mhh,
Zitat:
Ausnahme: Logfile zu gross
Dies kann passieren und wird passieren. Dann und nur dann kannst du dein Logfile anhängen oder gezippt anhängen. Anleitung dazu weiter unten.
Aber bedenke bitte: Anhänge erschweren deinem Helfer die Arbeit!
----
Code:
Alles auswählen Aufklappen ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 24-06-2017 01
durchgeführt von kevosaurus (Administrator) auf LAPTOP-5SM2C4B0 (25-06-2017 02:07:54)
Gestartet von C:\Users\kevosaurus\Downloads
Geladene Profile: kevosaurus (Verfügbare Profile: kevosaurus)
Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Alcatel\IK40\BackgroundService\ServiceManager.exe
() C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cnext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTServer.exe
() C:\Program Files (x86)\Alcatel\IK40\BackgroundService\ModemListener.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Piotr Pawlowski) C:\Program Files (x86)\foobar2000\foobar2000.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8848640 2016-02-25] (Realtek Semiconductor)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [657424 2016-01-11] (HP Inc.)
HKLM-x32\...\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [258600 2016-01-05] (HP)
HKLM-x32\...\Run: [PowerDVD14Agent] => C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795336 2016-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [97512 2017-05-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [918008 2017-06-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [66656 2017-06-13] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2487143384-3610853813-1122141480-1001\...\Run: [VLC Updater] => C:\Program Files (x86)\VLC Updater\vlc-updater.exe [360776 2017-05-16] () <===== ACHTUNG
HKU\S-1-5-21-2487143384-3610853813-1122141480-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-03-23] (Valve Corporation)
HKU\S-1-5-21-2487143384-3610853813-1122141480-1001\...\MountPoints2: {ee7091f5-9a1c-11e6-b914-ccb0da31f422} - "H:\autorun.exe"
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5200ce38-7328-475f-a0f6-e1f1eecc379c}: [DhcpNameServer] 192.168.224.1
Tcpip\..\Interfaces\{5da9240a-813b-4640-8dc5-2aa329db530d}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{68954510-a24e-4c81-927e-6266f3893d86}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about :blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about :blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\S-1-5-21-2487143384-3610853813-1122141480-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about :blank
HKU\S-1-5-21-2487143384-3610853813-1122141480-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
SearchScopes: HKLM -> {33C822EF-EADB-489F-8838-0D5426A51B66} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {33C822EF-EADB-489F-8838-0D5426A51B66} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-2487143384-3610853813-1122141480-1001 -> {33C822EF-EADB-489F-8838-0D5426A51B66} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-16] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-04-14] (Oracle Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-16] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-04-14] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2015-12-20] (Hewlett-Packard Company)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-16] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-16] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-16] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-16] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: uinu3j7t.default
FF ProfilePath: C:\Users\kevosaurus\AppData\Roaming\Mozilla\Firefox\Profiles\uinu3j7t.default [2017-06-25]
FF Homepage: Mozilla\Firefox\Profiles\uinu3j7t.default -> www.google.de
FF Extension: (Startfenster.de) - C:\Users\kevosaurus\AppData\Roaming\Mozilla\Firefox\Profiles\uinu3j7t.default\Extensions\2@startfenster.de.xpi [2017-05-18]
FF Extension: (Avira Browser Safety) - C:\Users\kevosaurus\AppData\Roaming\Mozilla\Firefox\Profiles\uinu3j7t.default\Extensions\abs@avira.com.xpi [2017-06-06]
FF Extension: (Adblock Plus) - C:\Users\kevosaurus\AppData\Roaming\Mozilla\Firefox\Profiles\uinu3j7t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-08]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-23] ()
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-04-14] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-04-14] (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-04-07] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-04-07] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-23] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1219159.dll [2015-06-26] (Adobe Systems, Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [djhangopedggnlnicpbjklghlckmndge] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AdaptiveSleepService; c:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [138752 2016-03-26] () [Datei ist nicht signiert]
R2 Alcatel KEY40 Modem Device Helper; C:\Program Files (x86)\Alcatel\IK40\BackgroundService\ServiceManager.exe [76584 2014-12-11] ()
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1128432 2017-06-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [490968 2017-06-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [490968 2017-06-14] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1524216 2017-06-14] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [374352 2017-05-22] (Avira Operations GmbH & Co. KG)
R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [334064 2017-05-18] (Avira Operations GmbH & Co. KG)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [127192 2015-11-19] ()
S4 chip1click; C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [91136 2016-10-27] (Chip Digital GmbH) [Datei ist nicht signiert]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4122816 2017-06-10] (Microsoft Corporation)
S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [29728 2016-08-15] (HP Inc.)
S4 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [606224 2016-01-11] (HP Inc.)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-25] (Realtek Semiconductor)
R2 SpeedupService; C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe [74800 2017-06-13] (Avira Operations GmbH & Co. KG)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [266872 2016-08-19] (Synaptics Incorporated)
R2 tbaseprovisioning; C:\WINDOWS\SysWOW64\tbaseprovisioning.exe [51208 2017-01-09] (Advanced Micro Devices, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 AmdAS4; C:\WINDOWS\System32\drivers\AmdAS4.sys [27384 2016-04-03] (Advanced Micro Devices, INC.)
S3 amdkmcsp; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [100744 2017-01-09] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [73976 2016-04-03] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\WINDOWS\System32\DRIVERS\amdpsp.sys [255368 2017-01-09] (Advanced Micro Devices, Inc. )
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [111120 2016-04-03] (Advanced Micro Devices)
R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [60920 2017-06-14] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [167504 2017-06-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [164824 2017-06-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-04-10] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-04-10] (Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [38048 2017-06-14] (Avira Operations GmbH & Co. KG)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 phantomtap; C:\WINDOWS\System32\drivers\phantomtap.sys [45056 2017-05-18] (The OpenVPN Project)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [935168 2016-02-25] (Realtek )
R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [611608 2015-10-07] (Realtek Semiconductor Corporation)
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [413912 2016-02-25] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [6868280 2017-06-19] (Realtek Semiconductor Corporation )
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R3 SmbDrv; C:\WINDOWS\system32\DRIVERS\Smb_driver_AMDASF.sys [68728 2016-08-19] (Synaptics Incorporated)
S3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [62568 2016-03-14] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30544 2015-08-12] (HP)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-06-25 02:07 - 2017-06-25 02:09 - 00017884 _____ C:\Users\kevosaurus\Downloads\FRST.txt
2017-06-25 02:07 - 2017-06-25 02:07 - 00000000 ____D C:\FRST
2017-06-25 02:06 - 2017-06-25 02:06 - 02440704 _____ (Farbar) C:\Users\kevosaurus\Downloads\FRST64.exe
2017-06-25 02:03 - 2017-06-25 02:03 - 01388448 _____ C:\Users\Public\ASR.dat
2017-06-25 01:51 - 2017-06-25 01:51 - 00865236 _____ C:\Users\kevosaurus\Downloads\Dschuang-Dsï(1).pdf
2017-06-25 01:25 - 2017-06-25 01:26 - 01620428 _____ C:\WINDOWS\Minidump\062517-32437-01.dmp
2017-06-24 16:49 - 2017-06-25 01:25 - 00000000 ____D C:\WINDOWS\Minidump
2017-06-24 16:49 - 2017-06-24 16:49 - 01620244 _____ C:\WINDOWS\Minidump\062417-38437-01.dmp
2017-06-24 16:48 - 2017-06-25 01:25 - 627417323 _____ C:\WINDOWS\MEMORY.DMP
2017-06-23 16:07 - 2017-06-25 02:02 - 00000000 ____D C:\Users\Public\Speedup Sessions
2017-06-21 21:57 - 2017-06-21 21:57 - 00000000 ____D C:\WINDOWS\LastGood
2017-06-17 18:54 - 2017-06-17 18:54 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-06-16 23:30 - 2017-06-16 23:30 - 00000782 _____ C:\Users\kevosaurus\Desktop\Downloads - Verknüpfung.lnk
2017-06-16 21:11 - 2017-06-16 21:13 - 00000000 ____D C:\Users\kevosaurus\Desktop\sopranos season4
2017-06-16 18:44 - 2017-06-16 18:44 - 00773592 _____ C:\Users\kevosaurus\Downloads\Jaspers_Philosophie.pdf
2017-06-16 18:34 - 2017-06-16 18:34 - 00219748 _____ C:\Users\kevosaurus\Downloads\29_dufner_-_sidgwicks_utilitarismus.pdf
2017-06-14 22:39 - 2017-06-14 22:38 - 00060920 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avdevprot.sys
2017-06-14 11:50 - 2017-06-03 12:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-14 11:50 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-14 11:50 - 2017-06-03 12:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-14 11:50 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-06-14 11:50 - 2017-06-03 12:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-14 11:50 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-14 11:50 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-06-14 11:50 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-06-14 11:50 - 2017-06-03 11:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-06-14 11:50 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-06-14 11:50 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-06-14 11:50 - 2017-06-03 11:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-06-14 11:50 - 2017-06-03 11:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-06-14 11:50 - 2017-06-03 11:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-14 11:50 - 2017-06-03 11:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-06-14 11:50 - 2017-06-03 11:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-06-14 11:50 - 2017-06-03 11:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-14 11:50 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll
2017-06-14 11:50 - 2017-06-03 11:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-06-14 11:50 - 2017-06-03 11:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-06-14 11:50 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2017-06-14 11:50 - 2017-06-03 11:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-06-14 11:50 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-06-14 11:50 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-14 11:50 - 2017-06-03 11:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-06-14 11:50 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-06-14 11:50 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-14 11:50 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-06-14 11:50 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-14 11:50 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-14 11:50 - 2017-06-03 11:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-14 11:50 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-14 11:50 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-06-14 11:50 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2017-06-14 11:50 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-06-14 11:50 - 2017-06-03 11:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-14 11:50 - 2017-06-03 11:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-14 11:50 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-06-14 11:50 - 2017-06-03 11:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-06-14 11:50 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-06-14 11:50 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll
2017-06-14 11:50 - 2017-06-03 11:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-14 11:50 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-14 11:50 - 2017-06-03 11:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-06-14 11:50 - 2017-06-03 11:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-06-14 11:50 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-06-14 11:50 - 2017-06-03 11:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-14 11:50 - 2017-06-03 11:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-14 11:50 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-14 11:50 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-06-14 11:50 - 2017-06-03 10:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-14 11:50 - 2017-06-03 10:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-06-14 11:50 - 2017-06-03 10:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-14 11:50 - 2017-06-03 10:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-14 11:50 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-14 11:50 - 2017-06-03 10:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-06-14 11:50 - 2017-06-03 10:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-06-14 11:50 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-06-14 11:50 - 2017-06-03 10:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-14 11:50 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-06-14 11:50 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-14 11:50 - 2017-06-03 10:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-06-14 11:50 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-06-14 11:50 - 2017-06-03 10:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-06-14 11:50 - 2017-06-03 10:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-14 11:50 - 2017-06-03 10:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-06-14 11:50 - 2017-06-03 10:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-06-14 11:50 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-06-14 11:50 - 2017-06-03 10:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-06-14 11:50 - 2017-06-03 10:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-06-14 11:50 - 2017-06-03 10:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-06-14 11:50 - 2017-06-03 10:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-06-14 11:50 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-06-14 11:50 - 2017-06-03 10:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-06-14 11:50 - 2017-06-03 10:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-06-14 11:49 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-14 11:49 - 2017-06-03 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-06-14 11:49 - 2017-06-03 12:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-06-14 11:49 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-14 11:49 - 2017-06-03 12:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-14 11:49 - 2017-06-03 12:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-14 11:49 - 2017-06-03 12:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-06-14 11:49 - 2017-06-03 12:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-06-14 11:49 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll
2017-06-14 11:49 - 2017-06-03 11:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-14 11:49 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2017-06-14 11:49 - 2017-06-03 11:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-06-14 11:49 - 2017-06-03 11:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-14 11:49 - 2017-06-03 11:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2017-06-14 11:49 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2017-06-14 11:49 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-14 11:49 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe
2017-06-14 11:49 - 2017-06-03 11:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-06-14 11:49 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2017-06-14 11:49 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-06-14 11:49 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-06-14 11:49 - 2017-06-03 11:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-14 11:49 - 2017-06-03 11:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-06-14 11:49 - 2017-06-03 11:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-06-14 11:49 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-06-14 11:49 - 2017-06-03 11:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-06-14 11:49 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-14 11:49 - 2017-06-03 10:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-14 11:49 - 2017-06-03 10:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-14 11:49 - 2017-06-03 10:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-06-14 11:49 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2017-06-01 13:13 - 2017-06-01 13:13 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 06551856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04537344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04446208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02158544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-06-01 13:13 - 2017-06-01 13:13 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-06-01 13:13 - 2017-06-01 13:13 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01219560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-06-01 13:13 - 2017-06-01 13:13 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-06-01 13:13 - 2017-06-01 13:13 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-06-01 13:13 - 2017-06-01 13:13 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-06-01 13:13 - 2017-06-01 13:13 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-06-01 13:13 - 2017-06-01 13:13 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00335808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2017-06-01 13:13 - 2017-06-01 13:13 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-06-01 13:13 - 2017-06-01 13:13 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-06-01 13:13 - 2017-06-01 13:13 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-06-01 13:13 - 2017-06-01 13:13 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-06-01 13:13 - 2017-06-01 13:13 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll
2017-06-01 13:13 - 2017-06-01 13:13 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2017-06-01 13:12 - 2017-06-01 13:13 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 17365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 04847928 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02635336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02443776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01803264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01325456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01295872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00980992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00406064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-06-01 13:12 - 2017-06-01 13:12 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00142240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
2017-06-01 13:12 - 2017-06-01 13:12 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys
2017-06-01 13:12 - 2017-06-01 13:12 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-06-01 13:12 - 2017-06-01 13:12 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2017-06-01 13:12 - 2017-06-01 13:12 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2017-06-01 13:05 - 2017-06-01 13:05 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-06-01 13:05 - 2017-06-01 12:23 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-06-01 13:04 - 2017-06-01 13:04 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2017-06-01 13:02 - 2017-06-01 13:02 - 00000020 ___SH C:\Users\kevosaurus\ntuser.ini
2017-06-01 13:02 - 2017-06-01 13:02 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-06-01 13:02 - 2017-06-01 13:02 - 00000000 ____D C:\Users\kevosaurus\AppData\Local\DBG
2017-06-01 13:02 - 2017-06-01 13:02 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-06-01 13:02 - 2017-06-01 13:02 - 00000000 ____D C:\Program Files\MSBuild
2017-06-01 13:02 - 2017-06-01 13:02 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-06-01 13:02 - 2017-06-01 13:02 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-06-01 13:02 - 2017-06-01 13:02 - 00000000 ____D C:\inetpub
2017-06-01 13:01 - 2017-06-01 13:01 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-06-01 13:01 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-06-01 13:01 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-06-01 13:01 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-06-01 13:01 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-06-01 13:01 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-06-01 13:01 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-06-01 12:54 - 2017-06-01 12:56 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2017-06-01 12:54 - 2017-06-01 12:56 - 00007623 _____ C:\WINDOWS\diagerr.xml
2017-06-01 12:48 - 2017-06-25 01:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-01 12:47 - 2017-06-23 16:07 - 00003782 _____ C:\WINDOWS\System32\Tasks\AviraSystemSpeedupUpdate
2017-06-01 12:47 - 2017-06-22 09:38 - 00003300 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-01 12:47 - 2017-06-21 23:07 - 00003296 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForkevosaurus
2017-06-01 12:47 - 2017-06-01 12:48 - 00003768 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2017-06-01 12:47 - 2017-06-01 12:48 - 00003544 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2017-06-01 12:47 - 2017-06-01 12:48 - 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-06-01 12:47 - 2017-06-01 12:48 - 00002542 _____ C:\WINDOWS\System32\Tasks\HPDAS
2017-06-01 12:47 - 2017-06-01 12:48 - 00002262 _____ C:\WINDOWS\System32\Tasks\DropboxOEM
2017-06-01 12:47 - 2017-06-01 12:47 - 00000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2017-06-01 12:47 - 2017-06-01 12:47 - 00000000 ____D C:\WINDOWS\System32\Tasks\Avira
2017-06-01 12:38 - 2017-06-01 12:38 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-06-01 12:34 - 2017-06-01 12:34 - 00000000 ____D C:\ProgramData\USOShared
2017-06-01 12:31 - 2017-06-01 12:39 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-06-01 12:29 - 2017-06-25 01:57 - 00000000 ____D C:\Users\kevosaurus
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Vorlagen
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Startmenü
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Netzwerkumgebung
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Lokale Einstellungen
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Eigene Dateien
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Druckumgebung
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Documents\Eigene Videos
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Documents\Eigene Musik
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Documents\Eigene Bilder
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\AppData\Local\Verlauf
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\AppData\Local\Anwendungsdaten
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 _SHDL C:\Users\kevosaurus\Anwendungsdaten
2017-06-01 12:28 - 2017-06-25 02:05 - 02303984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-06-01 12:27 - 2017-06-01 12:27 - 01931144 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-06-01 12:27 - 2017-06-01 12:27 - 00001863 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DTS Audio Control Panel.lnk
2017-06-01 12:27 - 2017-06-01 12:27 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2017-06-01 12:27 - 2017-06-01 12:27 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2017-06-01 12:26 - 2017-06-25 01:57 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-06-01 12:26 - 2017-06-01 12:32 - 00000000 ____D C:\Program Files\AMD
2017-06-01 12:26 - 2017-06-01 12:26 - 00096286 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2017-06-01 12:26 - 2017-06-01 12:26 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_AMDASF_01011.Wdf
2017-06-01 12:26 - 2017-06-01 12:26 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-06-01 12:26 - 2017-06-01 12:26 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2017-06-01 12:26 - 2017-06-01 12:26 - 00000000 ____D C:\Program Files\Synaptics
2017-06-01 12:26 - 2017-06-01 12:26 - 00000000 ____D C:\Program Files\Realtek
2017-06-01 12:26 - 2017-06-01 12:26 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2017-06-01 12:26 - 2017-06-01 12:26 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2017-06-01 12:26 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-06-01 12:25 - 2017-06-01 12:25 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_amdpsp_01011.Wdf
2017-06-01 12:23 - 2017-06-24 16:36 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-01 12:23 - 2017-06-16 20:39 - 00399536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-06-01 11:31 - 2017-06-01 11:32 - 142182064 _____ (Microsoft Corporation) C:\Users\kevosaurus\Downloads\movie-maker-setup-nw.exe
2017-05-31 15:09 - 2017-05-31 15:13 - 00000000 ____D C:\Users\kevosaurus\Downloads\Stenchman - The Stranger Things EP
2017-05-31 15:02 - 2017-05-31 12:57 - 60625196 _____ C:\Users\kevosaurus\Desktop\Philestine + Pillgrim - Philestine - Vague EP - 02 Just Clicked It.wav
2017-05-31 15:02 - 2017-05-31 12:57 - 53250796 _____ C:\Users\kevosaurus\Desktop\Philestine - Philestine - Vague EP - 04 So Sad.wav
2017-05-31 15:02 - 2017-05-31 12:57 - 44043144 _____ C:\Users\kevosaurus\Desktop\Philestine - Philestine - Vague EP - 03 Vague.wav
2017-05-31 15:01 - 2017-05-31 12:57 - 45914360 _____ C:\Users\kevosaurus\Desktop\Philestine - Philestine - Vague EP - 01 That's Not Submarinesque.wav
2017-05-31 15:00 - 2017-05-31 15:06 - 225864251 _____ C:\Users\kevosaurus\Downloads\Stenchman - The Dark Side E.P.zip
2017-05-31 14:57 - 2017-05-31 15:08 - 501697359 _____ C:\Users\kevosaurus\Downloads\Stenchman - THE CLASSICS.zip
2017-05-31 14:57 - 2017-05-31 15:07 - 779568437 _____ C:\Users\kevosaurus\Downloads\Stenchman - 2015 - A Bass Oddity.zip
2017-05-31 14:57 - 2017-05-31 15:02 - 194982650 _____ C:\Users\kevosaurus\Downloads\Stenchman - The Stranger Things EP.zip
2017-05-31 14:57 - 2017-05-31 15:02 - 176230664 _____ C:\Users\kevosaurus\Downloads\Suspicious Stench - Gladiator EP.zip
2017-05-31 14:57 - 2017-05-31 15:00 - 204148984 _____ C:\Users\kevosaurus\Downloads\Philestine - Philestine - Vague EP.zip
2017-05-31 14:56 - 2017-05-31 15:04 - 446530576 _____ C:\Users\kevosaurus\Downloads\Stenchman - V.I.P.E.P.zip
2017-05-30 23:44 - 2017-05-30 23:44 - 00109970 _____ C:\Users\kevosaurus\Downloads\Argumentieren in Wissenschaft und Lebenswelt - Programm_20170413.pdf
2017-05-30 23:44 - 2017-05-30 23:44 - 00109970 _____ C:\Users\kevosaurus\Downloads\Argumentieren in Wissenschaft und Lebenswelt - Programm_20170413(1).pdf
2017-05-30 23:37 - 2017-05-30 23:37 - 00508741 _____ C:\Users\kevosaurus\Desktop\Tetens, Versuch über rationale Theologie.pdf
2017-05-28 17:34 - 2017-06-01 13:02 - 00000000 ___DC C:\WINDOWS\Panther
2017-05-28 01:56 - 2017-05-28 01:56 - 00000000 ____D C:\WINDOWS\pss
2017-05-28 01:55 - 2017-05-28 01:55 - 00000000 ____D C:\Users\kevosaurus\AppData\Local\AviraSpeedup
2017-05-28 01:54 - 2017-05-28 01:54 - 00000000 ____D C:\Users\kevosaurus\AppData\Local\Avira
2017-05-28 01:50 - 2017-05-28 01:50 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Avira
2017-05-28 01:48 - 2017-05-28 01:48 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2017-05-28 01:46 - 2017-06-14 22:38 - 00167504 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2017-05-28 01:46 - 2017-06-14 22:38 - 00164824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2017-05-28 01:46 - 2017-06-14 22:38 - 00038048 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2017-05-28 01:46 - 2017-04-10 13:23 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2017-05-28 01:46 - 2017-04-10 13:23 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2017-05-28 01:39 - 2017-06-23 16:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-05-28 01:39 - 2017-06-23 16:06 - 00000000 ____D C:\Program Files (x86)\Avira
2017-05-28 01:39 - 2017-05-28 01:54 - 00000000 ____D C:\ProgramData\Avira
2017-05-28 01:34 - 2017-05-28 01:34 - 04793496 _____ (Avira Operations GmbH & Co. KG) C:\Users\kevosaurus\Downloads\avira_de_av_592a0cdb5ec13__ws.exe
2017-05-26 16:33 - 2017-05-18 22:25 - 00000000 ____D C:\Users\kevosaurus\Desktop\KD
2017-05-26 14:52 - 2017-05-26 15:41 - 147750550 _____ C:\Users\kevosaurus\Downloads\KD.rar
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-06-25 02:05 - 2017-03-20 06:35 - 01014990 _____ C:\WINDOWS\system32\perfh007.dat
2017-06-25 02:05 - 2017-03-20 06:35 - 00233052 _____ C:\WINDOWS\system32\perfc007.dat
2017-06-25 02:02 - 2016-11-25 02:44 - 00000000 ____D C:\Users\kevosaurus\AppData\LocalLow\Mozilla
2017-06-25 02:02 - 2016-10-22 02:18 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\foobar2000
2017-06-25 01:57 - 2017-03-18 13:40 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-06-25 01:55 - 2017-02-17 14:39 - 00000000 ____D C:\Program Files (x86)\VstPlugins
2017-06-25 01:55 - 2017-02-17 14:38 - 00000000 ____D C:\Program Files (x86)\DSPRobotics
2017-06-25 01:53 - 2017-02-17 14:39 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-06-25 01:53 - 2017-02-17 14:39 - 00000000 ____D C:\Program Files\Image-Line
2017-06-25 01:53 - 2017-02-17 14:33 - 00000000 ____D C:\Program Files (x86)\Image-Line
2017-06-24 16:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-06-24 16:48 - 2017-03-18 17:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-24 16:48 - 2016-10-21 23:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-24 16:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-24 03:11 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF
2017-06-23 16:00 - 2016-10-29 11:06 - 00000384 _____ C:\WINDOWS\Tasks\HPCeeScheduleForkevosaurus.job
2017-06-23 15:39 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-22 09:38 - 2016-10-21 19:05 - 00002409 _____ C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-06-22 09:38 - 2016-10-21 19:05 - 00000000 ___RD C:\Users\kevosaurus\OneDrive
2017-06-19 03:13 - 2017-05-03 04:27 - 06868280 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\rtwlane.sys
2017-06-19 03:13 - 2017-05-03 04:27 - 01182520 _____ (Realtek Semiconductor Corp. ) C:\WINDOWS\system32\Rtlihvs.dll
2017-06-17 17:29 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache
2017-06-16 21:04 - 2016-04-16 05:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-06-16 20:45 - 2015-11-02 20:02 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-16 20:37 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-06-16 20:37 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-16 06:33 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-14 12:00 - 2016-10-21 23:13 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-14 11:55 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-14 11:55 - 2016-10-21 23:12 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-06-11 13:22 - 2016-12-09 00:42 - 00000000 ____D C:\Users\kevosaurus\Documents\My Kindle Content
2017-06-08 08:05 - 2016-11-02 22:10 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\vlc
2017-06-06 21:54 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat
2017-06-03 08:32 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-03 08:32 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-01 13:21 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-06-01 13:20 - 2016-10-21 19:01 - 00000000 ____D C:\Users\kevosaurus\AppData\Local\Packages
2017-06-01 13:15 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-06-01 13:14 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-06-01 13:14 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-06-01 13:02 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-06-01 13:02 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-06-01 13:02 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-06-01 13:02 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-06-01 13:02 - 2017-03-18 22:59 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2017-06-01 13:02 - 2017-03-18 22:59 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2017-06-01 13:02 - 2017-03-18 22:59 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2017-06-01 13:02 - 2017-03-18 22:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00465408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2017-06-01 13:02 - 2017-03-18 22:56 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2017-06-01 13:02 - 2017-03-18 22:56 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2017-06-01 13:02 - 2017-03-18 22:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2017-06-01 13:02 - 2017-03-18 22:56 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2017-06-01 13:02 - 2016-11-18 10:49 - 00000000 ____D C:\Users\kevosaurus\AppData\Local\ConnectedDevicesPlatform
2017-06-01 12:57 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT
2017-06-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-06-01 12:54 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration
2017-06-01 12:54 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-06-01 12:48 - 2017-03-20 06:37 - 00000000 ____D C:\WINDOWS\HoloShell
2017-06-01 12:48 - 2016-11-18 04:12 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-06-01 12:46 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-06-01 12:42 - 2016-08-20 14:55 - 00000000 ____D C:\WINDOWS\tbaseregistry
2017-06-01 12:39 - 2017-05-18 20:17 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startfenster-Replace
2017-06-01 12:39 - 2017-05-18 20:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster Symbol
2017-06-01 12:39 - 2017-05-18 20:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoodGame
2017-06-01 12:39 - 2017-05-11 23:00 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-06-01 12:39 - 2017-05-06 18:11 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
2017-06-01 12:39 - 2017-04-14 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-06-01 12:39 - 2017-02-17 14:42 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KORG
2017-06-01 12:39 - 2017-02-17 14:40 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2017-06-01 12:39 - 2017-02-17 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-06-01 12:39 - 2016-11-25 20:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-06-01 12:39 - 2016-11-22 19:44 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-06-01 12:39 - 2016-11-22 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-06-01 12:39 - 2016-11-16 12:03 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2017-06-01 12:39 - 2016-11-16 11:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack
2017-06-01 12:39 - 2016-11-02 22:04 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC Updater
2017-06-01 12:39 - 2016-10-24 21:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Web Connection
2017-06-01 12:39 - 2016-10-21 19:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools
2017-06-01 12:39 - 2016-08-20 14:59 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-06-01 12:39 - 2016-08-20 14:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2017-06-01 12:39 - 2016-04-16 05:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2017-06-01 12:38 - 2015-10-30 08:28 - 00000000 ____D C:\Users\Default.migrated
2017-06-01 12:34 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-06-01 12:34 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool
2017-06-01 12:34 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-06-01 12:34 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-06-01 12:34 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate
2017-06-01 12:34 - 2016-11-14 20:51 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2017-06-01 12:34 - 2016-08-20 14:52 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-06-01 12:34 - 2016-04-16 05:32 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe
2017-06-01 12:33 - 2016-11-14 20:51 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2017-06-01 12:32 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-06-01 12:31 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-06-01 12:30 - 2016-12-09 00:42 - 00000000 ____D C:\Users\kevosaurus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2017-06-01 12:27 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-05-28 02:09 - 2016-11-16 11:18 - 00000000 ____D C:\Program Files\WinHTTrack
2017-05-28 02:09 - 2016-08-20 14:58 - 00000000 ____D C:\WINDOWS\HP
2017-05-28 02:08 - 2016-11-25 20:20 - 00000000 ____D C:\Program Files (x86)\Steam
2017-05-28 01:52 - 2016-10-23 22:07 - 00000000 ____D C:\Program Files\TrueKey
2017-05-28 01:52 - 2016-08-20 15:15 - 00000000 ____D C:\ProgramData\McAfee
2017-05-28 01:45 - 2016-10-22 01:02 - 00000000 ____D C:\ProgramData\Intel Security
2017-05-28 01:39 - 2016-04-16 05:31 - 00000000 ____D C:\ProgramData\Package Cache
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2016-11-04 14:22 - 2016-11-04 14:22 - 0009336 _____ () C:\Users\kevosaurus\AppData\Roaming\Durch Trennzeichen getrennte Werte.EML
2017-05-28 02:11 - 2017-06-25 02:02 - 0074275 _____ () C:\Users\kevosaurus\AppData\Local\BTServer.log
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Program Files (x86)\VLC Updater\vlc-updater.exe
C:\Users\Public\ASR.dat
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-06-15 12:49
==================== Ende von FRST.txt ============================
__________________