D C:\Program Files\Common Files\EPSON 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\Program Files (x86)\EPSON Software 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\Program Files (x86)\epson 2017-05-22 01:15 - 2017-05-22 01:15 - 00001003 _____ C:\Users\Public\Desktop\EPSON Scan.lnk 2017-05-22 01:15 - 2014-06-03 00:00 - 00472064 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\esxw2ud.dll 2017-05-22 01:15 - 2014-03-05 04:06 - 00180224 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YLMBPLE.DLL 2017-05-22 01:15 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc64.exe 2017-05-22 01:15 - 2011-03-15 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YD4BPLE.DLL 2017-05-22 01:14 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Epson 2017-05-21 23:13 - 2017-05-22 15:29 - 00084960 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON23.SYS 2017-05-21 22:47 - 2017-06-14 17:12 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-05-21 22:47 - 2017-06-14 17:10 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-05-21 22:47 - 2017-04-28 03:19 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2017-05-21 22:47 - 2017-04-28 03:16 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2017-05-21 22:47 - 2017-04-28 03:11 - 02158544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2017-05-21 22:47 - 2017-04-28 03:09 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2017-05-21 22:47 - 2017-04-28 03:08 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-05-21 22:47 - 2017-04-28 03:08 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2017-05-21 22:47 - 2017-04-28 03:07 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-05-21 22:47 - 2017-04-28 03:06 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2017-05-21 22:47 - 2017-04-28 03:03 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2017-05-21 22:47 - 2017-04-28 02:59 - 02635336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2017-05-21 22:47 - 2017-04-28 02:59 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2017-05-21 22:47 - 2017-04-28 02:58 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2017-05-21 22:47 - 2017-04-28 02:57 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2017-05-21 22:47 - 2017-04-28 02:55 - 01325456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-05-21 22:47 - 2017-04-28 02:52 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2017-05-21 22:47 - 2017-04-28 02:40 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2017-05-21 22:47 - 2017-04-28 02:37 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-05-21 22:47 - 2017-04-28 02:15 - 01051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2017-05-21 22:47 - 2017-04-28 02:06 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll 2017-05-21 22:47 - 2017-04-28 02:03 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2017-05-21 22:47 - 2017-04-28 02:03 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2017-05-21 22:47 - 2017-04-28 01:59 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-05-21 22:47 - 2017-04-28 01:58 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2017-05-21 22:47 - 2017-04-28 01:57 - 01803264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-05-21 22:47 - 2017-04-28 01:54 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2017-05-21 22:47 - 2017-04-28 01:54 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2017-05-21 22:47 - 2017-04-28 01:54 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2017-05-21 22:47 - 2017-04-19 09:06 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2017-05-21 22:47 - 2017-04-19 09:04 - 00142240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys 2017-05-21 22:47 - 2017-04-19 09:02 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2017-05-21 22:47 - 2017-04-19 08:18 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys 2017-05-21 22:47 - 2017-04-19 08:15 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2017-05-21 22:47 - 2017-04-19 08:14 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll 2017-05-21 22:47 - 2017-04-19 08:12 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2017-05-21 22:47 - 2017-04-19 08:11 - 04446208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2017-05-21 22:47 - 2017-04-19 08:07 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2017-05-21 22:47 - 2017-04-19 08:07 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2017-05-21 22:47 - 2017-04-19 08:02 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2017-05-21 22:47 - 2017-04-19 07:59 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2017-05-21 22:47 - 2017-04-19 07:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2017-05-21 22:47 - 2017-04-19 07:32 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2017-05-21 22:47 - 2017-04-14 02:35 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2017-05-21 22:47 - 2017-04-14 02:33 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2017-05-21 22:47 - 2017-04-14 02:32 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll 2017-05-21 22:47 - 2017-04-14 02:30 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll 2017-05-21 22:47 - 2017-04-14 01:40 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll 2017-05-21 22:47 - 2017-04-14 01:39 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe 2017-05-21 22:47 - 2017-04-14 01:39 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll 2017-05-21 22:47 - 2017-04-14 01:39 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2017-05-21 22:47 - 2017-04-14 01:38 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll 2017-05-21 22:47 - 2017-04-14 01:37 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe 2017-05-21 22:47 - 2017-04-14 01:37 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2017-05-21 22:47 - 2017-04-14 01:37 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-05-21 22:47 - 2017-04-14 01:36 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll 2017-05-21 22:47 - 2017-04-14 01:35 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2017-05-21 22:47 - 2017-04-14 01:35 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2017-05-21 22:47 - 2017-04-14 01:33 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2017-05-21 22:47 - 2017-04-14 01:33 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2017-05-21 22:47 - 2017-04-14 01:31 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll 2017-05-21 22:47 - 2017-04-14 01:31 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 01295872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2017-05-21 22:47 - 2017-04-14 01:28 - 02443776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-05-21 22:47 - 2017-04-14 01:26 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2017-05-21 22:47 - 2017-04-14 01:24 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll 2017-05-21 22:47 - 2017-04-14 01:21 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll 2017-05-21 22:47 - 2017-04-14 01:18 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe 2017-05-21 22:47 - 2017-04-14 01:15 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2017-05-21 22:47 - 2017-04-14 01:08 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2017-05-21 22:47 - 2017-04-14 01:04 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2017-05-21 22:47 - 2017-04-14 01:01 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll 2017-05-21 22:47 - 2017-04-01 02:52 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-05-21 22:47 - 2017-04-01 02:51 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-05-21 22:47 - 2017-04-01 02:29 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-05-21 22:47 - 2017-04-01 02:28 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2017-05-21 22:47 - 2017-04-01 02:04 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2017-05-21 22:47 - 2017-04-01 01:58 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll 2017-05-21 22:47 - 2017-04-01 01:58 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2017-05-21 22:47 - 2017-04-01 01:50 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2017-05-21 22:46 - 2017-04-28 02:59 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe 2017-05-21 22:46 - 2017-04-28 02:49 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2017-05-21 22:46 - 2017-04-28 02:46 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2017-05-21 22:46 - 2017-04-28 02:46 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2017-05-21 22:46 - 2017-04-28 02:45 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2017-05-21 22:46 - 2017-04-28 02:44 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2017-05-21 22:46 - 2017-04-28 02:44 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2017-05-21 22:46 - 2017-04-28 02:42 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2017-05-21 22:46 - 2017-04-28 02:40 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2017-05-21 22:46 - 2017-04-28 02:39 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-05-21 22:46 - 2017-04-28 02:34 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe 2017-05-21 22:46 - 2017-04-28 02:11 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2017-05-21 22:46 - 2017-04-28 02:09 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2017-05-21 22:46 - 2017-04-28 02:07 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2017-05-21 22:46 - 2017-04-28 02:06 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2017-05-21 22:46 - 2017-04-28 02:06 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2017-05-21 22:46 - 2017-04-28 02:05 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-05-21 22:46 - 2017-04-28 02:04 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2017-05-21 22:46 - 2017-04-28 02:01 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2017-05-21 22:46 - 2017-04-28 01:54 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe 2017-05-21 22:46 - 2017-04-28 01:52 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll 2017-05-21 22:46 - 2017-04-19 08:16 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2017-05-21 22:46 - 2017-04-19 08:01 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll 2017-05-21 22:46 - 2017-04-19 07:37 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2017-05-21 22:46 - 2017-04-14 02:35 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll 2017-05-21 22:46 - 2017-04-14 01:43 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll 2017-05-21 22:46 - 2017-04-14 01:41 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2017-05-21 22:46 - 2017-04-14 01:38 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll 2017-05-21 22:46 - 2017-04-14 01:37 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2017-05-21 22:46 - 2017-04-14 01:36 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll 2017-05-21 22:46 - 2017-04-14 01:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2017-05-21 22:46 - 2017-04-14 01:34 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll 2017-05-21 22:46 - 2017-04-14 01:25 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2017-05-21 22:46 - 2017-04-14 01:15 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll 2017-05-21 22:46 - 2017-04-14 01:13 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll 2017-05-21 22:46 - 2017-04-14 01:13 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2017-05-21 22:46 - 2017-04-14 01:06 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2017-05-21 22:46 - 2017-04-01 02:02 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2017-05-21 22:46 - 2017-04-01 02:01 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2017-05-21 22:46 - 2017-04-01 01:56 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2017-05-21 22:46 - 2017-04-01 01:55 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-05-21 22:46 - 2017-04-01 01:55 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2017-05-21 22:46 - 2017-04-01 01:52 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll 2017-05-21 22:46 - 2017-04-01 01:52 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2017-05-21 22:46 - 2017-04-01 01:50 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2017-05-21 22:46 - 2017-04-01 01:45 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll 2017-05-21 22:46 - 2017-04-01 01:44 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll |
19.06.2017, 22:09 | #5 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" FRST Part 2: Code:
ATTFilter 2017-05-21 22:46 - 2017-03-31 23:00 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin 2017-05-21 15:49 - 2017-06-17 23:13 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Notepad++ 2017-05-21 15:49 - 2017-05-21 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2017-05-21 15:02 - 2017-05-21 15:02 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\Program Files\WinRAR 2017-05-21 14:57 - 2017-06-14 18:16 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Twitch 2017-05-21 14:57 - 2017-05-21 14:57 - 00001092 _____ C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk 2017-05-21 14:57 - 2017-05-21 14:57 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Twitch Setup 2017-05-21 02:23 - 2017-05-21 02:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft 2017-05-20 21:45 - 2017-05-20 21:45 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\UnrealEngine 2017-05-20 21:45 - 2017-05-20 21:45 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\TslGame 2017-05-20 21:45 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll 2017-05-20 21:45 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll 2017-05-20 21:45 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll 2017-05-20 21:45 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll 2017-05-20 21:45 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll 2017-05-20 21:45 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll 2017-05-20 21:45 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll 2017-05-20 21:45 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll 2017-05-20 21:45 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll 2017-05-20 21:45 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll 2017-05-20 21:45 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll 2017-05-20 21:45 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll 2017-05-20 21:45 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll 2017-05-20 21:45 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll 2017-05-20 21:45 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll 2017-05-20 21:45 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll 2017-05-20 21:44 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll 2017-05-20 21:44 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll 2017-05-20 21:44 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll 2017-05-20 21:44 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll 2017-05-20 21:44 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll 2017-05-20 21:44 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll 2017-05-20 21:44 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll 2017-05-20 21:44 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll 2017-05-20 21:44 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll 2017-05-20 21:44 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll 2017-05-20 21:44 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll 2017-05-20 21:44 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll 2017-05-20 21:44 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll 2017-05-20 21:44 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll 2017-05-20 21:44 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll 2017-05-20 21:44 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll 2017-05-20 21:44 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll 2017-05-20 21:44 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll 2017-05-20 21:44 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll 2017-05-20 21:44 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll 2017-05-20 21:44 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll 2017-05-20 21:44 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll 2017-05-20 21:44 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll 2017-05-20 21:44 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll 2017-05-20 21:44 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll 2017-05-20 21:44 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll 2017-05-20 21:44 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll 2017-05-20 21:44 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll 2017-05-20 21:44 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll 2017-05-20 21:44 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll 2017-05-20 21:44 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll 2017-05-20 21:44 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll 2017-05-20 21:44 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll 2017-05-20 21:44 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll 2017-05-20 21:44 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll 2017-05-20 21:44 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll 2017-05-20 21:44 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll 2017-05-20 21:44 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll 2017-05-20 21:44 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll 2017-05-20 21:44 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll 2017-05-20 21:44 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll 2017-05-20 21:44 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll 2017-05-20 21:44 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll 2017-05-20 21:44 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll 2017-05-20 21:44 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll 2017-05-20 21:44 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll 2017-05-20 21:44 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll 2017-05-20 21:44 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll 2017-05-20 21:44 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll 2017-05-20 21:44 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll 2017-05-20 21:44 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll 2017-05-20 21:44 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll 2017-05-20 21:44 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll 2017-05-20 21:44 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll 2017-05-20 21:44 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll 2017-05-20 21:44 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll 2017-05-20 21:44 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll 2017-05-20 21:44 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll 2017-05-20 21:44 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll 2017-05-20 21:44 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll 2017-05-20 21:44 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll 2017-05-20 21:44 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll 2017-05-20 21:44 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll 2017-05-20 21:44 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll 2017-05-20 21:44 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll 2017-05-20 21:44 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll 2017-05-20 21:44 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll 2017-05-20 21:44 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll 2017-05-20 21:44 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll 2017-05-20 21:44 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll 2017-05-20 21:44 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll 2017-05-20 21:44 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll 2017-05-20 21:44 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll 2017-05-20 21:44 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll 2017-05-20 21:44 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll 2017-05-20 21:44 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll 2017-05-20 21:44 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll 2017-05-20 21:44 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll 2017-05-20 21:44 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll 2017-05-20 21:44 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll 2017-05-20 21:44 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll 2017-05-20 21:44 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll 2017-05-20 21:44 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll 2017-05-20 21:44 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll 2017-05-20 21:44 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll 2017-05-20 21:44 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll 2017-05-20 21:44 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll 2017-05-20 21:44 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll 2017-05-20 21:44 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll 2017-05-20 21:44 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll 2017-05-20 21:44 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll 2017-05-20 21:44 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll 2017-05-20 21:44 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll 2017-05-20 21:44 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll 2017-05-20 21:44 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll 2017-05-20 21:44 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll 2017-05-20 21:44 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll 2017-05-20 21:44 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll 2017-05-20 21:44 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll 2017-05-20 21:44 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll 2017-05-20 21:44 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll 2017-05-20 21:44 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll 2017-05-20 21:44 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll 2017-05-20 21:44 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll 2017-05-20 21:44 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll 2017-05-20 21:44 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll 2017-05-20 21:44 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll 2017-05-20 21:44 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll 2017-05-20 21:44 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll 2017-05-20 21:44 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll 2017-05-20 21:44 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll 2017-05-20 21:44 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll 2017-05-20 21:44 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll 2017-05-20 21:44 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll 2017-05-20 21:44 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll 2017-05-20 21:44 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll 2017-05-20 21:44 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll 2017-05-20 21:44 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll 2017-05-20 21:44 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll 2017-05-20 21:44 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll 2017-05-20 21:44 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll 2017-05-20 21:44 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll 2017-05-20 21:44 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll 2017-05-20 21:44 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll 2017-05-20 21:44 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll 2017-05-20 21:44 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll 2017-05-20 21:44 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll 2017-05-20 21:44 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll 2017-05-20 21:44 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll 2017-05-20 21:44 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll 2017-05-20 21:44 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll 2017-05-20 21:44 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll 2017-05-20 21:44 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll 2017-05-20 21:44 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll 2017-05-20 21:41 - 2017-06-07 11:02 - 00000000 ____D C:\Users\BrainWasheD\Documents\Overwatch 2017-05-20 21:32 - 2017-05-20 21:32 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Skype 2017-05-20 21:28 - 2017-05-20 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm 2017-05-20 21:23 - 2017-05-20 21:23 - 00002586 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002583 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002579 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002558 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002536 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002533 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002500 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002497 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk 2017-05-20 21:23 - 2017-05-20 21:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools 2017-05-20 21:20 - 2017-06-17 01:09 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-05-20 21:20 - 2017-05-20 21:20 - 00000000 ____D C:\Program Files\Microsoft Office 15 2017-05-20 21:19 - 2017-05-20 21:19 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2017-05-20 21:19 - 2017-05-20 21:19 - 00000000 ____D C:\WINDOWS\system32\DAX2 2017-05-20 21:18 - 2017-05-20 21:18 - 00000000 ____D C:\Program Files\Realtek 2017-05-20 21:18 - 2015-06-18 18:45 - 04496600 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2017-05-20 21:18 - 2015-06-18 17:59 - 02862488 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2017-05-20 21:18 - 2015-06-17 19:47 - 02930904 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll 2017-05-20 21:18 - 2015-06-17 19:47 - 02585816 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll 2017-05-20 21:18 - 2015-06-17 14:45 - 03234520 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll 2017-05-20 21:18 - 2015-06-15 17:39 - 01748184 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll 2017-05-20 21:18 - 2015-06-11 19:40 - 03157796 _____ C:\WINDOWS\system32\Drivers\rtkSSTsetting.dat 2017-05-20 21:18 - 2015-06-10 13:20 - 03129672 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSSTAPO.dll 2017-05-20 21:18 - 2015-06-10 13:20 - 00728392 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSstCApoPropPage.dll 2017-05-20 21:18 - 2015-06-09 11:17 - 05708736 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll 2017-05-20 21:18 - 2015-06-02 19:25 - 01576976 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll 2017-05-20 21:18 - 2015-05-27 18:51 - 02461016 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll 2017-05-20 21:18 - 2015-05-27 18:51 - 02393432 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll 2017-05-20 21:18 - 2015-05-27 18:51 - 00944984 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll 2017-05-20 21:18 - 2015-05-27 18:51 - 00349528 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll 2017-05-20 21:18 - 2015-05-27 17:38 - 02825944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll 2017-05-20 21:18 - 2015-05-26 11:59 - 00166616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2017-05-20 21:18 - 2015-05-25 15:18 - 03195416 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll 2017-05-20 21:18 - 2015-05-18 14:47 - 02702040 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl 2017-05-20 21:18 - 2015-05-15 19:27 - 02918104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll 2017-05-20 21:18 - 2015-05-15 16:32 - 01316056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll 2017-05-20 21:18 - 2015-05-11 18:53 - 12996528 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO3064.dll 2017-05-20 21:18 - 2015-05-11 13:08 - 01374640 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO6064.dll 2017-05-20 21:18 - 2015-05-11 13:08 - 01192368 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll 2017-05-20 21:18 - 2015-05-11 13:08 - 01145264 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll 2017-05-20 21:18 - 2015-05-11 13:08 - 00980400 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll 2017-05-20 21:18 - 2015-04-27 16:09 - 00328816 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll 2017-05-20 21:18 - 2015-04-24 05:42 - 00858256 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll 2017-05-20 21:18 - 2015-04-24 05:42 - 00684176 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll 2017-05-20 21:18 - 2015-04-24 05:42 - 00435856 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll 2017-05-20 21:18 - 2015-04-24 05:41 - 00555664 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.DLL 2017-05-20 21:18 - 2015-04-13 16:25 - 03262184 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll 2017-05-20 21:18 - 2015-02-05 17:48 - 12834736 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO4064.dll 2017-05-20 21:18 - 2015-02-05 17:48 - 02789808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO7064.dll 2017-05-20 21:18 - 2015-02-04 00:38 - 01413776 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll 2017-05-20 21:18 - 2015-02-04 00:38 - 00454288 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll 2017-05-20 21:18 - 2015-02-04 00:38 - 00369296 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll 2017-05-20 21:18 - 2015-02-04 00:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll 2017-05-20 21:18 - 2015-02-04 00:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll 2017-05-20 21:18 - 2015-01-23 18:16 - 00213432 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tossaemaxapo64.dll 2017-05-20 21:18 - 2015-01-19 18:10 - 72113152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat 2017-05-20 21:18 - 2014-12-11 08:10 - 01104040 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\slcnt64.dll 2017-05-20 21:18 - 2014-12-11 08:10 - 00943784 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll 2017-05-20 21:18 - 2014-12-11 08:10 - 00734376 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll 2017-05-20 21:18 - 2014-12-11 08:10 - 00250536 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll 2017-05-20 21:18 - 2014-11-11 13:44 - 00631000 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2017-05-20 21:18 - 2014-11-04 13:42 - 06242576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll 2017-05-20 21:18 - 2014-11-04 13:42 - 01933584 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll 2017-05-20 21:18 - 2014-11-04 13:42 - 00336144 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll 2017-05-20 21:18 - 2014-11-04 13:42 - 00284944 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll 2017-05-20 21:18 - 2014-10-24 10:12 - 05234952 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll 2017-05-20 21:18 - 2014-10-24 10:12 - 00995120 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll 2017-05-20 21:18 - 2014-09-24 11:31 - 07087448 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll 2017-05-20 21:18 - 2014-09-24 11:31 - 01939800 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll 2017-05-20 21:18 - 2014-09-24 11:31 - 00315736 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll 2017-05-20 21:18 - 2014-09-24 11:31 - 00261464 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll 2017-05-20 21:18 - 2014-08-14 19:16 - 05804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat 2017-05-20 21:18 - 2014-06-17 19:17 - 00856992 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll 2017-05-20 21:18 - 2014-06-09 10:59 - 00560328 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll 2017-05-20 21:18 - 2014-05-22 16:24 - 00096568 _____ C:\WINDOWS\system32\audioLibVc.dll 2017-05-20 21:18 - 2014-04-10 12:19 - 02101848 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll 2017-05-20 21:18 - 2014-04-10 12:19 - 02041432 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll 2017-05-20 21:18 - 2014-02-27 20:02 - 02162992 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll 2017-05-20 21:18 - 2014-01-31 17:27 - 01313904 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll 2017-05-20 21:18 - 2013-10-11 12:47 - 00113576 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll 2017-05-20 21:18 - 2013-10-11 11:31 - 00947760 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll 2017-05-20 21:18 - 2013-10-07 00:26 - 00501184 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll 2017-05-20 21:18 - 2013-10-07 00:26 - 00487360 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll 2017-05-20 21:18 - 2013-10-07 00:26 - 00415680 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll 2017-05-20 21:18 - 2013-08-14 15:36 - 00662784 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll 2017-05-20 21:18 - 2013-08-14 15:35 - 00663296 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll 2017-05-20 21:18 - 2013-07-23 15:39 - 14048512 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRealtek64.dll 2017-05-20 21:18 - 2013-07-23 15:39 - 00922880 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll 2017-05-20 21:18 - 2013-06-25 12:47 - 00871856 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tossaeapo64.dll 2017-05-20 21:18 - 2013-06-25 12:47 - 00162224 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\toseaeapo64.dll 2017-05-20 21:18 - 2013-06-25 12:46 - 00582056 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosasfapo64.dll 2017-05-20 21:18 - 2013-06-21 11:01 - 00109848 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll 2017-05-20 21:18 - 2013-04-03 14:13 - 00906800 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll 2017-05-20 21:18 - 2012-08-31 19:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll 2017-05-20 21:18 - 2012-08-31 19:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll 2017-05-20 21:18 - 2012-08-31 19:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll 2017-05-20 21:18 - 2012-08-31 19:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll 2017-05-20 21:18 - 2012-08-31 19:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll 2017-05-20 21:18 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll 2017-05-20 21:18 - 2012-01-10 10:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll 2017-05-20 21:18 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll 2017-05-20 21:18 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll 2017-05-20 21:18 - 2011-09-02 14:21 - 00221024 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll 2017-05-20 21:18 - 2011-09-02 14:21 - 00081248 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll 2017-05-20 21:18 - 2011-09-02 14:21 - 00078688 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll 2017-05-20 21:18 - 2011-08-23 17:00 - 00603984 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 01756264 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 01568360 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 01486952 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00728680 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00712296 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00693352 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00491112 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00432744 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00428648 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll 2017-05-20 21:18 - 2011-05-31 09:42 - 00241768 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll 2017-05-20 21:18 - 2011-03-17 12:17 - 01361336 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll 2017-05-20 21:18 - 2011-03-07 17:11 - 00148416 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll 2017-05-20 21:18 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll 2017-05-20 21:18 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll 2017-05-20 21:18 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll 2017-05-20 21:18 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll 2017-05-20 21:18 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll 2017-05-20 21:18 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll 2017-05-20 21:18 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll 2017-05-20 21:18 - 2010-07-22 16:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll 2017-05-20 21:18 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll 2017-05-20 21:18 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll 2017-05-20 21:18 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll 2017-05-20 21:18 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll 2017-05-20 21:14 - 2017-05-20 21:43 - 00000000 ____D C:\Users\BrainWasheD\Documents\Heroes of the Storm 2017-05-20 21:14 - 2017-05-20 21:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch 2017-05-20 21:08 - 2017-06-03 08:07 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Adobe 2017-05-20 21:02 - 2017-05-20 21:03 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Steam 2017-05-20 21:01 - 2017-05-21 21:25 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\discord 2017-05-20 21:01 - 2017-05-20 21:01 - 00002307 _____ C:\Users\BrainWasheD\Desktop\Discord.lnk 2017-05-20 21:01 - 2017-05-20 21:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc 2017-05-20 21:01 - 2017-05-20 21:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\SquirrelTemp 2017-05-20 21:01 - 2017-05-20 21:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Discord 2017-05-20 21:01 - 2017-05-20 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2017-05-20 21:00 - 2017-05-20 21:00 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2017-05-20 20:55 - 2017-06-18 21:56 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\MicrosoftEdge 2017-05-20 20:45 - 2017-05-20 20:45 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2017-05-20 20:43 - 2017-05-20 22:01 - 00001547 _____ C:\Users\BrainWasheD\Desktop\Musik.lnk 2017-05-20 20:25 - 2017-05-20 20:25 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2017-05-20 20:25 - 2017-05-20 20:25 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2017-05-20 20:25 - 2017-05-20 20:25 - 00000000 ____D C:\Program Files\Reference Assemblies 2017-05-20 20:25 - 2017-05-20 20:25 - 00000000 ____D C:\Program Files\MSBuild 2017-05-20 20:25 - 2017-05-20 20:25 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-05-20 20:25 - 2017-05-20 20:25 - 00000000 ____D C:\Program Files (x86)\MSBuild 2017-05-20 20:25 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2017-05-20 20:25 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2017-05-20 20:25 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2017-05-20 20:25 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2017-05-20 20:25 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2017-05-20 20:25 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2017-05-20 20:01 - 2017-05-20 21:42 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2017-05-20 20:01 - 2017-05-20 20:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Blizzard Entertainment 2017-05-20 20:00 - 2017-06-19 22:41 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Battle.net 2017-05-20 20:00 - 2017-05-20 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blizzard App 2017-05-20 19:58 - 2017-05-20 20:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Battle.net 2017-05-20 19:58 - 2017-05-20 19:58 - 00000000 ____D C:\ProgramData\Battle.net 2017-05-20 19:55 - 2017-05-20 19:55 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Logitech 2017-05-20 19:55 - 2017-05-20 19:55 - 00000000 ____D C:\ProgramData\LogiShrd 2017-05-20 19:54 - 2017-05-20 19:55 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2017-05-20 19:54 - 2017-05-20 19:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2017-05-20 19:53 - 2017-05-20 19:53 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Logitech 2017-05-20 19:53 - 2017-05-20 19:53 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Logishrd 2017-05-20 19:51 - 2017-05-20 19:51 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-05-20 19:51 - 2017-05-01 22:14 - 00134592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2017-05-20 19:51 - 2017-03-10 23:17 - 00536864 _____ C:\WINDOWS\system32\vulkan-1.dll 2017-05-20 19:51 - 2017-03-10 23:17 - 00525600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2017-05-20 19:51 - 2017-03-10 23:17 - 00254240 _____ C:\WINDOWS\system32\vulkaninfo.exe 2017-05-20 19:51 - 2017-03-10 23:17 - 00233760 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2017-05-20 19:49 - 2017-05-02 00:38 - 40201848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 35388864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 35281528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 28623480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 11056456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 11024384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 10547440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 09245744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 09014792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 08805232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 03792320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 03247736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 01988032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438205.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 01589696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438205.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 01278528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 01276128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 01054144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00995736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00993872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00991168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00960960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00911992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00821184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00776048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00688968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00651200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00618744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00612088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00609912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00577728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00499320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00046008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll 2017-05-20 19:49 - 2017-05-02 00:38 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json 2017-05-20 19:49 - 2017-05-02 00:38 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json 2017-05-20 19:44 - 2017-05-21 23:22 - 00003236 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 21:52 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\NVIDIA Corporation 2017-05-20 19:44 - 2017-05-20 21:44 - 00000000 ____D C:\ProgramData\Package Cache 2017-05-20 19:44 - 2017-05-20 19:44 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 19:44 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 19:44 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 19:44 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 19:44 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 19:44 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 19:44 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-20 19:44 - 2017-05-20 19:44 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\NVIDIA 2017-05-20 19:44 - 2017-05-03 22:16 - 01893312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 01755072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 01477056 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 01317312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 00175552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 00143296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 00121280 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 00048064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys 2017-05-20 19:44 - 2017-05-03 21:28 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat 2017-05-20 19:44 - 2017-05-02 00:38 - 00059448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys 2017-05-20 19:44 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll 2017-05-20 19:44 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll 2017-05-20 19:44 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll 2017-05-20 19:44 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll 2017-05-20 19:44 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll 2017-05-20 19:44 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll 2017-05-20 19:42 - 2017-05-20 19:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-05-20 19:42 - 2017-05-20 19:42 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Comms 2017-05-20 19:40 - 2017-06-19 02:39 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\CrashDumps 2017-05-20 19:40 - 2017-05-20 19:40 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\DBG 2017-05-20 19:38 - 2017-06-19 22:40 - 00000000 ____D C:\ProgramData\NVIDIA 2017-05-20 19:38 - 2017-06-19 00:17 - 02340330 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-05-20 19:38 - 2017-05-01 22:52 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat 2017-05-20 19:38 - 2017-05-01 22:51 - 06437312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2017-05-20 19:38 - 2017-05-01 22:51 - 02479552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2017-05-20 19:38 - 2017-05-01 22:51 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2017-05-20 19:38 - 2017-05-01 22:51 - 00548800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2017-05-20 19:38 - 2017-05-01 22:51 - 00392312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2017-05-20 19:38 - 2017-05-01 22:51 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2017-05-20 19:38 - 2017-05-01 22:51 - 00069752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2017-05-20 19:38 - 2017-04-25 23:11 - 07944687 _____ C:\WINDOWS\system32\nvcoproc.bin 2017-05-20 19:38 - 2017-03-23 15:44 - 00521656 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2017-05-20 19:38 - 2017-03-23 15:44 - 00427448 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2017-05-20 19:37 - 2017-05-20 19:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-05-20 19:37 - 2017-05-20 19:51 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-05-20 19:37 - 2017-05-20 19:50 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-05-20 19:36 - 2017-05-21 23:16 - 00000000 ___RD C:\Users\BrainWasheD\OneDrive 2017-05-20 19:36 - 2017-05-20 19:36 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2017-05-20 19:35 - 2017-06-15 09:50 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-05-20 19:35 - 2017-06-13 16:05 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Packages 2017-05-20 19:35 - 2017-05-20 21:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\ConnectedDevicesPlatform 2017-05-20 19:35 - 2017-05-20 19:35 - 00000020 ___SH C:\Users\BrainWasheD\ntuser.ini 2017-05-20 19:35 - 2017-05-20 19:35 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Adobe 2017-05-20 19:35 - 2017-05-20 19:35 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\TileDataLayer 2017-05-20 19:35 - 2017-05-20 19:35 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Publishers 2017-05-20 19:33 - 2017-05-20 19:33 - 00007623 _____ C:\WINDOWS\diagwrn.xml 2017-05-20 19:33 - 2017-05-20 19:33 - 00007623 _____ C:\WINDOWS\diagerr.xml 2017-05-20 19:33 - 2017-05-20 19:33 - 00000000 ____D C:\ProgramData\USOShared 2017-05-20 19:32 - 2017-06-19 00:11 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-05-20 19:32 - 2017-05-20 19:32 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat 2017-05-20 19:32 - 2017-05-20 19:32 - 00004024 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2017-05-20 19:32 - 2017-05-20 19:32 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD 2017-05-20 19:32 - 2017-05-20 19:32 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software 2017-05-20 19:31 - 2017-05-20 19:31 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-05-20 19:30 - 2017-06-19 16:45 - 00000000 ____D C:\Users\BrainWasheD 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Vorlagen 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Startmenü 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Netzwerkumgebung 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Lokale Einstellungen 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Eigene Dateien 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Druckumgebung 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Documents\Eigene Videos 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Documents\Eigene Musik 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Documents\Eigene Bilder 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\AppData\Local\Verlauf 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\AppData\Local\Anwendungsdaten 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 _SHDL C:\Users\BrainWasheD\Anwendungsdaten 2017-05-20 19:30 - 2017-05-20 19:30 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines 2017-05-20 19:30 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2017-05-20 19:29 - 2017-05-20 21:18 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2017-05-20 19:28 - 2017-06-19 16:45 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-05-20 19:28 - 2017-06-15 09:49 - 00386600 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-05-20 19:28 - 2017-05-20 19:28 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2017-05-20 18:43 - 2017-06-18 22:37 - 00000000 ___DC C:\WINDOWS\Panther 2017-05-20 18:41 - 2017-05-20 18:43 - 00000036 _____ C:\WINDOWS\progress.ini 2017-05-20 18:25 - 2017-05-20 18:25 - 00032600 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2017-05-20 18:25 - 2017-05-20 18:25 - 00001043 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2017-05-20 18:25 - 2017-05-20 18:25 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\AVAST Software 2017-05-20 18:25 - 2017-05-20 18:25 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\CEF 2017-05-20 18:24 - 2017-05-20 19:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2017-05-20 18:24 - 2017-05-20 18:24 - 01007160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00569192 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00400456 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2017-05-20 18:24 - 2017-05-20 18:24 - 00339696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00158880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswstm.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00128648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00101152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00075704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2017-05-20 18:24 - 2017-05-20 18:24 - 00000000 ____D C:\Program Files\Common Files\AV 2017-05-20 18:24 - 2017-05-20 18:23 - 00334576 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys 2017-05-20 18:24 - 2017-05-20 18:23 - 00311808 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys 2017-05-20 18:24 - 2017-05-20 18:23 - 00190256 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys 2017-05-20 18:24 - 2017-05-20 18:23 - 00049016 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys 2017-05-20 18:23 - 2017-05-20 19:49 - 00000000 ____D C:\ProgramData\AVAST Software 2017-05-20 18:23 - 2017-05-20 19:35 - 00000000 ___HD C:\$GetCurrent 2017-05-20 18:23 - 2017-05-20 18:25 - 00000000 ____D C:\Program Files\AVAST Software 2017-05-20 18:20 - 2017-05-20 19:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asmedia Technology 2017-05-20 18:20 - 2017-05-20 18:20 - 00000000 ____D C:\Program Files (x86)\Intel 2017-05-20 18:20 - 2017-05-20 18:20 - 00000000 ____D C:\Program Files (x86)\ASM104xUSB3 2017-05-20 18:20 - 2017-05-20 18:20 - 00000000 ____D C:\Intel 2017-05-20 18:20 - 2010-12-23 05:09 - 00053248 ____R (Windows XP Bundled build C-Centric Single User) C:\WINDOWS\SysWOW64\CSVer.dll 2017-05-20 18:19 - 2017-05-20 18:20 - 00001769 _____ C:\WINDOWS\Language_trs.ini 2017-05-20 18:19 - 2017-05-20 18:19 - 00021262 _____ C:\WINDOWS\Ascd_tmp.ini 2017-05-20 18:18 - 2017-05-20 21:19 - 00000000 ___HD C:\Program Files (x86)\Temp 2017-05-20 18:14 - 2017-05-20 18:14 - 00057560 _____ C:\Users\BrainWasheD\AppData\Local\GDIPFONTCACHEV1.DAT 2017-05-20 18:14 - 2017-05-20 18:14 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Apps\2.0 2017-05-20 18:11 - 2017-05-22 01:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-05-20 18:11 - 2017-05-20 18:18 - 00000000 ____D C:\Program Files (x86)\Realtek 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Videos 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Vorlagen 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Startmenü 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Programme 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\ProgramData\Vorlagen 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\ProgramData\Startmenü 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\ProgramData\Favoriten 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\ProgramData\Dokumente 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 _SHDL C:\Dokumente und Einstellungen 2017-05-20 18:09 - 2017-05-20 18:09 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\VirtualStore 2017-05-20 18:09 - 2010-11-21 09:00 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Media Center Programs ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-19 10:17 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-06-19 10:17 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-06-19 00:17 - 2017-03-20 06:35 - 01065450 _____ C:\WINDOWS\system32\perfh007.dat 2017-06-19 00:17 - 2017-03-20 06:35 - 00237930 _____ C:\WINDOWS\system32\perfc007.dat 2017-06-19 00:10 - 2017-03-18 13:40 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-06-18 22:37 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-06-18 13:12 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-06-17 01:09 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-06-15 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-06-14 17:10 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-06-03 08:32 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-06-03 08:32 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-05-23 10:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning 2017-05-22 01:42 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-05-22 00:19 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-05-22 00:18 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-05-21 11:01 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat 2017-05-20 21:20 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-05-20 20:27 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2017-05-20 20:26 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup 2017-05-20 20:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2017-05-20 20:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI 2017-05-20 19:38 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Help 2017-05-20 19:34 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool 2017-05-20 19:34 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT 2017-05-20 19:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2017-05-20 19:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration 2017-05-20 19:33 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate 2017-05-20 19:33 - 2017-03-18 13:40 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2017-05-20 19:33 - 2009-07-14 05:20 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2017-05-20 19:32 - 2017-03-18 23:03 - 00000000 __RSD C:\WINDOWS\Media 2017-05-20 19:32 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries 2017-05-20 19:31 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2017-05-20 19:30 - 2017-03-20 06:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2017-05-20 19:30 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files\Windows Sidebar 2017-05-20 19:30 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2017-05-20 19:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2017-05-20 19:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\IME 2017-05-20 19:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\schemas 2017-05-20 19:30 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2017-05-20 19:30 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games 2017-05-20 19:30 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker 2017-05-20 19:29 - 2017-03-20 06:37 - 00000000 ____D C:\WINDOWS\HoloShell 2017-05-20 19:29 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\PrintDialog 2017-05-20 19:29 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\MiracastView 2017-05-20 18:54 - 2009-07-14 06:45 - 00021664 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-05-20 18:54 - 2009-07-14 06:45 - 00021664 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-05-20 18:04 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-06-18 13:02 - 2017-06-18 13:02 - 0000053 _____ () C:\Users\BrainWasheD\AppData\Roaming\LogFile.txt 2017-05-20 21:19 - 2017-05-20 21:19 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-06-15 10:48 ==================== Ende von FRST.txt ============================ |
20.06.2017, 15:28 | #6 |
/// TB-Ausbilder | New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Servus, Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2
Schritt 3
Bitte poste mit deiner nächsten Antwort
|
20.06.2017, 16:16 | #7 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Hi Matthias, Hier der Log von Schritt 1, fange jetzt mit Schritt 2 an. Anmerkung: Es wurde etwas gefunden und gelöscht und das erste Symptom des Öffnens der Website beim Neustart ist nicht aufgetreten. Es wurde etwas von delta-search.com gefunden Code:
ATTFilter # AdwCleaner v6.047 - Bericht erstellt am 20/06/2017 um 17:02:33 # Aktualisiert am 19/05/2017 von Malwarebytes # Datenbank : 2017-06-19.1 [Server] # Betriebssystem : Windows 10 Home (X64) # Benutzername : BrainWasheD - BRAINWASHED-PC # Gestartet von : C:\Users\BrainWasheD\Desktop\adwcleaner_6.047.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** ***** [ Dateien ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** [-] [C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Gelöscht: delta-search.com ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: "Image File Execution Options" Schlüssel gelöscht :: "Prefetch" Dateien gelöscht :: Proxy Einstellungen zurückgesetzt :: Firewall Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht :: Chrome Einstellungen zurückgesetzt: C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default :: Hosts-Datei wiederhergestellt ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [2517 Bytes] - [18/06/2017 23:30:26] C:\AdwCleaner\AdwCleaner[C2].txt - [1419 Bytes] - [20/06/2017 17:02:33] C:\AdwCleaner\AdwCleaner[S0].txt - [2508 Bytes] - [18/06/2017 23:29:58] C:\AdwCleaner\AdwCleaner[S1].txt - [1784 Bytes] - [20/06/2017 17:02:02] ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1638 Bytes] ########## Schritt 2: Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 20.06.17 Scan-Zeit: 17:08 Protokolldatei: mbam.txt Administrator: Ja -Softwaredaten- Version: 3.1.2.1733 Komponentenversion: 1.0.141 Version des Aktualisierungspakets: 1.0.2192 Lizenz: Testversion -Systemdaten- Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: BrainWasheD-PC\BrainWasheD -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Ergebnis: Abgeschlossen Gescannte Objekte: 370396 Erkannte Bedrohungen: 0 (keine bösartigen Elemente erkannt) In die Quarantäne verschobene Bedrohungen: 0 (keine bösartigen Elemente erkannt) Abgelaufene Zeit: 2 Min., 35 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswert: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Datei: 0 (keine bösartigen Elemente erkannt) Physischer Sektor: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (Administrator) auf BRAINWASHED-PC (20-06-2017 17:13:38) Gestartet von C:\Users\BrainWasheD\Desktop Geladene Profile: BrainWasheD (Verfügbare Profile: BrainWasheD) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.5676\Agent.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Blizzard Entertainment) D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamuseragent.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-20] (AVAST Software) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17494136 2017-04-06] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <====== ACHTUNG HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Discord] => C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Battle.net] => D:\Program Files (x86)\Blizzard App\Battle.net Launcher.exe [3229160 2017-05-20] (Blizzard Entertainment) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9803992 2017-06-13] (Piriform Ltd) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-20] (AVAST Software) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 80.69.96.12 81.210.129.4 Tcpip\..\Interfaces\{00f4a4f9-90c8-4abb-b592-61cb1208f787}: [DhcpNameServer] 80.69.96.12 81.210.129.4 Internet Explorer: ================== BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-05-20] (AVAST Software) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-20] (AVAST Software) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: mguelu0x.default FF ProfilePath: C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default [2017-06-20] FF Homepage: Mozilla\Firefox\Profiles\mguelu0x.default -> Fa FF Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\sp@avast.com.xpi [2017-06-18] FF Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\wrc@avast.com.xpi [2017-06-18] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.de/ CHR StartupUrls: Default -> "hxxp://www.facebook.com/","hxxp://www.mmo-champion.com/content/","hxxp://www.google.de/","hxxp://www.youtube.com/" CHR Profile: C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default [2017-06-20] CHR Extension: (Google Präsentationen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-20] CHR Extension: (Google Docs) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-20] CHR Extension: (Google Drive) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-20] CHR Extension: (YouTube) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-20] CHR Extension: (Adblock Plus) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-06-20] CHR Extension: (Legacy MindMup (discontinued)) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnenaecjcgeppfpaokiifokeieopppej [2017-06-20] CHR Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-06-20] CHR Extension: (Google Tabellen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-20] CHR Extension: (Google Docs Offline) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-20] CHR Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-20] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-20] CHR Extension: (Google Mail) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-20] CHR Extension: (Chrome Media Router) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-20] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7346208 2017-05-20] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-20] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1522184 2017-05-20] () R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4412616 2017-06-09] (Microsoft Corporation) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation) R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON CORPORATION) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [225400 2017-04-06] (Logitech Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [819672 2017-06-05] (Seiko Epson Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) R3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-05-03] (NVIDIA Corporation) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1326408 2017-06-06] (Overwolf LTD) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) S2 BitDefenderCOM; "C:\Program Files\BDServices\BitDefenderCom.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [311808 2017-05-20] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [190256 2017-05-20] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334576 2017-05-20] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [49016 2017-05-20] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-05-20] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32600 2017-05-20] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [128648 2017-05-20] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [101152 2017-05-20] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-05-20] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1007160 2017-05-20] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [569192 2017-05-20] (AVAST Software) R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [158880 2017-05-20] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [339696 2017-05-20] (AVAST Software) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-05-25] () R3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [54552 2017-04-06] (Logitech Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2017-04-06] (Logitech Inc.) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188312 2017-06-20] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [113592 2017-06-20] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [44960 2017-06-20] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [252832 2017-06-20] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-06-20] (Malwarebytes) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys [14456944 2017-05-02] (NVIDIA Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-05-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-05-03] (NVIDIA Corporation) R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59448 2017-05-02] (NVIDIA Corporation) U5 PROCMON23; C:\Windows\System32\Drivers\PROCMON23.sys [84960 2017-05-22] (Sysinternals - www.sysinternals.com) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [898296 2016-01-13] (Realtek ) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 Trufos; C:\WINDOWS\System32\DRIVERS\Trufos.sys [442848 2017-05-05] (BitDefender S.R.L.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) U3 idsvc; kein ImagePath U3 wpcsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-20 17:13 - 2017-06-20 17:13 - 00020391 _____ C:\Users\BrainWasheD\Desktop\FRST.txt 2017-06-20 17:12 - 2017-06-20 17:12 - 00001393 _____ C:\Users\BrainWasheD\Desktop\mbam.txt 2017-06-20 16:58 - 2017-06-20 16:58 - 04110280 _____ C:\Users\BrainWasheD\Downloads\adwcleaner_6.047.exe 2017-06-20 16:58 - 2017-06-20 16:58 - 04110280 _____ C:\Users\BrainWasheD\Desktop\adwcleaner_6.047.exe 2017-06-20 02:17 - 2017-06-20 12:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\vlc 2017-06-20 02:17 - 2017-06-20 02:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-06-20 02:17 - 2017-06-20 02:17 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-06-20 02:16 - 2017-06-20 02:16 - 30950664 _____ C:\Users\BrainWasheD\Downloads\vlc-2.2.6-win32.exe 2017-06-19 23:00 - 2017-06-19 23:01 - 00066692 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_23.00.31_log.txt 2017-06-19 23:00 - 2017-06-19 23:00 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\55876282.sys 2017-06-19 22:52 - 2017-06-19 22:56 - 00068040 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_22.52.10_log.txt 2017-06-19 22:52 - 2017-06-19 22:52 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\55192664.sys 2017-06-19 22:51 - 2017-06-19 22:51 - 04830473 _____ C:\Users\BrainWasheD\Downloads\tdsskiller (1).zip 2017-06-19 22:51 - 2017-06-19 22:51 - 02213976 _____ (Kaspersky Lab ZAO) C:\Users\BrainWasheD\Desktop\tdsskiller.exe 2017-06-19 22:51 - 2017-06-19 22:51 - 00000354 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_22.51.12_log.txt 2017-06-19 22:46 - 2017-06-20 17:13 - 00000000 ____D C:\FRST 2017-06-19 22:46 - 2017-06-19 22:46 - 02439680 _____ (Farbar) C:\Users\BrainWasheD\Desktop\FRST64.exe 2017-06-19 13:49 - 2017-06-19 13:49 - 09836385 _____ C:\Users\BrainWasheD\Downloads\01_Studi.pdf 2017-06-19 01:23 - 2017-06-19 01:23 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\85203316.sys 2017-06-19 01:23 - 2017-06-19 01:23 - 00064778 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.23.11_log.txt 2017-06-19 01:22 - 2017-06-19 01:22 - 04830473 _____ C:\Users\BrainWasheD\Downloads\tdsskiller.zip 2017-06-19 01:22 - 2017-06-19 01:22 - 00000356 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.22.26_log.txt 2017-06-19 00:31 - 2017-06-19 00:31 - 00000000 ____D C:\ProgramData\Emsisoft 2017-06-19 00:30 - 2017-06-19 00:32 - 00000000 ____D C:\EEK 2017-06-18 23:28 - 2017-06-20 17:02 - 00000000 ____D C:\AdwCleaner 2017-06-18 22:39 - 2017-06-18 22:39 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Google 2017-06-18 22:38 - 2017-06-18 22:38 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-06-18 22:38 - 2017-06-18 22:38 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-06-18 22:38 - 2017-06-18 22:38 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-06-18 21:20 - 2017-06-18 22:35 - 00000000 ____D C:\Program Files\CCleaner 2017-06-18 21:20 - 2017-06-18 21:20 - 00002880 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2017-06-18 21:20 - 2017-06-18 21:20 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-06-18 21:20 - 2017-06-18 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-06-18 21:19 - 2017-06-18 22:47 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Google 2017-06-18 21:19 - 2017-06-18 22:38 - 00000000 ____D C:\Program Files (x86)\Google 2017-06-18 21:18 - 2017-06-18 21:52 - 00000000 ____D C:\Users\BrainWasheD\AppData\LocalLow\Mozilla 2017-06-18 21:18 - 2017-06-18 21:41 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Mozilla 2017-06-18 21:18 - 2017-06-18 21:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Mozilla 2017-06-18 21:03 - 2017-06-18 21:03 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\7BA52E92.sys 2017-06-18 15:45 - 2017-06-19 01:22 - 02213976 _____ (Kaspersky Lab ZAO) C:\Users\BrainWasheD\Downloads\tdsskiller.exe 2017-06-18 15:43 - 2017-06-18 15:46 - 00000000 ____D C:\ProgramData\HitmanPro 2017-06-18 13:31 - 2017-06-18 21:54 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Deployment 2017-06-18 13:31 - 2017-06-18 13:31 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Macromedia 2017-06-18 13:21 - 2017-06-18 13:21 - 00001173 _____ C:\Users\BrainWasheD\Desktop\JRT.txt 2017-06-18 12:52 - 2017-06-18 13:00 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-06-18 12:51 - 2017-06-18 13:00 - 00000000 ____D C:\Users\BrainWasheD\Desktop\mbar 2017-06-18 03:03 - 2017-06-20 17:03 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-06-18 03:03 - 2017-06-20 17:03 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-06-18 03:03 - 2017-06-20 17:03 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-06-18 03:03 - 2017-06-20 17:03 - 00044960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-06-18 03:03 - 2017-06-20 10:47 - 00188312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-06-18 03:03 - 2017-06-18 12:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\Program Files\Malwarebytes 2017-06-18 03:03 - 2017-05-25 11:58 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-06-17 23:13 - 2017-06-17 23:13 - 00000000 ____D C:\Program Files (x86)\Notepad++ 2017-06-17 21:04 - 2017-06-17 21:04 - 00000000 ____D C:\Users\BrainWasheD\Documents\League of Legends 2017-06-17 21:03 - 2017-06-17 21:04 - 00000863 _____ C:\Users\Public\Desktop\League of Legends.lnk 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Riot Games 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2017-06-17 21:03 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2017-06-17 21:02 - 2017-06-17 21:03 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Riot Games 2017-06-15 10:19 - 2017-06-15 10:19 - 00000713 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk 2017-06-15 10:19 - 2017-06-15 10:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2 2017-06-15 10:17 - 2017-06-15 10:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Guild Wars 2 2017-06-15 09:57 - 2017-06-15 09:57 - 00061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys 2017-06-14 17:08 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-06-14 17:08 - 2017-06-03 11:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-06-14 17:08 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-06-14 17:08 - 2017-06-03 11:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2017-06-14 17:08 - 2017-06-03 11:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-06-14 17:08 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2017-06-14 17:08 - 2017-06-03 11:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-06-14 17:08 - 2017-06-03 11:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-06-14 17:08 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-06-14 17:08 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-06-14 17:08 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2017-06-14 17:08 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2017-06-14 17:08 - 2017-06-03 10:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-06-14 17:08 - 2017-06-03 10:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-06-14 17:08 - 2017-06-03 10:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-06-14 17:08 - 2017-06-03 10:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2017-06-14 17:07 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2017-06-14 17:07 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2017-06-14 17:07 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2017-06-14 17:07 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2017-06-14 17:07 - 2017-06-03 11:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2017-06-14 17:07 - 2017-06-03 11:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2017-06-14 17:07 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2017-06-14 17:07 - 2017-06-03 11:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-06-14 17:07 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-06-14 17:07 - 2017-06-03 11:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-06-14 17:07 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2017-06-14 17:07 - 2017-06-03 11:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2017-06-14 17:07 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2017-06-14 17:07 - 2017-06-03 11:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-06-14 17:07 - 2017-06-03 11:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2017-06-14 17:07 - 2017-06-03 11:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-06-14 17:07 - 2017-06-03 10:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-06-14 17:07 - 2017-06-03 10:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-06-14 17:07 - 2017-06-03 10:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-06-14 17:06 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-06-14 17:06 - 2017-06-03 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-06-14 17:06 - 2017-06-03 12:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-06-14 17:06 - 2017-06-03 12:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-06-14 17:06 - 2017-06-03 12:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2017-06-14 17:06 - 2017-06-03 12:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-06-14 17:06 - 2017-06-03 12:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-06-14 17:06 - 2017-06-03 12:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-06-14 17:06 - 2017-06-03 11:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-06-14 17:06 - 2017-06-03 11:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-06-14 17:06 - 2017-06-03 11:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-06-14 17:06 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-06-14 17:06 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-06-14 17:06 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe 2017-06-14 17:06 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:06 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe 2017-06-14 17:06 - 2017-06-03 11:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-06-14 17:06 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-06-14 17:06 - 2017-06-03 11:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2017-06-14 17:06 - 2017-06-03 10:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-06-14 17:06 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe 2017-06-06 18:03 - 2017-06-18 23:30 - 00012800 ___SH C:\Users\BrainWasheD\Desktop\Thumbs.db 2017-06-03 08:08 - 2017-06-20 12:21 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000819 _____ C:\Users\BrainWasheD\Desktop\UseNeXT by Tangysoft.lnk 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\Users\BrainWasheD\Documents\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT 2017-06-03 08:05 - 2017-06-06 18:58 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-06-03 08:05 - 2017-06-03 16:08 - 00000000 ____D C:\ProgramData\Adobe 2017-06-03 08:05 - 2017-06-03 08:05 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-06-03 08:05 - 2017-06-03 08:05 - 00000000 ____D C:\Program Files (x86)\Adobe 2017-05-30 16:35 - 2017-05-30 16:35 - 00000000 ____D C:\Users\BrainWasheD\Documents\Benutzerdefinierte Office-Vorlagen 2017-05-29 12:51 - 2017-05-20 11:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-05-29 12:51 - 2017-05-20 10:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 10:48 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-05-29 12:51 - 2017-05-20 10:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 10:45 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 10:24 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2017-05-29 12:51 - 2017-05-20 10:23 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 10:20 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 10:19 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 10:18 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 10:17 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 10:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2017-05-29 12:51 - 2017-05-20 10:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-05-29 12:51 - 2017-05-20 09:07 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2017-05-29 12:51 - 2017-05-20 09:03 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 08:59 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2017-05-29 12:51 - 2017-05-20 08:58 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 04847928 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-05-29 12:51 - 2017-05-20 08:56 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-05-29 12:51 - 2017-05-20 08:55 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-05-29 12:51 - 2017-05-20 08:54 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00335808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2017-05-29 12:51 - 2017-05-20 08:53 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 06551856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01219560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 00406064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 08:48 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys 2017-05-29 12:51 - 2017-05-20 08:09 - 17365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll 2017-05-29 12:51 - 2017-05-20 08:07 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe 2017-05-29 12:51 - 2017-05-20 08:06 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 08:00 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 07:57 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-05-29 12:51 - 2017-05-20 07:56 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe 2017-05-29 12:51 - 2017-05-20 07:56 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04537344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll 2017-05-25 17:23 - 2017-05-25 17:23 - 00001150 _____ C:\Users\Public\Desktop\Overwolf.lnk 2017-05-25 17:23 - 2017-05-25 17:23 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\NVIDIA 2017-05-25 17:22 - 2017-06-13 17:22 - 00000000 ____D C:\Program Files (x86)\Overwolf 2017-05-25 17:22 - 2017-06-02 12:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\TS3Client 2017-05-25 17:22 - 2017-06-02 08:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Overwolf 2017-05-25 17:22 - 2017-05-25 17:24 - 00000000 ____D C:\ProgramData\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00004382 _____ C:\WINDOWS\System32\Tasks\Overwolf Updater Task 2017-05-25 17:22 - 2017-05-25 17:22 - 00001342 _____ C:\Users\BrainWasheD\Desktop\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00001300 _____ C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\TeamSpeak 3 Client 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.TeamSpeak 3 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.QtWebEngineProcess 2017-05-23 10:31 - 2017-06-18 22:37 - 00000000 ____D C:\WINDOWS\Minidump 2017-05-22 01:31 - 2017-06-20 10:50 - 00004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{08FEE1D4-25C0-4D3B-B4B9-6E4636D53EB8} 2017-05-22 01:25 - 2017-05-22 01:25 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Epson 2017-05-22 01:21 - 2017-05-22 12:07 - 00000949 _____ C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job 2017-05-22 01:21 - 2017-05-22 01:21 - 00004146 _____ C:\WINDOWS\System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} 2017-05-22 01:21 - 2017-05-22 01:21 - 00000000 ____D C:\Program Files\Common Files\EPSON 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\Program Files (x86)\EPSON Software 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\Program Files (x86)\epson 2017-05-22 01:15 - 2017-05-22 01:15 - 00001003 _____ C:\Users\Public\Desktop\EPSON Scan.lnk 2017-05-22 01:15 - 2014-06-03 00:00 - 00472064 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\esxw2ud.dll 2017-05-22 01:15 - 2014-03-05 04:06 - 00180224 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YLMBPLE.DLL 2017-05-22 01:15 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc64.exe 2017-05-22 01:15 - 2011-03-15 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YD4BPLE.DLL 2017-05-22 01:14 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Epson 2017-05-21 23:13 - 2017-05-22 15:29 - 00084960 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON23.SYS 2017-05-21 22:47 - 2017-06-14 17:12 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-05-21 22:47 - 2017-06-14 17:10 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-05-21 22:47 - 2017-04-28 03:19 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2017-05-21 22:47 - 2017-04-28 03:16 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2017-05-21 22:47 - 2017-04-28 03:11 - 02158544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2017-05-21 22:47 - 2017-04-28 03:09 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2017-05-21 22:47 - 2017-04-28 03:08 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-05-21 22:47 - 2017-04-28 03:08 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2017-05-21 22:47 - 2017-04-28 03:07 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-05-21 22:47 - 2017-04-28 03:06 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2017-05-21 22:47 - 2017-04-28 03:03 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2017-05-21 22:47 - 2017-04-28 02:59 - 02635336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2017-05-21 22:47 - 2017-04-28 02:59 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2017-05-21 22:47 - 2017-04-28 02:58 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2017-05-21 22:47 - 2017-04-28 02:57 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2017-05-21 22:47 - 2017-04-28 02:55 - 01325456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-05-21 22:47 - 2017-04-28 02:52 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2017-05-21 22:47 - 2017-04-28 02:40 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2017-05-21 22:47 - 2017-04-28 02:37 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-05-21 22:47 - 2017-04-28 02:15 - 01051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2017-05-21 22:47 - 2017-04-28 02:06 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll 2017-05-21 22:47 - 2017-04-28 02:03 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2017-05-21 22:47 - 2017-04-28 02:03 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2017-05-21 22:47 - 2017-04-28 01:59 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-05-21 22:47 - 2017-04-28 01:58 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2017-05-21 22:47 - 2017-04-28 01:57 - 01803264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-05-21 22:47 - 2017-04-28 01:54 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2017-05-21 22:47 - 2017-04-28 01:54 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2017-05-21 22:47 - 2017-04-28 01:54 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2017-05-21 22:47 - 2017-04-19 09:06 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2017-05-21 22:47 - 2017-04-19 09:04 - 00142240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys 2017-05-21 22:47 - 2017-04-19 09:02 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2017-05-21 22:47 - 2017-04-19 08:18 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys 2017-05-21 22:47 - 2017-04-19 08:15 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2017-05-21 22:47 - 2017-04-19 08:14 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll 2017-05-21 22:47 - 2017-04-19 08:12 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2017-05-21 22:47 - 2017-04-19 08:11 - 04446208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2017-05-21 22:47 - 2017-04-19 08:07 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2017-05-21 22:47 - 2017-04-19 08:07 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2017-05-21 22:47 - 2017-04-19 08:02 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2017-05-21 22:47 - 2017-04-19 07:59 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2017-05-21 22:47 - 2017-04-19 07:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2017-05-21 22:47 - 2017-04-19 07:32 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2017-05-21 22:47 - 2017-04-14 02:35 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2017-05-21 22:47 - 2017-04-14 02:33 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2017-05-21 22:47 - 2017-04-14 02:32 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll 2017-05-21 22:47 - 2017-04-14 02:30 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll 2017-05-21 22:47 - 2017-04-14 01:40 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll 2017-05-21 22:47 - 2017-04-14 01:39 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe 2017-05-21 22:47 - 2017-04-14 01:39 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll 2017-05-21 22:47 - 2017-04-14 01:39 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2017-05-21 22:47 - 2017-04-14 01:38 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll 2017-05-21 22:47 - 2017-04-14 01:37 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe 2017-05-21 22:47 - 2017-04-14 01:37 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2017-05-21 22:47 - 2017-04-14 01:37 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-05-21 22:47 - 2017-04-14 01:36 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll 2017-05-21 22:47 - 2017-04-14 01:35 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2017-05-21 22:47 - 2017-04-14 01:35 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2017-05-21 22:47 - 2017-04-14 01:33 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2017-05-21 22:47 - 2017-04-14 01:33 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2017-05-21 22:47 - 2017-04-14 01:31 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll 2017-05-21 22:47 - 2017-04-14 01:31 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 01295872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2017-05-21 22:47 - 2017-04-14 01:28 - 02443776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-05-21 22:47 - 2017-04-14 01:26 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2017-05-21 22:47 - 2017-04-14 01:24 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll 2017-05-21 22:47 - 2017-04-14 01:21 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll 2017-05-21 22:47 - 2017-04-14 01:18 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe 2017-05-21 22:47 - 2017-04-14 01:15 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2017-05-21 22:47 - 2017-04-14 01:08 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2017-05-21 22:47 - 2017-04-14 01:04 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2017-05-21 22:47 - 2017-04-14 01:01 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll 2017-05-21 22:47 - 2017-04-01 02:52 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-05-21 22:47 - 2017-04-01 02:51 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-05-21 22:47 - 2017-04-01 02:29 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-05-21 22:47 - 2017-04-01 02:28 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2017-05-21 22:47 - 2017-04-01 02:04 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2017-05-21 22:47 - 2017-04-01 01:58 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll 2017-05-21 22:47 - 2017-04-01 01:58 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2017-05-21 22:47 - 2017-04-01 01:50 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2017-05-21 22:46 - 2017-04-28 02:59 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe 2017-05-21 22:46 - 2017-04-28 02:49 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2017-05-21 22:46 - 2017-04-28 02:46 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2017-05-21 22:46 - 2017-04-28 02:46 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2017-05-21 22:46 - 2017-04-28 02:45 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2017-05-21 22:46 - 2017-04-28 02:44 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2017-05-21 22:46 - 2017-04-28 02:44 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2017-05-21 22:46 - 2017-04-28 02:42 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2017-05-21 22:46 - 2017-04-28 02:40 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2017-05-21 22:46 - 2017-04-28 02:39 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-05-21 22:46 - 2017-04-28 02:34 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe 2017-05-21 22:46 - 2017-04-28 02:11 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2017-05-21 22:46 - 2017-04-28 02:09 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2017-05-21 22:46 - 2017-04-28 02:07 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2017-05-21 22:46 - 2017-04-28 02:06 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2017-05-21 22:46 - 2017-04-28 02:06 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2017-05-21 22:46 - 2017-04-28 02:05 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-05-21 22:46 - 2017-04-28 02:04 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2017-05-21 22:46 - 2017-04-28 02:01 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2017-05-21 22:46 - 2017-04-28 01:54 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe 2017-05-21 22:46 - 2017-04-28 01:52 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll 2017-05-21 22:46 - 2017-04-19 08:16 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2017-05-21 22:46 - 2017-04-19 08:01 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll 2017-05-21 22:46 - 2017-04-19 07:37 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2017-05-21 22:46 - 2017-04-14 02:35 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll 2017-05-21 22:46 - 2017-04-14 01:43 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll 2017-05-21 22:46 - 2017-04-14 01:41 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2017-05-21 22:46 - 2017-04-14 01:38 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll 2017-05-21 22:46 - 2017-04-14 01:37 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2017-05-21 22:46 - 2017-04-14 01:36 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll 2017-05-21 22:46 - 2017-04-14 01:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2017-05-21 22:46 - 2017-04-14 01:34 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll 2017-05-21 22:46 - 2017-04-14 01:25 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2017-05-21 22:46 - 2017-04-14 01:15 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll 2017-05-21 22:46 - 2017-04-14 01:13 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll 2017-05-21 22:46 - 2017-04-14 01:13 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2017-05-21 22:46 - 2017-04-14 01:06 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2017-05-21 22:46 - 2017-04-01 02:02 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2017-05-21 22:46 - 2017-04-01 02:01 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2017-05-21 22:46 - 2017-04-01 01:56 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2017-05-21 22:46 - 2017-04-01 01:55 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-05-21 22:46 - 2017-04-01 01:55 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2017-05-21 22:46 - 2017-04-01 01:52 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll 2017-05-21 22:46 - 2017-04-01 01:52 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2017-05-21 22:46 - 2017-04-01 01:50 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2017-05-21 22:46 - 2017-04-01 01:45 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll 2017-05-21 22:46 - 2017-04-01 01:44 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2017-05-21 22:46 - 2017-03-31 23:00 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin 2017-05-21 15:49 - 2017-06-17 23:13 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Notepad++ 2017-05-21 15:49 - 2017-05-21 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2017-05-21 15:02 - 2017-05-21 15:02 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\Program Files\WinRAR 2017-05-21 14:57 - 2017-06-14 18:16 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Twitch 2017-05-21 14:57 - 2017-05-21 14:57 - 00001092 _____ C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk 2017-05-21 14:57 - 2017-05-21 14:57 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Twitch Setup 2017-05-21 02:23 - 2017-05-21 02:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-20 17:09 - 2017-05-20 19:38 - 02369520 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-06-20 17:09 - 2017-03-20 06:35 - 01081138 _____ C:\WINDOWS\system32\perfh007.dat 2017-06-20 17:09 - 2017-03-20 06:35 - 00242448 _____ C:\WINDOWS\system32\perfc007.dat 2017-06-20 17:04 - 2017-05-20 20:00 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Battle.net 2017-06-20 17:04 - 2017-05-20 19:38 - 00000000 ____D C:\ProgramData\NVIDIA 2017-06-20 17:03 - 2017-05-20 19:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-06-20 17:02 - 2017-03-18 13:40 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-06-20 14:17 - 2017-05-20 19:30 - 00000000 ____D C:\Users\BrainWasheD 2017-06-20 13:05 - 2017-05-20 19:40 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\CrashDumps 2017-06-20 12:43 - 2017-05-20 19:28 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-06-20 10:50 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-06-20 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-06-18 22:37 - 2017-05-20 18:43 - 00000000 ___DC C:\WINDOWS\Panther 2017-06-18 22:37 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-06-18 21:56 - 2017-05-20 20:55 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\MicrosoftEdge 2017-06-18 13:12 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-06-17 01:09 - 2017-05-20 21:20 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-06-17 01:09 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-06-15 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-06-15 09:50 - 2017-05-20 19:35 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-06-15 09:49 - 2017-05-20 19:28 - 00386600 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-06-14 17:10 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-06-13 16:05 - 2017-05-20 19:35 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Packages 2017-06-07 11:02 - 2017-05-20 21:41 - 00000000 ____D C:\Users\BrainWasheD\Documents\Overwatch 2017-06-03 08:32 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-06-03 08:32 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-06-03 08:07 - 2017-05-20 21:08 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Adobe 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-05-23 10:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning 2017-05-22 01:42 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-05-22 01:24 - 2017-05-20 18:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-05-22 00:19 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-05-22 00:18 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-05-21 23:22 - 2017-05-20 19:44 - 00003236 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-21 23:16 - 2017-05-20 19:36 - 00000000 ___RD C:\Users\BrainWasheD\OneDrive 2017-05-21 21:25 - 2017-05-20 21:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\discord 2017-05-21 11:01 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-06-18 13:02 - 2017-06-18 13:02 - 0000053 _____ () C:\Users\BrainWasheD\AppData\Roaming\LogFile.txt 2017-05-20 21:19 - 2017-05-20 21:19 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-06-15 10:48 ==================== Ende von FRST.txt ============================ Geändert von BrainWasheD (20.06.2017 um 16:12 Uhr) |
20.06.2017, 17:51 | #8 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Addition: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (20-06-2017 17:14:08) Gestartet von C:\Users\BrainWasheD\Desktop Windows 10 Home Version 1703 (X64) (2017-05-20 17:35:03) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1290209912-1044598962-369420843-500 - Administrator - Disabled) BrainWasheD (S-1-5-21-1290209912-1044598962-369420843-1000 - Administrator - Enabled) => C:\Users\BrainWasheD DefaultAccount (S-1-5-21-1290209912-1044598962-369420843-503 - Limited - Disabled) Gast (S-1-5-21-1290209912-1044598962-369420843-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1290209912-1044598962-369420843-1002 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Ansel (Version: 382.05 - NVIDIA Corporation) Hidden Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.4.2294 - AVAST Software) Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform) Discord (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.) Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION) EPSON XP-630 Series Printer Uninstall (HKLM\...\EPSON XP-630 Series) (Version: - Seiko Epson Corporation) EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.53.0.0 - Seiko Epson Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.104 - Google Inc.) Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden Guild Wars 2 (HKLM\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games) League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden Logitech Gaming Software 8.92 (HKLM\...\Logitech Gaming Software) (Version: 8.92.67 - Logitech Inc.) Malwarebytes Version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 16.0.8229.2041 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) MyEpson Portal (x32 Version: 1.1.2.2 - SEIKO EPSON CORPORATION) Hidden Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.4.1 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation) NVIDIA GeForce Experience 3.6.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.6.0.74 - NVIDIA Corporation) NVIDIA Grafiktreiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation) NvNodejs (Version: 3.6.0.74 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.4.10.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.104.211.0 - Overwolf Ltd.) Overwolf.Setup.VC100CRTx64.Dist (HKLM\...\{EC9D5554-6852-4A55-81BB-AC02C7A8CFED}) (Version: 1.0.0 - Overwolf) Overwolf.Setup.VC100CRTx86.Dist (x32 Version: 1.0.0 - Overwolf) Hidden PLAYERUNKNOWN'S BATTLEGROUNDS (HKLM\...\Steam App 578080) (Version: - Bluehole, Inc.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.91.1119.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.) SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden SHIELD Streaming (Version: 7.1.0370 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.6.0.74 - NVIDIA Corporation) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\TeamSpeak 3 Client) (Version: 3.1.4 - TeamSpeak Systems GmbH) Twitch (HKLM-x32\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Twitch Interactive, Inc.) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0EA1CF12-4D4E-4351-94B7-84115E3AB914} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {18BD4184-9849-4FDB-9B2D-24D03803CE9D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {197019C0-A39E-4251-AA72-360935C4A061} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {1B4E6278-16D4-45A6-8BDE-8BAA2F57111A} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03] (NVIDIA Corporation) Task: {2A01F3FF-934C-4158-998B-12E9A8BA31B2} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-20] (AVAST Software) Task: {3BF8BA78-4AC9-4CB9-9335-A07B87708F74} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {420B7897-F154-4134-B3AE-149DECC6BAF7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {4D07E85B-84E3-41BF-B128-048A1B11ABD7} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {4D092839-43B2-4855-AB19-8D6325F14541} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {5832288D-E503-4966-AF8E-965743410F82} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5A7E1579-B6EB-4F42-9120-BC6031D5793C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5B4D641C-AF35-4B5B-8EDB-D191464EBBE8} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {61C6518D-C13B-4071-9836-2975C78C13FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd) Task: {6F7AC86E-5FFA-4710-9A38-0BE5F3CB4539} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {7270ECB5-AEA9-489F-BA3C-BC230228194A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {74D85C90-A46D-4914-B0DE-2B320BE872A4} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-05-03] (NVIDIA Corporation) Task: {7CA44C16-4C06-4287-B3F5-C92E3853D309} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-05-20] (AVAST Software) Task: {7E801DA2-CF04-4FED-BCA3-31CF6097C3C2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {7FB80D08-E1BE-4B3C-BDA4-6AA519217046} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {925B5788-1503-42EF-BA35-28AAED84F0DD} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {93A58816-DD3E-4BF6-9C17-F4D3BAC595AC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {95284773-EAF4-481E-B224-DB2BF54EDA8F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {957EF89D-E1CF-4C48-BEC4-14BB44D42D51} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {96F95AF5-1C8C-4718-A36B-24E45D8224B4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {9CC7B1AB-F5C2-46E8-AF00-3CA249EBFF9A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {A150F5A9-E5F0-4935-BD77-219558415C65} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A34D82D1-35D7-40D5-BFBD-1228C53033DF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A4D1A90D-EB59-4F32-94B7-FF32DB04EE43} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A664084A-B808-467F-AAE7-749AE16EAF62} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {A81ACE1F-61CB-4BC1-A7FA-8C924339B59A} - System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [2013-11-22] (SEIKO EPSON CORPORATION) Task: {B428955E-0F10-42B9-9BC2-C8E0D4A2E8CA} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {B74E1E8C-4791-48B9-AB80-C95F3E9408B5} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-06-06] (Overwolf LTD) Task: {BE535D16-1CEE-4C7F-B997-0936C38FD171} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {BFCFEED0-3A42-43DE-9DB8-3EB9C8A3436B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {C0E93ABF-6B28-43AF-9233-8C6C60788FCE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C2F94150-B72D-4E77-AF25-E4B46736A963} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {DE170156-FC9E-4655-9B93-0A1102B1FB76} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {E3B079A5-9C71-41C8-B6DF-3EF03C091D3E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-05-03] (NVIDIA Corporation) Task: {E413BE20-6FCF-4881-9CF1-2A7117D6ED3A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-17] (Microsoft Corporation) Task: {E8B61091-544C-404C-8B07-6E8782293A49} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F43B762F-7560-433A-B5B4-784D6E925E58} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-05-03] (NVIDIA Corporation) Task: {F848E963-1286-4D26-917B-4090052424C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {FCA81C28-8677-43F7-B312-4732D381BE28} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {FCC70481-09E8-4295-9EA9-2E5D1007F50D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE :/EXE:{61C1FF77-ABA5-4555-868B-77F3A3B348E5} /F:Update WORKGROUP\BRAINWASHED-PC$ ÄŠSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-05-20 19:44 - 2017-05-03 22:16 - 01267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-06-18 03:03 - 2017-05-25 14:11 - 02270664 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-03-08 04:42 - 2017-03-08 04:42 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2017-03-18 22:59 - 2017-03-20 06:36 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-06-08 11:14 - 2017-06-08 11:14 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2017-05-20 19:44 - 2017-05-03 22:15 - 00034240 _____ () C:\Program Files\NVIDIA Corporation\nvstreamsrv\boost_system-vc120-mt-1_58.dll 2017-05-20 19:44 - 2017-05-03 22:15 - 00920000 _____ () C:\Program Files\NVIDIA Corporation\nvstreamsrv\boost_regex-vc120-mt-1_58.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 01529320 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe 2017-05-20 19:44 - 2017-05-03 22:15 - 00018880 _____ () c:\program files\nvidia corporation\nvstreamsrv\detoured.dll 2017-06-18 22:38 - 2017-06-15 09:29 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libglesv2.dll 2017-06-18 22:38 - 2017-06-15 09:29 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libegl.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 01040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-05-20 18:23 - 2017-05-20 18:23 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-05-20 21:01 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\SDL2.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 04969248 _____ () D:\Program Files (x86)\Steam\v8.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 02485536 _____ () D:\Program Files (x86)\Steam\video.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01563936 _____ () D:\Program Files (x86)\Steam\icui18n.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01195296 _____ () D:\Program Files (x86)\Steam\icuuc.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 02549760 _____ () D:\Program Files (x86)\Steam\libavcodec-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00491008 _____ () D:\Program Files (x86)\Steam\libavformat-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00332800 _____ () D:\Program Files (x86)\Steam\libavresample-2.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00442880 _____ () D:\Program Files (x86)\Steam\libavutil-54.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00485888 _____ () D:\Program Files (x86)\Steam\libswscale-3.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00877856 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-05-20 19:44 - 2017-05-03 22:16 - 00018880 _____ () c:\program files (x86)\nvidia corporation\nvstreamsrv\detoured.dll 2017-05-20 21:01 - 2016-07-05 00:17 - 00266560 _____ () D:\Program Files (x86)\Steam\openvr_api.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\ffmpeg.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 01082880 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node 2017-05-20 21:01 - 2017-05-20 21:01 - 03750400 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 00914432 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node 2017-05-20 21:01 - 2017-05-20 21:01 - 01127424 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node 2017-05-20 19:44 - 2017-05-03 22:15 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libglesv2.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libegl.dll 2017-05-20 21:02 - 2017-05-08 21:45 - 69516064 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2017-06-08 14:55 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00385312 _____ () D:\Program Files (x86)\Steam\steam.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 00540336 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\ortp.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 55758824 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libcef.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 00133632 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libEGL.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 03384832 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libGLESv2.dll 2017-06-20 17:04 - 2017-06-20 17:04 - 00148992 _____ () \\?\C:\Users\BrainWasheD\AppData\Local\Temp\3C4.tmp.node 2017-05-20 21:01 - 2017-05-20 21:01 - 02658296 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node 2017-05-20 21:02 - 2017-05-20 21:02 - 02665976 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\sharepoint.com -> hxxps://uniduesseldorf-files.sharepoint.com ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2017-06-20 17:02 - 00000832 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 80.69.96.12 - 81.210.129.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run: => "Malwarebytes TrayApp" HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [TCP Query User{F05852CB-FC98-4B64-8AB0-3CCE7BD55022}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{A7CB0C50-42A6-41E1-8599-F3AFC5382948}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{FD301B80-A53F-4E10-9C9C-AD1668391E6E}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{53833F05-1347-4A1D-B298-03D20DEB4D9F}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{5370EBE1-96F9-47AD-9C2E-8749F2DA028A}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{F981958C-9BA8-44E8-9E22-8AC71C5A7E23}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{BE444A7B-766C-4FA6-89C6-86D1F4A62015}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{65DD080D-DD95-495D-966C-F927BB3BC001}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{369A23D4-5E2C-41D8-AAC3-DB8FA7CEE0F8}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{31C92797-7734-4228-89E5-C822CC9C4BC5}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (06/20/2017 01:05:39 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000006369f2 ID des fehlerhaften Prozesses: 0x220c Startzeit der fehlerhaften Anwendung: 0x01d2e9a1c3daf504 Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe Berichtskennung: 1e49e754-5401-4a40-b18a-2644aa57ab20 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/20/2017 10:49:43 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/20/2017 02:17:41 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/20/2017 02:17:22 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000006369f2 ID des fehlerhaften Prozesses: 0x6b4 Startzeit der fehlerhaften Anwendung: 0x01d2e93c547501e2 Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe Berichtskennung: dea542fd-77a0-4e1d-bdf8-dea9abaeaac8 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:51:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TDSSKiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x1ee8 Startzeit der fehlerhaften Anwendung: 0x01d2e93de51ee5dc Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\TDSSKiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 58632f18-ac33-4fed-a732-47b5a89de301 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:51:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TDSSKiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x1e30 Startzeit der fehlerhaften Anwendung: 0x01d2e93ddf3ca77b Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\TDSSKiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: f064a5b2-73c8-4ecf-ae3a-d8b8e2b21fa7 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:49:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x207c Startzeit der fehlerhaften Anwendung: 0x01d2e93d827fab03 Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\tdsskiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: a05921b1-33ad-4545-a408-0612385a22c4 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:48:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0xfd0 Startzeit der fehlerhaften Anwendung: 0x01d2e93d69d8837f Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\tdsskiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 42a9638f-a987-4350-8c8c-4b49c681857c Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:48:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x1a7c Startzeit der fehlerhaften Anwendung: 0x01d2e93d61c85b0d Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\tdsskiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 5a3f58a3-9068-4dbb-967a-5a2c24df6ae9 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 04:43:29 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Systemfehler: ============= Error: (06/20/2017 05:03:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "BitDefenderCOM" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (06/20/2017 05:03:35 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "HomeGroupListener" wurde mit dem folgenden dienstspezifischen Fehler beendet: %%2147944153 = In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar. Error: (06/20/2017 05:03:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (06/20/2017 05:02:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" ist vom Dienst "Windows Search" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden. Error: (06/20/2017 05:02:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden. Error: (06/20/2017 05:02:49 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: Die Anforderung wird nicht unterstützt. Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/20/2017 05:02:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/20/2017 05:02:19 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/20/2017 05:02:19 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/20/2017 05:02:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2017-06-18 22:36:46.693 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.372 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.197 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.659 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.652 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.252 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.244 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.324 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.317 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:58:02.048 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz Prozentuale Nutzung des RAM: 42% Installierter physikalischer RAM: 8173.24 MB Verfügbarer physikalischer RAM: 4714.5 MB Summe virtueller Speicher: 16877.24 MB Verfügbarer virtueller Speicher: 12942.14 MB ==================== Laufwerke ================================ Drive a: (Volume) (Fixed) (Total:223.57 GB) (Free:165.94 GB) NTFS Drive c: () (Fixed) (Total:111.25 GB) (Free:70.25 GB) NTFS Drive d: () (Fixed) (Total:488.06 GB) (Free:437.51 GB) NTFS Drive e: (Volume) (Fixed) (Total:443.23 GB) (Free:402.06 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 1E55C42B) Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: DBC5041D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 2 (Size: 931.5 GB) (Disk ID: C99F686A) Partition: GPT. ==================== Ende von Addition.txt ============================ Code:
ATTFilter Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (20-06-2017 17:14:18) Gestartet von C:\Users\BrainWasheD\Desktop Start-Modus: Normal ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C51411C0-11DB-AD74-0008-BDAB669A0C20}\SupportTasks\1\Guild Wars 2 Support Webseite.lnk -> hxxp://support.guildwars2.com Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C51411C0-11DB-AD74-0008-BDAB669A0C20}\SupportTasks\0\Guild Wars 2 Webseite.lnk -> hxxp://www.guildwars2.com Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\BrainWasheD\Documents () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\BrainWasheD\Downloads () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\BrainWasheD\Music () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\BrainWasheD\Pictures () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\BrainWasheD\Videos () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk -> Microsoft.Windows.Homegroup Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk -> Microsoft.Windows.Network Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\BrainWasheD () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}\SC_Reader.ico (Flexera Software LLC) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk -> C:\Program Files\AVAST Software\SZBrowser\launcher.exe (Avast Software) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk -> C:\Windows\MiracastView\MiracastView.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVE.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk -> C:\Windows\PrintDialog\PrintDialog.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\MSPUB.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft\World of Warcraft.lnk -> D:\Program Files (x86)\World of Warcraft\World of Warcraft Launcher.exe (Blizzard Entertainment) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Benutzerhandbuch für die Konsolenversion von RAR.lnk -> C:\Program Files\WinRAR\Rar.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Hilfe zu WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Was ist neu in dieser Version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk -> C:\Program Files (x86)\VideoLAN\VLC\Documentation.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk -> C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk -> C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT\UseNeXT.lnk -> D:\Program Files (x86)\UseNeXT\UseNeXT.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> D:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch\Overwatch.lnk -> A:\Program Files (x86)\Overwatch\Overwatch Launcher.exe (Blizzard Entertainment) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe (NVIDIA Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Notepad++.lnk -> C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools\Aufzeichnungs-Manager von Skype for Business.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools\Office 2016-Spracheinstellungen.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools\Telemetriedashboard für Office 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\msotd.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools\Telemetrieprotokoll für Office 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Uninstall Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech\Logitech Gaming Software 8.92.lnk -> C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends\League of Legends.lnk -> D:\Riot Games\League of Legends\LeagueClient.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm\Heroes of the Storm.lnk -> A:\Program Files (x86)\Heroes of the Storm\Heroes of the Storm.exe (Blizzard Entertainment) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2\Guild Wars 2.lnk -> A:\Program Files (x86)\Guild Wars 2\Gw2-64.exe (ArenaNet) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software\Event Manager.lnk -> C:\Program Files (x86)\EPSON Software\Event Manager\EProjManager.exe (SEIKO EPSON CORPORATION) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON\EPSON Scan\EPSON Scan-Einstellungen.lnk -> C:\Windows\twain_32\escndv\escfg.exe (SEIKO EPSON CORP.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON\EPSON Scan\EPSON Scan.lnk -> C:\Windows\twain_32\escndv\escndv.exe (SEIKO EPSON CORP.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blizzard App\Blizzard App.lnk -> D:\Program Files (x86)\Blizzard App\Battle.net Launcher.exe (Blizzard Entertainment) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software\Avast Free Antivirus.lnk -> C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk -> C:\Windows\System32\quickassist.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C51411C0-11DB-AD74-0008-BDAB669A0C20}\PlayTasks\0\Play.lnk -> A:\Program Files (x86)\Guild Wars 2\Gw2-64.exe (ArenaNet) Shortcut: C:\Users\BrainWasheD\Links\Desktop.lnk -> C:\Users\BrainWasheD\Desktop () Shortcut: C:\Users\BrainWasheD\Links\Downloads.lnk -> C:\Users\BrainWasheD\Downloads () Shortcut: C:\Users\BrainWasheD\Links\RecentPlaces.lnk -> [::{22877A6D-37A1-461A-91B0-DBDA5AAEBC99}] Shortcut: C:\Users\BrainWasheD\Documents\Heroes of the Storm\T_41205923_415@2.lnk -> C:\Users\BrainWasheD\Documents\Heroes of the Storm\Accounts\1288076\2-Hero-1-677619 () Shortcut: C:\Users\BrainWasheD\Desktop\Musik.lnk -> E:\Musik () Shortcut: C:\Users\BrainWasheD\Desktop\TeamSpeak 3 Client.lnk -> C:\Users\BrainWasheD\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe (TeamSpeak Systems GmbH) Shortcut: C:\Users\BrainWasheD\Desktop\UseNeXT by Tangysoft.lnk -> D:\Program Files (x86)\UseNeXT\UseNeXT.exe () Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk -> C:\Users\BrainWasheD\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe (TeamSpeak Systems GmbH) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk -> C:\Users\BrainWasheD\AppData\Roaming\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc.) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Benutzerhandbuch für die Konsolenversion von RAR.lnk -> C:\Program Files\WinRAR\Rar.txt () Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Hilfe zu WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Was ist neu in dieser Version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt () Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf\Overwolf.lnk -> C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe () Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf\Uninstall Overwolf.lnk -> C:\Program Files (x86)\Overwolf\OWUninstaller.exe (Overwolf Ltd.) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth-Dateiübertragung.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd) Shortcut: C:\Users\Public\Desktop\EPSON Scan.lnk -> C:\Windows\twain_32\escndv\escndv.exe (SEIKO EPSON CORP.) Shortcut: C:\Users\Public\Desktop\Guild Wars 2.lnk -> A:\Program Files (x86)\Guild Wars 2\Gw2-64.exe (ArenaNet) Shortcut: C:\Users\Public\Desktop\League of Legends.lnk -> D:\Riot Games\League of Legends\LeagueClient.exe () Shortcut: C:\Users\Public\Desktop\Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes) Shortcut: C:\Users\Public\Desktop\Overwolf.lnk -> C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe () ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) -> --reset-config --reset-plugins-cache vlc://quit ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) -> -Iskins ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /show ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools\Database Compare 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\DCF\DATABASECOMPARE.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools\Office 2016 Upload Center.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\MSOUC.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools\Spreadsheet Compare 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\DCF\SPREADSHEETCOMPARE.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software\EPSON Software Updater.lnk -> C:\Program Files (x86)\EPSON Software\Download Navigator\EPSDNAVI.EXE (Seiko Epson Corporation) -> /ST ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software\EPSON-Handbücher.lnk -> C:\Program Files (x86)\Epson Software\Epson Manual\Launcher\EPSMLAN.EXE (Seiko Epson Corporation) -> /LA "DE" /FR "STARTMENU" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON\MyEpson Portal.lnk -> C:\Program Files (x86)\epson\MyEpson Portal\mep.exe (Seiko Epson Corporation) -> /S ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asmedia Technology\ASM104x USB 3.0 Driver\Uninstall.lnk -> C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) -> /x {E4FB0B39-C991-4EE7-95DD-1A1A7857D33D} ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\Users\BrainWasheD\Desktop\Discord.lnk -> C:\Users\BrainWasheD\AppData\Local\Discord\Update.exe (GitHub) -> --processStart Discord.exe ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc\Discord.lnk -> C:\Users\BrainWasheD\AppData\Local\Discord\Update.exe (GitHub) -> --processStart Discord.exe ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\BrainWasheD\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.url -> URL: hxxp://support.steampowered.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2\Guild Wars 2 Support Webseite.url -> URL: hxxp://support.guildwars2.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2\Guild Wars 2 Webseite.url -> URL: hxxp://www.guildwars2.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON\EpsonLink\Epson Connect Site.url -> URL: hxxps://www.epsonconnect.com/?p=0 InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> URL: hxxp://www.piriform.com/ccleaner InternetURL: C:\Users\BrainWasheD\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\BrainWasheD\Favorites\Windows Live\Windows Live Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=70742 InternetURL: C:\Users\BrainWasheD\Favorites\Windows Live\Windows Live Ideas.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72700 InternetURL: C:\Users\BrainWasheD\Favorites\Windows Live\Windows Live Mail.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72681 InternetURL: C:\Users\BrainWasheD\Favorites\Windows Live\Windows Live Spaces.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72682 InternetURL: C:\Users\BrainWasheD\Favorites\MSN-Websites\MSN Auto.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72680 InternetURL: C:\Users\BrainWasheD\Favorites\MSN-Websites\MSN Fernsehen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72659 InternetURL: C:\Users\BrainWasheD\Favorites\MSN-Websites\MSN Money.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72640 InternetURL: C:\Users\BrainWasheD\Favorites\MSN-Websites\MSN Nachrichten.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72636 InternetURL: C:\Users\BrainWasheD\Favorites\MSN-Websites\MSN Sport.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72635 InternetURL: C:\Users\BrainWasheD\Favorites\MSN-Websites\MSN.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72630 InternetURL: C:\Users\BrainWasheD\Favorites\Microsoft-Websites\IE-Site auf Microsoft.com.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72186 InternetURL: C:\Users\BrainWasheD\Favorites\Microsoft-Websites\Microsoft Deutschland GmbH.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72520 InternetURL: C:\Users\BrainWasheD\Favorites\Microsoft-Websites\Microsoft Store.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=140813 InternetURL: C:\Users\BrainWasheD\Favorites\Microsoft-Websites\Microsoft Windows - Start.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72629 InternetURL: C:\Users\BrainWasheD\Favorites\Microsoft-Websites\Microsoft zu Hause.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72406 InternetURL: C:\Users\BrainWasheD\Favorites\Microsoft-Websites\Microsoft.com durchsuchen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72893 InternetURL: C:\Users\BrainWasheD\Favorites\Microsoft-Websites\Site für IE Add-Ons.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893 InternetURL: C:\Users\BrainWasheD\Favorites\Links\Vorgeschlagene Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice InternetURL: C:\Users\BrainWasheD\Favorites\Links\Web Slice-Katalog.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315 ==================== Ende vom Shortcut.txt ============================= |
20.06.2017, 20:21 | #9 |
/// TB-Ausbilder | New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Servus, Schritt 1
Schritt 2 Bitte setze deine Brower wie folgt zurück: IE ::: Setze folgendermassen den Internet Explorer zurück:
EDGE ::: Edge zurücksetzen FF ::: Firefox zurücksetzen CHR::: Chrome zurücksetzen OPR:: Opera zurücksetzen Schritt 3
Bitte poste mit deiner nächsten Antwort
|
20.06.2017, 22:23 | #10 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Huhu, ich habe einmal ausversehen FRST Entfernen ohne den Codeblock ausgeführt, da genau in dem Moment als ich STRG+V gedrückt habe, der Fokus weg ging. Habe danach das Programm nochmal mit deinem Code ausgeführt. Hoffe dass das nicht all zu schlimm ist, aber wollte es erwähnt haben. Fixlog: Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (20-06-2017 23:08:24) Run:2 Gestartet von C:\Users\BrainWasheD\Desktop Geladene Profile: BrainWasheD (Verfügbare Profile: BrainWasheD) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** CloseProcesses: FF Homepage: Mozilla\Firefox\Profiles\mguelu0x.default -> Fa HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <====== ACHTUNG C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*hosted.*.* Hosts: RemoveProxy: CMD: ipconfig /flushdns CMD: netsh winsock reset EmptyTemp: ***************** Prozesse erfolgreich geschlossen. FF Homepage: Mozilla\Firefox\Profiles\mguelu0x.default -> Fa => nicht gefunden HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <====== ACHTUNG => erfolgreich wiederhergestellt =========== "C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*hosted.*.*" ========== nicht gefunden ========= Ende -> "C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*hosted.*.*" ======== C:\Windows\System32\Drivers\etc\hosts => erfolgreich verschoben Hosts erfolgreich wiederhergestellt. ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt HKU\S-1-5-21-1290209912-1044598962-369420843-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt HKU\S-1-5-21-1290209912-1044598962-369420843-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt ========= Ende von RemoveProxy: ========= ========= ipconfig /flushdns ========= Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. ========= Ende von CMD: ========= ========= netsh winsock reset ========= Der Winsock-Katalog wurde zurckgesetzt. Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen. ========= Ende von CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 9461760 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 7596174 B Java, Flash, Steam htmlcache => 138240 B Windows/system/drivers => 10558 B Edge => 0 B Chrome => 11618196 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 0 B LocalService => 818 B NetworkService => 0 B BrainWasheD => 256014 B RecycleBin => 0 B EmptyTemp: => 27.7 MB temporäre Dateien entfernt. ================================ Das System musste neu gestartet werden. ==== Ende von Fixlog 23:08:29 ==== FRST: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (Administrator) auf BRAINWASHED-PC (20-06-2017 23:14:57) Gestartet von C:\Users\BrainWasheD\Desktop Geladene Profile: BrainWasheD (Verfügbare Profile: BrainWasheD) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.5676\Agent.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamuseragent.exe (Blizzard Entertainment) D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-20] (AVAST Software) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17494136 2017-04-06] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Discord] => C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Battle.net] => D:\Program Files (x86)\Blizzard App\Battle.net Launcher.exe [3229160 2017-05-20] (Blizzard Entertainment) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9803992 2017-06-13] (Piriform Ltd) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-20] (AVAST Software) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 80.69.96.12 81.210.129.4 Tcpip\..\Interfaces\{00f4a4f9-90c8-4abb-b592-61cb1208f787}: [DhcpNameServer] 80.69.96.12 81.210.129.4 Internet Explorer: ================== BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-05-20] (AVAST Software) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-20] (AVAST Software) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: mguelu0x.default FF ProfilePath: C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default [2017-06-20] FF Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\sp@avast.com.xpi [2017-06-18] FF Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\wrc@avast.com.xpi [2017-06-18] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.de/ CHR StartupUrls: Default -> "hxxp://www.facebook.com/","hxxp://www.mmo-champion.com/content/","hxxp://www.google.de/","hxxp://www.youtube.com/" CHR Profile: C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default [2017-06-20] CHR Extension: (Google Präsentationen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-20] CHR Extension: (Google Docs) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-20] CHR Extension: (Google Drive) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-20] CHR Extension: (YouTube) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-20] CHR Extension: (Adblock Plus) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-06-20] CHR Extension: (Legacy MindMup (discontinued)) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnenaecjcgeppfpaokiifokeieopppej [2017-06-20] CHR Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-06-20] CHR Extension: (Google Tabellen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-20] CHR Extension: (Google Docs Offline) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-20] CHR Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-20] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-20] CHR Extension: (Google Mail) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-20] CHR Extension: (Chrome Media Router) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-20] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7346208 2017-05-20] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-20] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1522184 2017-05-20] () R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4412616 2017-06-09] (Microsoft Corporation) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation) R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON CORPORATION) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [225400 2017-04-06] (Logitech Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [819672 2017-06-05] (Seiko Epson Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) R3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-05-03] (NVIDIA Corporation) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1326408 2017-06-06] (Overwolf LTD) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) S2 BitDefenderCOM; "C:\Program Files\BDServices\BitDefenderCom.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [311808 2017-05-20] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [190256 2017-05-20] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334576 2017-05-20] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [49016 2017-05-20] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-05-20] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32600 2017-05-20] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [128648 2017-05-20] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [101152 2017-05-20] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-05-20] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1007160 2017-05-20] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [569192 2017-05-20] (AVAST Software) R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [158880 2017-05-20] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [339696 2017-05-20] (AVAST Software) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-05-25] () R3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [54552 2017-04-06] (Logitech Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2017-04-06] (Logitech Inc.) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188312 2017-06-20] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [113592 2017-06-20] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [44960 2017-06-20] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [252832 2017-06-20] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-06-20] (Malwarebytes) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys [14456944 2017-05-02] (NVIDIA Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-05-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-05-03] (NVIDIA Corporation) R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59448 2017-05-02] (NVIDIA Corporation) U5 PROCMON23; C:\Windows\System32\Drivers\PROCMON23.sys [84960 2017-05-22] (Sysinternals - www.sysinternals.com) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [898296 2016-01-13] (Realtek ) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 Trufos; C:\WINDOWS\System32\DRIVERS\Trufos.sys [442848 2017-05-05] (BitDefender S.R.L.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) U3 idsvc; kein ImagePath U3 wpcsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-20 23:14 - 2017-06-20 23:15 - 00020315 _____ C:\Users\BrainWasheD\Desktop\FRST.txt 2017-06-20 23:05 - 2017-06-20 23:08 - 00002988 _____ C:\Users\BrainWasheD\Desktop\Fixlog1.txt 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\.mono 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\Users\BrainWasheD\AppData\LocalLow\Blizzard Entertainment 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Blizzard 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\ProgramData\.mono 2017-06-20 17:46 - 2017-06-20 17:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2017-06-20 17:45 - 2017-06-20 18:03 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\HearthstoneDeckTracker 2017-06-20 17:45 - 2017-06-20 17:45 - 00002641 _____ C:\Users\BrainWasheD\Desktop\Hearthstone Deck Tracker.lnk 2017-06-20 17:45 - 2017-06-20 17:45 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HearthSim 2017-06-20 17:45 - 2017-06-20 17:45 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\HearthstoneDeckTracker 2017-06-20 17:44 - 2017-06-20 17:44 - 22687008 _____ (HearthSim) C:\Users\BrainWasheD\Downloads\HDT-Installer.exe 2017-06-20 17:12 - 2017-06-20 17:12 - 00001393 _____ C:\Users\BrainWasheD\Desktop\mbam.txt 2017-06-20 16:58 - 2017-06-20 16:58 - 04110280 _____ C:\Users\BrainWasheD\Downloads\adwcleaner_6.047.exe 2017-06-20 16:58 - 2017-06-20 16:58 - 04110280 _____ C:\Users\BrainWasheD\Desktop\adwcleaner_6.047.exe 2017-06-20 02:17 - 2017-06-20 12:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\vlc 2017-06-20 02:17 - 2017-06-20 02:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-06-20 02:17 - 2017-06-20 02:17 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-06-20 02:16 - 2017-06-20 02:16 - 30950664 _____ C:\Users\BrainWasheD\Downloads\vlc-2.2.6-win32.exe 2017-06-19 23:00 - 2017-06-19 23:01 - 00066692 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_23.00.31_log.txt 2017-06-19 23:00 - 2017-06-19 23:00 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\55876282.sys 2017-06-19 22:52 - 2017-06-19 22:56 - 00068040 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_22.52.10_log.txt 2017-06-19 22:52 - 2017-06-19 22:52 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\55192664.sys 2017-06-19 22:51 - 2017-06-19 22:51 - 04830473 _____ C:\Users\BrainWasheD\Downloads\tdsskiller (1).zip 2017-06-19 22:51 - 2017-06-19 22:51 - 02213976 _____ (Kaspersky Lab ZAO) C:\Users\BrainWasheD\Desktop\tdsskiller.exe 2017-06-19 22:51 - 2017-06-19 22:51 - 00000354 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_22.51.12_log.txt 2017-06-19 22:46 - 2017-06-20 23:14 - 00000000 ____D C:\FRST 2017-06-19 22:46 - 2017-06-19 22:46 - 02439680 _____ (Farbar) C:\Users\BrainWasheD\Desktop\FRST64.exe 2017-06-19 13:49 - 2017-06-19 13:49 - 09836385 _____ C:\Users\BrainWasheD\Downloads\01_Studi.pdf 2017-06-19 01:23 - 2017-06-19 01:23 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\85203316.sys 2017-06-19 01:23 - 2017-06-19 01:23 - 00064778 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.23.11_log.txt 2017-06-19 01:22 - 2017-06-19 01:22 - 04830473 _____ C:\Users\BrainWasheD\Downloads\tdsskiller.zip 2017-06-19 01:22 - 2017-06-19 01:22 - 00000356 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.22.26_log.txt 2017-06-19 00:31 - 2017-06-19 00:31 - 00000000 ____D C:\ProgramData\Emsisoft 2017-06-19 00:30 - 2017-06-19 00:32 - 00000000 ____D C:\EEK 2017-06-18 23:28 - 2017-06-20 17:02 - 00000000 ____D C:\AdwCleaner 2017-06-18 22:39 - 2017-06-18 22:39 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Google 2017-06-18 22:38 - 2017-06-18 22:38 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-06-18 22:38 - 2017-06-18 22:38 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-06-18 22:38 - 2017-06-18 22:38 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-06-18 21:20 - 2017-06-18 22:35 - 00000000 ____D C:\Program Files\CCleaner 2017-06-18 21:20 - 2017-06-18 21:20 - 00002880 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2017-06-18 21:20 - 2017-06-18 21:20 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-06-18 21:20 - 2017-06-18 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-06-18 21:19 - 2017-06-18 22:47 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Google 2017-06-18 21:19 - 2017-06-18 22:38 - 00000000 ____D C:\Program Files (x86)\Google 2017-06-18 21:18 - 2017-06-18 21:52 - 00000000 ____D C:\Users\BrainWasheD\AppData\LocalLow\Mozilla 2017-06-18 21:18 - 2017-06-18 21:41 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Mozilla 2017-06-18 21:18 - 2017-06-18 21:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Mozilla 2017-06-18 21:03 - 2017-06-18 21:03 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\7BA52E92.sys 2017-06-18 15:45 - 2017-06-19 01:22 - 02213976 _____ (Kaspersky Lab ZAO) C:\Users\BrainWasheD\Downloads\tdsskiller.exe 2017-06-18 15:43 - 2017-06-18 15:46 - 00000000 ____D C:\ProgramData\HitmanPro 2017-06-18 13:31 - 2017-06-18 21:54 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Deployment 2017-06-18 13:31 - 2017-06-18 13:31 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Macromedia 2017-06-18 13:21 - 2017-06-18 13:21 - 00001173 _____ C:\Users\BrainWasheD\Desktop\JRT.txt 2017-06-18 12:52 - 2017-06-18 13:00 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-06-18 12:51 - 2017-06-18 13:00 - 00000000 ____D C:\Users\BrainWasheD\Desktop\mbar 2017-06-18 03:03 - 2017-06-20 23:09 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-06-18 03:03 - 2017-06-20 23:09 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-06-18 03:03 - 2017-06-20 23:09 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-06-18 03:03 - 2017-06-20 23:09 - 00044960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-06-18 03:03 - 2017-06-20 10:47 - 00188312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-06-18 03:03 - 2017-06-18 12:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\Program Files\Malwarebytes 2017-06-18 03:03 - 2017-05-25 11:58 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-06-17 23:13 - 2017-06-17 23:13 - 00000000 ____D C:\Program Files (x86)\Notepad++ 2017-06-17 21:04 - 2017-06-17 21:04 - 00000000 ____D C:\Users\BrainWasheD\Documents\League of Legends 2017-06-17 21:03 - 2017-06-17 21:04 - 00000863 _____ C:\Users\Public\Desktop\League of Legends.lnk 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Riot Games 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2017-06-17 21:03 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2017-06-17 21:02 - 2017-06-17 21:03 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Riot Games 2017-06-15 10:19 - 2017-06-15 10:19 - 00000713 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk 2017-06-15 10:19 - 2017-06-15 10:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2 2017-06-15 10:17 - 2017-06-15 10:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Guild Wars 2 2017-06-15 09:57 - 2017-06-15 09:57 - 00061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys 2017-06-14 17:08 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-06-14 17:08 - 2017-06-03 11:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-06-14 17:08 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-06-14 17:08 - 2017-06-03 11:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2017-06-14 17:08 - 2017-06-03 11:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-06-14 17:08 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2017-06-14 17:08 - 2017-06-03 11:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-06-14 17:08 - 2017-06-03 11:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-06-14 17:08 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-06-14 17:08 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-06-14 17:08 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2017-06-14 17:08 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2017-06-14 17:08 - 2017-06-03 10:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-06-14 17:08 - 2017-06-03 10:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-06-14 17:08 - 2017-06-03 10:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-06-14 17:08 - 2017-06-03 10:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2017-06-14 17:07 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2017-06-14 17:07 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2017-06-14 17:07 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2017-06-14 17:07 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2017-06-14 17:07 - 2017-06-03 11:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2017-06-14 17:07 - 2017-06-03 11:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2017-06-14 17:07 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2017-06-14 17:07 - 2017-06-03 11:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-06-14 17:07 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-06-14 17:07 - 2017-06-03 11:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-06-14 17:07 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2017-06-14 17:07 - 2017-06-03 11:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2017-06-14 17:07 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2017-06-14 17:07 - 2017-06-03 11:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-06-14 17:07 - 2017-06-03 11:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2017-06-14 17:07 - 2017-06-03 11:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-06-14 17:07 - 2017-06-03 10:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-06-14 17:07 - 2017-06-03 10:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-06-14 17:07 - 2017-06-03 10:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-06-14 17:06 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-06-14 17:06 - 2017-06-03 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-06-14 17:06 - 2017-06-03 12:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-06-14 17:06 - 2017-06-03 12:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-06-14 17:06 - 2017-06-03 12:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2017-06-14 17:06 - 2017-06-03 12:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-06-14 17:06 - 2017-06-03 12:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-06-14 17:06 - 2017-06-03 12:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-06-14 17:06 - 2017-06-03 11:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-06-14 17:06 - 2017-06-03 11:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-06-14 17:06 - 2017-06-03 11:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-06-14 17:06 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-06-14 17:06 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-06-14 17:06 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe 2017-06-14 17:06 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:06 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe 2017-06-14 17:06 - 2017-06-03 11:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-06-14 17:06 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-06-14 17:06 - 2017-06-03 11:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2017-06-14 17:06 - 2017-06-03 10:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-06-14 17:06 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe 2017-06-06 18:03 - 2017-06-20 23:09 - 00012800 ___SH C:\Users\BrainWasheD\Desktop\Thumbs.db 2017-06-03 08:08 - 2017-06-20 12:21 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000819 _____ C:\Users\BrainWasheD\Desktop\UseNeXT by Tangysoft.lnk 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\Users\BrainWasheD\Documents\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT 2017-06-03 08:05 - 2017-06-06 18:58 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-06-03 08:05 - 2017-06-03 16:08 - 00000000 ____D C:\ProgramData\Adobe 2017-06-03 08:05 - 2017-06-03 08:05 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-06-03 08:05 - 2017-06-03 08:05 - 00000000 ____D C:\Program Files (x86)\Adobe 2017-05-30 16:35 - 2017-05-30 16:35 - 00000000 ____D C:\Users\BrainWasheD\Documents\Benutzerdefinierte Office-Vorlagen 2017-05-29 12:51 - 2017-05-20 11:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-05-29 12:51 - 2017-05-20 10:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 10:48 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-05-29 12:51 - 2017-05-20 10:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 10:45 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 10:24 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2017-05-29 12:51 - 2017-05-20 10:23 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 10:20 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 10:19 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 10:18 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 10:17 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 10:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2017-05-29 12:51 - 2017-05-20 10:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-05-29 12:51 - 2017-05-20 09:07 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2017-05-29 12:51 - 2017-05-20 09:03 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 08:59 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2017-05-29 12:51 - 2017-05-20 08:58 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 04847928 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-05-29 12:51 - 2017-05-20 08:56 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-05-29 12:51 - 2017-05-20 08:55 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-05-29 12:51 - 2017-05-20 08:54 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00335808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2017-05-29 12:51 - 2017-05-20 08:53 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 06551856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01219560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 00406064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 08:48 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys 2017-05-29 12:51 - 2017-05-20 08:09 - 17365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll 2017-05-29 12:51 - 2017-05-20 08:07 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe 2017-05-29 12:51 - 2017-05-20 08:06 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 08:00 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 07:57 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-05-29 12:51 - 2017-05-20 07:56 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe 2017-05-29 12:51 - 2017-05-20 07:56 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04537344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll 2017-05-25 17:23 - 2017-05-25 17:23 - 00001150 _____ C:\Users\Public\Desktop\Overwolf.lnk 2017-05-25 17:23 - 2017-05-25 17:23 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\NVIDIA 2017-05-25 17:22 - 2017-06-13 17:22 - 00000000 ____D C:\Program Files (x86)\Overwolf 2017-05-25 17:22 - 2017-06-02 12:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\TS3Client 2017-05-25 17:22 - 2017-06-02 08:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Overwolf 2017-05-25 17:22 - 2017-05-25 17:24 - 00000000 ____D C:\ProgramData\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00004382 _____ C:\WINDOWS\System32\Tasks\Overwolf Updater Task 2017-05-25 17:22 - 2017-05-25 17:22 - 00001342 _____ C:\Users\BrainWasheD\Desktop\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00001300 _____ C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\TeamSpeak 3 Client 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.TeamSpeak 3 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.QtWebEngineProcess 2017-05-23 10:31 - 2017-06-18 22:37 - 00000000 ____D C:\WINDOWS\Minidump 2017-05-22 01:31 - 2017-06-20 17:19 - 00004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{08FEE1D4-25C0-4D3B-B4B9-6E4636D53EB8} 2017-05-22 01:25 - 2017-05-22 01:25 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Epson 2017-05-22 01:21 - 2017-05-22 12:07 - 00000949 _____ C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job 2017-05-22 01:21 - 2017-05-22 01:21 - 00004146 _____ C:\WINDOWS\System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} 2017-05-22 01:21 - 2017-05-22 01:21 - 00000000 ____D C:\Program Files\Common Files\EPSON 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\Program Files (x86)\EPSON Software 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\Program Files (x86)\epson 2017-05-22 01:15 - 2017-05-22 01:15 - 00001003 _____ C:\Users\Public\Desktop\EPSON Scan.lnk 2017-05-22 01:15 - 2014-06-03 00:00 - 00472064 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\esxw2ud.dll 2017-05-22 01:15 - 2014-03-05 04:06 - 00180224 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YLMBPLE.DLL 2017-05-22 01:15 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc64.exe 2017-05-22 01:15 - 2011-03-15 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YD4BPLE.DLL 2017-05-22 01:14 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Epson 2017-05-21 23:13 - 2017-05-22 15:29 - 00084960 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON23.SYS 2017-05-21 22:47 - 2017-06-14 17:12 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-05-21 22:47 - 2017-06-14 17:10 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-05-21 22:47 - 2017-04-28 03:19 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2017-05-21 22:47 - 2017-04-28 03:16 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2017-05-21 22:47 - 2017-04-28 03:11 - 02158544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2017-05-21 22:47 - 2017-04-28 03:09 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2017-05-21 22:47 - 2017-04-28 03:08 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-05-21 22:47 - 2017-04-28 03:08 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2017-05-21 22:47 - 2017-04-28 03:07 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-05-21 22:47 - 2017-04-28 03:06 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2017-05-21 22:47 - 2017-04-28 03:03 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2017-05-21 22:47 - 2017-04-28 02:59 - 02635336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2017-05-21 22:47 - 2017-04-28 02:59 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2017-05-21 22:47 - 2017-04-28 02:58 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2017-05-21 22:47 - 2017-04-28 02:57 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2017-05-21 22:47 - 2017-04-28 02:55 - 01325456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-05-21 22:47 - 2017-04-28 02:52 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2017-05-21 22:47 - 2017-04-28 02:40 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2017-05-21 22:47 - 2017-04-28 02:37 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-05-21 22:47 - 2017-04-28 02:15 - 01051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2017-05-21 22:47 - 2017-04-28 02:06 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll 2017-05-21 22:47 - 2017-04-28 02:03 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2017-05-21 22:47 - 2017-04-28 02:03 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2017-05-21 22:47 - 2017-04-28 01:59 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-05-21 22:47 - 2017-04-28 01:58 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2017-05-21 22:47 - 2017-04-28 01:57 - 01803264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-05-21 22:47 - 2017-04-28 01:54 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2017-05-21 22:47 - 2017-04-28 01:54 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2017-05-21 22:47 - 2017-04-28 01:54 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2017-05-21 22:47 - 2017-04-19 09:06 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2017-05-21 22:47 - 2017-04-19 09:04 - 00142240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys 2017-05-21 22:47 - 2017-04-19 09:02 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2017-05-21 22:47 - 2017-04-19 08:18 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys 2017-05-21 22:47 - 2017-04-19 08:15 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2017-05-21 22:47 - 2017-04-19 08:14 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll 2017-05-21 22:47 - 2017-04-19 08:12 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll 2017-05-21 22:47 - 2017-04-19 08:11 - 04446208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll 2017-05-21 22:47 - 2017-04-19 08:10 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2017-05-21 22:47 - 2017-04-19 08:07 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2017-05-21 22:47 - 2017-04-19 08:07 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2017-05-21 22:47 - 2017-04-19 08:02 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2017-05-21 22:47 - 2017-04-19 07:59 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2017-05-21 22:47 - 2017-04-19 07:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2017-05-21 22:47 - 2017-04-19 07:32 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2017-05-21 22:47 - 2017-04-14 02:35 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2017-05-21 22:47 - 2017-04-14 02:33 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2017-05-21 22:47 - 2017-04-14 02:32 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll 2017-05-21 22:47 - 2017-04-14 02:30 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll 2017-05-21 22:47 - 2017-04-14 01:40 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll 2017-05-21 22:47 - 2017-04-14 01:39 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe 2017-05-21 22:47 - 2017-04-14 01:39 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll 2017-05-21 22:47 - 2017-04-14 01:39 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2017-05-21 22:47 - 2017-04-14 01:38 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll 2017-05-21 22:47 - 2017-04-14 01:37 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe 2017-05-21 22:47 - 2017-04-14 01:37 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2017-05-21 22:47 - 2017-04-14 01:37 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-05-21 22:47 - 2017-04-14 01:36 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll 2017-05-21 22:47 - 2017-04-14 01:35 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2017-05-21 22:47 - 2017-04-14 01:35 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2017-05-21 22:47 - 2017-04-14 01:33 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2017-05-21 22:47 - 2017-04-14 01:33 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2017-05-21 22:47 - 2017-04-14 01:31 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll 2017-05-21 22:47 - 2017-04-14 01:31 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 01295872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2017-05-21 22:47 - 2017-04-14 01:29 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2017-05-21 22:47 - 2017-04-14 01:28 - 02443776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-05-21 22:47 - 2017-04-14 01:26 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2017-05-21 22:47 - 2017-04-14 01:24 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll 2017-05-21 22:47 - 2017-04-14 01:21 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll 2017-05-21 22:47 - 2017-04-14 01:18 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe 2017-05-21 22:47 - 2017-04-14 01:15 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2017-05-21 22:47 - 2017-04-14 01:08 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2017-05-21 22:47 - 2017-04-14 01:04 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2017-05-21 22:47 - 2017-04-14 01:01 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll 2017-05-21 22:47 - 2017-04-01 02:52 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-05-21 22:47 - 2017-04-01 02:51 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-05-21 22:47 - 2017-04-01 02:29 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-05-21 22:47 - 2017-04-01 02:28 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2017-05-21 22:47 - 2017-04-01 02:04 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2017-05-21 22:47 - 2017-04-01 01:58 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll 2017-05-21 22:47 - 2017-04-01 01:58 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2017-05-21 22:47 - 2017-04-01 01:50 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2017-05-21 22:46 - 2017-04-28 02:59 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe 2017-05-21 22:46 - 2017-04-28 02:49 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2017-05-21 22:46 - 2017-04-28 02:46 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2017-05-21 22:46 - 2017-04-28 02:46 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2017-05-21 22:46 - 2017-04-28 02:45 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2017-05-21 22:46 - 2017-04-28 02:44 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2017-05-21 22:46 - 2017-04-28 02:44 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2017-05-21 22:46 - 2017-04-28 02:42 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2017-05-21 22:46 - 2017-04-28 02:40 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2017-05-21 22:46 - 2017-04-28 02:39 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-05-21 22:46 - 2017-04-28 02:34 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe 2017-05-21 22:46 - 2017-04-28 02:11 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2017-05-21 22:46 - 2017-04-28 02:09 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2017-05-21 22:46 - 2017-04-28 02:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2017-05-21 22:46 - 2017-04-28 02:07 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2017-05-21 22:46 - 2017-04-28 02:06 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2017-05-21 22:46 - 2017-04-28 02:06 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2017-05-21 22:46 - 2017-04-28 02:05 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-05-21 22:46 - 2017-04-28 02:04 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2017-05-21 22:46 - 2017-04-28 02:01 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2017-05-21 22:46 - 2017-04-28 01:54 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe 2017-05-21 22:46 - 2017-04-28 01:52 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll 2017-05-21 22:46 - 2017-04-19 08:16 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2017-05-21 22:46 - 2017-04-19 08:01 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll 2017-05-21 22:46 - 2017-04-19 07:37 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2017-05-21 22:46 - 2017-04-14 02:35 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll 2017-05-21 22:46 - 2017-04-14 01:43 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll 2017-05-21 22:46 - 2017-04-14 01:41 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2017-05-21 22:46 - 2017-04-14 01:38 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll 2017-05-21 22:46 - 2017-04-14 01:37 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2017-05-21 22:46 - 2017-04-14 01:36 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll 2017-05-21 22:46 - 2017-04-14 01:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2017-05-21 22:46 - 2017-04-14 01:34 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll 2017-05-21 22:46 - 2017-04-14 01:25 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2017-05-21 22:46 - 2017-04-14 01:15 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll 2017-05-21 22:46 - 2017-04-14 01:13 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll 2017-05-21 22:46 - 2017-04-14 01:13 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2017-05-21 22:46 - 2017-04-14 01:06 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2017-05-21 22:46 - 2017-04-01 02:02 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2017-05-21 22:46 - 2017-04-01 02:01 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2017-05-21 22:46 - 2017-04-01 01:56 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2017-05-21 22:46 - 2017-04-01 01:55 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-05-21 22:46 - 2017-04-01 01:55 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2017-05-21 22:46 - 2017-04-01 01:52 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll 2017-05-21 22:46 - 2017-04-01 01:52 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2017-05-21 22:46 - 2017-04-01 01:50 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2017-05-21 22:46 - 2017-04-01 01:45 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll 2017-05-21 22:46 - 2017-04-01 01:44 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2017-05-21 22:46 - 2017-03-31 23:00 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin 2017-05-21 15:49 - 2017-06-17 23:13 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Notepad++ 2017-05-21 15:49 - 2017-05-21 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2017-05-21 15:02 - 2017-05-21 15:02 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-05-21 15:01 - 2017-05-21 15:01 - 00000000 ____D C:\Program Files\WinRAR 2017-05-21 14:57 - 2017-06-14 18:16 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Twitch 2017-05-21 14:57 - 2017-05-21 14:57 - 00001092 _____ C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk 2017-05-21 14:57 - 2017-05-21 14:57 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Twitch Setup 2017-05-21 02:23 - 2017-05-21 02:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-20 23:10 - 2017-05-20 20:00 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Battle.net 2017-06-20 23:10 - 2017-05-20 19:38 - 00000000 ____D C:\ProgramData\NVIDIA 2017-06-20 23:09 - 2017-05-20 19:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-06-20 23:08 - 2017-03-18 13:40 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-06-20 23:06 - 2017-05-20 19:30 - 00000000 ____D C:\Users\BrainWasheD 2017-06-20 19:06 - 2017-05-20 19:28 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-06-20 17:45 - 2017-05-20 21:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\SquirrelTemp 2017-06-20 17:09 - 2017-05-20 19:38 - 02369520 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-06-20 17:09 - 2017-03-20 06:35 - 01081138 _____ C:\WINDOWS\system32\perfh007.dat 2017-06-20 17:09 - 2017-03-20 06:35 - 00242448 _____ C:\WINDOWS\system32\perfc007.dat 2017-06-20 13:05 - 2017-05-20 19:40 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\CrashDumps 2017-06-20 10:50 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-06-20 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-06-18 22:37 - 2017-05-20 18:43 - 00000000 ___DC C:\WINDOWS\Panther 2017-06-18 22:37 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-06-18 21:56 - 2017-05-20 20:55 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\MicrosoftEdge 2017-06-18 13:12 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-06-17 01:09 - 2017-05-20 21:20 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-06-17 01:09 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-06-15 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-06-15 09:50 - 2017-05-20 19:35 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-06-15 09:49 - 2017-05-20 19:28 - 00386600 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-06-14 17:10 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-06-13 16:05 - 2017-05-20 19:35 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Packages 2017-06-07 11:02 - 2017-05-20 21:41 - 00000000 ____D C:\Users\BrainWasheD\Documents\Overwatch 2017-06-03 08:32 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-06-03 08:32 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-06-03 08:07 - 2017-05-20 21:08 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Adobe 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-05-23 10:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning 2017-05-22 01:42 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-05-22 01:24 - 2017-05-20 18:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-05-22 00:19 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-05-22 00:18 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-05-21 23:22 - 2017-05-20 19:44 - 00003236 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-05-21 23:16 - 2017-05-20 19:36 - 00000000 ___RD C:\Users\BrainWasheD\OneDrive 2017-05-21 21:25 - 2017-05-20 21:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\discord 2017-05-21 11:01 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-06-18 13:02 - 2017-06-18 13:02 - 0000053 _____ () C:\Users\BrainWasheD\AppData\Roaming\LogFile.txt 2017-05-20 21:19 - 2017-05-20 21:19 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-06-15 10:48 ==================== Ende von FRST.txt ============================ |
20.06.2017, 22:25 | #11 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Addition: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-06-2017 01 durchgeführt von BrainWasheD (20-06-2017 23:15:29) Gestartet von C:\Users\BrainWasheD\Desktop Windows 10 Home Version 1703 (X64) (2017-05-20 17:35:03) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1290209912-1044598962-369420843-500 - Administrator - Disabled) BrainWasheD (S-1-5-21-1290209912-1044598962-369420843-1000 - Administrator - Enabled) => C:\Users\BrainWasheD DefaultAccount (S-1-5-21-1290209912-1044598962-369420843-503 - Limited - Disabled) Gast (S-1-5-21-1290209912-1044598962-369420843-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1290209912-1044598962-369420843-1002 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Ansel (Version: 382.05 - NVIDIA Corporation) Hidden Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.4.2294 - AVAST Software) Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform) Discord (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.) Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION) EPSON XP-630 Series Printer Uninstall (HKLM\...\EPSON XP-630 Series) (Version: - Seiko Epson Corporation) EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.53.0.0 - Seiko Epson Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.104 - Google Inc.) Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden Guild Wars 2 (HKLM\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hearthstone Deck Tracker (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\HearthstoneDeckTracker) (Version: 1.3.5 - HearthSim) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games) League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden Logitech Gaming Software 8.92 (HKLM\...\Logitech Gaming Software) (Version: 8.92.67 - Logitech Inc.) Malwarebytes Version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 16.0.8229.2041 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) MyEpson Portal (x32 Version: 1.1.2.2 - SEIKO EPSON CORPORATION) Hidden Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.4.1 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation) NVIDIA GeForce Experience 3.6.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.6.0.74 - NVIDIA Corporation) NVIDIA Grafiktreiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation) NvNodejs (Version: 3.6.0.74 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.4.10.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.104.211.0 - Overwolf Ltd.) Overwolf.Setup.VC100CRTx64.Dist (HKLM\...\{EC9D5554-6852-4A55-81BB-AC02C7A8CFED}) (Version: 1.0.0 - Overwolf) Overwolf.Setup.VC100CRTx86.Dist (x32 Version: 1.0.0 - Overwolf) Hidden PLAYERUNKNOWN'S BATTLEGROUNDS (HKLM\...\Steam App 578080) (Version: - Bluehole, Inc.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.91.1119.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.) SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden SHIELD Streaming (Version: 7.1.0370 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.6.0.74 - NVIDIA Corporation) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\TeamSpeak 3 Client) (Version: 3.1.4 - TeamSpeak Systems GmbH) Twitch (HKLM-x32\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Twitch Interactive, Inc.) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0EA1CF12-4D4E-4351-94B7-84115E3AB914} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {18BD4184-9849-4FDB-9B2D-24D03803CE9D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {197019C0-A39E-4251-AA72-360935C4A061} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {1B4E6278-16D4-45A6-8BDE-8BAA2F57111A} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03] (NVIDIA Corporation) Task: {2A01F3FF-934C-4158-998B-12E9A8BA31B2} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-20] (AVAST Software) Task: {3BF8BA78-4AC9-4CB9-9335-A07B87708F74} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {420B7897-F154-4134-B3AE-149DECC6BAF7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {4D07E85B-84E3-41BF-B128-048A1B11ABD7} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {4D092839-43B2-4855-AB19-8D6325F14541} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {5832288D-E503-4966-AF8E-965743410F82} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5A7E1579-B6EB-4F42-9120-BC6031D5793C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5B4D641C-AF35-4B5B-8EDB-D191464EBBE8} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {61C6518D-C13B-4071-9836-2975C78C13FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd) Task: {6F7AC86E-5FFA-4710-9A38-0BE5F3CB4539} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {7270ECB5-AEA9-489F-BA3C-BC230228194A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {74D85C90-A46D-4914-B0DE-2B320BE872A4} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-05-03] (NVIDIA Corporation) Task: {7CA44C16-4C06-4287-B3F5-C92E3853D309} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-05-20] (AVAST Software) Task: {7E801DA2-CF04-4FED-BCA3-31CF6097C3C2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {7FB80D08-E1BE-4B3C-BDA4-6AA519217046} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {925B5788-1503-42EF-BA35-28AAED84F0DD} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {93A58816-DD3E-4BF6-9C17-F4D3BAC595AC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {95284773-EAF4-481E-B224-DB2BF54EDA8F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {957EF89D-E1CF-4C48-BEC4-14BB44D42D51} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {96F95AF5-1C8C-4718-A36B-24E45D8224B4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {9CC7B1AB-F5C2-46E8-AF00-3CA249EBFF9A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {A150F5A9-E5F0-4935-BD77-219558415C65} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A34D82D1-35D7-40D5-BFBD-1228C53033DF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A4D1A90D-EB59-4F32-94B7-FF32DB04EE43} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A664084A-B808-467F-AAE7-749AE16EAF62} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {A81ACE1F-61CB-4BC1-A7FA-8C924339B59A} - System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [2013-11-22] (SEIKO EPSON CORPORATION) Task: {B428955E-0F10-42B9-9BC2-C8E0D4A2E8CA} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {B74E1E8C-4791-48B9-AB80-C95F3E9408B5} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-06-06] (Overwolf LTD) Task: {BE535D16-1CEE-4C7F-B997-0936C38FD171} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {BFCFEED0-3A42-43DE-9DB8-3EB9C8A3436B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {C0E93ABF-6B28-43AF-9233-8C6C60788FCE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C2F94150-B72D-4E77-AF25-E4B46736A963} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {DE170156-FC9E-4655-9B93-0A1102B1FB76} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {E3B079A5-9C71-41C8-B6DF-3EF03C091D3E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-05-03] (NVIDIA Corporation) Task: {E413BE20-6FCF-4881-9CF1-2A7117D6ED3A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-17] (Microsoft Corporation) Task: {E8B61091-544C-404C-8B07-6E8782293A49} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F43B762F-7560-433A-B5B4-784D6E925E58} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-05-03] (NVIDIA Corporation) Task: {F848E963-1286-4D26-917B-4090052424C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {FCA81C28-8677-43F7-B312-4732D381BE28} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {FCC70481-09E8-4295-9EA9-2E5D1007F50D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE :/EXE:{61C1FF77-ABA5-4555-868B-77F3A3B348E5} /F:Update WORKGROUP\BRAINWASHED-PC$ ÄŠSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-05-20 19:44 - 2017-05-03 22:16 - 01267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-06-18 03:03 - 2017-05-25 14:11 - 02270664 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-03-08 04:42 - 2017-03-08 04:42 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-03-18 22:59 - 2017-03-20 06:36 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-06-08 11:14 - 2017-06-08 11:14 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-06-08 11:14 - 2017-06-08 11:14 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2017-05-20 19:44 - 2017-05-03 22:15 - 00034240 _____ () C:\Program Files\NVIDIA Corporation\nvstreamsrv\boost_system-vc120-mt-1_58.dll 2017-05-20 19:44 - 2017-05-03 22:15 - 00920000 _____ () C:\Program Files\NVIDIA Corporation\nvstreamsrv\boost_regex-vc120-mt-1_58.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 01529320 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe 2017-05-20 19:44 - 2017-05-03 22:15 - 00018880 _____ () c:\program files\nvidia corporation\nvstreamsrv\detoured.dll 2017-06-18 22:38 - 2017-06-15 09:29 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libglesv2.dll 2017-06-18 22:38 - 2017-06-15 09:29 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libegl.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 01040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-05-20 18:23 - 2017-05-20 18:23 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-05-20 21:01 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\SDL2.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 04969248 _____ () D:\Program Files (x86)\Steam\v8.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 02485536 _____ () D:\Program Files (x86)\Steam\video.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01563936 _____ () D:\Program Files (x86)\Steam\icui18n.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01195296 _____ () D:\Program Files (x86)\Steam\icuuc.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 02549760 _____ () D:\Program Files (x86)\Steam\libavcodec-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00491008 _____ () D:\Program Files (x86)\Steam\libavformat-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00332800 _____ () D:\Program Files (x86)\Steam\libavresample-2.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00442880 _____ () D:\Program Files (x86)\Steam\libavutil-54.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00485888 _____ () D:\Program Files (x86)\Steam\libswscale-3.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00877856 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-05-20 19:44 - 2017-05-03 22:16 - 00018880 _____ () c:\program files (x86)\nvidia corporation\nvstreamsrv\detoured.dll 2017-05-20 21:01 - 2016-07-05 00:17 - 00266560 _____ () D:\Program Files (x86)\Steam\openvr_api.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\ffmpeg.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 01082880 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node 2017-05-20 21:01 - 2017-05-20 21:01 - 03750400 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 00914432 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node 2017-05-20 21:01 - 2017-05-20 21:01 - 01127424 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node 2017-05-20 19:44 - 2017-05-03 22:15 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libglesv2.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libegl.dll 2017-05-20 21:02 - 2017-05-08 21:45 - 69516064 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2017-06-08 14:55 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00385312 _____ () D:\Program Files (x86)\Steam\steam.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 55758824 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libcef.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 00540336 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\ortp.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 00133632 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libEGL.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 03384832 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libGLESv2.dll 2017-06-20 23:10 - 2017-06-20 23:10 - 00148992 _____ () \\?\C:\Users\BrainWasheD\AppData\Local\Temp\39.tmp.node 2017-05-20 21:01 - 2017-05-20 21:01 - 02658296 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node 2017-05-20 21:02 - 2017-05-20 21:02 - 02665976 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\sharepoint.com -> hxxps://uniduesseldorf-files.sharepoint.com ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2017-06-20 23:08 - 00000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 80.69.96.12 - 81.210.129.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run: => "Malwarebytes TrayApp" HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [TCP Query User{F05852CB-FC98-4B64-8AB0-3CCE7BD55022}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{A7CB0C50-42A6-41E1-8599-F3AFC5382948}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{FD301B80-A53F-4E10-9C9C-AD1668391E6E}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{53833F05-1347-4A1D-B298-03D20DEB4D9F}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{5370EBE1-96F9-47AD-9C2E-8749F2DA028A}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{F981958C-9BA8-44E8-9E22-8AC71C5A7E23}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{BE444A7B-766C-4FA6-89C6-86D1F4A62015}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{65DD080D-DD95-495D-966C-F927BB3BC001}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{369A23D4-5E2C-41D8-AAC3-DB8FA7CEE0F8}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{31C92797-7734-4228-89E5-C822CC9C4BC5}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [TCP Query User{862C416E-DF84-4895-AE25-037CC9650B62}A:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) A:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{6D202AB6-774C-4DFD-9E1A-76E28FB9E5F7}A:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) A:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{0BC67549-76D8-4DAE-AB9B-A9098BAB4661}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{996C5CB4-FFAD-43C7-80F4-277DF3A45059}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (06/20/2017 11:09:49 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/20/2017 11:07:25 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/20/2017 05:47:19 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/20/2017 01:05:39 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000006369f2 ID des fehlerhaften Prozesses: 0x220c Startzeit der fehlerhaften Anwendung: 0x01d2e9a1c3daf504 Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe Berichtskennung: 1e49e754-5401-4a40-b18a-2644aa57ab20 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/20/2017 10:49:43 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/20/2017 02:17:41 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/20/2017 02:17:22 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000006369f2 ID des fehlerhaften Prozesses: 0x6b4 Startzeit der fehlerhaften Anwendung: 0x01d2e93c547501e2 Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe Berichtskennung: dea542fd-77a0-4e1d-bdf8-dea9abaeaac8 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:51:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TDSSKiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x1ee8 Startzeit der fehlerhaften Anwendung: 0x01d2e93de51ee5dc Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\TDSSKiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 58632f18-ac33-4fed-a732-47b5a89de301 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:51:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TDSSKiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x1e30 Startzeit der fehlerhaften Anwendung: 0x01d2e93ddf3ca77b Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\TDSSKiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: f064a5b2-73c8-4ecf-ae3a-d8b8e2b21fa7 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/19/2017 10:49:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000409 Fehleroffset: 0xae2ca030 ID des fehlerhaften Prozesses: 0x207c Startzeit der fehlerhaften Anwendung: 0x01d2e93d827fab03 Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Desktop\tdsskiller.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: a05921b1-33ad-4545-a408-0612385a22c4 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Systemfehler: ============= Error: (06/20/2017 11:09:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "BitDefenderCOM" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (06/20/2017 11:09:34 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "HomeGroupListener" wurde mit dem folgenden dienstspezifischen Fehler beendet: %%2147944153 = In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar. Error: (06/20/2017 11:09:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (06/20/2017 11:08:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "NVIDIA NetworkService Container" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/20/2017 11:08:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/20/2017 11:08:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/20/2017 11:08:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/20/2017 11:08:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Logitech Gaming Registry Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/20/2017 11:08:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "MyEpson Portal Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/20/2017 11:08:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "NVIDIA LocalSystem Container" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 6000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2017-06-18 22:36:46.693 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.372 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.197 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.659 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.652 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.252 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.244 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.324 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.317 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:58:02.048 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz Prozentuale Nutzung des RAM: 41% Installierter physikalischer RAM: 8173.24 MB Verfügbarer physikalischer RAM: 4787.41 MB Summe virtueller Speicher: 16877.24 MB Verfügbarer virtueller Speicher: 13036.82 MB ==================== Laufwerke ================================ Drive a: (Volume) (Fixed) (Total:223.57 GB) (Free:164.24 GB) NTFS Drive c: () (Fixed) (Total:111.25 GB) (Free:70.96 GB) NTFS Drive d: () (Fixed) (Total:488.06 GB) (Free:437.51 GB) NTFS Drive e: (Volume) (Fixed) (Total:443.23 GB) (Free:402.06 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 1E55C42B) Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: DBC5041D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 2 (Size: 931.5 GB) (Disk ID: C99F686A) Partition: GPT. ==================== Ende von Addition.txt ============================ |
21.06.2017, 15:11 | #12 |
/// TB-Ausbilder | New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Servus, Hinweis: Der Suchlauf mit ESET kann länger dauern. Schritt 1 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 2 ESET Online Scanner
Schritt 3
Gibt es jetzt noch Probleme mit dem PC oder mit deinen Internet Browsern? Wenn ja, welche? Bitte poste mit deiner nächsten Antwort
|
21.06.2017, 17:57 | #13 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" hi, Hitman: Code:
ATTFilter
Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=8ab99ed73d8d9243b07b224118128218 # end=init # utc_time=2017-06-21 03:48:23 # local_time=2017-06-21 05:48:23 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 33799 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=8ab99ed73d8d9243b07b224118128218 # end=updated # utc_time=2017-06-21 04:03:40 # local_time=2017-06-21 06:03:40 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=8ab99ed73d8d9243b07b224118128218 # engine=33799 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2017-06-21 04:38:53 # local_time=2017-06-21 06:38:53 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Avast Antivirus' # compatibility_mode=798 16777213 66 86 89449 2765736 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 1995379 8196129 0 0 # scanned=205058 # found=3 # cleaned=0 # scan_time=2113 sh=BB85CE3BF198B3F9D294E152C012B92CD02D2A23 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="D:\UseNeXT\alt.binaries.erotica.divx\Vinny Andie Darling WTF Slut Andie Darling Video SZ227 720p.rar" sh=3E152AD52F026C76194C6D141FEE55CD4F43A42F ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="D:\UseNeXT\alt.binaries.nl\WTF Sluts Billie Star and Andie Darling Video SZ236 720p.rar" sh=55DBC2CCCB690677D9D0754F1324E7BFE35140ED ft=1 fh=2a15b25d2537faaa vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="E:\Neuinstallation\Windows 10 Update Assistent - CHIP-Installer.exe" Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 21-06-2017 01 durchgeführt von BrainWasheD (21-06-2017 18:46:00) Gestartet von C:\Users\BrainWasheD\Desktop Windows 10 Home Version 1703 (X64) (2017-05-20 17:35:03) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1290209912-1044598962-369420843-500 - Administrator - Disabled) BrainWasheD (S-1-5-21-1290209912-1044598962-369420843-1000 - Administrator - Enabled) => C:\Users\BrainWasheD DefaultAccount (S-1-5-21-1290209912-1044598962-369420843-503 - Limited - Disabled) Gast (S-1-5-21-1290209912-1044598962-369420843-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1290209912-1044598962-369420843-1002 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Ansel (Version: 382.05 - NVIDIA Corporation) Hidden Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.4.2294 - AVAST Software) Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform) Discord (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.) Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION) EPSON XP-630 Series Printer Uninstall (HKLM\...\EPSON XP-630 Series) (Version: - Seiko Epson Corporation) EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.53.0.0 - Seiko Epson Corporation) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.104 - Google Inc.) Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden Guild Wars 2 (HKLM\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hearthstone Deck Tracker (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\HearthstoneDeckTracker) (Version: 1.3.5 - HearthSim) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games) League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden Logitech Gaming Software 8.92 (HKLM\...\Logitech Gaming Software) (Version: 8.92.67 - Logitech Inc.) Malwarebytes Version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 16.0.8229.2041 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) MyEpson Portal (x32 Version: 1.1.2.2 - SEIKO EPSON CORPORATION) Hidden Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.4.1 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation) NVIDIA GeForce Experience 3.6.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.6.0.74 - NVIDIA Corporation) NVIDIA Grafiktreiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation) NvNodejs (Version: 3.6.0.74 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.4.10.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.104.211.0 - Overwolf Ltd.) Overwolf.Setup.VC100CRTx64.Dist (HKLM\...\{EC9D5554-6852-4A55-81BB-AC02C7A8CFED}) (Version: 1.0.0 - Overwolf) Overwolf.Setup.VC100CRTx86.Dist (x32 Version: 1.0.0 - Overwolf) Hidden PLAYERUNKNOWN'S BATTLEGROUNDS (HKLM\...\Steam App 578080) (Version: - Bluehole, Inc.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.91.1119.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.) SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden SHIELD Streaming (Version: 7.1.0370 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.6.0.74 - NVIDIA Corporation) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\TeamSpeak 3 Client) (Version: 3.1.4 - TeamSpeak Systems GmbH) Twitch (HKLM-x32\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Twitch Interactive, Inc.) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0EA1CF12-4D4E-4351-94B7-84115E3AB914} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {18BD4184-9849-4FDB-9B2D-24D03803CE9D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {197019C0-A39E-4251-AA72-360935C4A061} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {1B4E6278-16D4-45A6-8BDE-8BAA2F57111A} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03] (NVIDIA Corporation) Task: {2A01F3FF-934C-4158-998B-12E9A8BA31B2} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-20] (AVAST Software) Task: {3BF8BA78-4AC9-4CB9-9335-A07B87708F74} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation) Task: {420B7897-F154-4134-B3AE-149DECC6BAF7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {4D07E85B-84E3-41BF-B128-048A1B11ABD7} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {4D092839-43B2-4855-AB19-8D6325F14541} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {5832288D-E503-4966-AF8E-965743410F82} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5A7E1579-B6EB-4F42-9120-BC6031D5793C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5B4D641C-AF35-4B5B-8EDB-D191464EBBE8} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {61C6518D-C13B-4071-9836-2975C78C13FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd) Task: {6F7AC86E-5FFA-4710-9A38-0BE5F3CB4539} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {7270ECB5-AEA9-489F-BA3C-BC230228194A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {74D85C90-A46D-4914-B0DE-2B320BE872A4} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-05-03] (NVIDIA Corporation) Task: {7CA44C16-4C06-4287-B3F5-C92E3853D309} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-05-20] (AVAST Software) Task: {7E801DA2-CF04-4FED-BCA3-31CF6097C3C2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {7FB80D08-E1BE-4B3C-BDA4-6AA519217046} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {925B5788-1503-42EF-BA35-28AAED84F0DD} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] () Task: {93A58816-DD3E-4BF6-9C17-F4D3BAC595AC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation) Task: {95284773-EAF4-481E-B224-DB2BF54EDA8F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {957EF89D-E1CF-4C48-BEC4-14BB44D42D51} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.) Task: {96F95AF5-1C8C-4718-A36B-24E45D8224B4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {9CC7B1AB-F5C2-46E8-AF00-3CA249EBFF9A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {A150F5A9-E5F0-4935-BD77-219558415C65} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A34D82D1-35D7-40D5-BFBD-1228C53033DF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A4D1A90D-EB59-4F32-94B7-FF32DB04EE43} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A664084A-B808-467F-AAE7-749AE16EAF62} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {A81ACE1F-61CB-4BC1-A7FA-8C924339B59A} - System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [2013-11-22] (SEIKO EPSON CORPORATION) Task: {B428955E-0F10-42B9-9BC2-C8E0D4A2E8CA} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {B74E1E8C-4791-48B9-AB80-C95F3E9408B5} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-06-06] (Overwolf LTD) Task: {BE535D16-1CEE-4C7F-B997-0936C38FD171} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {BFCFEED0-3A42-43DE-9DB8-3EB9C8A3436B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {C0E93ABF-6B28-43AF-9233-8C6C60788FCE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C2F94150-B72D-4E77-AF25-E4B46736A963} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {DE170156-FC9E-4655-9B93-0A1102B1FB76} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation) Task: {E3B079A5-9C71-41C8-B6DF-3EF03C091D3E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-05-03] (NVIDIA Corporation) Task: {E413BE20-6FCF-4881-9CF1-2A7117D6ED3A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-17] (Microsoft Corporation) Task: {E8B61091-544C-404C-8B07-6E8782293A49} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F43B762F-7560-433A-B5B4-784D6E925E58} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-05-03] (NVIDIA Corporation) Task: {F848E963-1286-4D26-917B-4090052424C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {FCA81C28-8677-43F7-B312-4732D381BE28} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation) Task: {FCC70481-09E8-4295-9EA9-2E5D1007F50D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE :/EXE:{61C1FF77-ABA5-4555-868B-77F3A3B348E5} /F:Update WORKGROUP\BRAINWASHED-PC$ ÄŠSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-05-20 19:44 - 2017-05-03 22:16 - 01267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-06-18 03:03 - 2017-05-25 14:11 - 02270664 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-05-20 19:38 - 2017-05-01 22:51 - 00133752 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-03-18 22:59 - 2017-03-20 06:36 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2017-04-06 01:05 - 2017-04-06 01:05 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 01529320 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe 2017-06-18 22:38 - 2017-06-15 09:29 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libglesv2.dll 2017-06-18 22:38 - 2017-06-15 09:29 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libegl.dll 2017-06-21 12:54 - 2017-06-21 12:54 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-06-21 12:54 - 2017-06-21 12:54 - 00203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-06-21 12:54 - 2017-06-21 12:54 - 43454464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-06-21 12:54 - 2017-06-21 12:54 - 02437120 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\skypert.dll 2017-05-20 21:16 - 2017-05-20 21:16 - 00765440 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11703.1001.45.0_x64__8wekyb3d8bbwe\WinStore.Vui.dll 2017-05-20 21:16 - 2017-05-20 21:16 - 10601984 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11703.1001.45.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2017-05-20 21:16 - 2017-05-20 21:16 - 02640384 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11703.1001.45.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll 2017-06-01 10:40 - 2017-06-01 10:41 - 23661056 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Video.UI.exe 2017-06-01 10:40 - 2017-06-01 10:40 - 09016320 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\EntCommon.dll 2017-05-26 16:54 - 2017-05-26 16:54 - 03140520 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-05-20 19:44 - 2017-05-03 22:16 - 01040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-05-20 18:23 - 2017-05-20 18:23 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-05-20 18:24 - 2017-05-20 18:24 - 00684656 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-05-20 19:44 - 2017-05-03 22:15 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-05-20 21:01 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\SDL2.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 04969248 _____ () D:\Program Files (x86)\Steam\v8.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 02485536 _____ () D:\Program Files (x86)\Steam\video.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01563936 _____ () D:\Program Files (x86)\Steam\icui18n.dll 2017-05-20 21:01 - 2016-09-01 03:02 - 01195296 _____ () D:\Program Files (x86)\Steam\icuuc.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 02549760 _____ () D:\Program Files (x86)\Steam\libavcodec-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00491008 _____ () D:\Program Files (x86)\Steam\libavformat-56.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00332800 _____ () D:\Program Files (x86)\Steam\libavresample-2.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00442880 _____ () D:\Program Files (x86)\Steam\libavutil-54.dll 2017-05-20 21:01 - 2016-01-27 09:49 - 00485888 _____ () D:\Program Files (x86)\Steam\libswscale-3.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00877856 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-05-20 21:01 - 2016-07-05 00:17 - 00266560 _____ () D:\Program Files (x86)\Steam\openvr_api.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\ffmpeg.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 01082880 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node 2017-05-20 21:01 - 2017-05-20 21:01 - 03750400 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll 2017-05-20 21:01 - 2017-05-20 21:01 - 00914432 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node 2017-05-20 21:01 - 2017-05-20 21:01 - 01127424 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node 2017-05-20 21:02 - 2017-05-08 21:45 - 69516064 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2017-06-08 14:55 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2017-05-20 21:01 - 2017-06-08 07:42 - 00385312 _____ () D:\Program Files (x86)\Steam\steam.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libglesv2.dll 2017-05-20 21:01 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libegl.dll 2017-06-21 12:51 - 2017-06-21 12:51 - 00148992 _____ () \\?\C:\Users\BrainWasheD\AppData\Local\Temp\B7DC.tmp.node 2017-05-20 21:01 - 2017-05-20 21:01 - 02658296 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node 2017-05-20 21:02 - 2017-05-20 21:02 - 02665976 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node 2017-06-20 01:41 - 2017-06-20 01:41 - 55758824 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libcef.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 00540336 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\ortp.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 00133632 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libEGL.dll 2017-06-20 01:41 - 2017-06-20 01:41 - 03384832 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8941\libGLESv2.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\sharepoint.com -> hxxps://uniduesseldorf-files.sharepoint.com ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2017-06-20 23:08 - 00000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 80.69.96.12 - 81.210.129.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run: => "Malwarebytes TrayApp" HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [TCP Query User{F05852CB-FC98-4B64-8AB0-3CCE7BD55022}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{A7CB0C50-42A6-41E1-8599-F3AFC5382948}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{FD301B80-A53F-4E10-9C9C-AD1668391E6E}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{53833F05-1347-4A1D-B298-03D20DEB4D9F}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{5370EBE1-96F9-47AD-9C2E-8749F2DA028A}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{F981958C-9BA8-44E8-9E22-8AC71C5A7E23}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{BE444A7B-766C-4FA6-89C6-86D1F4A62015}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{65DD080D-DD95-495D-966C-F927BB3BC001}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{369A23D4-5E2C-41D8-AAC3-DB8FA7CEE0F8}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{31C92797-7734-4228-89E5-C822CC9C4BC5}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [TCP Query User{862C416E-DF84-4895-AE25-037CC9650B62}A:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) A:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{6D202AB6-774C-4DFD-9E1A-76E28FB9E5F7}A:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) A:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{0BC67549-76D8-4DAE-AB9B-A9098BAB4661}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{996C5CB4-FFAD-43C7-80F4-277DF3A45059}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe FirewallRules: [TCP Query User{D6EEA427-FCDA-4DFC-9910-FC1C5621B787}A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{68B483B4-2D2E-4EAE-8F21-D316E8733578}A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (06/21/2017 06:45:45 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Error: (06/21/2017 06:45:17 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/21/2017 06:45:14 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\eset\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Error: (06/21/2017 06:44:06 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Error: (06/21/2017 05:49:11 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Error: (06/21/2017 05:48:59 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (06/21/2017 05:48:58 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Error: (06/21/2017 05:48:22 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "c:\users\brainwashed\desktop\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Error: (06/21/2017 05:48:19 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\BrainWasheD\Desktop\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Error: (06/21/2017 05:48:09 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\BrainWasheD\Desktop\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_108e4f62dfe5d999.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.0_none_583b8639f462029f.manifest. Systemfehler: ============= Error: (06/21/2017 06:03:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (06/21/2017 06:03:32 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\BRAINW~1\AppData\Local\Temp\ehdrv.sys Error: (06/21/2017 06:03:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (06/21/2017 06:03:31 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\BRAINW~1\AppData\Local\Temp\ehdrv.sys Error: (06/21/2017 06:03:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (06/21/2017 06:03:31 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\BRAINW~1\AppData\Local\Temp\ehdrv.sys Error: (06/21/2017 06:02:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (06/21/2017 06:02:26 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\BRAINW~1\AppData\Local\Temp\ehdrv.sys Error: (06/21/2017 06:02:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: Der Treiber konnte nicht geladen werden. Error: (06/21/2017 06:02:26 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\BRAINW~1\AppData\Local\Temp\ehdrv.sys CodeIntegrity: =================================== Date: 2017-06-18 22:36:46.693 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.372 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:36:46.197 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.659 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:01:20.652 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.252 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 22:00:02.244 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.324 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:59:29.317 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-18 21:58:02.048 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz Prozentuale Nutzung des RAM: 49% Installierter physikalischer RAM: 8173.24 MB Verfügbarer physikalischer RAM: 4132.58 MB Summe virtueller Speicher: 16877.24 MB Verfügbarer virtueller Speicher: 11182.25 MB ==================== Laufwerke ================================ Drive a: (Volume) (Fixed) (Total:223.57 GB) (Free:164.24 GB) NTFS Drive c: () (Fixed) (Total:111.25 GB) (Free:69.84 GB) NTFS Drive d: () (Fixed) (Total:488.06 GB) (Free:437.51 GB) NTFS Drive e: (Volume) (Fixed) (Total:443.23 GB) (Free:402.06 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 1E55C42B) Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: DBC5041D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 2 (Size: 931.5 GB) (Disk ID: C99F686A) Partition: GPT. ==================== Ende von Addition.txt ============================ Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 21-06-2017 01 durchgeführt von BrainWasheD (Administrator) auf BRAINWASHED-PC (21-06-2017 18:45:28) Gestartet von C:\Users\BrainWasheD\Desktop Geladene Profile: BrainWasheD (Verfügbare Profile: BrainWasheD) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.5676\Agent.exe (Hammer & Chisel, Inc.) C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Blizzard Entertainment) D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe () D:\Program Files (x86)\Blizzard App\Battle.net.8941\Battle.net Helper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11703.1001.45.0_x64__8wekyb3d8bbwe\WinStore.App.exe () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Video.UI.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-20] (AVAST Software) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17494136 2017-04-06] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Discord] => C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [Battle.net] => D:\Program Files (x86)\Blizzard App\Battle.net Launcher.exe [3229160 2017-05-20] (Blizzard Entertainment) HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9803992 2017-06-13] (Piriform Ltd) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-20] (AVAST Software) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 80.69.96.12 81.210.129.4 Tcpip\..\Interfaces\{00f4a4f9-90c8-4abb-b592-61cb1208f787}: [DhcpNameServer] 80.69.96.12 81.210.129.4 Internet Explorer: ================== BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-05-20] (AVAST Software) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-06-17] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-20] (AVAST Software) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-17] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: mguelu0x.default FF ProfilePath: C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default [2017-06-20] FF Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\sp@avast.com.xpi [2017-06-18] FF Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Roaming\Mozilla\Firefox\Profiles\mguelu0x.default\Extensions\wrc@avast.com.xpi [2017-06-18] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-17] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.de/ CHR StartupUrls: Default -> "hxxp://www.facebook.com/","hxxp://www.mmo-champion.com/content/","hxxp://www.google.de/","hxxp://www.youtube.com/" CHR Profile: C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default [2017-06-21] CHR Extension: (Google Präsentationen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-20] CHR Extension: (Google Docs) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-20] CHR Extension: (Google Drive) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-20] CHR Extension: (YouTube) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-20] CHR Extension: (Adblock Plus) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-06-20] CHR Extension: (Legacy MindMup (discontinued)) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnenaecjcgeppfpaokiifokeieopppej [2017-06-20] CHR Extension: (Avast SafePrice) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-06-20] CHR Extension: (Google Tabellen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-20] CHR Extension: (Google Docs Offline) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-20] CHR Extension: (Avast Online Security) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-20] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-20] CHR Extension: (Google Mail) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-20] CHR Extension: (Chrome Media Router) - C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-20] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7346208 2017-05-20] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-20] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1522184 2017-05-20] () R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4412616 2017-06-09] (Microsoft Corporation) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation) R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON CORPORATION) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [225400 2017-04-06] (Logitech Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [819672 2017-06-05] (Seiko Epson Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-03] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-05-03] (NVIDIA Corporation) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1326408 2017-06-06] (Overwolf LTD) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) S2 BitDefenderCOM; "C:\Program Files\BDServices\BitDefenderCom.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [311808 2017-05-20] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [190256 2017-05-20] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334576 2017-05-20] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [49016 2017-05-20] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-05-20] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32600 2017-05-20] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [128648 2017-05-20] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [101152 2017-05-20] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-05-20] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1007160 2017-05-20] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [569192 2017-05-20] (AVAST Software) R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [158880 2017-05-20] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [339696 2017-05-20] (AVAST Software) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-05-25] () R3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [54552 2017-04-06] (Logitech Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2017-04-06] (Logitech Inc.) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188312 2017-06-20] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [113592 2017-06-20] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [44960 2017-06-20] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [252832 2017-06-20] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-06-21] (Malwarebytes) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys [14456944 2017-05-02] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-05-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-05-03] (NVIDIA Corporation) R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59448 2017-05-02] (NVIDIA Corporation) U5 PROCMON23; C:\Windows\System32\Drivers\PROCMON23.sys [84960 2017-05-22] (Sysinternals - www.sysinternals.com) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [898296 2016-01-13] (Realtek ) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 Trufos; C:\WINDOWS\System32\DRIVERS\Trufos.sys [442848 2017-05-05] (BitDefender S.R.L.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) U3 idsvc; kein ImagePath U3 wpcsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-21 18:45 - 2017-06-21 18:45 - 00020470 _____ C:\Users\BrainWasheD\Desktop\FRST.txt 2017-06-21 18:45 - 2017-06-21 18:45 - 00000000 ____D C:\Users\BrainWasheD\Desktop\FRST-OlderVersion 2017-06-21 17:48 - 2017-06-21 17:48 - 02870984 _____ (ESET) C:\Users\BrainWasheD\Desktop\esetsmartinstaller_deu.exe 2017-06-21 17:48 - 2017-06-21 17:48 - 00000000 ____D C:\Program Files (x86)\ESET 2017-06-21 17:42 - 2017-06-21 17:42 - 11584088 _____ (SurfRight B.V.) C:\Users\BrainWasheD\Desktop\HitmanPro_x64.exe 2017-06-21 13:11 - 2017-06-21 13:11 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\.mono 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\Users\BrainWasheD\AppData\LocalLow\Blizzard Entertainment 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Blizzard 2017-06-20 17:49 - 2017-06-20 17:49 - 00000000 ____D C:\ProgramData\.mono 2017-06-20 17:46 - 2017-06-20 17:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2017-06-20 17:45 - 2017-06-20 18:03 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\HearthstoneDeckTracker 2017-06-20 17:45 - 2017-06-20 17:45 - 00002641 _____ C:\Users\BrainWasheD\Desktop\Hearthstone Deck Tracker.lnk 2017-06-20 17:45 - 2017-06-20 17:45 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HearthSim 2017-06-20 17:45 - 2017-06-20 17:45 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\HearthstoneDeckTracker 2017-06-20 17:44 - 2017-06-20 17:44 - 22687008 _____ (HearthSim) C:\Users\BrainWasheD\Downloads\HDT-Installer.exe 2017-06-20 17:12 - 2017-06-20 17:12 - 00001393 _____ C:\Users\BrainWasheD\Desktop\mbam.txt 2017-06-20 16:58 - 2017-06-20 16:58 - 04110280 _____ C:\Users\BrainWasheD\Downloads\adwcleaner_6.047.exe 2017-06-20 16:58 - 2017-06-20 16:58 - 04110280 _____ C:\Users\BrainWasheD\Desktop\adwcleaner_6.047.exe 2017-06-20 02:17 - 2017-06-20 12:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\vlc 2017-06-20 02:17 - 2017-06-20 02:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-06-20 02:17 - 2017-06-20 02:17 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-06-20 02:16 - 2017-06-20 02:16 - 30950664 _____ C:\Users\BrainWasheD\Downloads\vlc-2.2.6-win32.exe 2017-06-19 23:00 - 2017-06-19 23:01 - 00066692 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_23.00.31_log.txt 2017-06-19 23:00 - 2017-06-19 23:00 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\55876282.sys 2017-06-19 22:52 - 2017-06-19 22:56 - 00068040 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_22.52.10_log.txt 2017-06-19 22:52 - 2017-06-19 22:52 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\55192664.sys 2017-06-19 22:51 - 2017-06-19 22:51 - 04830473 _____ C:\Users\BrainWasheD\Downloads\tdsskiller (1).zip 2017-06-19 22:51 - 2017-06-19 22:51 - 02213976 _____ (Kaspersky Lab ZAO) C:\Users\BrainWasheD\Desktop\tdsskiller.exe 2017-06-19 22:51 - 2017-06-19 22:51 - 00000354 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_22.51.12_log.txt 2017-06-19 22:46 - 2017-06-21 18:45 - 02439680 _____ (Farbar) C:\Users\BrainWasheD\Desktop\FRST64.exe 2017-06-19 22:46 - 2017-06-21 18:45 - 00000000 ____D C:\FRST 2017-06-19 13:49 - 2017-06-19 13:49 - 09836385 _____ C:\Users\BrainWasheD\Downloads\01_Studi.pdf 2017-06-19 01:23 - 2017-06-19 01:23 - 00208216 _____ (Kaspersky Lab, GERT) C:\WINDOWS\system32\Drivers\85203316.sys 2017-06-19 01:23 - 2017-06-19 01:23 - 00064778 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.23.11_log.txt 2017-06-19 01:22 - 2017-06-19 01:22 - 04830473 _____ C:\Users\BrainWasheD\Downloads\tdsskiller.zip 2017-06-19 01:22 - 2017-06-19 01:22 - 00000356 _____ C:\TDSSKiller.2.8.15.0_19.06.2017_01.22.26_log.txt 2017-06-19 00:31 - 2017-06-19 00:31 - 00000000 ____D C:\ProgramData\Emsisoft 2017-06-19 00:30 - 2017-06-19 00:32 - 00000000 ____D C:\EEK 2017-06-18 23:28 - 2017-06-20 17:02 - 00000000 ____D C:\AdwCleaner 2017-06-18 22:39 - 2017-06-18 22:39 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Google 2017-06-18 22:38 - 2017-06-18 22:38 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-06-18 22:38 - 2017-06-18 22:38 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-06-18 22:38 - 2017-06-18 22:38 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-06-18 21:20 - 2017-06-18 22:35 - 00000000 ____D C:\Program Files\CCleaner 2017-06-18 21:20 - 2017-06-18 21:20 - 00002880 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2017-06-18 21:20 - 2017-06-18 21:20 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-06-18 21:20 - 2017-06-18 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-06-18 21:19 - 2017-06-18 22:47 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Google 2017-06-18 21:19 - 2017-06-18 22:38 - 00000000 ____D C:\Program Files (x86)\Google 2017-06-18 21:18 - 2017-06-18 21:52 - 00000000 ____D C:\Users\BrainWasheD\AppData\LocalLow\Mozilla 2017-06-18 21:18 - 2017-06-18 21:41 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Mozilla 2017-06-18 21:18 - 2017-06-18 21:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Mozilla 2017-06-18 21:03 - 2017-06-18 21:03 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\7BA52E92.sys 2017-06-18 15:45 - 2017-06-19 01:22 - 02213976 _____ (Kaspersky Lab ZAO) C:\Users\BrainWasheD\Downloads\tdsskiller.exe 2017-06-18 15:43 - 2017-06-18 15:46 - 00000000 ____D C:\ProgramData\HitmanPro 2017-06-18 13:31 - 2017-06-18 21:54 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Deployment 2017-06-18 13:31 - 2017-06-18 13:31 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Macromedia 2017-06-18 13:21 - 2017-06-18 13:21 - 00001173 _____ C:\Users\BrainWasheD\Desktop\JRT.txt 2017-06-18 12:52 - 2017-06-18 13:00 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-06-18 12:51 - 2017-06-18 13:00 - 00000000 ____D C:\Users\BrainWasheD\Desktop\mbar 2017-06-18 03:03 - 2017-06-21 17:35 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-06-18 03:03 - 2017-06-20 23:09 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-06-18 03:03 - 2017-06-20 23:09 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-06-18 03:03 - 2017-06-20 23:09 - 00044960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-06-18 03:03 - 2017-06-20 10:47 - 00188312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-06-18 03:03 - 2017-06-18 12:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-06-18 03:03 - 2017-06-18 03:03 - 00000000 ____D C:\Program Files\Malwarebytes 2017-06-18 03:03 - 2017-05-25 11:58 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-06-17 23:13 - 2017-06-17 23:13 - 00000000 ____D C:\Program Files (x86)\Notepad++ 2017-06-17 21:04 - 2017-06-17 21:04 - 00000000 ____D C:\Users\BrainWasheD\Documents\League of Legends 2017-06-17 21:03 - 2017-06-17 21:04 - 00000863 _____ C:\Users\Public\Desktop\League of Legends.lnk 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Riot Games 2017-06-17 21:03 - 2017-06-17 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2017-06-17 21:03 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2017-06-17 21:03 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2017-06-17 21:02 - 2017-06-17 21:03 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Riot Games 2017-06-15 10:19 - 2017-06-15 10:19 - 00000713 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk 2017-06-15 10:19 - 2017-06-15 10:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2 2017-06-15 10:17 - 2017-06-15 10:19 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Guild Wars 2 2017-06-15 09:57 - 2017-06-15 09:57 - 00061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys 2017-06-14 17:08 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-06-14 17:08 - 2017-06-03 11:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-06-14 17:08 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-06-14 17:08 - 2017-06-03 11:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2017-06-14 17:08 - 2017-06-03 11:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-06-14 17:08 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:08 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2017-06-14 17:08 - 2017-06-03 11:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-06-14 17:08 - 2017-06-03 11:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-06-14 17:08 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-06-14 17:08 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-06-14 17:08 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:08 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-06-14 17:08 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2017-06-14 17:08 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-06-14 17:08 - 2017-06-03 10:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2017-06-14 17:08 - 2017-06-03 10:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-06-14 17:08 - 2017-06-03 10:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-06-14 17:08 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-06-14 17:08 - 2017-06-03 10:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-06-14 17:08 - 2017-06-03 10:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2017-06-14 17:08 - 2017-06-03 10:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-06-14 17:08 - 2017-06-03 10:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2017-06-14 17:07 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2017-06-14 17:07 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2017-06-14 17:07 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2017-06-14 17:07 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2017-06-14 17:07 - 2017-06-03 11:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-06-14 17:07 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2017-06-14 17:07 - 2017-06-03 11:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-06-14 17:07 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2017-06-14 17:07 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-06-14 17:07 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2017-06-14 17:07 - 2017-06-03 11:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-06-14 17:07 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-06-14 17:07 - 2017-06-03 11:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-06-14 17:07 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2017-06-14 17:07 - 2017-06-03 11:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2017-06-14 17:07 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2017-06-14 17:07 - 2017-06-03 11:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-06-14 17:07 - 2017-06-03 11:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2017-06-14 17:07 - 2017-06-03 11:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-06-14 17:07 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-06-14 17:07 - 2017-06-03 10:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-06-14 17:07 - 2017-06-03 10:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-06-14 17:07 - 2017-06-03 10:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-06-14 17:07 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-06-14 17:07 - 2017-06-03 10:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-06-14 17:06 - 2017-06-03 12:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-06-14 17:06 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-06-14 17:06 - 2017-06-03 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-06-14 17:06 - 2017-06-03 12:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-06-14 17:06 - 2017-06-03 12:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-06-14 17:06 - 2017-06-03 12:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2017-06-14 17:06 - 2017-06-03 12:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-06-14 17:06 - 2017-06-03 12:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-06-14 17:06 - 2017-06-03 12:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll 2017-06-14 17:06 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-06-14 17:06 - 2017-06-03 11:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-06-14 17:06 - 2017-06-03 11:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-06-14 17:06 - 2017-06-03 11:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2017-06-14 17:06 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-06-14 17:06 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-06-14 17:06 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-06-14 17:06 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe 2017-06-14 17:06 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll 2017-06-14 17:06 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-06-14 17:06 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe 2017-06-14 17:06 - 2017-06-03 11:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-06-14 17:06 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-06-14 17:06 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-06-14 17:06 - 2017-06-03 11:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2017-06-14 17:06 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2017-06-14 17:06 - 2017-06-03 10:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2017-06-14 17:06 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2017-06-14 17:06 - 2017-06-03 10:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-06-14 17:06 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe 2017-06-06 18:03 - 2017-06-20 23:09 - 00012800 ___SH C:\Users\BrainWasheD\Desktop\Thumbs.db 2017-06-03 08:08 - 2017-06-20 12:21 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000819 _____ C:\Users\BrainWasheD\Desktop\UseNeXT by Tangysoft.lnk 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\Users\BrainWasheD\Documents\UseNeXT 2017-06-03 08:08 - 2017-06-03 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT 2017-06-03 08:05 - 2017-06-06 18:58 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-06-03 08:05 - 2017-06-03 16:08 - 00000000 ____D C:\ProgramData\Adobe 2017-06-03 08:05 - 2017-06-03 08:05 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-06-03 08:05 - 2017-06-03 08:05 - 00000000 ____D C:\Program Files (x86)\Adobe 2017-05-30 16:35 - 2017-05-30 16:35 - 00000000 ____D C:\Users\BrainWasheD\Documents\Benutzerdefinierte Office-Vorlagen 2017-05-29 12:51 - 2017-05-20 11:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-05-29 12:51 - 2017-05-20 10:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 10:48 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-05-29 12:51 - 2017-05-20 10:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:46 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 10:45 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 10:44 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 10:43 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 10:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 10:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 10:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 10:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 10:24 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2017-05-29 12:51 - 2017-05-20 10:23 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 10:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 10:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-05-29 12:51 - 2017-05-20 10:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 10:20 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 10:19 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 10:18 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 10:17 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 10:17 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 10:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 10:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-05-29 12:51 - 2017-05-20 10:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 10:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2017-05-29 12:51 - 2017-05-20 10:10 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2017-05-29 12:51 - 2017-05-20 10:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-05-29 12:51 - 2017-05-20 09:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-05-29 12:51 - 2017-05-20 09:07 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2017-05-29 12:51 - 2017-05-20 09:03 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2017-05-29 12:51 - 2017-05-20 08:59 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2017-05-29 12:51 - 2017-05-20 08:58 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 04847928 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-05-29 12:51 - 2017-05-20 08:56 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-05-29 12:51 - 2017-05-20 08:56 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-05-29 12:51 - 2017-05-20 08:55 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2017-05-29 12:51 - 2017-05-20 08:55 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-05-29 12:51 - 2017-05-20 08:54 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-05-29 12:51 - 2017-05-20 08:54 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-05-29 12:51 - 2017-05-20 08:53 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-05-29 12:51 - 2017-05-20 08:53 - 00335808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2017-05-29 12:51 - 2017-05-20 08:53 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-05-29 12:51 - 2017-05-20 08:52 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 06551856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 01219560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-05-29 12:51 - 2017-05-20 08:51 - 00406064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2017-05-29 12:51 - 2017-05-20 08:48 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll 2017-05-29 12:51 - 2017-05-20 08:10 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys 2017-05-29 12:51 - 2017-05-20 08:09 - 17365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-05-29 12:51 - 2017-05-20 08:09 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-05-29 12:51 - 2017-05-20 08:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2017-05-29 12:51 - 2017-05-20 08:07 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll 2017-05-29 12:51 - 2017-05-20 08:07 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe 2017-05-29 12:51 - 2017-05-20 08:06 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll 2017-05-29 12:51 - 2017-05-20 08:06 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-05-29 12:51 - 2017-05-20 08:05 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll 2017-05-29 12:51 - 2017-05-20 08:03 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2017-05-29 12:51 - 2017-05-20 08:02 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-05-29 12:51 - 2017-05-20 08:01 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2017-05-29 12:51 - 2017-05-20 08:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-05-29 12:51 - 2017-05-20 08:00 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-05-29 12:51 - 2017-05-20 07:59 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2017-05-29 12:51 - 2017-05-20 07:58 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-05-29 12:51 - 2017-05-20 07:57 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-05-29 12:51 - 2017-05-20 07:56 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe 2017-05-29 12:51 - 2017-05-20 07:56 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2017-05-29 12:51 - 2017-05-20 07:55 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 04537344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-05-29 12:51 - 2017-05-20 07:54 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2017-05-29 12:51 - 2017-05-20 07:52 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-05-29 12:51 - 2017-05-20 07:51 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll 2017-05-29 12:51 - 2017-05-20 07:50 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2017-05-29 12:51 - 2017-05-20 07:48 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2017-05-29 12:51 - 2017-05-20 07:47 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll 2017-05-25 17:23 - 2017-05-25 17:23 - 00001150 _____ C:\Users\Public\Desktop\Overwolf.lnk 2017-05-25 17:23 - 2017-05-25 17:23 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\NVIDIA 2017-05-25 17:22 - 2017-06-13 17:22 - 00000000 ____D C:\Program Files (x86)\Overwolf 2017-05-25 17:22 - 2017-06-02 12:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\TS3Client 2017-05-25 17:22 - 2017-06-02 08:18 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Overwolf 2017-05-25 17:22 - 2017-05-25 17:24 - 00000000 ____D C:\ProgramData\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00004382 _____ C:\WINDOWS\System32\Tasks\Overwolf Updater Task 2017-05-25 17:22 - 2017-05-25 17:22 - 00001342 _____ C:\Users\BrainWasheD\Desktop\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00001300 _____ C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\TeamSpeak 3 Client 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.TeamSpeak 3 2017-05-25 17:22 - 2017-05-25 17:22 - 00000000 ____D C:\Users\BrainWasheD\.QtWebEngineProcess 2017-05-23 10:31 - 2017-06-18 22:37 - 00000000 ____D C:\WINDOWS\Minidump 2017-05-22 01:31 - 2017-06-21 17:48 - 00004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{08FEE1D4-25C0-4D3B-B4B9-6E4636D53EB8} 2017-05-22 01:25 - 2017-05-22 01:25 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Epson 2017-05-22 01:21 - 2017-05-22 12:07 - 00000949 _____ C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job 2017-05-22 01:21 - 2017-05-22 01:21 - 00004146 _____ C:\WINDOWS\System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} 2017-05-22 01:21 - 2017-05-22 01:21 - 00000000 ____D C:\Program Files\Common Files\EPSON 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software 2017-05-22 01:16 - 2017-05-22 01:24 - 00000000 ____D C:\Program Files (x86)\EPSON Software 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2017-05-22 01:15 - 2017-05-22 01:25 - 00000000 ____D C:\Program Files (x86)\epson 2017-05-22 01:15 - 2017-05-22 01:15 - 00001003 _____ C:\Users\Public\Desktop\EPSON Scan.lnk 2017-05-22 01:15 - 2014-06-03 00:00 - 00472064 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\esxw2ud.dll 2017-05-22 01:15 - 2014-03-05 04:06 - 00180224 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YLMBPLE.DLL 2017-05-22 01:15 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc64.exe 2017-05-22 01:15 - 2011-03-15 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YD4BPLE.DLL 2017-05-22 01:14 - 2017-05-22 01:25 - 00000000 ____D C:\ProgramData\Epson ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-21 18:41 - 2017-05-20 20:00 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Battle.net 2017-06-21 18:26 - 2017-05-20 19:28 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-06-21 13:12 - 2017-05-20 19:30 - 00000000 ____D C:\Users\BrainWasheD 2017-06-21 12:54 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-06-21 12:54 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-06-21 12:53 - 2017-05-20 19:38 - 00000000 ____D C:\ProgramData\NVIDIA 2017-06-20 23:15 - 2017-05-20 19:38 - 02398710 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-06-20 23:15 - 2017-03-20 06:35 - 01096826 _____ C:\WINDOWS\system32\perfh007.dat 2017-06-20 23:15 - 2017-03-20 06:35 - 00246966 _____ C:\WINDOWS\system32\perfc007.dat 2017-06-20 23:09 - 2017-05-20 19:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-06-20 23:08 - 2017-03-18 13:40 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-06-20 17:45 - 2017-05-20 21:01 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\SquirrelTemp 2017-06-20 13:05 - 2017-05-20 19:40 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\CrashDumps 2017-06-18 22:37 - 2017-05-20 18:43 - 00000000 ___DC C:\WINDOWS\Panther 2017-06-18 22:37 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-06-18 21:56 - 2017-05-20 20:55 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\MicrosoftEdge 2017-06-18 13:12 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-06-17 23:13 - 2017-05-21 15:49 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Notepad++ 2017-06-17 01:09 - 2017-05-20 21:20 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-06-17 01:09 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-06-15 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-06-15 09:50 - 2017-05-20 19:35 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-06-15 09:49 - 2017-05-20 19:28 - 00386600 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-06-14 21:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-06-14 18:16 - 2017-05-21 14:57 - 00000000 ____D C:\Users\BrainWasheD\AppData\Roaming\Twitch 2017-06-14 17:12 - 2017-05-21 22:47 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-06-14 17:10 - 2017-05-21 22:47 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-06-14 17:10 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-06-13 16:05 - 2017-05-20 19:35 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Packages 2017-06-07 11:02 - 2017-05-20 21:41 - 00000000 ____D C:\Users\BrainWasheD\Documents\Overwatch 2017-06-03 08:32 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-06-03 08:32 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-06-03 08:07 - 2017-05-20 21:08 - 00000000 ____D C:\Users\BrainWasheD\AppData\Local\Adobe 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-05-29 16:22 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-05-23 10:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-05-22 15:29 - 2017-05-21 23:13 - 00084960 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON23.SYS 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-05-22 01:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning 2017-05-22 01:42 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-05-22 01:24 - 2017-05-20 18:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-05-22 00:19 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-05-22 00:18 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-06-18 13:02 - 2017-06-18 13:02 - 0000053 _____ () C:\Users\BrainWasheD\AppData\Roaming\LogFile.txt 2017-05-20 21:19 - 2017-05-20 21:19 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-06-15 10:48 ==================== Ende von FRST.txt ============================ Ich habe mit ESET die Bedrohungen noch nicht gelöscht, wie es in dem Guide stand. Grüße Raphael |
21.06.2017, 21:34 | #14 | |
/// TB-Ausbilder | New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Servus, Servus, Zitat:
Reste entfernen
Die Fixlog von FRST gleich posten, da diese sonst mit DelFix (siehe weiter unten) automatisch entfernt wird! Dann wären wir durch! Wenn du keine Probleme mehr mit Malware hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst... Vielleicht möchtest du das Forum mit einer kleinen Spende unterstützen. Hinweise: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Cleanup Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte deinen Rechner anschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst du diese bedenkenlos löschen. Virenscanner + Firewall Vorab sei erwähnt, dass man niemals die Schutzwirkung eines Virenscanners überbewerten darf! Kein Antivirusprogramm erkennt 100% der Schadsoftware. Sofern du noch unentschieden bist, verwende MAXIMAL EIN EINZIGES der folgenden Antivirusprogramme mit Echtzeitscanner und stets aktueller Signaturendatenbank:
Microsoft Security Essentials (MSE) / Windows Defender (WD) ist ab Windows 8 fest eingebaut, wenn du also Windows 8, 8.1 oder 10 und dich für MSE/WD entschieden hast, brauchst du nicht extra MSE/WD zu installieren. Bei Windows 7 muss es aber manuell installiert oder über die Windows Updates als optionales Update bezogen werden. Selbstverständlich ist ein legales/aktiviertes Windows Voraussetzung dafür. Verwende immer nur reine Virenscanner (keine Produkte mit "Suite", "Internet Security", "Endpoint" oder "Total Security" in Namen, denn diese bringen kontraproduktive Firewalls mit - die Windows-Firewall ist alles was benötigt wird) Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware , AdwCleaner und mit dem ESET Online Scanner scannen. Diese Programme sind alle kostenlos und stören nicht den Betrieb deines Antivirenprogramms. Absicherungen Beim Betriebsystem Windows ist es wichtig, die automatischen Updates zu aktivieren. Auch sicherheitsrelevante Software sollte immer in aktueller Version vorliegen. Das zeitnahe Einspielen von Updates ist erforderlich, damit Sicherheitslücken geschlossen werden. Sicherheitslücken werden beispielsweise dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Besonders aufpassen bzgl. der Aktualität musst du insbesondere bei folgender Software - sofern diese überhaupt benötigt wird:
Optionale Browsererweiterungen
Grundsätzliches
Lesestoff: Backup-/Image-Tools Damit man sinnvolle Backups hat, muss man regelmäßig (z. B. wöchentlich) ein Image auf eine separate externe Festplatte erstellen. Diese externe Festplatte wird nur dann angeschlossen, wenn man das Backup erstellen will (oder etwas wiederherstellen muss), ansonsten bleibt sie aus Sicherheitsgründen sicher im Schrank verwahrt - allein schon aus dem Grund, die Backups vor "Verschlüsselungstrojanern" zu schützen. Du solltest dich für eines der folgenden Programmen entscheiden und damit regelmäßig deine Daten sichern. Option 1 - Drivesnapshot Drive Snapshot - Disk Image Backup for Windows NT/2000/XP/2003/X64 Download (32-Bit) => http://www.drivesnapshot.de/download/snapshot.exe Download (64-Bit) => http://www.drivesnapshot.de/download/snapshot64.exe Screenshots: http://www.drivesnapshot.de/images/startup.png http://www.drivesnapshot.de/images/save3.png Option 2 - Seagate DiscWizard Seagate DiscWizard - Download - Filepony Screenshots: http://filepony.de/screenshot/seagate_discwizard5.jpg http://filepony.de/screenshot/seagate_discwizard4.png http://filepony.de/screenshot/seagate_discwizard3.jpg Option 3 - Acronis TrueImage WD Edition Acronis True Image WD Edition - Download - Filepony Screenshots: http://filepony.de/screenshot/acroni...d_edition1.jpg http://filepony.de/screenshot/acroni...d_edition2.jpg |
22.06.2017, 18:13 | #15 |
| New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" Hallo Matthias, bis jetzt habe ich keine neuen Tabs bekommen - bin sehr zufrieden mit deiner Hilfe, vielen lieben Dank! Ich werde mich morgen/ übermorgen nochmal melden, ob oder ob keine Tabs geöffnet wurden. Hier der Fixlog: Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 21-06-2017 01 durchgeführt von BrainWasheD (22-06-2017 02:03:47) Run:3 Gestartet von C:\Users\BrainWasheD\Desktop Geladene Profile: BrainWasheD (Verfügbare Profile: BrainWasheD) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** CloseProcesses: E:\Neuinstallation\Windows 10 Update Assistent - CHIP-Installer.exe CMD: del /f /q /s "C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\http_hosted.ap.org_0.localstorage.html" CMD: del /f /q /s "C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\http_hosted.ap.org_0.localstorage-journal.html" EmptyTemp: ***************** Prozesse erfolgreich geschlossen. E:\Neuinstallation\Windows 10 Update Assistent - CHIP-Installer.exe => erfolgreich verschoben ========= del /f /q /s "C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\http_hosted.ap.org_0.localstorage.html" ========= C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\http_hosted.ap.org_0.localstorage.html konnte nicht gefunden werden ========= Ende von CMD: ========= ========= del /f /q /s "C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\http_hosted.ap.org_0.localstorage-journal.html" ========= C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\http_hosted.ap.org_0.localstorage-journal.html konnte nicht gefunden werden ========= Ende von CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 9461760 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9547564 B Java, Flash, Steam htmlcache => 138240 B Windows/system/drivers => 1453888 B Edge => 0 B Chrome => 751684489 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 0 B LocalService => 818 B NetworkService => 0 B BrainWasheD => 184911810 B RecycleBin => 0 B EmptyTemp: => 912.9 MB temporäre Dateien entfernt. ================================ Das System musste neu gestartet werden. ==== Ende von Fixlog 02:03:58 ==== Nachtrag: Leider ist das Problem noch nicht behoben. Gerade nach dem Neustart durchs Nutzen von DelFix kam wieder direkt die Seite 3x aufgeklappt. Also das Problem besteht definitiv weiterhin. Heute mehrfach die Tabs bekommen =/ Geändert von BrainWasheD (22.06.2017 um 01:24 Uhr) |
Themen zu New Tab spam durch "hosted.ap.org" bzw "Cincinnati Enquirer" |
antivirus, dateien, einstellung, erstell, erstellt, explorer, firefox, folge, folgende, geblockt, home, link, minute, problem, seite, spam, standard, startup, stunden, tab, unregelmäßige, verhindern, versucht, windows, zugreifen |