|
Log-Analyse und Auswertung: Malware verhindert MBAM/Windows DefenderWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.07.2017, 20:14 | #1 |
| Malware verhindert MBAM/Windows Defender Guten Abend, Leider habe ich vergessen, eine Datei aus unsicherer Quelle zu scannen und mir prompt Ad-/Mal ware eingefangen. Sofort nach dem Starten der .exe Datei öffneten sich einige cmd-Konsolen, verschwanden wieder und der PC ist herunter gefahren. Meine Datengrab HDD habe ich vor dem neu starten abgezogen und bis jetzt nicht wieder angeschlossen. Nach dem Neustart haben sich alle paar Sekunden Tabs im Firefox mit dubioser Werbung geöffnet. Ich habe auf eigene Faust reflexmäßig die kostenlose Variante von MBAM installiert und einen Suchlauf gestartet. Es wurden Treffer "bitcoin.mine" sowie "adware" gefunden, unter Quarantäne gestellt und gelöscht. Nach einem 2. Neustart das gleiche Spiel, nur die Adware-Tabs blieben aus. Aber wieder wurden die gleichen Treffer gefunden. Nach dem dritten Neustart ließ sich MBAM nicht mehr starten oder deinstallieren. Es erfolgt keine Fehlermeldung beim Startversuch, es passiert jedoch auch nichts und der Balken bei der Deinstallation bleibt auch nach 2 Stunden einfach leer. Da ich MBAM nicht mehr starten kann habe ich leider auch keinen Zugriff auf dieses Log. Auch der Windows Defender wird automatisch wieder ausgeschaltet, sobald ich ihn aktiviere. In einem Akt der Verzweiflung habe ich noch Kaspersky Security Scan installiert, der jedoch nur auf Risiken im System, wie z.B. aktivierten Autostart aufmerksam gemacht hat. Vielen Dank vorab für die Hilfe und hier die nötigen Logs: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 05-07-2017 durchgeführt von Raphael (Administrator) auf RAPHAEL-PC (05-07-2017 20:32:36) Gestartet von F:\Downloads Geladene Profile: Raphael (Verfügbare Profile: Raphael & Silvia & Browsergame & DefaultAppPool) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe () C:\Windows\SysWOW64\ASGT.exe (Aqua Computer GmbH & Co. KG) C:\Program Files\aquasuite\AquaComputerService.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Copyright (c) 2016 Plays.tv, LLC) C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Electronic Arts) F:\Origin\OriginWebHelperService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Malwarebytes) C:\ProgramData\Malwarebytes\MBAMService\ctlrupdate\mbupdatr.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe (Mega Limited) C:\Users\Raphael\AppData\Local\MEGAsync\MEGAsync.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Aqua Computer GmbH & Co. KG) C:\Program Files\aquasuite\aquasuite.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Rainmeter) C:\Program Files\Rainmeter\Rainmeter.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\assistant.exe (MegaDev GmbH) C:\Program Files (x86)\MegaDev\MegaTrainerUltimate\MegaTrainerClient.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2016-08-22] (Realtek Semiconductor) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation) HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [502328 2012-05-22] (MSI) HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [317824 2016-01-18] () HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2016-06-16] (Razer Inc.) HKLM-x32\...\Run: [PlaysTV] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [50448 2016-10-26] (Copyright (c) 2016 Plays.tv, LLC) HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58584 2016-09-29] (Raptr, Inc) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [Steam] => F:\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Raphael\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [397632 2013-05-02] () HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [4006464 2017-03-04] (GOG.com) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [Dropbox Update] => C:\Users\Raphael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-12] (Dropbox, Inc.) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [Kaspersky Software Updater] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe [1565000 2016-11-26] (AO Kaspersky Lab) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [570880 2017-03-18] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab) Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-07-11] ShortcutTarget: Dropbox.lnk -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2017-07-02] ShortcutTarget: MEGAsync.lnk -> C:\Users\Raphael\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited) Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Persbackup.lnk [2017-01-27] ShortcutTarget: Persbackup.lnk -> C:\Program Files\Personal Backup 5\Persbackup.exe (Dr. J. Rathlev, D-24222 Schwentinental) Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2016-10-12] ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Rainmeter) CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\..\Interfaces\{39551bc5-e46b-426e-8acf-0fa574427924}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{644abf41-5e82-4883-afee-da3d640e572b}: [NameServer] 192.168.0.1,8.8.8.8 Internet Explorer: ================== BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-07-02] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-02] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-07-02] (Oracle Corporation) BHO-x32: Flagfox -> {BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} -> C:\Users\Raphael\AppData\LocalLow\Flagfox\IE\Flagfox.dll [2013-04-28] (Dave G) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-02] (Oracle Corporation) FireFox: ======== FF ProfilePath: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default [2017-07-05] FF user.js: detected! => C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\user.js [2017-07-02] FF NewTab: Mozilla\Firefox\Profiles\3akgwe11.default -> chrome://unitedtb/content/newtab/newtab-page.xhtml FF SelectedSearchEngine: Mozilla\Firefox\Profiles\3akgwe11.default -> Bing® FF Homepage: Mozilla\Firefox\Profiles\3akgwe11.default -> about:home FF Session Restore: Mozilla\Firefox\Profiles\3akgwe11.default -> ist aktiviert. FF NetworkProxy: Mozilla\Firefox\Profiles\3akgwe11.default -> type", 0 FF Extension: (WEB.DE MailCheck) - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\Extensions\mailcheck@web.de [2015-06-19] [ist nicht signiert] FF Extension: (Adblock Plus) - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-07-29] FF Extension: (Bitdefender QuickScan) - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2017-01-31] FF SearchPlugin: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\searchplugins\bing-lavasoft.xml [2016-04-13] FF SearchPlugin: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\searchplugins\deskmodder-wiki-de.xml [2017-01-27] FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-07-03] [ist nicht signiert] FF Extension: (UITBAutoInstaller) - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2015-07-03] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff => nicht gefunden FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-16] () FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-02] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-02] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-16] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-02] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-02] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3946114199-4031152989-3939253435-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Raphael\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-11] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3946114199-4031152989-3939253435-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Raphael\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-02] (Amazon.com, Inc.) FF Plugin HKU\S-1-5-21-3946114199-4031152989-3939253435-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2017-03-03] () Chrome: ======= CHR Profile: C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default [2017-07-02] CHR Extension: (Google Präsentationen) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-22] CHR Extension: (Google Docs) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-22] CHR Extension: (Google Drive) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-22] CHR Extension: (YouTube) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-22] CHR Extension: (Google Cast) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2017-01-22] CHR Extension: (Flagfox) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfdfamfnacokbbbnmpdfmhonipnhmbid [2017-01-22] [UpdateUrl: hxxp://www.35de-jhdsfhjdfs.com/a/update/chrome/update.xml] <==== ACHTUNG CHR Extension: (Adobe Acrobat) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-22] CHR Extension: (Google Tabellen) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-22] CHR Extension: (Google Docs Offline) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-22] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-22] CHR Extension: (Google Mail) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-22] CHR Extension: (Chrome Media Router) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-22] CHR HKLM-x32\...\Chrome\Extension: [cfdfamfnacokbbbnmpdfmhonipnhmbid] - C:\Users\Raphael\AppData\LocalLow\Flagfox\CHROME\Flagfox.crx [2013-04-28] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Aqua Computer Service; C:\Program Files\aquasuite\AquaComputerService.exe [2413960 2016-12-07] (Aqua Computer GmbH & Co. KG) R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [Datei ist nicht signiert] R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [388968 2016-04-26] (Digital Wave Ltd.) S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [284736 2017-03-04] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6625856 2017-03-04] (GOG.com) S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert] R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-03-29] (Intel Corporation) R2 kss; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab) R3 ksu; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe [1565000 2016-11-26] (AO Kaspersky Lab) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [142904 2012-05-22] (MSI) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S3 Origin Client Service; F:\Origin\OriginClientService.exe [2168208 2017-06-15] (Electronic Arts) R2 Origin Web Helper Service; F:\Origin\OriginWebHelperService.exe [3148184 2017-06-15] (Electronic Arts) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [Datei ist nicht signiert] R2 PlaysService; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [54544 2016-10-26] (Copyright (c) 2016 Plays.tv, LLC) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-12-25] () R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.) R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmdag.sys [36558208 2017-05-16] (Advanced Micro Devices, Inc.) R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmpag.sys [528760 2017-05-16] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-12-08] (Advanced Micro Devices) S3 atillk64; C:\Program Files (x86)\ASUS\GPU Tweak\atillk64.sys [14608 2006-07-19] (ATI Technologies Inc.) R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [314016 2014-08-09] () S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [23680 2010-02-23] (ASUSTeK Computer Inc.) R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [43680 2013-04-24] () R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188312 2017-07-02] (Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [252832 2017-07-02] (Malwarebytes) R1 MpKsl8b871e5b; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{239C8D54-62BE-4DB3-9E03-C1BB900AD565}\MpKsl8b871e5b.sys [44928 2017-07-02] (Microsoft Corporation) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [14136 2010-01-18] (MSI) S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v2B0\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [Datei ist nicht signiert] R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [937728 2016-05-17] (Realtek ) R3 rzdaendpt; C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720 2015-08-13] (Razer Inc) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-22] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-14] (Razer, Inc.) S3 RzSynapse; C:\WINDOWS\System32\drivers\RzSynapse.sys [166400 2011-10-11] (Razer USA Ltd) [Datei ist nicht signiert] R3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 ssudserd; C:\WINDOWS\system32\DRIVERS\ssudserd.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) R3 WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [268800 2014-04-28] (Jungo Connectivity) R3 WinRing0_1_2_0; C:\Program Files\aquasuite\AquaComputerService.sys [14544 2017-07-02] (OpenLibSys.org) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-07-05 20:31 - 2017-07-05 20:32 - 00000000 ____D C:\FRST 2017-07-04 19:41 - 2017-07-04 19:41 - 00001313 _____ C:\Users\Public\Desktop\Kaspersky Software Updater.lnk 2017-07-04 19:41 - 2017-07-04 19:41 - 00001131 _____ C:\Users\Public\Desktop\Kaspersky Security Scan.lnk 2017-07-04 19:41 - 2017-07-04 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Software Updater 2017-07-04 19:41 - 2017-07-04 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan 2017-07-04 19:41 - 2017-07-04 19:41 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2017-07-04 19:41 - 2017-07-04 19:41 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2017-07-04 19:39 - 2017-07-04 19:39 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2017-07-02 23:14 - 2017-07-02 23:14 - 00000306 __RSH C:\ProgramData\ntuser.pol 2017-07-02 23:08 - 2017-07-03 20:29 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-07-02 23:08 - 2017-07-03 20:29 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-07-02 23:08 - 2017-07-03 20:29 - 00044960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-07-02 23:08 - 2017-07-02 23:09 - 00188312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-07-02 23:08 - 2017-07-02 23:08 - 00001915 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-07-02 23:08 - 2017-07-02 23:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-07-02 23:08 - 2017-07-02 23:08 - 00000000 ____D C:\Program Files\Malwarebytes 2017-07-02 23:08 - 2017-05-31 11:09 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-07-02 22:58 - 2017-07-02 23:13 - 00000000 ____D C:\Program Files\UXW6ZEE8PL 2017-07-02 22:58 - 2017-07-02 22:58 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\k1zwksbzduz 2017-07-02 22:51 - 2017-07-02 22:51 - 00003764 _____ C:\WINDOWS\System32\Tasks\updater 2017-07-02 22:51 - 2017-07-02 22:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件 2017-07-02 22:50 - 2017-07-02 23:13 - 00000000 ____D C:\Program Files (x86)\fL3y0Saiyu 2017-07-02 22:50 - 2017-07-02 23:12 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\devnull 2017-07-02 22:50 - 2017-07-02 22:50 - 00930816 _____ C:\Users\Raphael\AppData\Local\test_db_cara.db 2017-07-02 22:50 - 2017-07-02 22:50 - 00140800 _____ C:\Users\Raphael\AppData\Local\installer.dat 2017-07-02 22:50 - 2017-07-02 22:50 - 00016838 _____ C:\WINDOWS\System32\Tasks\CooRink Portable 2017-07-02 22:50 - 2017-07-02 22:50 - 00016788 _____ C:\WINDOWS\System32\Tasks\SwapHome 2017-07-02 22:50 - 2017-07-02 22:50 - 00011568 _____ C:\Users\Raphael\AppData\Local\InstallationConfiguration.xml 2017-07-02 22:50 - 2017-07-02 22:50 - 00000002 _____ C:\END 2017-07-02 22:50 - 2017-07-02 22:50 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Tencent 2017-07-02 22:50 - 2017-07-02 22:50 - 00000000 ____D C:\Users\Raphael\AppData\Local\AdvinstAnalytics 2017-07-02 22:50 - 2017-07-02 22:50 - 00000000 ____D C:\ProgramData\Tencent 2017-07-02 22:50 - 2017-07-02 22:50 - 00000000 ____D C:\Program Files (x86)\Tencent 2017-07-02 22:50 - 2017-07-02 01:40 - 02001920 ___SH (Micrasaft Carparation) C:\WINDOWS\C_02iu47.dat 2017-07-02 22:50 - 2017-06-08 03:59 - 00158920 _____ (Tencent) C:\WINDOWS\SysWOW64\MMInstaller.dll 2017-07-02 22:49 - 2017-07-02 23:13 - 00000000 ____D C:\Program Files\TH3XPQP0V1 2017-07-02 22:49 - 2017-07-02 23:13 - 00000000 ____D C:\Program Files\R3MCTN2THA 2017-07-02 22:49 - 2017-07-02 22:50 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\2y2slneb2xm 2017-07-02 22:49 - 2017-07-02 22:50 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\2xwswhtv2rl 2017-07-02 22:49 - 2017-07-02 22:49 - 00000000 ____D C:\Users\Raphael\AppData\Local\CrashRpt 2017-07-02 22:49 - 2017-07-02 22:49 - 00000000 ____D C:\Program Files (x86)\jena5f2tmwt 2017-07-02 22:24 - 2017-07-02 22:26 - 00000000 ____D C:\ProgramData\MegaTrainerUltimate 2017-07-02 22:24 - 2017-07-02 22:24 - 00001443 _____ C:\Users\Public\Desktop\MegaTrainer.lnk 2017-07-02 22:24 - 2017-07-02 22:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MegaTrainerUltimate 2017-07-02 22:24 - 2017-07-02 22:24 - 00000000 ____D C:\Program Files (x86)\MegaDev 2017-07-02 21:41 - 2017-07-02 21:41 - 00000000 ____D C:\Users\Raphael\Documents\screens 2017-07-02 21:41 - 2017-07-02 21:41 - 00000000 ____D C:\Users\Raphael\Documents\fmdata 2017-07-02 21:41 - 2017-07-02 21:41 - 00000000 ____D C:\Users\Raphael\Documents\desk_objects 2017-07-02 21:40 - 2017-07-02 21:40 - 00000000 ____D C:\Users\Raphael\Documents\art_fm 2017-07-02 21:39 - 2017-07-02 21:40 - 00000000 ____D C:\Users\Raphael\Documents\art 2017-07-02 21:33 - 2017-07-02 21:33 - 01207319 _____ C:\WINDOWS\unins000.exe 2017-07-02 21:33 - 2017-07-02 21:33 - 00010826 _____ C:\WINDOWS\unins000.dat 2017-07-02 21:33 - 2017-07-02 21:33 - 00001998 _____ C:\AiOLog.txt 2017-07-02 21:33 - 2017-04-01 20:44 - 03450616 _____ (Red Hat) C:\WINDOWS\system32\cygwin1.dll 2017-07-02 21:33 - 2017-01-26 07:25 - 01265664 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\libeay32.dll 2017-07-02 21:33 - 2017-01-26 07:25 - 00274944 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\ssleay32.dll 2017-07-02 21:33 - 2017-01-26 07:25 - 00274944 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\libssl32.dll 2017-07-02 21:33 - 2015-07-10 11:51 - 00456008 _____ (AutoIt Team) C:\WINDOWS\system32\autoitx3.dll 2017-07-02 21:33 - 2014-01-31 03:14 - 01055676 _____ (Free Software Foundation) C:\WINDOWS\system32\libiconv2.dll 2017-07-02 21:33 - 2014-01-25 14:30 - 00131072 _____ (Sereby Corporation) C:\WINDOWS\system32\AiORuntimes.dll 2017-07-02 21:33 - 2013-12-23 15:44 - 00163480 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 01070232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscomctl.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00660120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscomct2.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00617896 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00444328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshflxgd.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00416408 _____ (Microsoft Corporation ) C:\WINDOWS\system32\comct332.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00279192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdatgrd.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00259736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msflxgrd.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00253080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdatlst.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00222360 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabctl32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00219288 _____ (Microsoft Corporation) C:\WINDOWS\system32\richtx32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00218776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dblist32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00212112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mci32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00179352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmask32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00170920 _____ (Microsoft Corporation) C:\WINDOWS\system32\comct232.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00131728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinet.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00130712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msstdfmt.dll 2017-07-02 21:33 - 2013-12-20 01:48 - 00127640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswinsck.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00119960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscomm32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00108696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msstkprp.dll 2017-07-02 21:33 - 2013-12-20 01:48 - 00104088 _____ (Microsoft Corporation) C:\WINDOWS\system32\picclp32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00084624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysinfo.ocx 2017-07-02 21:33 - 2012-06-14 15:36 - 00107520 _____ C:\WINDOWS\system32\zlib1.dll 2017-07-02 21:33 - 2012-04-03 17:11 - 00138752 _____ C:\WINDOWS\system32\libpng15.dll 2017-07-02 21:33 - 2011-10-12 04:09 - 04033440 _____ (Intel Corporation) C:\WINDOWS\system32\libmmd.dll 2017-07-02 21:33 - 2011-01-12 14:36 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71u.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71DEU.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71ITA.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71FRA.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71ESP.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71ENU.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71KOR.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71JPN.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71CHT.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71CHS.dll 2017-07-02 21:33 - 2011-01-12 14:19 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71.dll 2017-07-02 21:33 - 2011-01-12 13:53 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl71.dll 2017-07-02 21:33 - 2010-06-27 18:44 - 00053248 _____ (Adobe Systems, Incorporated) C:\WINDOWS\system\plugin.dll 2017-07-02 21:33 - 2010-03-18 21:21 - 00799568 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdia100.dll 2017-07-02 21:33 - 2008-08-26 07:40 - 00162304 _____ C:\WINDOWS\system32\libpng13.dll 2017-07-02 21:33 - 2007-02-01 23:13 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp71.dll 2017-07-02 21:33 - 2007-02-01 20:11 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr71.dll 2017-07-02 21:33 - 2007-01-30 23:04 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr70.dll 2017-07-02 21:33 - 2006-08-26 01:28 - 01017344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70u.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70ITA.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70FRA.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70ESP.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70DEU.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70ENU.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70KOR.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70JPN.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70CHT.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70CHS.dll 2017-07-02 21:33 - 2006-08-26 01:07 - 01024000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70.dll 2017-07-02 21:33 - 2006-08-26 00:17 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl70.dll 2017-07-02 21:33 - 2005-05-06 14:52 - 00103424 _____ (GNU <www.gnu.org>) C:\WINDOWS\system32\libintl3.dll 2017-07-02 21:33 - 2005-01-20 20:25 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvci70.dll 2017-07-02 21:33 - 2002-01-05 06:40 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp70.dll 2017-07-02 21:33 - 1996-01-12 04:00 - 00935632 _____ (Microsoft Corporation) C:\WINDOWS\system\vb40016.dll 2017-07-02 21:33 - 1996-01-12 04:00 - 00722192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vb40032.dll 2017-07-02 21:33 - 1994-11-17 14:00 - 00210944 _____ C:\WINDOWS\system\msvcrt10.dll 2017-07-02 21:33 - 1993-05-11 20:00 - 00398416 _____ (Microsoft Corporation) C:\WINDOWS\system\vbrun300.dll 2017-07-02 21:33 - 1992-10-21 01:00 - 00356992 _____ (Microsoft Corporation) C:\WINDOWS\system\vbrun200.dll 2017-07-02 21:33 - 1991-05-10 02:00 - 00271264 _____ C:\WINDOWS\system\vbrun100.dll 2017-07-02 21:31 - 2017-07-02 21:31 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2017-07-02 21:31 - 2017-07-02 21:31 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2017-07-02 21:31 - 2017-07-02 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-07-02 19:20 - 2017-07-02 19:20 - 00001179 _____ C:\Users\Raphael\Desktop\MEGAsync.lnk 2017-07-02 19:20 - 2017-07-02 19:20 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync 2017-07-02 19:20 - 2017-07-02 19:20 - 00000000 ____D C:\Users\Raphael\AppData\Local\MEGAsync 2017-07-02 19:20 - 2017-07-02 19:20 - 00000000 ____D C:\Users\Raphael\AppData\Local\Mega Limited 2017-07-02 19:11 - 2017-07-02 21:42 - 00000000 ____D C:\Users\Raphael\Documents\FUSSBALL MANAGER 16-17 2017-06-27 22:31 - 2017-06-27 22:31 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-06-26 14:40 - 2017-06-26 14:40 - 00070424 _____ (Driver Lace514) C:\WINDOWS\system32\Drivers\Lace_wpf_x64.sys 2017-06-15 18:44 - 2017-06-15 18:44 - 00000000 ____D C:\Users\Raphael\.mputils 2017-06-15 18:33 - 2017-06-15 18:33 - 00030263 _____ C:\Users\Raphael\Documents\Hochzeit Isabell u. Gabriel.pdf 2017-06-15 17:59 - 2017-06-15 17:59 - 00001036 _____ C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk 2017-06-15 17:59 - 2017-06-15 17:59 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Twitch 2017-06-15 16:52 - 2017-06-15 16:52 - 00000000 ____D C:\Users\Raphael\AppData\Local\DBG 2017-06-15 12:49 - 2017-06-15 18:28 - 00039566 _____ C:\Users\Raphael\Documents\Hochzeit Isabell u. Gabriel.odg 2017-06-15 11:24 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-06-15 11:24 - 2017-06-03 12:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-06-15 11:24 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-06-15 11:24 - 2017-06-03 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-06-15 11:24 - 2017-06-03 12:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-06-15 11:24 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2017-06-15 11:24 - 2017-06-03 12:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-06-15 11:24 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2017-06-15 11:24 - 2017-06-03 12:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2017-06-15 11:24 - 2017-06-03 12:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-06-15 11:24 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2017-06-15 11:24 - 2017-06-03 12:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-06-15 11:24 - 2017-06-03 12:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-06-15 11:24 - 2017-06-03 12:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-06-15 11:24 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll 2017-06-15 11:24 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-06-15 11:24 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-06-15 11:24 - 2017-06-03 11:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-06-15 11:24 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-06-15 11:24 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2017-06-15 11:24 - 2017-06-03 11:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-06-15 11:24 - 2017-06-03 11:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-06-15 11:24 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2017-06-15 11:24 - 2017-06-03 11:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-06-15 11:24 - 2017-06-03 11:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-06-15 11:24 - 2017-06-03 11:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-06-15 11:24 - 2017-06-03 11:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2017-06-15 11:24 - 2017-06-03 11:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-06-15 11:24 - 2017-06-03 11:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-06-15 11:24 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll 2017-06-15 11:24 - 2017-06-03 11:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-06-15 11:24 - 2017-06-03 11:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-06-15 11:24 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2017-06-15 11:24 - 2017-06-03 11:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-06-15 11:24 - 2017-06-03 11:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-06-15 11:24 - 2017-06-03 11:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll 2017-06-15 11:24 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2017-06-15 11:24 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2017-06-15 11:24 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-06-15 11:24 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-06-15 11:24 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-06-15 11:24 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-06-15 11:24 - 2017-06-03 11:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-06-15 11:24 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-06-15 11:24 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe 2017-06-15 11:24 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll 2017-06-15 11:24 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll 2017-06-15 11:24 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-06-15 11:24 - 2017-06-03 11:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-06-15 11:24 - 2017-06-03 11:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-06-15 11:24 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2017-06-15 11:24 - 2017-06-03 11:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2017-06-15 11:24 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe 2017-06-15 11:24 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2017-06-15 11:24 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2017-06-15 11:24 - 2017-06-03 11:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-06-15 11:24 - 2017-06-03 11:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-06-15 11:24 - 2017-06-03 11:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-06-15 11:24 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll 2017-06-15 11:24 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll 2017-06-15 11:24 - 2017-06-03 11:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-06-15 11:24 - 2017-06-03 11:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-06-15 11:24 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-06-15 11:24 - 2017-06-03 11:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-06-15 11:24 - 2017-06-03 11:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2017-06-15 11:24 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2017-06-15 11:24 - 2017-06-03 11:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-06-15 11:24 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-06-15 11:24 - 2017-06-03 11:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-06-15 11:24 - 2017-06-03 11:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-06-15 11:24 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-06-15 11:24 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-06-15 11:24 - 2017-06-03 10:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2017-06-15 11:24 - 2017-06-03 10:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2017-06-15 11:24 - 2017-06-03 10:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-06-15 11:24 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-06-15 11:24 - 2017-06-03 10:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-06-15 11:24 - 2017-06-03 10:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2017-06-15 11:24 - 2017-06-03 10:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-06-15 11:24 - 2017-06-03 10:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-06-15 11:24 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-06-15 11:24 - 2017-06-03 10:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-06-15 11:24 - 2017-06-03 10:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-06-15 11:24 - 2017-06-03 10:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-06-15 11:24 - 2017-06-03 10:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-06-15 11:24 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2017-06-15 11:24 - 2017-06-03 10:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-06-15 11:24 - 2017-06-03 10:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2017-06-15 11:24 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe 2017-06-15 11:24 - 2017-05-20 11:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-06-15 11:24 - 2017-05-20 10:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2017-06-15 11:24 - 2017-05-20 10:48 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-06-15 11:24 - 2017-05-20 10:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-06-15 11:24 - 2017-05-20 10:46 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-06-15 11:24 - 2017-05-20 10:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2017-06-15 11:24 - 2017-05-20 10:46 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-06-15 11:24 - 2017-05-20 10:45 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-06-15 11:24 - 2017-05-20 10:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-06-15 11:24 - 2017-05-20 10:44 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2017-06-15 11:24 - 2017-05-20 10:29 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-06-15 11:24 - 2017-05-20 10:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2017-06-15 11:24 - 2017-05-20 10:27 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-06-15 11:24 - 2017-05-20 10:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll 2017-06-15 11:24 - 2017-05-20 10:26 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll 2017-06-15 11:24 - 2017-05-20 10:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2017-06-15 11:24 - 2017-05-20 10:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2017-06-15 11:24 - 2017-05-20 10:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll 2017-06-15 11:24 - 2017-05-20 10:24 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2017-06-15 11:24 - 2017-05-20 10:23 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-06-15 11:24 - 2017-05-20 10:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-06-15 11:24 - 2017-05-20 10:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2017-06-15 11:24 - 2017-05-20 10:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2017-06-15 11:24 - 2017-05-20 10:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2017-06-15 11:24 - 2017-05-20 10:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2017-06-15 11:24 - 2017-05-20 10:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2017-06-15 11:24 - 2017-05-20 10:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-06-15 11:24 - 2017-05-20 10:20 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-06-15 11:24 - 2017-05-20 10:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-06-15 11:24 - 2017-05-20 10:20 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2017-06-15 11:24 - 2017-05-20 10:19 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-06-15 11:24 - 2017-05-20 10:18 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-06-15 11:24 - 2017-05-20 10:17 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-06-15 11:24 - 2017-05-20 10:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-06-15 11:24 - 2017-05-20 10:17 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-06-15 11:24 - 2017-05-20 10:17 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll 2017-06-15 11:24 - 2017-05-20 10:16 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-06-15 11:24 - 2017-05-20 10:16 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-06-15 11:24 - 2017-05-20 10:16 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2017-06-15 11:24 - 2017-05-20 10:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-06-15 11:24 - 2017-05-20 10:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2017-06-15 11:24 - 2017-05-20 10:14 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-06-15 11:24 - 2017-05-20 10:14 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-06-15 11:24 - 2017-05-20 10:14 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2017-06-15 11:24 - 2017-05-20 10:14 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-06-15 11:24 - 2017-05-20 10:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-06-15 11:24 - 2017-05-20 10:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-06-15 11:24 - 2017-05-20 10:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll 2017-06-15 11:24 - 2017-05-20 10:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2017-06-15 11:24 - 2017-05-20 10:10 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2017-06-15 11:24 - 2017-05-20 10:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll 2017-06-15 11:24 - 2017-05-20 09:08 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-06-15 11:24 - 2017-05-20 09:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-06-15 11:24 - 2017-05-20 09:07 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2017-06-15 11:24 - 2017-05-20 09:03 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2017-06-15 11:24 - 2017-05-20 08:59 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2017-06-15 11:24 - 2017-05-20 08:58 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2017-06-15 11:24 - 2017-05-20 08:56 - 04847928 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-06-15 11:24 - 2017-05-20 08:56 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-06-15 11:24 - 2017-05-20 08:56 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-06-15 11:24 - 2017-05-20 08:55 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-06-15 11:24 - 2017-05-20 08:54 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-06-15 11:24 - 2017-05-20 08:54 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-06-15 11:24 - 2017-05-20 08:54 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys 2017-06-15 11:24 - 2017-05-20 08:53 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-06-15 11:24 - 2017-05-20 08:53 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-06-15 11:24 - 2017-05-20 08:53 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-06-15 11:24 - 2017-05-20 08:53 - 00335808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2017-06-15 11:24 - 2017-05-20 08:53 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2017-06-15 11:24 - 2017-05-20 08:52 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-06-15 11:24 - 2017-05-20 08:52 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-06-15 11:24 - 2017-05-20 08:51 - 06551856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-06-15 11:24 - 2017-05-20 08:51 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-06-15 11:24 - 2017-05-20 08:51 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-06-15 11:24 - 2017-05-20 08:51 - 01219560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-06-15 11:24 - 2017-05-20 08:51 - 00406064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2017-06-15 11:24 - 2017-05-20 08:48 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys 2017-06-15 11:24 - 2017-05-20 08:09 - 17365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-06-15 11:24 - 2017-05-20 08:09 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-06-15 11:24 - 2017-05-20 08:09 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll 2017-06-15 11:24 - 2017-05-20 08:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll 2017-06-15 11:24 - 2017-05-20 08:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-06-15 11:24 - 2017-05-20 08:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys 2017-06-15 11:24 - 2017-05-20 08:07 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2017-06-15 11:24 - 2017-05-20 08:07 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll 2017-06-15 11:24 - 2017-05-20 08:07 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe 2017-06-15 11:24 - 2017-05-20 08:06 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2017-06-15 11:24 - 2017-05-20 08:06 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll 2017-06-15 11:24 - 2017-05-20 08:06 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 2017-06-15 11:24 - 2017-05-20 08:05 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-06-15 11:24 - 2017-05-20 08:05 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-06-15 11:24 - 2017-05-20 08:02 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2017-06-15 11:24 - 2017-05-20 08:02 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll 2017-06-15 11:24 - 2017-05-20 08:00 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-06-15 11:24 - 2017-05-20 08:00 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll 2017-06-15 11:24 - 2017-05-20 08:00 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2017-06-15 11:24 - 2017-05-20 08:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-06-15 11:24 - 2017-05-20 08:00 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-06-15 11:24 - 2017-05-20 07:57 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-06-15 11:24 - 2017-05-20 07:56 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe 2017-06-15 11:24 - 2017-05-20 07:56 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-06-15 11:24 - 2017-05-20 07:55 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-06-15 11:24 - 2017-05-20 07:55 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-06-15 11:24 - 2017-05-20 07:55 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2017-06-15 11:24 - 2017-05-20 07:55 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-06-15 11:24 - 2017-05-20 07:54 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-06-15 11:24 - 2017-05-20 07:54 - 04537344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-06-15 11:24 - 2017-05-20 07:54 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-06-15 11:24 - 2017-05-20 07:54 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-06-15 11:24 - 2017-05-20 07:54 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-06-15 11:24 - 2017-05-20 07:52 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-06-15 11:24 - 2017-05-20 07:52 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-06-15 11:24 - 2017-05-20 07:52 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2017-06-15 11:24 - 2017-05-20 07:52 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-06-15 11:24 - 2017-05-20 07:51 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-06-15 11:24 - 2017-05-20 07:51 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2017-06-15 11:24 - 2017-05-20 07:50 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll 2017-06-15 11:24 - 2017-05-20 07:50 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2017-06-15 11:24 - 2017-05-20 07:48 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2017-06-15 11:24 - 2017-05-20 07:48 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2017-06-15 11:24 - 2017-05-20 07:47 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2017-06-15 11:24 - 2017-05-20 07:47 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll 2017-06-12 22:12 - 2017-06-12 22:31 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Autodesk 2017-06-12 22:12 - 2017-06-12 22:12 - 00002281 _____ C:\Users\Public\Desktop\DWG TrueView 2018 - English.lnk 2017-06-12 22:12 - 2017-06-12 22:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DWG TrueView 2018 - English 2017-06-12 22:11 - 2017-06-12 22:11 - 00000000 ____D C:\Users\Raphael\AppData\Local\Autodesk 2017-06-12 22:11 - 2017-06-12 22:11 - 00000000 ____D C:\Users\Public\Documents\Autodesk 2017-06-12 22:11 - 2017-06-12 22:11 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2017-06-12 22:11 - 2017-06-12 22:11 - 00000000 ____D C:\Program Files\Autodesk 2017-06-12 22:10 - 2017-06-12 22:31 - 00000000 ____D C:\ProgramData\Autodesk 2017-06-12 22:07 - 2017-06-12 22:09 - 00000000 ____D C:\Autodesk 2017-06-11 17:27 - 2017-06-11 17:27 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-07-05 20:33 - 2017-02-22 01:18 - 00000000 ____D C:\ProgramData\aquasuite-data 2017-07-05 20:25 - 2017-01-26 23:06 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\PersBackup5 2017-07-05 20:24 - 2016-06-17 10:37 - 00000000 __SHD C:\Users\Raphael\IntelGraphicsProfiles 2017-07-04 22:04 - 2017-05-30 19:20 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-07-04 18:08 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-07-04 18:08 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-07-02 23:15 - 2017-05-30 19:21 - 00000000 ____D C:\Users\Raphael 2017-07-02 23:13 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\SwapHome 2017-07-02 23:13 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\CooRink Portable 2017-07-02 23:13 - 2015-12-07 00:14 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.4 2017-07-02 23:08 - 2016-11-24 23:38 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-07-02 23:08 - 2016-11-24 23:38 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-07-02 23:08 - 2016-11-24 23:38 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2017-07-02 23:03 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-07-02 23:02 - 2017-05-30 19:21 - 02555688 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-07-02 23:02 - 2017-03-20 06:35 - 01103786 _____ C:\WINDOWS\system32\perfh007.dat 2017-07-02 23:02 - 2017-03-20 06:35 - 00265716 _____ C:\WINDOWS\system32\perfc007.dat 2017-07-02 22:57 - 2017-05-30 19:30 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-07-02 22:50 - 2017-05-30 19:30 - 00003616 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-07-02 22:50 - 2017-05-30 19:30 - 00003392 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-07-02 22:26 - 2013-03-23 20:41 - 00000000 ____D C:\ProgramData\Origin 2017-07-02 21:46 - 2017-05-30 19:20 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin 2017-07-02 21:46 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-07-02 21:46 - 2017-03-18 13:40 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2017-07-02 21:46 - 2013-03-23 20:45 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Origin 2017-07-02 21:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\System 2017-07-02 21:32 - 2017-05-30 19:21 - 00000000 ____D C:\ProgramData\Package Cache 2017-07-02 21:31 - 2015-01-26 14:13 - 00000000 ____D C:\Program Files\Java 2017-07-02 21:30 - 2012-09-24 21:32 - 00000000 ____D C:\Program Files (x86)\Java 2017-07-02 19:56 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-06-29 19:35 - 2017-01-22 23:41 - 00002267 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-06-29 19:35 - 2017-01-22 23:41 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-06-27 22:32 - 2013-05-20 10:34 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Dropbox 2017-06-21 20:13 - 2016-12-21 22:01 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Curse Client 2017-06-18 19:55 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-06-16 16:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-06-16 10:49 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-06-16 10:41 - 2016-04-27 07:56 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-06-16 10:40 - 2017-05-30 19:20 - 00377624 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-06-16 10:40 - 2013-03-07 19:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-06-16 10:40 - 2013-03-07 19:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-06-15 19:45 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-06-15 19:43 - 2013-03-07 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-06-15 19:42 - 2013-08-15 09:30 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-06-15 19:39 - 2012-09-10 16:21 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-06-15 11:20 - 2017-01-26 23:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Personal Backup 2017-06-15 11:20 - 2017-01-26 23:05 - 00000000 ____D C:\Program Files\Personal Backup 5 2017-06-14 21:30 - 2015-06-16 11:08 - 00000000 ____D C:\Users\Raphael\AppData\Local\Dropbox 2017-06-14 20:34 - 2017-05-30 19:30 - 00004428 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2017-06-14 20:29 - 2017-02-22 01:17 - 00000000 ____D C:\Program Files\aquasuite 2017-06-11 17:27 - 2017-05-30 19:21 - 00000000 ____D C:\Users\DefaultAppPool ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2012-12-25 16:51 - 2017-01-05 15:01 - 0000161 _____ () C:\Users\Raphael\AppData\Roaming\default.rss 2013-08-11 10:24 - 2013-08-11 10:24 - 0000000 _____ () C:\Users\Raphael\AppData\Roaming\downloads.m3u 2013-12-27 01:10 - 2016-04-15 22:21 - 0004031 _____ () C:\Users\Raphael\AppData\Roaming\LTspiceIV.ini 2013-12-21 20:12 - 2016-04-15 22:19 - 0000363 _____ () C:\Users\Raphael\AppData\Roaming\Solve Elec 2.5 Prefs 2016-10-11 21:44 - 2017-03-03 16:08 - 1307648 _____ () C:\Users\Raphael\AppData\Local\file__0.localstorage 2017-07-02 22:50 - 2017-07-02 22:50 - 0011568 _____ () C:\Users\Raphael\AppData\Local\InstallationConfiguration.xml 2017-07-02 22:50 - 2017-07-02 22:50 - 0140800 _____ () C:\Users\Raphael\AppData\Local\installer.dat 2014-03-04 02:48 - 2014-03-04 02:48 - 0002742 _____ () C:\Users\Raphael\AppData\Local\recently-used.xbel 2015-05-15 21:09 - 2015-09-12 21:03 - 0007604 _____ () C:\Users\Raphael\AppData\Local\Resmon.ResmonCfg 2017-07-02 22:50 - 2017-07-02 22:50 - 0930816 _____ () C:\Users\Raphael\AppData\Local\test_db_cara.db 2012-09-08 14:54 - 2012-09-08 14:54 - 0010719 _____ () C:\ProgramData\xml39BA.tmp 2012-09-08 14:54 - 2012-09-08 14:54 - 0013814 _____ () C:\ProgramData\xml456F.tmp 2012-09-08 14:54 - 2012-09-08 14:54 - 0000000 _____ () C:\ProgramData\xml49A4.tmp 2012-09-08 14:54 - 2012-09-08 14:54 - 0000000 _____ () C:\ProgramData\xml4DAB.tmp Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Raphael\pb-setup-x64-5.8.0602.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-06-25 19:41 ==================== Ende von FRST.txt ============================ |
06.07.2017, 22:21 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malware verhindert MBAM/Windows DefenderLesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
07.07.2017, 16:09 | #3 |
| Malware verhindert MBAM/Windows Defender Hallo Cosinus,
__________________Danke für deine Antwort. Ich habe versucht mich so genau wie möglich an die Anleitung zu halten die besagt, dass man nicht auf seine eigenen Beiträge antworten soll. Sorry wenn ich etwas falsch verstanden habe. Hier die Addition.txt Teil 1: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 05-07-2017 durchgeführt von Raphael (05-07-2017 20:33:09) Gestartet von F:\Downloads Windows 10 Home Version 1703 (X64) (2017-05-30 17:32:24) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3946114199-4031152989-3939253435-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3946114199-4031152989-3939253435-503 - Limited - Disabled) Gast (S-1-5-21-3946114199-4031152989-3939253435-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3946114199-4031152989-3939253435-1002 - Limited - Enabled) Raphael (S-1-5-21-3946114199-4031152989-3939253435-1000 - Administrator - Enabled) => C:\Users\Raphael Silvia (S-1-5-21-3946114199-4031152989-3939253435-1003 - Limited - Enabled) => C:\Users\Silvia ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Acrobat.com (HKLM-x32\...\{77DCDCE3-2DED-62F3-8154-05E745472D07}) (Version: 0.0.0 - Adobe Systems Incorporated) Hidden Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.) Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated) Advertising Center (HKLM-x32\...\{B2EC4A38-B545-4A00-8214-13FE0E915E6D}) (Version: 0.0.0.2 - Nero AG) Hidden AirDroid 3.3.2.0 (HKLM-x32\...\AirDroid) (Version: 3.3.2.0 - Sand Studio) Airline Tycoon 2 Patch v1.27 (HKLM-x32\...\AirlineTycoon2_is1) (Version: - Kalypso Media) ALDI Bestellsoftware 4.12.2 (HKLM-x32\...\ALDI Bestellsoftware) (Version: 4.12.2 - ORWO Net) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.5.1 - Sereby Corporation) Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) AMD Settings (HKLM\...\WUCCCApp) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.) Anno 1701 (HKLM-x32\...\{A2433A63-5F5D-40E5-B529-9123C2B3E734}) (Version: 1.02 - Sunflowers) ANNO 2070 (HKLM-x32\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft) aquasuite (HKLM-x32\...\aquasuite5) (Version: 2017-1.3 - Aqua Computer GmbH & Co. KG) ArcaniA - Gothic 4 (HKLM-x32\...\{EE74D039-45D7-44E9-BF95-B9CFB015964F}_is1) (Version: - JoWooD Entertainment AG) Arduino (HKLM-x32\...\Arduino) (Version: 1.6.9 - Arduino LLC) ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\...\ARMA 2 Operation Arrowhead) (Version: - ) ArmA 2 Uninstall (HKLM-x32\...\ArmA 2) (Version: - ) Arma Cold War Assault Uninstall (HKLM-x32\...\Arma Cold War Assault) (Version: - ) ArmA Uninstall (HKLM-x32\...\ArmA) (Version: - ) ArtMoney SE v7.39.1 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.39 - System SoftLab) ASUS GPU Tweak (HKLM-x32\...\{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.1.1.2 - ASUSTek COMPUTER INC.) Hidden ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.1.1.2 - ASUSTek COMPUTER INC.) ASUS Utility (HKLM-x32\...\{003A5708-9078-45C9-A2FE-EBBF422B3D0A}) (Version: 1.00.0000 - ASUSTek) Hidden ASUS VGA Driver (HKLM-x32\...\{90157C5D-D791-4D36-8C2B-7553DC01D601}) (Version: 3.0.0.1 - Ihr Firmenname) Hidden Atmel JungoUSB (HKLM-x32\...\{495AA4EB-6AF7-4D8E-89E0-EDEFD1D58950}) (Version: 6.2.86 - Atmel) Hidden Atmel LibUSB (HKLM-x32\...\{89D20A20-5E12-435E-ABD6-C85461114332}) (Version: 6.2.38 - Atmel) Hidden Atmel SeggerUSB (HKLM-x32\...\{586416F9-AACB-424A-B3B4-CFA7A850A6E6}) (Version: 6.2.22 - Atmel) Hidden Atmel Studio InfFiles (HKLM-x32\...\{DD8CABB7-6F70-46CB-A3C7-A544E3BFF0A7}) (Version: 6.2.80 - Atmel Corporation) Hidden Atmel USB Driver Package (HKLM-x32\...\{0b919373-80a6-47d9-8542-540e14f914dc}) (Version: 6.2.241 - Atmel) Atmel WinUSB (HKLM-x32\...\{4884F982-C0BF-48FD-BF05-4517757984C9}) (Version: 6.2.22 - Atmel) Hidden Autodesk DWG TrueView 2018 - English (HKLM\...\DWG TrueView 2018 - English) (Version: 22.0.50.0 - Autodesk) B4A Trial v5.20 (HKLM-x32\...\{DA51676B-4318-4AF6-B94F-A8A9067622AD}_is1) (Version: - Anywhere Software) BASCOM-AVR (HKLM-x32\...\{47F94730-ABD2-47F6-920E-EA8CDB6DD0C6}_is1) (Version: 2.0.7.5 - MCS Electronics) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) BattlEye Uninstall (HKLM-x32\...\BattlEye for A1) (Version: - ) BattlEye Uninstall (HKLM-x32\...\BattlEye for A2) (Version: - ) Blender (HKLM\...\{2BBF253B-4DC9-49DA-AE78-5991452AC317}) (Version: 2.78.2 - Blender Foundation) Blood & Gold: Caribbean! (HKLM\...\Steam App 413710) (Version: - Snowbird Games) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Call of Duty: Advanced Warfare - Multiplayer (HKLM-x32\...\Steam App 209660) (Version: - Sledgehammer Games) Call of Duty: Advanced Warfare (HKLM-x32\...\Steam App 209650) (Version: - Sledgehammer Games) Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version: - Infinity Ward) Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward) Catalyst Control Center Next Localization BR (HKLM\...\{118C2119-84B6-E32C-63E2-B56DBCF41CE5}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (HKLM\...\{3E245378-BF77-6946-C6F6-096DBE5EAB82}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (HKLM\...\{55A4D3AB-C8DF-26B2-89A8-7E16E1E40700}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (HKLM\...\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (HKLM\...\{365AEAB2-4CF3-7CBB-0DAC-E9E14B688E65}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (HKLM\...\{45907537-804A-514F-5280-5F4F12A6DCBC}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (HKLM\...\{5A083A57-10D6-D4E5-292C-F274870E73A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (HKLM\...\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (HKLM\...\{7ABC6D83-816E-6D48-E65D-B0CEDD294E4E}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (HKLM\...\{962364E4-08BB-347D-32E7-2B789F37BF8A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (HKLM\...\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (HKLM\...\{DF0D7C1C-72B6-9FFB-DF66-B3720237BB80}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (HKLM\...\{238F6F6F-2544-86CF-3AB6-2CDADAB58CF0}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (HKLM\...\{36EDC500-E4C0-371C-9865-08450415C1E9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (HKLM\...\{A0407E39-2AA4-60B3-885F-3C5347B6909E}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (HKLM\...\{C3EE628C-7394-FE2C-0C90-C05284EB528D}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (HKLM\...\{0989D0EA-AFF3-5F9A-3D25-20EE133E409B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (HKLM\...\{2F544F46-5F6E-97BB-3550-A0242A3C5754}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (HKLM\...\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (HKLM\...\{EC688BD0-240D-AE40-55F3-234E54919AE6}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (HKLM\...\{A8689A0F-5928-7300-B82B-C5E85131B7BA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (HKLM\...\{D74218A3-C503-57EF-AC9F-2220082E7ADE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (HKLM\...\{E27224E3-7913-DA1E-5B08-9BEEC8FEE3D1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (HKLM\...\{FC4086D6-E345-5F43-08BB-280FB57DAF49}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (HKLM\...\{76AAF56B-93D8-161D-809A-EC05F3B913DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (HKLM\...\{95A52FC1-C728-841D-1BFC-CC793B77B0A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (HKLM\...\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (HKLM\...\{F8EBE530-A4D5-BF51-F623-3787E6B8A878}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (HKLM\...\{063CED74-F5F0-870E-DC9C-2D78FDEDA3EE}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (HKLM\...\{42FBD43F-DE53-6D4D-5134-E3C93B45CBEF}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (HKLM\...\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (HKLM\...\{A22CDEBA-6DB5-12CD-F6CE-6238C2D78363}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (HKLM\...\{13BB60AA-88F7-4B1F-2DEC-D81EEDE8B3AA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (HKLM\...\{20D46801-147B-30AD-7C5A-AC4560A79096}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (HKLM\...\{AC85CF50-9A55-0103-ADBF-365C37603AA4}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (HKLM\...\{C0BFC67D-E447-02C8-6046-C078DFE9EC97}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (HKLM\...\{22C39711-2747-D264-319A-1550BEEAAEC6}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (HKLM\...\{37AA6227-FF2C-95AC-87C0-45DCC0BB87DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (HKLM\...\{94C72EBE-2908-F0AC-62DA-D61951830F8F}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (HKLM\...\{B349892D-B015-033C-4CA8-3635E6B655D7}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (HKLM\...\{1DBACFDB-5E43-7882-36BD-53526D34BD22}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (HKLM\...\{5B987681-3652-492B-6A11-E02AC0FE5959}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (HKLM\...\{BE8D6AB1-3049-2F0C-67FA-00C0A5D321A3}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (HKLM\...\{EB328356-1DF0-1CCE-3607-6361DD329219}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (HKLM\...\{26567561-DFB2-2B63-9BA8-6A490ED37016}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (HKLM\...\{86BFE5B4-1FCE-3C02-6373-92B1AE6431E8}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (HKLM\...\{87E6EC29-AEC5-28CB-F773-93EB6C1B8A2B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (HKLM\...\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (HKLM\...\{0742432E-42D9-2240-4CA1-8595CCCBAA77}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (HKLM\...\{0809FEC1-EF86-51E9-8210-DC1B1BDB6745}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (HKLM\...\{CA55697D-BD74-3ED8-6B21-D7EDAD3B7D02}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (HKLM\...\{ED75A775-03A7-F214-868D-497748707968}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (HKLM\...\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (HKLM\...\{5FD706FF-6AD8-E372-A35A-879409982655}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (HKLM\...\{CFC860C8-4F51-E08C-A74C-2E444ED06160}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (HKLM\...\{EAEAA839-44F4-22DF-D1CC-88C3B2A3D4B1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (HKLM\...\{9338D693-38B7-1ED4-9B42-BFA1D5600CCB}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (HKLM\...\{A3973655-E448-4A1B-477C-988A79D132D9}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (HKLM\...\{A4E7CA0C-84EB-5E29-2F04-06C4E4790C2F}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (HKLM\...\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (HKLM\...\{59D2664C-949B-7FA7-9880-ECB993B6616A}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (HKLM\...\{6DC92550-D065-4B36-C4D3-D8D7A702A7A7}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (HKLM\...\{C971C145-258D-6650-7088-13DDB161327A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (HKLM\...\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (HKLM\...\{970A40CA-46AB-986C-1798-976ED0EA00FA}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (HKLM\...\{B2A83706-3F14-1532-20CD-B4EE715A8945}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (HKLM\...\{EBA09DAF-14B4-7BE7-676E-6E2FB21EDBDD}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (HKLM\...\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (HKLM\...\{44ED2CDA-4197-E9E9-B328-26E1FB749116}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (HKLM\...\{4707CBFC-8ED4-463E-0FF9-DE86F4A743E9}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (HKLM\...\{4D1D5407-9B69-6422-629C-8518A26004A4}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (HKLM\...\{9AA4DD93-94BF-22EA-C9D2-7084F304A31B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (HKLM\...\{3450566C-4561-0EE8-B1AB-D5C79CCE8D2C}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (HKLM\...\{379D900B-A785-6DB0-012E-434356A365B3}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (HKLM\...\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (HKLM\...\{C14A3A5B-8A86-C239-37D7-158211778C54}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (HKLM\...\{24DF617A-CD23-6E6A-126B-23630D2781CE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (HKLM\...\{366C4FB5-CF6E-258B-418D-E6D29549A278}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (HKLM\...\{A50C89BC-8D8E-8828-824A-7171F6D583D5}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (HKLM\...\{FCE8438C-3272-D63F-479F-670F082B294B}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (HKLM\...\{0B5633F0-C415-2F08-671E-4C9E2FAACD45}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (HKLM\...\{25D1751E-7CA2-5F6D-0125-0A16E47AF9FE}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (HKLM\...\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (HKLM\...\{B10089DE-934F-6E0F-683A-B788F89348DF}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine) chip 1-click download service (HKLM-x32\...\{503CA94E-0834-4CEE-AD92-BA17AF4E809A}) (Version: 3.6.9.0 - Chip Digital GmbH) Cities XXL (HKLM-x32\...\Steam App 313010) (Version: - Focus Home Interactive) Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version: - Colossal Order Ltd.) Command & Conquer™ and The Covert Operations™ (HKLM-x32\...\{050E298D-C9B8-4582-A332-26201268A297}) (Version: 1.0.0.0 - Electronic Arts, Inc.) Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.) Command & Conquer™ Red Alert, Counterstrike and The Aftermath (HKLM-x32\...\{B9A7CCBE-48F7-4B3E-BD20-76ADDD4DC69F}) (Version: 1.0.0.0 - Electronic Arts, Inc.) Command & Conquer™ Renegade (HKLM-x32\...\{24DFBE4C-FD7F-48F2-A7D9-D1A0929B2113}) (Version: 1.0.0.0 - Electronic Arts, Inc.) compasX 19.6 (HKLM-x32\...\{D0A26D5D-CC81-4CA7-9F5B-95C53DB98C41}) (Version: 19.6 - TELENOT electronic GmbH) Core Temp 1.5.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.5.1 - ALCPU) CPUID CPU-Z 1.77 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Creation Kit (HKLM-x32\...\Steam App 202480) (Version: - bgs.bethsoft.com) Curse (HKLM-x32\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Curse) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Darksiders II (HKLM-x32\...\Steam App 50650) (Version: - Vigil Games) Die Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.31.37.1020 - Electronic Arts Inc.) DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version: - Codemasters) dm-Fotowelt (HKLM-x32\...\dm-Fotowelt) (Version: 5.1.5 - CEWE Stiftung u Co. KGaA) DOOM (HKLM\...\Steam App 379720) (Version: - id Software) Dropbox (HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Dropbox) (Version: 29.4.20 - Dropbox, Inc.) Dungeon Keeper (HKLM-x32\...\{B9E79070-56B6-4980-A7E9-C28D6480D050}) (Version: 1.0.0.1 - Electronic Arts) DWG TrueView 2018 - English (HKLM\...\{28B89EEF-1028-0409-0100-CF3F3A09B77D}) (Version: 22.0.50.0 - Autodesk) Hidden EAGLE 6.5.0 (HKLM-x32\...\EAGLE 6.5.0) (Version: 6.5.0 - CadSoft Computer GmbH) ELECTRA Freeware 4.50 (HKLM-x32\...\ELECTRA_is1) (Version: - KONEKT) Europa Universalis IV (HKLM-x32\...\Steam App 236850) (Version: - Paradox Development Studio) Fallout 4 (HKLM-x32\...\Steam App 377160) (Version: - Bethesda Game Studios) Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft) Far Cry Primal (HKLM-x32\...\Uplay Install 2010) (Version: - Ubisoft) Farming Simulator 2013 (HKLM\...\Steam App 220260) (Version: - Giants Software) FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.8.0.0 - Electronic Arts) FileZilla Client 3.23.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.23.0.2 - Tim Kosse) FINAL FANTASY VII (HKLM-x32\...\Steam App 39140) (Version: - Square Enix) Fotogalerie (HKLM-x32\...\{0FD66C6F-4023-4C74-AF8E-9B8B2053868E}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Free YouTube Download (HKLM-x32\...\Free YouTube Download_is1) (Version: 4.1.7.426 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.61.805 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.61.805 - DVDVideoSoft Ltd.) Frontplatten Designer (HKLM\...\Frontplatten Designer) (Version: 5.0.1 - Schaeffer AG) FUSSBALL MANAGER 13 (HKLM-x32\...\{80AF0300-866F-400F-A350-D53E3C3E34E0}) (Version: 1.0.4.0 - Electronic Arts) Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden Grand Theft Auto: Episodes from Liberty City (HKLM-x32\...\{5454083B-1308-4485-BF17-111000038701}) (Version: 1.0.0003.135 - Rockstar Games Inc.) Hidden Grand Theft Auto: Episodes From Liberty City (HKLM-x32\...\{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}) (Version: 1.1.0.0 - Rockstar Games) Hearts of Iron III - Their Finest Hour version 4.02 (HKLM-x32\...\{25D080C2-19A4-427D-A12A-979D674B57F8}}_is1) (Version: 4.02 - Paradox Interactive) Hearts of Iron III (HKLM-x32\...\Steam App 25890) (Version: - Paradox Interactive) Hearts of Iron IV (HKLM\...\Steam App 394360) (Version: - Paradox Development Studios) Heaven Benchmark version 4.0 (HKLM-x32\...\Unigine Heaven Benchmark (Basic Edition)_is1) (Version: 4.0 - Unigine Corp.) Helium (HKLM-x32\...\{9A781940-AC41-4D5E-8E1E-76A04B916FB9}) (Version: 1.0.0 - ClockworkMod) Hex-Editor MX (HKLM-x32\...\{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1) (Version: 6.0 - NEXT-Soft) Hotfix für Microsoft Visual Basic 2010 Express - DEU (KB2635973) (HKLM-x32\...\{CCAC7E52-ECCE-3C4D-B1BE-BC2ACF1C1C0E}.KB2635973) (Version: 1 - Microsoft Corporation) ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.8.251 - Intel Corporation) IPTInstaller (HKLM-x32\...\{6965F2F4-1CD2-4F42-A8EF-9EF433F9AA72}) (Version: 4.0.4 - HTC) Jagged Alliance - Back in Action (HKLM-x32\...\Steam App 57740) (Version: - Coreplay GmbH) Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Junk Mail filter update (HKLM-x32\...\{F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Just Cause 2 (HKLM-x32\...\Steam App 8190) (Version: - Avalanche Studios) Just Cause 2: Multiplayer Mod (HKLM-x32\...\Steam App 259080) (Version: - Avalanche Studios) Kaspersky Security Scan (HKLM-x32\...\{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab) Hidden Kaspersky Security Scan (HKLM-x32\...\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab) Kaspersky Software Updater (HKLM-x32\...\{DEEDA858-A9B4-4212-8873-2F2CE2706E68}) (Version: 2.0.0.623 - Kaspersky Lab) Hidden Kaspersky Software Updater (HKLM-x32\...\InstallWIX_{DEEDA858-A9B4-4212-8873-2F2CE2706E68}) (Version: 2.0.0.623 - Kaspersky Lab) Lidl-Fotos (HKLM-x32\...\Lidl-Fotos_is1) (Version: - ) LinCity-NG 2.0 (HKLM-x32\...\LinCity-NG_is1) (Version: - LinCity-NG Developers) LOGO!Soft Comfort V6.1 (HKLM-x32\...\LOGO!Soft Comfort V6.1) (Version: 6.1.0.0 - Siemens AG) LOGO!Soft Comfort V7.1 (HKLM\...\LOGO!Soft Comfort V7.1 ) (Version: 7.1.0.0 - Siemens AG) LTspice IV (HKLM-x32\...\LTspice IV) (Version: - ) Malwarebytes Version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Mass Effect™ 2 (HKLM-x32\...\{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}) (Version: 1.2.1604.0 - Electronic Arts) Medal of Honor: Pacific Assault™ (HKLM-x32\...\{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}) (Version: 1.2.1.280 - Electronic Arts) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) MegaTrainer Ultimate Version 1.4.8.1 (HKLM-x32\...\{68A5CFDB-E05C-46BC-B2EB-988D1E2C2444}_is1) (Version: 1.4.8.1 - MegaDev) Men of War (Nur entfernen) (HKLM-x32\...\{137D91E1-2347-4EAC-BB0B-CC06C6B92A52}_is1) (Version: 1.0.2.0 - 1C) Men of War patch Version 1.17.5.1 (HKLM-x32\...\{E8169D02-FE93-4916-856E-223D0415DE20}_is1) (Version: 1.17.5.1 - 1C Company) Menu Templates - Pack 1 (HKLM-x32\...\{56ABA277-EE53-4478-A607-FA42208FF5A9}) (Version: 9.6.0.0 - Nero AG) Hidden Menu Templates - Starter Kit (HKLM-x32\...\{B78120A0-CF84-4366-A393-4D0A59BC546C}) (Version: 9.6.0.0 - Nero AG) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation) Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 Browser (HKLM-x32\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 Native Client (HKLM\...\{8325FD0C-2FDB-46C3-921A-3A78385EA972}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{877B76B2-F83F-4F5A-B28D-3F398641ADB6}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{28D06854-572C-4A65-83E5-F8CAF26B9FDC}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (HKLM-x32\...\Microsoft Visual Basic 2010 Express - DEU) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{82f2609e-68ba-408d-963f-530ad8809435}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{577ff5ba-39aa-4d8c-a3a9-f95012763438}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25017 (HKLM-x32\...\{e9d78d68-c26c-4da7-9158-99355d8ef3ad}) (Version: 14.10.25017.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{58b3beca-b999-4f6f-a48c-81681136a620}) (Version: 14.10.25017.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (HKLM\...\{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\...\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Might & Magic X Legacy (HKLM-x32\...\Uplay Install 401) (Version: 1.3 - Ubisoft) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Minecraft Editor 64 bits (HKLM\...\{64C3313F-DAD0-461C-B6B2-37586B67F98B}) (Version: 1.9.7 - Axialmedia) Mount & Blade: With Fire and Sword (HKLM-x32\...\Steam App 48720) (Version: - ) Movie Maker (HKLM-x32\...\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{6066D3FE-3692-4449-A3C8-D1EAA2C0E9E7}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Movie Templates - Starter Kit (HKLM-x32\...\{E498385E-1C51-459A-B45F-1721E37AA1A0}) (Version: 9.6.0.0 - Nero AG) Hidden Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MTX (HKLM-x32\...\{6583D00E-0924-4950-8BE9-5D09FE70B333}) (Version: 1.0.0 - mektek.net) MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 1.1 - MusicBrainz) Nero 9 Essentials (HKLM-x32\...\{3ce857f4-e185-4fe0-b26f-542c5c6c895e}) (Version: - Nero AG) NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM-x32\...\{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.01.10 - NETGEAR) Hidden NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM-x32\...\InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.01.10 - NETGEAR) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.9 - Black Tree Gaming) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9.2 - Notepad++ Team) NSU (HKLM-x32\...\{A3EA81D6-07A2-4116-9EA3-60B741572FD6}) (Version: 2.02.1030 - ZyXEL) NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation) ohm_lib (HKLM-x32\...\{74A6FE5F-E688-4B09-B67B-046BCD22253D}) (Version: 1.0.0 - Microsoft) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenOffice 4.1.3 (HKLM-x32\...\{8D5FCC56-BB9F-4122-923C-71753F50F6F5}) (Version: 4.13.9783 - Apache Software Foundation) Oracle VM VirtualBox 4.3.20 (HKLM\...\{86401870-7AB7-4A8D-8AD6-12B27DF2E6E3}) (Version: 4.3.20 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 10.4.13.6637 - Electronic Arts, Inc.) paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC) Personal Backup 5.8.9.5 (64-bit) (HKLM\...\Personal Backup 5_is1) (Version: 5.8.9.5 - Dr. J. Rathlev) PlaysTV (HKLM-x32\...\PlaysTV) (Version: 1.15.6-r117528-release - Plays.tv, LLC) Port Royale 3 (HKLM-x32\...\{E07A21E5-1C16-41E7-9617-2D38CF3A642C}) (Version: 1.3.2.0 - Gaming Minds Studios GmbH) ProfiCAD 7.5.8 (HKLM-x32\...\ProfiCAD_is1) (Version: - ) ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.14 - ProtectDisc Software GmbH) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.0 beta r2627 - ) Raptr (HKLM-x32\...\Raptr) (Version: 5.2.7-r116720-release - Raptr, Inc) Rapture3D 2.4.11 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) Razer Megalodon Firmware Updater (HKLM-x32\...\{C67A3F9D-E55D-4288-B4EC-1B9863EFB288}) (Version: 2.12.02 - Razer USA Ltd.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.15.616 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.9.422.2016 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7910 - Realtek Semiconductor Corp.) Risen - ModStarter 1.3.4.1 (Online Mods DB version) (HKLM-x32\...\Risen - ModStarter_is1) (Version: - LordOfWAR(WorldOfRisen.de), Odin68(Mighty DWARF Mod-Team)) Risen (HKLM-x32\...\{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}) (Version: 1.00.0000 - Deep Silver) RivaTuner Statistics Server 6.5.0 Beta 5 (HKLM-x32\...\RTSS) (Version: 6.5.0 Beta 5 - Unwinder) S.T.A.L.K.E.R. - Clear Sky (HKLM-x32\...\S.T.A.L.K.E.R. - Clear Sky_is1) (Version: 1.0001 - Deep Silver) Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.6.0 - Samsung Electronics Co., Ltd.) Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung) ScummVM (HKLM-x32\...\ScummVM_is1) (Version: - The ScummVM Team) Service Pack 1 für SQL Server 2008 (KB 968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation) Shadow of Fear 8842 RC3 (HKLM-x32\...\Shadow_0) (Version: 8842 RC3 - Microsoft Games) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) SketchUp 2017 (HKLM\...\{C711666A-E8CC-4E2A-802F-BAA35E76045F}) (Version: 17.2.2555 - Trimble Navigation Limited) Solve Elec 2.5 (HKLM-x32\...\Solve Elec_is1) (Version: - ) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Sql Server Customer Experience Improvement Program (HKLM\...\{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}) (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.010 - MSI) Sweet Home 3D version 4.1 (HKLM-x32\...\Sweet Home 3D_is1) (Version: - eTeks) Sweet Home 3D version 5.2 (HKLM\...\Sweet Home 3D_is1) (Version: 5.2 - eTeks) Syberia II (HKLM-x32\...\{BF1534B0-BE09-457E-A4CF-0EFC803125F2}) (Version: 1.0.0.16 - Microids) Target 3001! V16 discover (HKLM-x32\...\Target 3001! V16 discover) (Version: - Ing. Buero FRIEDRICH) Target 3001! V16 pcb-pool (HKLM-x32\...\Target 3001! V16 pcb-pool) (Version: - Ing. Buero FRIEDRICH) Target 3001! V18 pcb-pool (HKLM-x32\...\Target 3001! V18 pcb-pool) (Version: - Ing. Buero FRIEDRICH) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.6 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.41110 - TeamViewer) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Elder Scrolls V: Skyrim Special Edition (HKLM\...\Steam App 489830) (Version: - Bethesda Game Studios) The Guild 2 - Renaissance (HKLM-x32\...\{THEGUILDREN-0010-2010-300520102330}_is1) (Version: - JoWooD Entertainment AG) The Guild II Venice Version 3.5 (HKLM-x32\...\{8DDACFE4-8415-43EC-80CB-966F4318AC39}_is1) (Version: 3.5 - Nordic Games GmbH) The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.31.0.0 - GOG.com) Theme Hospital (HKLM-x32\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.5 - Electronic Arts) tiptoi® Manager 3.1.6 (HKLM-x32\...\9978-5763-2995-5228) (Version: 3.1.6 - Ravensburger AG) Titan Quest (HKLM-x32\...\{412B69AF-C352-4F6F-A318-B92B3CB9ACC6}) (Version: 1.00.0000 - Iron Lore) Tom Clancy's The Division (HKLM\...\Steam App 365590) (Version: - Massive Entertainment) Ultima 8 (HKLM-x32\...\{428C6B01-D292-46F9-9321-75668ED17DA2}) (Version: 1.0.0.1 - Electronic Arts) Unity Web Player (HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\UnityWebPlayer) (Version: 5.1.2f1 - Unity Technologies ApS) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{6AF73222-EE90-434C-AE7E-B96F70A68D89}) (Version: 10.1.2731.0 - Microsoft Corporation) Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) Visual Basic 5.0 Enterprise Edition (HKLM-x32\...\VB5) (Version: - ) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation) VTech Download Agent Library (HKLM-x32\...\{DB083AE1-3354-4AAD-BD44-5F2CC4B2ECE6}) (Version: 1.00.0000 - VTech) Hidden VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version: - VTech) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0-2) (Version: 1.0.26.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1-2) (Version: 1.0.3.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.37.0 (HKLM\...\VulkanRT1.0.37.0) (Version: 1.0.37.0 - LunarG, Inc.) Wartung Samsung CLX-3180 Series (HKLM-x32\...\Samsung CLX-3180 Series) (Version: - Samsung Electronics Co., Ltd.) WEB.DE MailCheck für Mozilla Firefox (HKLM-x32\...\1&1 Mail & Media GmbH Toolbar FF) (Version: 3.0.2.1739 - 1&1 Mail & Media GmbH) WestwoodChat (HKLM-x32\...\{7CAE6A67-AF7B-4A6A-8705-8AFACA45BB60}) (Version: 1.0.0.0 - WestwoodChat) WestwoodOnline (HKLM-x32\...\{BBCD6D56-8A26-4DDE-9482-DBC9C7B7341D}) (Version: 1.0.0.0 - WestwoodOnline) Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows-Treiberpaket - Segger (jlink) USB (04/11/2012 2.6.8.2) (HKLM\...\419546AE8E4244C647A348987F769803F43B9C4F) (Version: 04/11/2012 2.6.8.2 - Segger) Windows-Treiberpaket - SEGGER (usbser) Ports (01/25/2012 6.0.2600.4) (HKLM\...\BD6BF8BBF7BE0D0091163F649A1A423B7EB9D4F1) (Version: 01/25/2012 6.0.2600.4 - SEGGER) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) X Rebirth (HKLM-x32\...\Steam App 2870) (Version: - Egosoft) XCOM: Enemy Unknown (HKLM-x32\...\Steam App 200510) (Version: - ) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2018 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Raphael\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{B6EB585B-B467-4E46-A9C7-48D7D6FD26CB}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2018 - English\dwgviewr.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Raphael\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Raphael\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Raphael\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll => Keine Datei ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] () ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] () ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] () ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2017-02-15] (Autodesk, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll -> Keine Datei ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll -> Keine Datei ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll -> Keine Datei ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll -> Keine Datei ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX32.dll [2017-06-07] () ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX32.dll [2017-06-07] () ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX32.dll [2017-06-07] () ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.) ContextMenuHandlers01: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) ContextMenuHandlers01: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2017-02-15] (Autodesk) ContextMenuHandlers01: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2016-05-18] () ContextMenuHandlers01: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => -> Keine Datei ContextMenuHandlers01: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] () ContextMenuHandlers02: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] () ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes) ContextMenuHandlers03: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] () ContextMenuHandlers04: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) ContextMenuHandlers04: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] () ContextMenuHandlers05: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-04-24] (Advanced Micro Devices, Inc.) ContextMenuHandlers05: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> Keine Datei ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Keine Datei ContextMenuHandlers05: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Intel Corporation) ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes) ContextMenuHandlers1_S-1-5-21-3946114199-4031152989-3939253435-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll -> Keine Datei ContextMenuHandlers4_S-1-5-21-3946114199-4031152989-3939253435-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll -> Keine Datei ContextMenuHandlers5_S-1-5-21-3946114199-4031152989-3939253435-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Raphael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll -> Keine Datei ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0484B896-8179-4E1B-A47F-12DD84B2C288} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {054F143D-BED6-4F03-AB18-8C68E578BF2D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {058D9DF8-1776-4727-A412-2861179AD6CB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {084F94A3-CC70-47F8-9A5A-DBD26CCF9D36} - System32\Tasks\CooRink Portable => Rundll32.exe "C:\Program Files\CooRink Portable\CooRink Portable.dll",QqJnzFgBAjtK <==== ACHTUNG Task: {11CCB11C-E6D0-486E-B02F-75B1EA539C0D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {17D34AC5-16AE-47EF-9656-62C5E4C17ADE} - \Microsoft\Windows\Setup\gwx\rundetector -> Keine Datei <==== ACHTUNG Task: {1A12D34C-42AA-42C9-8A7B-8056D985E1B1} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {1BEAFB71-0D00-4944-B618-4336CA14BCED} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {1D889A13-F855-40BA-9032-10343F23FFDB} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {1E0ACFEA-2883-47AC-8257-47019CCA67C7} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {2500375E-8E49-429E-BF2A-FFED226DDD19} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3946114199-4031152989-3939253435-1000Core1d23cd699aebef8 => C:\Users\Raphael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-12] (Dropbox, Inc.) Task: {2919501E-0B84-4348-8564-E56A8DD43CE5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {2AEBC444-CC48-4A6D-966E-8997B78B8D05} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Keine Datei <==== ACHTUNG Task: {2C7FD148-E5A4-49EE-9946-8713A920116F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {3D0F7DFB-68E5-44CB-81A0-34852F41D45D} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {481B398C-E7EC-43AB-BB32-825EA7550B8A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {4CEC537E-E301-4772-BA72-F4192374F1E8} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {5192D95E-AD5D-4ACB-80A2-1AB8E47F6FC3} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Silvia\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe Task: {526A0AC0-36E2-4285-A407-3CD99D3A9F87} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {615316D1-CD11-4F47-95D9-8685D7B9116E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {638275E4-6D9E-405C-865F-2C7BFC2C0903} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe Task: {779D2B3A-C451-46B4-AD26-61D3C7D7DD53} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {789B7C15-30F9-4453-9BFD-4B81183C34B6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {7A30E4E0-6A3B-44D3-BFC0-21CFD91D6F25} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {7B4087BE-215F-4197-BFFB-BB74D0BE80A4} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3946114199-4031152989-3939253435-1000UA1d23cd699b86bf1 => C:\Users\Raphael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-12] (Dropbox, Inc.) Task: {7C10554F-CCDB-42CB-B321-8090660CAC01} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-04-24] (Advanced Micro Devices, Inc.) Task: {8256470E-DCD2-4505-BBD8-85FF5D377688} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {82EB5F11-5A7F-454B-9236-AE6632594A60} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {8AFF1C46-45DC-472A-BA63-EBB8C93A30EC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-22] (Google Inc.) Task: {8B257691-F808-47B4-BF55-6B90D862CE23} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {8BA8D0D5-843E-483D-BFDE-43B31695CA94} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe Task: {8BEE47D6-1D0D-4E73-B883-5F1BCDCCFF67} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-16] (Adobe Systems Incorporated) Task: {8C12AC11-C158-4058-9534-E2E89A2A4EB8} - System32\Tasks\OneDrive Standalone Update Task v2 => C:\Users\Raphael\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {9A98DCD3-4536-4F9D-82C7-78962B2BAFB8} - System32\Tasks\Microsoft\Windows\Windows Error Reporting\ErrorReporting => C:\\ProgramData\\WindowsVideoErrorReporting\\wvermgr.exe <==== ACHTUNG Task: {9FEF19A2-FE31-434B-A145-A5B07FB3F7AC} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A0B7A1F9-2965-4168-AC65-FFDE335ABFBD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {A162A85E-A78A-4A55-89D0-5D767940720C} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {B2DE7F2F-5DF0-41B7-AF64-53F4A85EACE1} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BB21631A-8E55-438E-B030-1F488E6A2708} - System32\Tasks\SwapHome => Rundll32.exe "C:\Program Files\SwapHome\SwapHome.dll",ysTDXoPrsTD <==== ACHTUNG Task: {BBE91F70-138E-4CA5-8DA6-E51E68CE8CAD} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BCC3F4E0-D953-42DA-A816-74E53543A2D2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {BE969B6D-8B6F-433B-B9AC-D1009D2E2249} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-22] (Google Inc.) Task: {C43837BF-36DB-4C65-A648-032489F46DDE} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG Task: {D1E5AA6D-8927-4DA9-975F-69B70BA6818E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D496BA9E-17CA-4B9F-A278-5063DEBF74C0} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D8E153A9-9B8E-4C46-A62D-749991C24FFB} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {E06CF480-154B-4F4F-A31C-9B78867890B6} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {E156016E-CCA9-452B-8250-5B713FBC142F} - System32\Tasks\{E4940BAB-8064-4FA8-9FC2-D5086AC50294} => pcalua.exe -a "C:\Users\Raphael\AppData\Local\Temp\Temp1_d2a536_4e9f3e7be5271.zip\FInal 7.exe" <==== ACHTUNG Task: {E2BCEDA5-D072-4357-89C8-4E1B63B0DDAF} - System32\Tasks\aquasuite autostart => C:\Program Files\aquasuite\aquasuite.exe [2016-12-07] (Aqua Computer GmbH & Co. KG) Task: {E2F18998-AF21-42E2-8A16-6C948C1D872E} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {EB05EA3F-20C0-43C8-9F7C-F20E903A4F92} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EEFFC121-9772-4D37-9A1F-8DF00AD5BA37} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {FBCA7BEA-731B-431D-862E-06E5FC876936} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3946114199-4031152989-3939253435-1000Core1d23cd699aebef8.job => C:\Users\Raphael\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3946114199-4031152989-3939253435-1000UA1d23cd699b86bf1.job => C:\Users\Raphael\AppData\Local\Dropbox\Update\DropboxUpdate.exe ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TARGET 3001! V18 pcb-pool\Online Hilfe.lnk -> hxxp://server.ibfriedrich.com/wiki/ibfwikide/index.ph Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TARGET 3001! V16 pcb-pool\Online Hilfe.lnk -> hxxp://server.ibfriedrich.com/wiki/ibfwikide/index.ph Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TARGET 3001! V16 discover\Online Hilfe.lnk -> hxxp://server.ibfriedrich.com/wiki/ibfwikide/index.ph ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2011-06-22 10:44 - 2011-06-22 10:44 - 00034304 _____ () C:\WINDOWS\System32\sst2cl6.dll 2011-06-22 10:43 - 2011-06-22 10:43 - 00826880 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\sst2cdu.dll 2012-01-17 11:24 - 2012-01-17 11:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2012-10-08 17:04 - 2012-10-08 17:04 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe 2012-12-25 17:33 - 2012-12-25 17:33 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2015-11-05 01:11 - 2015-11-05 01:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2011-01-27 15:28 - 2011-01-27 15:28 - 00706048 _____ () C:\WINDOWS\system32\SnMinDrv.dll 2017-06-07 22:09 - 2017-06-07 22:09 - 00598528 _____ () C:\Users\Raphael\AppData\Local\MEGAsync\ShellExtX64.dll 2016-05-18 00:42 - 2016-05-18 00:42 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2016-09-14 03:00 - 2016-09-14 03:00 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2016-09-14 03:00 - 2016-09-14 03:00 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-09-14 03:00 - 2016-09-14 03:00 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2016-09-14 03:00 - 2016-09-14 03:00 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2016-09-14 02:59 - 2016-09-14 02:59 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll 2016-09-14 02:59 - 2016-09-14 02:59 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2016-09-14 03:00 - 2016-09-14 03:00 - 00191488 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll 2017-03-18 22:59 - 2017-03-20 06:36 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-06-21 17:59 - 2017-06-21 18:00 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-06-21 17:59 - 2017-06-21 18:00 - 00203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-06-21 17:59 - 2017-06-21 18:00 - 43454464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-06-21 17:59 - 2017-06-21 18:00 - 02437120 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\skypert.dll 2016-09-12 12:51 - 2016-09-12 12:51 - 00118272 _____ () C:\Program Files\Rainmeter\Plugins\SpeedFanPlugin.DLL 2016-10-12 21:44 - 2016-10-12 21:44 - 00018432 _____ () C:\Users\Raphael\AppData\Roaming\Rainmeter\Plugins\GPUInfo_ohm.dll 2016-09-12 12:51 - 2016-09-12 12:51 - 00096256 _____ () C:\Program Files\Rainmeter\Plugins\PingPlugin.DLL 2015-08-22 20:35 - 2016-04-26 13:42 - 00110952 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll 2015-08-22 20:35 - 2016-04-26 13:42 - 00343400 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\collector.dll 2015-08-22 20:35 - 2016-04-26 13:42 - 00378728 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\stat.dll 2015-08-22 20:35 - 2016-04-26 13:42 - 00104296 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll 2015-08-22 20:35 - 2016-04-26 13:42 - 00020328 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll 2015-08-22 20:35 - 2016-04-26 13:42 - 00044392 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll 2016-09-13 22:07 - 2016-09-13 22:07 - 00033280 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\cx_Logging.cp35-win32.pyd 2016-08-16 00:38 - 2016-08-16 00:38 - 00103424 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32api.pyd 2016-01-12 00:11 - 2016-01-12 00:11 - 00111616 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\pywintypes35.dll 2016-08-16 00:38 - 2016-08-16 00:38 - 00041984 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32process.pyd 2016-01-12 00:12 - 2016-01-12 00:12 - 00405504 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\pythoncom35.dll 2016-08-16 00:38 - 2016-08-16 00:38 - 00173568 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32gui.pyd 2016-08-16 00:33 - 2016-08-16 00:33 - 01934336 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtGui.pyd 2016-08-16 00:33 - 2016-08-16 00:33 - 00077824 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\sip.pyd 2016-08-16 00:33 - 2016-08-16 00:33 - 01780736 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtCore.pyd 2016-08-16 00:33 - 2016-08-16 00:33 - 00505856 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtNetwork.pyd 2016-08-16 00:33 - 2016-08-16 00:33 - 03812864 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtWidgets.pyd 2016-10-06 22:43 - 2017-05-03 20:16 - 02493440 _____ () F:\Origin\libGLESv2.dll 2012-09-07 20:35 - 2012-03-29 07:18 - 01198872 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2016-11-26 23:42 - 2016-11-26 23:42 - 00332104 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\dblite.dll 2016-11-26 23:37 - 2016-11-26 23:37 - 00418512 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\ipm_service.dll 2015-12-15 13:38 - 2015-12-15 13:38 - 00326112 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\dblite.dll 2015-10-27 16:44 - 2015-10-27 16:44 - 00404952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\ipm_service.dll 2016-06-02 18:06 - 2016-06-02 18:06 - 45077376 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\libcef.dll 2016-06-02 18:06 - 2016-06-02 18:06 - 01650560 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\libglesv2.dll 2016-06-02 18:06 - 2016-06-02 18:06 - 00082304 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\libegl.dll 2016-12-21 20:21 - 2016-12-21 20:21 - 45077376 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\libcef.dll 2016-12-21 20:21 - 2016-12-21 20:21 - 01650560 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\libglesv2.dll 2016-12-21 20:21 - 2016-12-21 20:21 - 00082304 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\libegl.dll 2016-04-13 10:38 - 2016-04-13 10:38 - 00482304 _____ () C:\Users\Raphael\AppData\Local\MEGAsync\libsodium.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Classes\.scr: DWGTrueViewScriptFile => C:\WINDOWS\system32\notepad.exe "%1" ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2017-07-02 23:13 - 00001694 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 wemsofts.com 127.0.0.1 bongadoom.com 127.0.0.1 wepcmainsystem.com 127.0.0.1 internalcampaigntargets.com 127.0.0.1 bongadoom.com 127.0.0.1 getthefilenow.com 127.0.0.1 bigpicturepop.com 127.0.0.1 wizzcaster.com 127.0.0.1 bestoffersfortoday.com 127.0.0.1 wepcmainsystem.com 127.0.0.1 agent.wizztrakys.com 127.0.0.1 csdimonetize.com 127.0.0.1 dl.azalee.site 127.0.0.1 titiaredh.com 127.0.0.1 wepcdisplaysystem.com 127.0.0.1 wepcanalyticsystem.com 127.0.0.1 healthydownload.com 127.0.0.1 leading2download.com 127.0.0.1 dwl0.wizzlabs.com 127.0.0.1 dwl1.wizzlabs.com 127.0.0.1 installpixel.com 127.0.0.1 burningcube.ru 127.0.0.1 mess1.wizzmonetize.com 127.0.0.1 dl.azalee.site 127.0.0.1 dl.smashdl.com 127.0.0.1 downloadmyhost.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07022017230852965\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07022017230852987\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Raphael\Pictures\SGE_Wallpaper_Wappen-Rot_1920x1080.jpg DNS Servers: 192.168.0.1 - 8.8.8.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run32: => "AgentMonitor" HKLM\...\StartupApproved\Run32: => "BlueStacks Agent" HKLM\...\StartupApproved\Run32: => "PlaysTV" HKLM\...\StartupApproved\Run32: => "Raptr" HKLM\...\StartupApproved\Run32: => "Razer Synapse" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\StartupFolder: => "Dropbox.lnk" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\StartupFolder: => "OpenOffice.org 3.3.lnk" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\StartupFolder: => "Curse.lnk" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\Run: => "AmazonMP3DownloaderHelper" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\Run: => "Dropbox Update" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\Run: => "GalaxyClient" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\StartupApproved\Run: => "Steam" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{2C4E116D-D715-4CB1-91A3-9C0370CBD7BD}] => (Allow) G:\Games\Installed\Syberia II\Syberia2.exe FirewallRules: [{2A84A75C-C4A4-4C11-9236-9A64769FAE49}] => (Allow) G:\Games\Installed\Syberia II\Syberia2.exe FirewallRules: [{6E5E38BE-E8ED-49C9-8FD3-8F60D6108AD7}] => (Allow) F:\Steam\SteamApps\common\Blood & Gold Caribbean!\Launcher.exe FirewallRules: [{1F36614E-E430-4628-9800-E4F3112D8C0F}] => (Allow) F:\Steam\SteamApps\common\Blood & Gold Caribbean!\Launcher.exe FirewallRules: [{EFAD043A-14DF-4CE8-AF31-5EFDB46EE6E4}] => (Allow) F:\Steam\SteamApps\common\DOOM\DOOMx64.exe FirewallRules: [{7183A495-8F3D-42A8-81A0-932AB3926E36}] => (Allow) F:\Steam\SteamApps\common\DOOM\DOOMx64.exe FirewallRules: [{174DA33C-0D5B-4EE0-B6B3-428645B756D5}] => (Allow) G:\Games\Installed\Anno 2070\InitEngine.exe FirewallRules: [{72BB4C4D-0C67-48BE-AFDE-7641911F069A}] => (Allow) G:\Games\Installed\Anno 2070\InitEngine.exe FirewallRules: [{01A12F25-883A-4AF9-9FFB-F1845ED5D73C}] => (Allow) G:\Games\Installed\Anno 2070\AutoPatcher.exe FirewallRules: [{62F4A5E5-B96F-4A88-87E1-F26FA431D172}] => (Allow) G:\Games\Installed\Anno 2070\AutoPatcher.exe FirewallRules: [{660290BE-E1CF-48A6-AB24-8F294A394F39}] => (Allow) G:\Games\Installed\Anno 2070\Anno5.exe FirewallRules: [{5DE65E60-317E-4AB4-8491-133F4D15D88D}] => (Allow) G:\Games\Installed\Anno 2070\Anno5.exe FirewallRules: [UDP Query User{190A429D-652D-4F17-AF73-7D9A72641378}G:\games\installed\mass effect 2\binaries\me2game.exe] => (Allow) G:\games\installed\mass effect 2\binaries\me2game.exe FirewallRules: [TCP Query User{6CE87BBB-8B74-499C-BAAC-C3A1EE4D624C}G:\games\installed\mass effect 2\binaries\me2game.exe] => (Allow) G:\games\installed\mass effect 2\binaries\me2game.exe FirewallRules: [{789578DA-CC70-4474-B3E1-87F10D62CB6F}] => (Allow) G:\Games\Installed\Mass Effect 2\Binaries\MassEffect2.exe FirewallRules: [{D3A50C79-C713-4182-B1BD-9692FB370003}] => (Allow) G:\Games\Installed\Mass Effect 2\Binaries\MassEffect2.exe FirewallRules: [{961D430E-5093-4F79-B06D-941F3872EFCD}] => (Allow) F:\Steam\SteamApps\common\Skyrim Special Edition\SkyrimSELauncher.exe FirewallRules: [{D9E293DB-210E-4D16-97C2-FEE54B793938}] => (Allow) F:\Steam\SteamApps\common\Skyrim Special Edition\SkyrimSELauncher.exe FirewallRules: [UDP Query User{ADC5B833-384A-42AE-BFAA-59083BD7B8ED}G:\games\installed\diablo 3\diablo iii\x64\diablo iii64.exe] => (Allow) G:\games\installed\diablo 3\diablo iii\x64\diablo iii64.exe FirewallRules: [TCP Query User{A84B3B3F-5D42-4303-9B8A-DCD73E59BD3D}G:\games\installed\diablo 3\diablo iii\x64\diablo iii64.exe] => (Allow) G:\games\installed\diablo 3\diablo iii\x64\diablo iii64.exe FirewallRules: [{B6B42FE4-E624-4D5B-8C7F-384447C24E5C}] => (Allow) G:\Games\Installed\Command and Conquer Red Alert\RA95Launcher.exe FirewallRules: [{96D4942F-3D38-4FC8-B9AE-3475771F900A}] => (Allow) G:\Games\Installed\Command and Conquer Red Alert\RA95Launcher.exe FirewallRules: [{9115FC70-4933-4E3E-95E1-70BC33531F30}] => (Allow) F:\Steam\SteamApps\common\Blood & Gold Caribbean!\bg_caribbean.exe FirewallRules: [{93FFE842-F985-449E-A6E7-2678D96BF5F8}] => (Allow) F:\Steam\SteamApps\common\Blood & Gold Caribbean!\bg_caribbean.exe FirewallRules: [{45AC7331-05B2-457E-B25A-46D48DE5308A}] => (Allow) G:\Games\Installed\CNC and The Covert Operations\CNC95Launcher.exe FirewallRules: [{4A7E415B-DFAF-48C5-8814-D3737152C15F}] => (Allow) G:\Games\Installed\CNC and The Covert Operations\CNC95Launcher.exe FirewallRules: [UDP Query User{23FDA948-3650-4296-B6B4-4D485FC0209D}C:\users\raphael\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\raphael\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{8D469DE0-3DDC-4045-96F4-3F71BE99DC76}C:\users\raphael\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\raphael\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [{497EB8D8-89AE-4E99-9FE4-64DAF157AEAA}] => (Allow) G:\Games\Installed\Renegade\RenegadeLauncher.exe FirewallRules: [{33C46438-CE0C-4AD0-B945-CA90D0D35E39}] => (Allow) G:\Games\Installed\Renegade\RenegadeLauncher.exe FirewallRules: [{594A89CE-013B-4539-9015-AA0B0972177C}] => (Allow) F:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{DEA9153B-F399-465E-9935-67FA23B9579D}] => (Allow) F:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{4C6F0419-AA4A-485E-B089-CCE6207B34CD}] => (Allow) G:\Games\Installed\FIFA 13\Game\fifa13.exe FirewallRules: [{4999AD50-2C0F-48E8-888A-DBC49108C6F9}] => (Allow) G:\Games\Installed\FIFA 13\Game\fifa13.exe FirewallRules: [{CA518199-9B60-4598-A689-C2408014F46F}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{75412833-0FCC-45D9-90D7-D1B959276121}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{783A052A-017F-4F3E-87A0-2B9A5F287EB7}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{9486DC9A-18E3-46C1-B959-97306C509A10}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{6CD2F35B-746F-43BD-B9A9-5519DFA470D7}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{1FD2174B-A1CF-4BD6-9897-C4F0721ED3E1}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [UDP Query User{2832BC30-1C31-41C8-8B9B-5FDBFA021E42}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe FirewallRules: [TCP Query User{22F882A1-1C68-46EE-91C5-4D13110472DF}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe FirewallRules: [{4E093346-5FCD-4C4B-AD11-B21DD5771319}] => (Allow) G:\Games\Installed\Dungeon Keeper\DATA\DOSBox\DOSBox.exe FirewallRules: [{426065C9-5B32-4586-95FB-B68A0B939D27}] => (Allow) G:\Games\Installed\Dungeon Keeper\DATA\DOSBox\DOSBox.exe FirewallRules: [{4799A43D-867B-4394-91AA-8C8DEF8ED975}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4_x64.exe FirewallRules: [{0091700C-D79F-4D9A-B5C3-2322EAED40F2}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4_x64.exe FirewallRules: [{BB544271-25C3-4FBD-AB4B-C0A45A8C2A08}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{2F2DD3F3-9149-4A1F-96AB-407B622D7C9B}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{C6200654-677B-4D7D-9D67-511CA0AA12E8}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{A231760C-49C4-4877-BCAC-64E6945DFAB4}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{8A478D77-DD62-49DF-9A6C-89135444BBCD}] => (Block) C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [{D92DD2F6-8493-46A4-A711-EDE887E7260D}] => (Block) C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{35105382-6E23-455A-B8A7-681633A14A9D}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{65154D9E-6680-476D-B755-E121B5C3DD74}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [{4F2D53A6-9A0E-4097-ADE5-FD68BEE213E0}] => (Block) C:\program files (x86)\arduino\java\bin\javaw.exe FirewallRules: [{E9495722-9BFC-4731-8B73-5BF418E30AD0}] => (Block) C:\program files (x86)\arduino\java\bin\javaw.exe FirewallRules: [UDP Query User{0E40C65B-9DB4-4D1B-B9B4-31BFC96EEC53}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe FirewallRules: [TCP Query User{3184FE95-5C85-4DAF-9E39-0B3228BCD775}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe FirewallRules: [{F5BC4839-E01D-4B6A-9ED3-0AB88CD17F15}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{E872D337-013E-4AB7-9830-4560A31C2A57}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{4A925840-2E84-4338-81AC-01035EA9CD37}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{D8880B03-0955-48A3-AB28-70A5E4078E61}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{55067876-5D10-4FD9-B881-DC9B4A8499AF}] => (Allow) F:\Steam\SteamApps\common\Tom Clancy's The Division\thedivision.exe FirewallRules: [{0BFBC947-E9C2-43A2-8C19-D0E31EB8084C}] => (Allow) F:\Steam\SteamApps\common\Tom Clancy's The Division\thedivision.exe FirewallRules: [{377C5813-D787-4B48-8C8D-68186FC3E26E}] => (Allow) F:\Steam\SteamApps\common\Farming Simulator 2013\FarmingSimulator2013Game.exe FirewallRules: [{AF9CC8D3-BCAD-4FA6-8F60-55DA36E6C658}] => (Allow) F:\Steam\SteamApps\common\Farming Simulator 2013\FarmingSimulator2013Game.exe FirewallRules: [{7B7FE4F2-E46C-4960-9D19-50C3AF803B2F}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{6C8ECA6C-FE1F-4FE2-918B-D14380CBD2CD}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{509F40A7-31BD-4E52-AA80-5492538746D2}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{8E4A75EB-1F41-452D-90D0-148C1EC492C7}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{FDEF9D06-F35D-4753-A196-E1C6F8BFD4A7}] => (Allow) F:\Steam\SteamApps\common\FINAL FANTASY VII\FF7_Launcher.exe FirewallRules: [{4129763A-9364-4DAE-8656-15C71CF3171A}] => (Allow) F:\Steam\SteamApps\common\FINAL FANTASY VII\FF7_Launcher.exe FirewallRules: [{5CD374BD-153D-419F-91AD-D0B3519754DE}] => (Allow) F:\Steam\SteamApps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe FirewallRules: [{1B7FB2C8-ACB1-4A21-BAD0-84CEC1822A09}] => (Allow) F:\Steam\SteamApps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe FirewallRules: [{9E14C0DB-FB7C-45B1-8EEF-1AD7601E3327}] => (Allow) F:\Steam\SteamApps\common\Just Cause 2\JustCause2.exe FirewallRules: [{599F1B02-B594-42A7-AF26-997D0636842C}] => (Allow) F:\Steam\SteamApps\common\Just Cause 2\JustCause2.exe FirewallRules: [{21EAB44B-DCDF-4B1C-B3CA-E3063BDF3E02}] => (Allow) G:\Games\Installed\Might & Magic 10 - Legacy\Might and Magic X Legacy.exe FirewallRules: [{7E62D139-9B00-4893-8F79-7FDD78DBD3A4}] => (Allow) G:\Games\Installed\Might & Magic 10 - Legacy\Might and Magic X Legacy.exe FirewallRules: [{3938F357-E024-4EF0-A3C9-6544A85DBF2C}] => (Allow) C:\Users\Raphael\AppData\Roaming\Andy\Setup.exe FirewallRules: [{801C8B2C-048A-446A-B8CE-FD89A33B4684}] => (Allow) C:\Users\Raphael\AppData\Roaming\Andy\Setup.exe FirewallRules: [{448E91BF-3E45-423F-9200-58071B90F01B}] => (Allow) C:\Program Files\Andy\HandyAndy.exe FirewallRules: [{EB7DABC0-93CC-4C38-92A9-08D3CB5124CF}] => (Allow) C:\Program Files\Andy\HandyAndy.exe FirewallRules: [{916CAE76-F0DD-463F-94A2-667B8FA25A16}] => (Allow) C:\Program Files\Andy\andy.exe FirewallRules: [{16FDBBFD-7EB7-4F27-AA05-6D4240248A60}] => (Allow) C:\Program Files\Andy\andy.exe FirewallRules: [{74428F5A-450D-489E-A0C7-10B39C335ADE}] => (Allow) F:\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [{BBCCAF73-D611-488F-85C8-CD2282A26E98}] => (Allow) F:\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [{B41B1289-28A3-40FE-84C3-DACC9F222D51}] => (Allow) F:\Steam\SteamApps\common\X Rebirth\XRebirth.exe FirewallRules: [{8F57AFBF-C3E4-4F28-AEE0-552B1008CF48}] => (Allow) F:\Steam\SteamApps\common\X Rebirth\XRebirth.exe FirewallRules: [{B7720823-D5DF-4ADA-98A1-42D7295F1D11}] => (Allow) G:\Games\Installed\Ultima 8\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{94345CC6-AA8E-4BB5-A10C-5F259384CECE}] => (Allow) G:\Games\Installed\Ultima 8\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{C5AF3133-BDB4-4AEA-B657-D5548B4ED88C}] => (Allow) G:\Games\Installed\Command and Conquer Red Alert II\RA2Launcher.exe FirewallRules: [{E3ACF104-E62D-4FA5-901C-21FEBE85E286}] => (Allow) G:\Games\Installed\Command and Conquer Red Alert II\RA2Launcher.exe FirewallRules: [{9035CBED-DACE-4116-BEF0-E2A2391F4F79}] => (Allow) G:\Games\Installed\Theme Hospital\data\Game\DOSBox\EALaunchHelper.exe FirewallRules: [{725ACEA1-B76B-4596-B250-147C6A057892}] => (Allow) G:\Games\Installed\Theme Hospital\data\Game\DOSBox\EALaunchHelper.exe FirewallRules: [{4462AE5A-2CCA-47A9-82B2-A28EE64705D4}] => (Allow) LPort=7882 FirewallRules: [UDP Query User{606C32D3-C852-4803-8714-B23485BF9BE5}F:\unity\editor\unity.exe] => (Allow) F:\unity\editor\unity.exe FirewallRules: [TCP Query User{2597D949-4602-4E60-AB8D-51D0CE5D59BB}F:\unity\editor\unity.exe] => (Allow) F:\unity\editor\unity.exe FirewallRules: [{98650E9F-DD14-4C97-BB7A-5A67BD72A08A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{D298B339-6766-47EE-9116-7FC5C82CCC99}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E9DC7E5C-2145-44C0-BD51-7D9BDE50D5F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3F941660-5562-46A2-9429-ACDDF2791ADE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [UDP Query User{51CC1E08-79FD-437A-B9AF-0BD00583B7A4}C:\windows\system32\java.exe] => (Allow) C:\windows\system32\java.exe FirewallRules: [TCP Query User{96FF3726-690F-4D66-B274-A8B30A81BCB6}C:\windows\system32\java.exe] => (Allow) C:\windows\system32\java.exe FirewallRules: [UDP Query User{4AF6CF16-B40A-44F0-90BE-B02B681FB097}G:\games\installed\mohaa\mohaa.exe] => (Allow) G:\games\installed\mohaa\mohaa.exe FirewallRules: [TCP Query User{5AD315DF-F028-4F9D-BC5F-96EF2E3E5DF1}G:\games\installed\mohaa\mohaa.exe] => (Allow) G:\games\installed\mohaa\mohaa.exe FirewallRules: [UDP Query User{0BC9C68B-2A04-46C0-B0ED-87AB6522659B}G:\games\installed\mtx\mtx.exe] => (Allow) G:\games\installed\mtx\mtx.exe FirewallRules: [TCP Query User{2AD2C5D2-5EFA-44E1-B7BD-4C6BAC54D785}G:\games\installed\mtx\mtx.exe] => (Allow) G:\games\installed\mtx\mtx.exe FirewallRules: [UDP Query User{74A2A5C2-0FF3-47EA-97BC-680011F7BF32}G:\games\installed\company of heroes - tales of valor\relicdownloader\relicdownloader.exe] => (Block) G:\games\installed\company of heroes - tales of valor\relicdownloader\relicdownloader.exe FirewallRules: [TCP Query User{1C166455-EA87-493D-B17F-98F2AF44ED3E}G:\games\installed\company of heroes - tales of valor\relicdownloader\relicdownloader.exe] => (Block) G:\games\installed\company of heroes - tales of valor\relicdownloader\relicdownloader.exe FirewallRules: [UDP Query User{62D2F10B-0F6C-4040-97E6-B0762F9DA85F}G:\games\installed\company of heroes - tales of valor\reliccoh.exe] => (Allow) G:\games\installed\company of heroes - tales of valor\reliccoh.exe FirewallRules: [TCP Query User{1633CDF9-11BB-4D39-B331-26D9CA9EACED}G:\games\installed\company of heroes - tales of valor\reliccoh.exe] => (Allow) G:\games\installed\company of heroes - tales of valor\reliccoh.exe FirewallRules: [{E95CCC39-E44C-4DAA-946A-1C0BACC6FC9C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{1D9D908D-54CE-4E2D-A483-B0EB62715706}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{EDB18E21-257B-439A-8415-1035F93138BC}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{D0EE1AB1-0F1E-4D09-9A28-CAB76853ADC0}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{759D9CB2-F777-466A-9A20-8AD84E580044}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe FirewallRules: [{6BA7A881-6DB9-4BD1-AADB-7C9DA9B5C149}] => (Allow) G:\Games\Installed\GTA - Episodes from Liberty City\EFLC\EFLC.exe FirewallRules: [{E3C22C52-E398-478E-A710-FB0E41F96A3A}] => (Allow) G:\Games\Installed\GTA - Episodes from Liberty City\EFLC\EFLC.exe FirewallRules: [{6CA4C141-E02C-49E3-BF59-76598427D135}] => (Allow) G:\Games\Installed\GTA - Episodes from Liberty City\EFLC\LaunchEFLC.exe FirewallRules: [{77BB468B-C745-4FEE-A933-83A9DEEF13C3}] => (Allow) G:\Games\Installed\GTA - Episodes from Liberty City\EFLC\LaunchEFLC.exe FirewallRules: [{A13AC988-AA11-4731-BD2A-481ABD112092}] => (Allow) G:\Games\Installed\Stalker - Clear Sky\bin\dedicated\xrEngine.exe FirewallRules: [{70F8FADA-862E-420E-A1D4-E36B1EF1F99B}] => (Allow) G:\Games\Installed\Stalker - Clear Sky\bin\dedicated\xrEngine.exe FirewallRules: [{85105F96-C78F-41F0-A2CE-15E1165CA69D}] => (Allow) G:\Games\Installed\Stalker - Clear Sky\bin\xrEngine.exe FirewallRules: [{9EF12E7F-27E9-4390-AD74-6C83D23D4B00}] => (Allow) G:\Games\Installed\Stalker - Clear Sky\bin\xrEngine.exe FirewallRules: [{E7CF29A6-B400-4B55-85B9-DF8CD1914E0C}] => (Allow) F:\Steam\SteamApps\common\Cities_Skylines\Cities.exe FirewallRules: [{9A5860DA-1B4C-4CF2-9D62-055F0CE81B85}] => (Allow) F:\Steam\SteamApps\common\Cities_Skylines\Cities.exe FirewallRules: [{50233585-16F1-42D3-BB01-AB7679B556CB}] => (Allow) F:\Steam\SteamApps\common\Cities XXL\CitiesXXL.exe FirewallRules: [{FADA3BD2-F5E8-49C4-8B14-2555B8F93036}] => (Allow) F:\Steam\SteamApps\common\Cities XXL\CitiesXXL.exe FirewallRules: [{8377FF38-114B-4ABE-B778-EC60399021B6}] => (Allow) F:\Steam\SteamApps\common\jabia\JaggedAllianceBIA.exe FirewallRules: [{F0BA9B76-ED30-41C7-A494-B5255C216E74}] => (Allow) F:\Steam\SteamApps\common\jabia\JaggedAllianceBIA.exe FirewallRules: [{80C06701-1967-41AC-B49E-C4D0AF41D0BF}] => (Allow) G:\Games\Installed\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{5D3B0610-D19E-4F4F-9953-00BF0D439AFB}] => (Allow) G:\Games\Installed\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{73626890-47A0-418F-8CB1-AE4506DC7F9B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{DC0B7474-AD4E-4C0E-9D9D-F035A75D99FB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3B329762-A431-4D91-A123-4A51F6718068}] => (Allow) F:\Steam\SteamApps\common\Europa Universalis IV\eu4.exe FirewallRules: [{FA71A84E-CABB-4772-9CB1-9DC5FABEA117}] => (Allow) F:\Steam\SteamApps\common\Europa Universalis IV\eu4.exe FirewallRules: [{D2F2F8D4-F7F1-4AD8-AA6E-9AC095F7E763}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Advanced Warfare\s1_mp64_ship.exe FirewallRules: [{7992B106-DBCA-45CF-9848-48CA7F774696}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Advanced Warfare\s1_mp64_ship.exe FirewallRules: [{0565681D-971C-421D-B7A5-D7455753F2F0}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Advanced Warfare\s1_sp64_ship.exe FirewallRules: [{1FC817AB-D938-4214-9B5B-A2A2A52B91BF}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Advanced Warfare\s1_sp64_ship.exe FirewallRules: [UDP Query User{C7386C87-96BF-4F55-9FA6-68447510E270}G:\games\installed\fifa manager 13\manager13.exe] => (Block) G:\games\installed\fifa manager 13\manager13.exe FirewallRules: [TCP Query User{C78AA092-4428-42B3-9952-E98287A681E4}G:\games\installed\fifa manager 13\manager13.exe] => (Block) G:\games\installed\fifa manager 13\manager13.exe FirewallRules: [UDP Query User{C9835174-352E-4E17-863A-DF9BF8187342}C:\users\raphael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\raphael\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{84BBF49F-D47F-4CA3-8AAF-23E0FAB91307}C:\users\raphael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\raphael\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{75A6D304-6D66-42F4-BB78-9F15A1F147A3}C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe] => (Allow) C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe FirewallRules: [TCP Query User{199F68F6-D3C2-4656-9258-871CD11E22DE}C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe] => (Allow) C:\program files (x86)\atmel\atmel studio 6.2\atmelstudio.exe FirewallRules: [{A2B57FCF-E38D-4A59-952B-869A4BA666B6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{E00DBD43-AF0A-485B-9F4C-E05DA444E9E6}] => (Allow) LPort=1900 FirewallRules: [{29A3C295-0317-4FD4-ACD0-6C196DFFF0B1}] => (Allow) LPort=2869 FirewallRules: [{F3A589DF-7F15-47E7-B37C-167C4413BC03}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{1C9679CD-063D-4135-9157-4FCEED04B6DF}] => (Allow) C:\Users\Raphael\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{595B532A-3DD8-45F0-A836-2958B53193A2}] => (Allow) F:\Steam\bin\steamwebhelper.exe FirewallRules: [{2043C4DC-410B-4D6F-BEB0-3F9AD82978EB}] => (Allow) F:\Steam\bin\steamwebhelper.exe FirewallRules: [{290C3520-2B37-4B0E-9EC9-C2858B1C88CD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [{EC35E65C-68C8-489F-8833-75856D739BD9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [UDP Query User{F8B1350C-2C7C-4A2A-91C9-D76DE0BD640B}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe FirewallRules: [TCP Query User{03933842-C770-4244-8887-9DA75EC42B9E}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe FirewallRules: [{7000BE5B-7D54-4D03-A437-23E61C0FCF8C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [{17884AE8-7058-40A9-9197-54A99E185BB6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [UDP Query User{A219D754-8A85-4DF9-9D44-DD441F2C5F9E}C:\programdata\battle.net\agent\agent.3109\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3109\agent.exe FirewallRules: [TCP Query User{2D7A0F55-8B84-481F-9E97-892FF7A610C1}C:\programdata\battle.net\agent\agent.3109\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3109\agent.exe FirewallRules: [{AF8E277E-2F14-484B-A512-648F97BA8F58}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [{37E86662-7B05-429F-86F3-550CEA6D95A7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [{1D4D2A0C-1A54-4580-85A9-7551A801987C}] => (Allow) G:\Games\Installed\Battle.net\Battle.net.exe FirewallRules: [{E1CE9F84-447D-4E37-B0EC-43A8DF566EF5}] => (Allow) G:\Games\Installed\Battle.net\Battle.net.exe FirewallRules: [{97D78EC8-8DEB-4AAA-984E-C744D47E97D1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{530F7B57-084C-4E83-95EB-B1AD8CF5DE62}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [UDP Query User{59C94A42-DA5B-468B-8B46-DB584E1F8FB2}C:\users\raphael\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light] => (Allow) C:\users\raphael\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light FirewallRules: [TCP Query User{60108FBB-0760-4F61-B292-507C04DB26B8}C:\users\raphael\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light] => (Allow) C:\users\raphael\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light FirewallRules: [UDP Query User{20504C4E-A1BB-4244-8D44-93E30DEE8D51}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [TCP Query User{EC18E7ED-63E6-4496-AFA3-7C76826ADEA5}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{8D3B9A13-C4D8-41AB-BD15-0D7253285C12}D:\programme\emule\emule.exe] => (Allow) D:\programme\emule\emule.exe FirewallRules: [TCP Query User{B294DB8C-72B7-41CD-AE06-21541D6570BE}D:\programme\emule\emule.exe] => (Allow) D:\programme\emule\emule.exe FirewallRules: [UDP Query User{F84B8968-92BF-43EC-BFD5-13210CDB0584}C:\program files (x86)\microsoft games\freelancer\exe\freelancer.exe] => (Allow) C:\program files (x86)\microsoft games\freelancer\exe\freelancer.exe FirewallRules: [TCP Query User{26B4B2C2-C30A-46C3-9C7F-CCAE9834F530}C:\program files (x86)\microsoft games\freelancer\exe\freelancer.exe] => (Allow) C:\program files (x86)\microsoft games\freelancer\exe\freelancer.exe FirewallRules: [UDP Query User{A1712B56-3C79-4D46-9AB3-CDDEB2A38515}G:\games\installed\anno 1701\anno1701.exe] => (Allow) G:\games\installed\anno 1701\anno1701.exe FirewallRules: [TCP Query User{BB75F8B5-80B0-4F92-B66F-BC3AEB7B40ED}G:\games\installed\anno 1701\anno1701.exe] => (Allow) G:\games\installed\anno 1701\anno1701.exe FirewallRules: [UDP Query User{95A1FFB2-0D1E-469D-9A31-CC1FF32CD07A}C:\program files (x86)\mcs electronics\bascom-avr\bascavr.exe] => (Allow) C:\program files (x86)\mcs electronics\bascom-avr\bascavr.exe FirewallRules: [TCP Query User{A61C2823-9034-4FAD-BA2F-6243DFEA7776}C:\program files (x86)\mcs electronics\bascom-avr\bascavr.exe] => (Allow) C:\program files (x86)\mcs electronics\bascom-avr\bascavr.exe FirewallRules: [{D4FB4D09-4061-4EC4-A95D-2FA8B85AD633}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{F0C00CBE-7706-4F39-A52A-4BD34DE51BC4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [UDP Query User{BE8682A3-89D1-4F00-8035-F47A9F3FC170}F:\steam\steam.exe] => (Allow) F:\steam\steam.exe FirewallRules: [TCP Query User{C0C503DA-036F-4E03-8872-AC8157188E94}F:\steam\steam.exe] => (Allow) F:\steam\steam.exe FirewallRules: [{28C334CF-717E-4D43-8905-CC4F17305D4D}] => (Allow) F:\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe FirewallRules: [{D984BB69-6F15-450D-AA98-3C7BEA72BB23}] => (Allow) F:\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe FirewallRules: [{C0121668-2F63-4131-905D-410700EAEF61}] => (Allow) F:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{224251C6-26A5-44C3-BE90-0AB74E6F7734}] => (Allow) F:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{C8B16472-C0E2-4AC2-AA8B-482FE7951E3D}] => (Allow) F:\Steam\SteamApps\common\skyrim\CreationKit.exe FirewallRules: [{3A0893C7-5B4B-4AE1-A63F-44E78A5CB743}] => (Allow) F:\Steam\SteamApps\common\skyrim\CreationKit.exe FirewallRules: [{3ED0E5CA-A575-45D7-B510-A3B8E25D7538}] => (Allow) F:\Steam\SteamApps\common\Darksiders 2\Darksiders2.exe FirewallRules: [{44AEAAB5-0BEC-44E3-AD00-5AF143A8BEB0}] => (Allow) F:\Steam\SteamApps\common\Darksiders 2\Darksiders2.exe FirewallRules: [UDP Query User{AA8E91A5-9C97-4CA8-9366-4D11249A45E1}G:\games\installed\diablo 3\diablo iii\diablo iii.exe] => (Allow) G:\games\installed\diablo 3\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{CA582549-DC96-499F-9E3B-25B71364C158}G:\games\installed\diablo 3\diablo iii\diablo iii.exe] => (Allow) G:\games\installed\diablo 3\diablo iii\diablo iii.exe FirewallRules: [{4121EA75-FC78-4BA1-954C-4FF416AC558C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [{156D36CB-E206-466B-9707-9B8ECFEF51EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [{4D81CDFF-7644-4CD0-AF16-035088D73DC1}] => (Allow) F:\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe FirewallRules: [{A59A11AE-FE0A-48C9-B82C-7E64EE7C319A}] => (Allow) F:\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe FirewallRules: [{D21321F0-93EA-48E2-8C5D-04CAA7B34D31}] => (Allow) C:\Users\Raphael\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{AEF76037-D110-4000-A364-05872FEE2735}] => (Allow) C:\Users\Raphael\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{9577366C-B4DE-4FB1-AA8D-1FAEFCEDA279}] => (Allow) F:\Steam\SteamApps\common\Mount & Blade With Fire and Sword\mb_wfas.exe FirewallRules: [{CB9CC515-C1E0-4814-A373-89054834E697}] => (Allow) F:\Steam\SteamApps\common\Mount & Blade With Fire and Sword\mb_wfas.exe FirewallRules: [{E9C69B8A-226D-4A9A-8FE7-32E186F0E20D}] => (Allow) F:\Steam\SteamApps\common\Hearts of Iron 3\hoi3.exe FirewallRules: [{FC1DADDF-D4A4-46D3-AD54-A13A6D16B422}] => (Allow) F:\Steam\SteamApps\common\Hearts of Iron 3\hoi3.exe FirewallRules: [{A09E4811-9090-4EA6-AFD9-B0382736F6F1}] => (Allow) F:\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe FirewallRules: [{C57EFACF-D8A4-4A6F-9AC6-50C7FFDD3557}] => (Allow) F:\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe FirewallRules: [UDP Query User{95BAAFB0-CDE7-4485-8CF2-D6DAC567FCFF}G:\games\installed\sacred 2\system\s2gs.exe] => (Allow) G:\games\installed\sacred 2\system\s2gs.exe FirewallRules: [TCP Query User{A6496F57-FED3-46C5-8991-5A9921B7B596}G:\games\installed\sacred 2\system\s2gs.exe] => (Allow) G:\games\installed\sacred 2\system\s2gs.exe FirewallRules: [UDP Query User{B98665C7-8178-4B47-80D0-E511CB586F37}G:\games\installed\silent hunter 5\goblineditorapp.exe] => (Block) G:\games\installed\silent hunter 5\goblineditorapp.exe FirewallRules: [TCP Query User{7A86DA73-9BB9-4097-9FB0-A1D95F91D83F}G:\games\installed\silent hunter 5\goblineditorapp.exe] => (Block) G:\games\installed\silent hunter 5\goblineditorapp.exe FirewallRules: [UDP Query User{ACC8D44E-6B80-46EF-90DD-3EC712E6FE4C}G:\games\installed\stronghold crusader\stronghold_crusader_extreme.exe] => (Allow) G:\games\installed\stronghold crusader\stronghold_crusader_extreme.exe FirewallRules: [TCP Query User{5C58628F-1AC8-4963-9BC0-9D521AA68565}G:\games\installed\stronghold crusader\stronghold_crusader_extreme.exe] => (Allow) G:\games\installed\stronghold crusader\stronghold_crusader_extreme.exe FirewallRules: [UDP Query User{59C6756C-2AB3-4B3C-9ABF-35AA82603E08}G:\games\installed\stronghold crusader\stronghold crusader.exe] => (Allow) G:\games\installed\stronghold crusader\stronghold crusader.exe FirewallRules: [TCP Query User{4A053A81-284E-4355-8E6A-446826264372}G:\games\installed\stronghold crusader\stronghold crusader.exe] => (Allow) G:\games\installed\stronghold crusader\stronghold crusader.exe FirewallRules: [UDP Query User{F7AB25AB-AE90-4096-8F20-4F105DE3D0BA}G:\games\installed\stronghold 2\stronghold2.exe] => (Allow) G:\games\installed\stronghold 2\stronghold2.exe FirewallRules: [TCP Query User{45D0FF32-44CE-4F02-9143-1CE70F62B96A}G:\games\installed\stronghold 2\stronghold2.exe] => (Allow) G:\games\installed\stronghold 2\stronghold2.exe FirewallRules: [UDP Query User{CF9207A2-606A-4631-B209-FA54653FF91B}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [TCP Query User{4AE70B9F-831F-4334-AB8A-D7DA7C675383}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [UDP Query User{B921AEB4-703F-4081-B9D0-BBB2A07E8542}G:\games\installed\stronghold\stronghold.exe] => (Allow) G:\games\installed\stronghold\stronghold.exe FirewallRules: [TCP Query User{0487B5E2-3BEC-4F71-B4D5-D443EB1FF8D0}G:\games\installed\stronghold\stronghold.exe] => (Allow) G:\games\installed\stronghold\stronghold.exe FirewallRules: [{3388B7AD-CA7B-4025-82C1-A3F24DD4B104}] => (Allow) G:\Games\Installed\Farcry 3\bin\FC3Editor.exe FirewallRules: [{01F68BAA-2164-4004-91DD-3C53040F9B5B}] => (Allow) G:\Games\Installed\Farcry 3\bin\FC3Editor.exe FirewallRules: [{A4386F28-A3B0-47C2-9BDD-23FDB27F85BB}] => (Allow) G:\Games\Installed\Farcry 3\bin\FC3Updater.exe FirewallRules: [{4ACF4F30-6A5F-4FDD-AD7E-88AD61103152}] => (Allow) G:\Games\Installed\Farcry 3\bin\FC3Updater.exe FirewallRules: [{A03F447F-95FB-4AD3-BFA3-4016D9D13708}] => (Allow) G:\Games\Installed\Farcry 3\bin\farcry3_d3d11.exe FirewallRules: [{2B7830F5-7FE9-401F-9D65-8708CCC434A9}] => (Allow) G:\Games\Installed\Farcry 3\bin\farcry3_d3d11.exe FirewallRules: [{0C87B412-BDD1-4306-B18C-E7D56D549438}] => (Allow) G:\Games\Installed\Farcry 3\bin\farcry3.exe FirewallRules: [{E8D72497-42A6-4E37-9ADB-0F9426439C06}] => (Allow) G:\Games\Installed\Farcry 3\bin\farcry3.exe FirewallRules: [{5F7CBF1D-82CE-4D7F-94BA-644B2FAA02F9}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{8745C613-656D-451D-BEAE-54AB316CD0F1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{81D3BA50-D636-4DFE-B530-259BEBC4DA7E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{A7215349-0092-4EB9-BA71-AA80843444B0}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{58A59899-C2AA-44EA-9D31-F0CFF5E8C865}] => (Allow) F:\Steam\SteamApps\common\dirt showdown\showdown.exe FirewallRules: [{5FEC985E-3BAF-442C-9264-4A12576EF736}] => (Allow) F:\Steam\SteamApps\common\dirt showdown\showdown.exe FirewallRules: [{BE20B14C-55D7-470B-957F-B8DF556A671C}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4mp.exe FirewallRules: [{CE30ECDC-C9DF-4AB9-84A8-9DAA3C865589}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4mp.exe FirewallRules: [{80A3D9C7-0C8D-474F-B6D2-5E2AC6F393C9}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [{29D58B63-61BD-471B-8409-3A361B4F1E93}] => (Allow) F:\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [UDP Query User{BBDFC2E5-255D-44E9-930B-DE93E27D5B8F}C:\program files (x86)\musicbrainz picard\picard.exe] => (Allow) C:\program files (x86)\musicbrainz picard\picard.exe FirewallRules: [TCP Query User{D454BF7E-F037-44EC-9AD7-978C6E799BE7}C:\program files (x86)\musicbrainz picard\picard.exe] => (Allow) C:\program files (x86)\musicbrainz picard\picard.exe FirewallRules: [UDP Query User{275E33BB-2E99-4837-825E-3FBBEB5A0067}C:\program files (x86)\zyxel\nsu\nsu.exe] => (Allow) C:\program files (x86)\zyxel\nsu\nsu.exe FirewallRules: [TCP Query User{B1257F71-DCF9-4756-9776-7C1912EA395F}C:\program files (x86)\zyxel\nsu\nsu.exe] => (Allow) C:\program files (x86)\zyxel\nsu\nsu.exe FirewallRules: [UDP Query User{7D3B88C1-94E0-436E-B8DA-C86EAAFD5DEC}G:\games\installed\steamlibrary\steamapps\common\call of duty modern warfare 2\iw4sp.exe] => (Block) G:\games\installed\steamlibrary\steamapps\common\call of duty modern warfare 2\iw4sp.exe FirewallRules: [TCP Query User{D97BFCD2-998F-429A-B067-E64C14D15F6A}G:\games\installed\steamlibrary\steamapps\common\call of duty modern warfare 2\iw4sp.exe] => (Block) G:\games\installed\steamlibrary\steamapps\common\call of duty modern warfare 2\iw4sp.exe FirewallRules: [{1A85B8A0-9791-4886-A48D-E38E1A8A2CF3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe FirewallRules: [{7580372C-3659-4670-B459-9D2269870E30}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe FirewallRules: [{46EB5038-D5C0-45E2-87B5-5D601CE0339F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{606EDAB8-883A-4AD8-94D4-8E11700F4DA1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{E0A7110F-4758-4E71-9084-8F117FD3B3EF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Farming Simulator 2013\FarmingSimulator2013Game.exe FirewallRules: [{43C142C7-F6C7-4BB6-8414-28ABA1392325}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Farming Simulator 2013\FarmingSimulator2013Game.exe FirewallRules: [{21C1F9D3-F1C7-49DA-9E00-9CBF27E4C9A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{73C18CB9-49EB-498C-A9E6-76316CF1A343}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{B1D552EE-328D-4D6F-89DE-0A1A03FA2C1E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe FirewallRules: [{6BCA3869-C81F-46D2-B0D7-7C515FC44CF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe FirewallRules: [UDP Query User{B2105485-2684-4B3A-824B-D0DFB81F075C}G:\games\diablo 3\diablo iii\diablo iii.exe] => (Allow) G:\games\diablo 3\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{33A5E969-9162-4710-87FD-01AEC77000C9}G:\games\diablo 3\diablo iii\diablo iii.exe] => (Allow) G:\games\diablo 3\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{D6EAFC87-6C85-4F45-85BA-E620B472220A}G:\games\installed\mechwarrior 4\mw4mercs.exe] => (Allow) G:\games\installed\mechwarrior 4\mw4mercs.exe FirewallRules: [TCP Query User{8269B233-4E47-4A38-86AB-DFB901B10BD3}G:\games\installed\mechwarrior 4\mw4mercs.exe] => (Allow) G:\games\installed\mechwarrior 4\mw4mercs.exe FirewallRules: [{3F553D91-4734-4C41-90F8-BA021CF2252C}] => (Allow) G:\Games\Installed\Bohemia Interactive\arma2OA.exe FirewallRules: [{AEC96F81-A3E2-408A-9E75-D870EA945A01}] => (Allow) G:\Games\Installed\Bohemia Interactive\arma2OA.exe FirewallRules: [{4F973B0D-0245-45AA-B293-3F67595FCA9B}] => (Allow) G:\Games\Installed\Bohemia Interactive\arma2.exe FirewallRules: [{4B87C2D1-3396-441B-9BD0-ED08C600B1F4}] => (Allow) G:\Games\Installed\Bohemia Interactive\arma2.exe FirewallRules: [{C0EA0A4F-5F21-4F32-BF37-74FD275E0DD8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe FirewallRules: [{DB9CF879-ABD4-40DA-8B66-23BDB2530EAE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe FirewallRules: [{353EE97E-08D3-403A-98BD-4D67ED028D09}] => (Allow) G:\Games\Installed\ArmA\arma_server.exe FirewallRules: [{A54F19D9-C456-4E5C-83F6-1A9ADEDB69B6}] => (Allow) G:\Games\Installed\ArmA\arma_server.exe FirewallRules: [{5AAEB360-7F29-4F40-B773-CCF7F043710B}] => (Allow) G:\Games\Installed\ArmA\arma.exe FirewallRules: [{B7CB25A9-F0C1-4047-B8F8-8588E0257D79}] => (Allow) G:\Games\Installed\ArmA\arma.exe FirewallRules: [{2847CFD6-D357-45BF-A374-66AAAC65AEE3}] => (Allow) G:\Games\Installed\Bohemia Interactive\ColdWarAssault_Server.exe FirewallRules: [{42C1F91F-8624-46E1-ABBD-9D932388DA88}] => (Allow) G:\Games\Installed\Bohemia Interactive\ColdWarAssault_Server.exe FirewallRules: [{223B1954-19D5-4A8F-85A5-A7A9735D7CAA}] => (Allow) G:\Games\Installed\Bohemia Interactive\ColdWarAssault.exe FirewallRules: [{A38DC24D-C7B8-4164-95C4-00EF32CA5935}] => (Allow) G:\Games\Installed\Bohemia Interactive\ColdWarAssault.exe FirewallRules: [{4360F54A-7FB9-4783-B436-6BC0417D62F3}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe FirewallRules: [{4C82523D-1792-493A-BAFD-1B031ECED5B5}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe FirewallRules: [{155D2A2A-E62E-4A4A-8716-1EF9B61C845C}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\USDAgent.exe FirewallRules: [{6399D845-F8A7-4672-9E94-8D126D79F2E6}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\USDAgent.exe FirewallRules: [{9FC1C746-356B-483E-9010-04A4240C253A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{4069ABD4-FDE7-4DFF-82C0-9E5337CAB9C1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{CAC89030-842A-43AF-A856-68189635E026}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{51E4DEC4-509E-4722-8DFD-C0D05FF1BE78}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{059CA906-D79C-4D3F-8632-C9475A6A2D1F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe FirewallRules: [{6E2335AB-34AC-42FC-9740-B487071DB3E8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe FirewallRules: [UDP Query User{DBC1451B-E7F4-4912-85EA-1DBA60F42D3E}G:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe] => (Allow) G:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe FirewallRules: [TCP Query User{DA785DDB-D2AC-40D2-9317-13FB1907C833}G:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe] => (Allow) G:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe FirewallRules: [{E0FEC11B-D8D4-4783-A382-F649FCA9A792}] => (Allow) G:\Games\World of Warcraft\Launcher.patch.exe FirewallRules: [{FDD52CD3-8B60-4BFE-A58E-12C074DD67F1}] => (Allow) G:\Games\World of Warcraft\Launcher.patch.exe FirewallRules: [UDP Query User{84DA5BDA-D978-42AE-B7EF-687D9197961D}G:\games\world of warcraft\launcher.exe] => (Allow) G:\games\world of warcraft\launcher.exe FirewallRules: [TCP Query User{1907FB46-25AA-4EEB-886A-79F5E72C15FC}G:\games\world of warcraft\launcher.exe] => (Allow) G:\games\world of warcraft\launcher.exe FirewallRules: [{5BCF122D-F60D-4F70-B198-919E9EF5D256}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dirt showdown\showdown.exe FirewallRules: [{BB1DFF9A-D1F2-48D1-9283-7C0B36EF63E1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dirt showdown\showdown.exe FirewallRules: [{BB116CCA-80C3-4F4D-9C9F-4FECE1C2B546}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{13441382-FF49-4FDC-92D0-DCE3E8847D12}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{E10B7FE6-7106-4AFC-8F27-460037F92C39}C:\program files (x86)\airdroid\airdroid.exe] => (Allow) C:\program files (x86)\airdroid\airdroid.exe FirewallRules: [UDP Query User{A8FB516D-886E-434D-87CE-BCF8C5C1AF4B}C:\program files (x86)\airdroid\airdroid.exe] => (Allow) C:\program files (x86)\airdroid\airdroid.exe FirewallRules: [TCP Query User{45E5C51D-10D1-4C27-9C81-32AA7D557621}G:\games\installed\.minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) G:\games\installed\.minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{1F1400CD-54BC-43B8-BB7E-898BDAF0FCA5}G:\games\installed\.minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) G:\games\installed\.minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [{AFB0A761-FFDB-4B7C-AB3E-56FD9458AEDF}] => (Allow) F:\Steam\SteamApps\common\Hearts of Iron IV\hoi4.exe FirewallRules: [{A93A3937-FE7C-4A63-A899-EFF10CB3B8AE}] => (Allow) F:\Steam\SteamApps\common\Hearts of Iron IV\hoi4.exe FirewallRules: [{6D29FC8B-7D04-48E5-83DA-F0D14173183B}] => (Allow) G:\Games\Installed\Far Cry Primal\bin\FCPrimal.exe FirewallRules: [{491BF064-40DE-4083-8330-7A9738A59FB4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{45277417-8EA4-4B6B-BF9D-5EC099A5AE25}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{A75AEEDE-7FBF-4078-9D42-750173958964}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{62955289-573C-4464-92E0-D33341364D17}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{458F62DB-6EAE-4E0E-B644-AE9D0F733F7A}] => (Allow) G:\Games\Installed\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{91373339-C451-473F-BEBA-A5139879D7E0}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{13B1E357-E582-460F-94B8-EE36DA6A4680}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{ABAC7599-8AAE-4FFE-B0AC-27113127EF34}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4_x64.exe FirewallRules: [{A9EFCAC4-8679-48D3-81DF-B45A5663820A}] => (Allow) G:\Games\Installed\The Sims 4\Game\Bin\TS4_x64.exe FirewallRules: [{A5EC54EB-2AC0-473C-8870-EDDB1F8A45C9}] => (Allow) G:\Games\Installed\FIFA Manager 13\Manager13.exe FirewallRules: [{8C9BBA92-2BF8-47A6-B31F-0B944064B3BA}] => (Allow) G:\Games\Installed\FIFA Manager 13\Manager13.exe FirewallRules: [{53452A78-073A-45B4-A7A1-CC76B9D08905}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [{07050E64-F1B0-401E-AFB4-D59855A7A0C0}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{01CE60FB-9949-4136-9B9A-599B8065CB22}] => (Allow) C:\Windows\System32\rundll32.exe ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. |
07.07.2017, 16:10 | #4 |
| Malware verhindert MBAM/Windows Defender Und hier Addition.txt Teil 2: Code:
ATTFilter ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (07/05/2017 08:24:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Monitor.exe, Version: 1.1.0.3, Zeitstempel: 0x4f912217 Name des fehlerhaften Moduls: Exeio.dll, Version: 1.0.2.7, Zeitstempel: 0x4f8f7487 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00004317 ID des fehlerhaften Prozesses: 0x850 Startzeit der fehlerhaften Anwendung: 0x01d2f5bbf43af2f9 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\ASUS\GPU Tweak\Exeio.dll Berichtskennung: ea70794a-c4ae-4b41-8992-1ee0580d0c07 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/04/2017 10:04:57 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 40234 Error: (07/04/2017 10:04:57 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 40234 Error: (07/04/2017 10:04:57 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/04/2017 10:04:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 39156 Error: (07/04/2017 10:04:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 39156 Error: (07/04/2017 10:04:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/04/2017 10:04:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 38156 Error: (07/04/2017 10:04:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 38156 Error: (07/04/2017 10:04:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Systemfehler: ============= Error: (07/04/2017 10:04:16 PM) (Source: DCOM) (EventID: 10010) (User: Raphael-PC) Description: Der Server "{9BA05972-F6A8-11CF-A442-00A0C90A8F39}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (07/02/2017 10:57:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Error: (07/02/2017 10:57:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (07/02/2017 10:57:49 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 02.07.2017 um 22:36:57 unerwartet heruntergefahren. Error: (07/02/2017 10:49:45 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT-AUTORITÄT) Description: Fehler beim Lesen der Datei für lokale Hosts. Error: (07/02/2017 09:46:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Error: (07/02/2017 09:46:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (06/27/2017 06:05:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Origin Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/27/2017 04:55:26 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Error: (06/27/2017 04:55:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. CodeIntegrity: =================================== Date: 2017-07-02 22:48:45.442 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 22:48:45.442 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 21:57:01.286 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 21:57:01.285 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 21:30:01.993 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 21:30:01.993 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 19:54:17.918 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 19:54:17.918 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 19:10:30.424 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-02 19:10:30.423 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz Prozentuale Nutzung des RAM: 46% Installierter physikalischer RAM: 8072.42 MB Verfügbarer physikalischer RAM: 4296.39 MB Summe virtueller Speicher: 16264.42 MB Verfügbarer virtueller Speicher: 11504.38 MB ==================== Laufwerke ================================ Drive c: (SSD) (Fixed) (Total:118.7 GB) (Free:4.94 GB) NTFS Drive d: (Alte Platte) (Fixed) (Total:465.75 GB) (Free:465.6 GB) NTFS Drive e: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive f: (Daten/Musik/Steam) (Fixed) (Total:689.95 GB) (Free:220.39 GB) NTFS Drive g: (Spiele) (Fixed) (Total:690.21 GB) (Free:95.58 GB) NTFS ==================== MBR & Partitionstabelle ================== ==================== Ende von Addition.txt ============================ |
08.07.2017, 10:56 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malware verhindert MBAM/Windows Defender Dann probier mal bitte MBAR: Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ Logfiles bitte immer in CODE-Tags posten |
08.07.2017, 19:41 | #6 |
| Malware verhindert MBAM/Windows Defender MBAR meldet "Scan finished: No malware found!" und "Congratulations, no cleanup is required!" Allerdings ist mir im Startmenü unter "Zuletzt hinzugefügt" eine Software mit chinesischen Schriftzeichen als Name aufgefallen. Die ist nicht wissentlich da gelandet und nagelneu. Niemand außer mir benutzt diesen PC. |
09.07.2017, 15:30 | #7 |
| Malware verhindert MBAM/Windows Defender Sorry vergessen: Hier das Log von MBAR Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2017.07.08.05 rootkit: v2017.05.27.01 Windows 10 x64 NTFS Internet Explorer 11.413.15063.0 Raphael :: RAPHAEL-PC [administrator] 08.07.2017 20:07:26 mbar-log-2017-07-08 (20-07-26).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 458395 Time elapsed: 6 minute(s), 33 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
10.07.2017, 09:31 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malware verhindert MBAM/Windows Defender Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ Logfiles bitte immer in CODE-Tags posten |
10.07.2017, 16:27 | #9 |
| Malware verhindert MBAM/Windows Defender Ich kann mein AV-Programm nicht deaktivieren. Malwarebytes ist angeblich an und lässt sich aber nicht mehr starten oder deinstallieren. Es passiert einach garnichts wenn man es starten will. Egal ob mit Doppelklick oder R-Klick/Öffnen oder R-Klick/Als Administrator. Soll ich deine Anweisungen trotzdem ausführen? Oder gibts es eine andere Möglichkeit zur Deaktivierung? |
10.07.2017, 19:45 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malware verhindert MBAM/Windows Defender malwarebytes is eh unkritisch mach einfach weiter.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.07.2017, 16:59 | #11 |
| Malware verhindert MBAM/Windows Defender Oh Mann und ich dachte, ich sei vorsichtig genug was Adware angeht Nach JRT ließ sich Malwarebytes wieder starten! Hier das Log von meinem ersten Scan bevor ich dich um Rat ersucht habe: Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 03.07.17 Scan-Zeit: 17:29 Protokolldatei: Administrator: Ja -Softwaredaten- Version: 3.1.2.1733 Komponentenversion: 1.0.139 Version des Aktualisierungspakets: 1.0.2285 Lizenz: Testversion -Systemdaten- Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: Raphael-PC\Raphael -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Ergebnis: Abgeschlossen Gescannte Objekte: 525640 Erkannte Bedrohungen: 5 In die Quarantäne verschobene Bedrohungen: 5 Abgelaufene Zeit: 1 Min., 44 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 1 Adware.Tuto4PC, HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\SOFTWARE\MICROSOFT\BIGTIME, In Quarantäne, [934], [412877],1.0.2285 Registrierungswert: 1 Adware.Tuto4PC, HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\SOFTWARE\MICROSOFT\BIGTIME|PARTNER, In Quarantäne, [934], [412877],1.0.2285 Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 1 Adware.Tuto4PC.Generic, C:\USERS\RAPHAEL\APPDATA\LOCAL\TEMP\23-91864-569-1249A-6102BDD5B628E, In Quarantäne, [1343], [368102],1.0.2285 Datei: 2 PUP.Optional.BitCoinMiner, C:\Users\Raphael\AppData\Roaming\gplyra\gplyra\gplyra.exe, In Quarantäne, [206], [316518],1.0.2285 Adware.Tuto4PC.Generic, C:\USERS\RAPHAEL\APPDATA\LOCAL\TEMP\23-91864-569-1249A-6102BDD5B628E\LUDPVZUPWG.EXE, In Quarantäne, [1343], [368102],1.0.2285 Physischer Sektor: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v6.047 - Bericht erstellt am 11/07/2017 um 17:46:50 # Aktualisiert am 19/05/2017 von Malwarebytes # Datenbank : 2017-07-10.1 [Server] # Betriebssystem : Windows 10 Home (X64) # Benutzername : Raphael - RAPHAEL-PC # Gestartet von : F:\Downloads\AdwCleaner_6.047.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner gelöscht: C:\Users\Raphael\AppData\Local\DownloadManager [-] Ordner gelöscht: C:\Users\Raphael\AppData\Local\eSupport.com [-] Ordner gelöscht: C:\Users\Raphael\AppData\Local\AdvinstAnalytics [-] Ordner gelöscht: C:\Users\Raphael\AppData\LocalLow\FlagFox [-] Ordner gelöscht: C:\Users\Raphael\AppData\Roaming\dvdvideosoftiehelpers [-] Ordner gelöscht: C:\Users\Raphael\AppData\Roaming\Tencent [-] Ordner gelöscht: C:\Users\Raphael\AppData\Roaming\devnull [-] Ordner gelöscht: C:\Users\Silvia\AppData\Local\DownloadManager [-] Ordner gelöscht: C:\ProgramData\Tencent [-] Ordner gelöscht: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件 [-] Ordner gelöscht: C:\Program Files (x86)\eSupport.com [-] Ordner gelöscht: C:\Program Files (x86)\Tencent [-] Ordner gelöscht: C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Tencent [-] Ordner gelöscht: C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfdfamfnacokbbbnmpdfmhonipnhmbid ***** [ Dateien ] ***** [-] Datei gelöscht: C:\Users\Raphael\appdata\local\installationconfiguration.xml [-] Datei gelöscht: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\腾讯视频.lnk [-] Datei gelöscht: C:\WINDOWS\SysNative\LavasoftTcpService64.dll [-] Datei gelöscht: C:\WINDOWS\SysNative\LavasoftTcpServiceOff.ini [-] Datei gelöscht: C:\WINDOWS\SysNative\drivers\LACE_WPF_X64.SYS [#] Datei gelöscht: C:\WINDOWS\SysNative\drivers\Lace_wpf_x64.sys [-] Datei gelöscht: C:\END [-] Datei gelöscht: C:\WINDOWS\SysWOW64\lavasofttcpservice.dll [-] Datei gelöscht: C:\WINDOWS\SysWOW64\LavasoftTcpServiceOff.ini [-] Datei gelöscht: C:\WINDOWS\SysWOW64\MMInstaller.dll [-] Datei gelöscht: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\searchplugins\bing-lavasoft.xml ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** [-] Aufgabe gelöscht: updater [-] Aufgabe gelöscht: Microsoft\Windows\Windows Error Reporting\ErrorReporting ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\qqlive [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1 [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\qqlive [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{0015CAC9-FC30-4CD0-BFAA-7412CC2C4DD9} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{26C7AFDB-3690-449E-B979-B0AF5CC56DD4} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{3A5A5381-DAAF-4C0D-B032-2C66B3EE4A8D} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{472EF1D2-4AAE-470D-AE85-6AF8177916FD} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{8F010D54-C023-457F-AF03-497EACB6D519} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{9A754403-27B1-4ED7-96D7-588F07888EBF} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{CB31FF8F-BF80-4D2B-ADBE-12C6F5347890} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{FCAA532B-E807-4027-940C-BA16B9D50105} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} [-] Schlüssel gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} [-] Schlüssel gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\eSupport.com [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Installer [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Softonic [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Amigo [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\VideoBox [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Hotspot [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Speedownloader0099 [-] Schlüssel gelöscht: HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} [#] Schlüssel mit Neustart gelöscht: HKCU\Software\eSupport.com [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Installer [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Softonic [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Amigo [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} [#] Schlüssel mit Neustart gelöscht: HKCU\Software\VideoBox [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Hotspot [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Speedownloader0099 [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Lavasoft\Web Companion [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} [-] Schlüssel gelöscht: HKLM\SOFTWARE\Speedownloader0099 [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\eSupport.com [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Installer [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Softonic [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Amigo [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\VideoBox [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Hotspot [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Speedownloader0099 [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\DMunversion [-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} [-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com [-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com [-] Schlüssel gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com [#] Schlüssel mit Neustart gelöscht: HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} [-] Wert gelöscht: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] [#] Wert mit Neustart gelöscht: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] [#] Wert mit Neustart gelöscht: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] [-] Schlüssel gelöscht: HKLM\SOFTWARE\Google\Chrome\Extensions\cfdfamfnacokbbbnmpdfmhonipnhmbid ***** [ Browser ] ***** [-] Firefox Einstellungen bereinigt: "browser.newtab.url" - "chrome://unitedtb/content/newtab/newtab-page.xhtml" [-] Firefox Einstellungen bereinigt: "browser.newtabpage.url" - "hxxp://www.bing.com/?pc=COSP&ptag=D120615-A166D148A50&form=CONMHP&conlogo=CT3334470" [-] Firefox Einstellungen bereinigt: "browser.newtab.url" - "chrome://unitedtb/content/newtab/newtab-page.xhtml" [-] [C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default] [extension] Gelöscht: cfdfamfnacokbbbnmpdfmhonipnhmbid ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: "Prefetch" Dateien gelöscht :: Proxy Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [12423 Bytes] - [11/07/2017 17:46:50] C:\AdwCleaner\AdwCleaner[S0].txt - [11917 Bytes] - [11/07/2017 17:42:46] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [12571 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.3 (04.10.2017) Operating System: Windows 10 Home x64 Ran by Raphael (Administrator) on 11.07.2017 at 17:53:52.78 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 5 Successfully deleted: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\user.js (File) Successfully deleted: C:\WINDOWS\system32\REN6077.tmp (File) Successfully deleted: C:\WINDOWS\system32\REN98AD.tmp (File) Successfully deleted: C:\WINDOWS\system32\RENE30F.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\REN1D13.tmp (File) Deleted the following from C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\prefs.js user_pref(extensions.unitedinternet.email.runonceNewUsersShown, true); Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.07.2017 at 17:55:33.54 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Geändert von Ravemail (11.07.2017 um 17:40 Uhr) |
12.07.2017, 00:13 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malware verhindert MBAM/Windows Defender Okay, beide Tools(adwcleaner+jrt) bitte zwecks Kontrolle wiederholen.
__________________ Logfiles bitte immer in CODE-Tags posten |
13.07.2017, 10:07 | #13 |
| Malware verhindert MBAM/Windows Defender Falls das relevant ist: Mein Personal Backup hat zwischenzeitlich ein Update durchgeführt. Code:
ATTFilter # AdwCleaner v6.047 - Bericht erstellt am 13/07/2017 um 10:55:51 # Aktualisiert am 19/05/2017 von Malwarebytes # Datenbank : 2017-07-11.1 [Server] # Betriebssystem : Windows 10 Home (X64) # Benutzername : Raphael - RAPHAEL-PC # Gestartet von : F:\Downloads\AdwCleaner_6.047.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** ***** [ Dateien ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\tschmna [#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\tschmna ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: "Prefetch" Dateien gelöscht :: Proxy Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [12783 Bytes] - [11/07/2017 17:46:50] C:\AdwCleaner\AdwCleaner[C2].txt - [1156 Bytes] - [13/07/2017 10:55:51] C:\AdwCleaner\AdwCleaner[S0].txt - [11917 Bytes] - [11/07/2017 17:42:46] C:\AdwCleaner\AdwCleaner[S1].txt - [1521 Bytes] - [13/07/2017 10:54:01] ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1376 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.3 (04.10.2017) Operating System: Windows 10 Home x64 Ran by Raphael (Administrator) on 13.07.2017 at 11:03:51.62 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 0 Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.07.2017 at 11:05:29.17 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
13.07.2017, 10:27 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malware verhindert MBAM/Windows Defender Ich brauche neue FRST-Logs . Haken setzen bei addition.txt dann auf Untersuchen klicken.
__________________ Logfiles bitte immer in CODE-Tags posten |
13.07.2017, 19:46 | #15 |
| Malware verhindert MBAM/Windows Defender FRST 1/2: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 11-07-2017 durchgeführt von Raphael (Administrator) auf RAPHAEL-PC (13-07-2017 20:35:52) Gestartet von F:\Downloads Geladene Profile: Raphael (Verfügbare Profile: Raphael & Silvia & Browsergame & DefaultAppPool) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe () C:\Windows\SysWOW64\ASGT.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Aqua Computer GmbH & Co. KG) C:\Program Files\aquasuite\AquaComputerService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Copyright (c) 2016 Plays.tv, LLC) C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Electronic Arts) F:\Origin\OriginWebHelperService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Aqua Computer GmbH & Co. KG) C:\Program Files\aquasuite\aquasuite.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Rainmeter) C:\Program Files\Rainmeter\Rainmeter.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2016-08-22] (Realtek Semiconductor) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation) HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [502328 2012-05-22] (MSI) HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [317824 2016-01-18] () HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2016-06-16] (Razer Inc.) HKLM-x32\...\Run: [PlaysTV] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [50448 2016-10-26] (Copyright (c) 2016 Plays.tv, LLC) HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58584 2016-09-29] (Raptr, Inc) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [Steam] => F:\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Raphael\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [397632 2013-05-02] () HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [4006464 2017-03-04] (GOG.com) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Run: [Dropbox Update] => C:\Users\Raphael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-12] (Dropbox, Inc.) HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-3946114199-4031152989-3939253435-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [570880 2017-07-07] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [KSS] => "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe" autorun Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-07-11] ShortcutTarget: Dropbox.lnk -> C:\Users\Raphael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2017-07-02] ShortcutTarget: MEGAsync.lnk -> C:\Users\Raphael\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited) Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Persbackup.lnk [2017-01-27] ShortcutTarget: Persbackup.lnk -> C:\Program Files\Personal Backup 5\Persbackup.exe (Dr. J. Rathlev, D-24222 Schwentinental) Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2016-10-12] ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Rainmeter) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\..\Interfaces\{39551bc5-e46b-426e-8acf-0fa574427924}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{644abf41-5e82-4883-afee-da3d640e572b}: [NameServer] 192.168.0.1,8.8.8.8 ManualProxies: Internet Explorer: ================== BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-07-02] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-02] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-07-02] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-02] (Oracle Corporation) FireFox: ======== FF ProfilePath: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default [2017-07-13] FF SelectedSearchEngine: Mozilla\Firefox\Profiles\3akgwe11.default -> Bing® FF Homepage: Mozilla\Firefox\Profiles\3akgwe11.default -> about:home FF Session Restore: Mozilla\Firefox\Profiles\3akgwe11.default -> ist aktiviert. FF NetworkProxy: Mozilla\Firefox\Profiles\3akgwe11.default -> type", 0 FF Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\Extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}.xpi [2017-07-13] FF Extension: (Adblock Plus) - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-07-29] FF Extension: (Bitdefender QuickScan) - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2017-01-31] FF SearchPlugin: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\3akgwe11.default\searchplugins\deskmodder-wiki-de.xml [2017-01-27] FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-07-03] [ist nicht signiert] FF Extension: (Kein Name) - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2017-07-08] [ist nicht signiert] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_137.dll [2017-07-13] () FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-02] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-02] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll [2017-07-13] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-02] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-02] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3946114199-4031152989-3939253435-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Raphael\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-11] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3946114199-4031152989-3939253435-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Raphael\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-02] (Amazon.com, Inc.) FF Plugin HKU\S-1-5-21-3946114199-4031152989-3939253435-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2017-03-03] () Chrome: ======= CHR Profile: C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default [2017-07-02] CHR Extension: (Google Präsentationen) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-22] CHR Extension: (Google Docs) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-22] CHR Extension: (Google Drive) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-22] CHR Extension: (YouTube) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-22] CHR Extension: (Google Cast) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2017-01-22] CHR Extension: (Adobe Acrobat) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-22] CHR Extension: (Google Tabellen) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-22] CHR Extension: (Google Docs Offline) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-22] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-22] CHR Extension: (Google Mail) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-22] CHR Extension: (Chrome Media Router) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-22] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Aqua Computer Service; C:\Program Files\aquasuite\AquaComputerService.exe [2413960 2016-12-07] (Aqua Computer GmbH & Co. KG) R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [Datei ist nicht signiert] R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [388968 2016-04-26] (Digital Wave Ltd.) S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [284736 2017-03-04] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6625856 2017-03-04] (GOG.com) S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert] R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-03-29] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [142904 2012-05-22] (MSI) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S3 Origin Client Service; F:\Origin\OriginClientService.exe [2168208 2017-06-15] (Electronic Arts) R2 Origin Web Helper Service; F:\Origin\OriginWebHelperService.exe [3148184 2017-06-15] (Electronic Arts) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [Datei ist nicht signiert] R2 PlaysService; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [54544 2016-10-26] (Copyright (c) 2016 Plays.tv, LLC) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-12-25] () R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.) R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmdag.sys [36558208 2017-05-16] (Advanced Micro Devices, Inc.) R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmpag.sys [528760 2017-05-16] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-12-08] (Advanced Micro Devices) S3 atillk64; C:\Program Files (x86)\ASUS\GPU Tweak\atillk64.sys [14608 2006-07-19] (ATI Technologies Inc.) R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [314016 2014-08-09] () S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-07-11] () R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [23680 2010-02-23] (ASUSTeK Computer Inc.) R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [43680 2013-04-24] () R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188312 2017-07-02] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [113592 2017-07-13] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [44960 2017-07-13] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [252832 2017-07-13] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-07-13] (Malwarebytes) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [14136 2010-01-18] (MSI) S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v2B0\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [Datei ist nicht signiert] R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [937728 2016-05-17] (Realtek ) R3 rzdaendpt; C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720 2015-08-13] (Razer Inc) R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-22] (Razer, Inc.) R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-14] (Razer, Inc.) S3 RzSynapse; C:\WINDOWS\System32\drivers\RzSynapse.sys [166400 2011-10-11] (Razer USA Ltd) [Datei ist nicht signiert] R3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 ssudserd; C:\WINDOWS\system32\DRIVERS\ssudserd.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) R3 WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [268800 2014-04-28] (Jungo Connectivity) R3 WinRing0_1_2_0; C:\Program Files\aquasuite\AquaComputerService.sys [14544 2017-07-13] (OpenLibSys.org) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-07-13 11:08 - 2017-07-07 16:00 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll 2017-07-13 11:08 - 2017-07-07 09:24 - 00117664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2017-07-13 11:08 - 2017-07-07 09:23 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-07-13 11:08 - 2017-07-07 09:21 - 32688336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll 2017-07-13 11:08 - 2017-07-07 09:21 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2017-07-13 11:08 - 2017-07-07 09:20 - 02021680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2017-07-13 11:08 - 2017-07-07 09:20 - 00519584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys 2017-07-13 11:08 - 2017-07-07 09:14 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-07-13 11:08 - 2017-07-07 09:13 - 00554392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2017-07-13 11:08 - 2017-07-07 09:13 - 00336320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2017-07-13 11:08 - 2017-07-07 09:11 - 00094624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2017-07-13 11:08 - 2017-07-07 09:10 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-07-13 11:08 - 2017-07-07 09:10 - 01325968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-07-13 11:08 - 2017-07-07 09:10 - 00254168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-07-13 11:08 - 2017-07-07 09:07 - 01106848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2017-07-13 11:08 - 2017-07-07 09:07 - 00058488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe 2017-07-13 11:08 - 2017-07-07 08:57 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-07-13 11:08 - 2017-07-07 08:57 - 00125344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll 2017-07-13 11:08 - 2017-07-07 08:40 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-07-13 11:08 - 2017-07-07 08:39 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2017-07-13 11:08 - 2017-07-07 08:39 - 00096128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll 2017-07-13 11:08 - 2017-07-07 08:37 - 31652264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll 2017-07-13 11:08 - 2017-07-07 08:37 - 02259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-07-13 11:08 - 2017-07-07 08:37 - 01339352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll 2017-07-13 11:08 - 2017-07-07 08:31 - 05820984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-07-13 11:08 - 2017-07-07 08:31 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-07-13 11:08 - 2017-07-07 08:31 - 00129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2017-07-13 11:08 - 2017-07-07 08:30 - 02165752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2017-07-13 11:08 - 2017-07-07 08:30 - 00949920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2017-07-13 11:08 - 2017-07-07 08:30 - 00750496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2017-07-13 11:08 - 2017-07-07 08:29 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-07-13 11:08 - 2017-07-07 08:29 - 00123520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Clipc.dll 2017-07-13 11:08 - 2017-07-07 08:27 - 06759512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-07-13 11:08 - 2017-07-07 08:27 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll 2017-07-13 11:08 - 2017-07-07 08:26 - 20373408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-07-13 11:08 - 2017-07-07 08:26 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-07-13 11:08 - 2017-07-07 08:26 - 01195240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2017-07-13 11:08 - 2017-07-07 08:26 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-07-13 11:08 - 2017-07-07 08:25 - 00035232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininitext.dll 2017-07-13 11:08 - 2017-07-07 08:23 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-07-13 11:08 - 2017-07-07 08:23 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2017-07-13 11:08 - 2017-07-07 08:23 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2017-07-13 11:08 - 2017-07-07 08:20 - 23681536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-07-13 11:08 - 2017-07-07 08:20 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-07-13 11:08 - 2017-07-07 08:20 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll 2017-07-13 11:08 - 2017-07-07 08:19 - 07149056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2017-07-13 11:08 - 2017-07-07 08:19 - 00165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2017-07-13 11:08 - 2017-07-07 08:18 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2017-07-13 11:08 - 2017-07-07 08:17 - 00692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2017-07-13 11:08 - 2017-07-07 08:17 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-07-13 11:08 - 2017-07-07 08:17 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2017-07-13 11:08 - 2017-07-07 08:16 - 12786176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-07-13 11:08 - 2017-07-07 08:16 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-07-13 11:08 - 2017-07-07 08:15 - 08238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-07-13 11:08 - 2017-07-07 08:14 - 08211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2017-07-13 11:08 - 2017-07-07 08:14 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2017-07-13 11:08 - 2017-07-07 08:14 - 02956800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-07-13 11:08 - 2017-07-07 08:14 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2017-07-13 11:08 - 2017-07-07 08:14 - 00790016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2017-07-13 11:08 - 2017-07-07 08:14 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr 2017-07-13 11:08 - 2017-07-07 08:13 - 13839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-07-13 11:08 - 2017-07-07 08:12 - 04730880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-07-13 11:08 - 2017-07-07 08:12 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-07-13 11:08 - 2017-07-07 08:12 - 01142272 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2017-07-13 11:08 - 2017-07-07 08:12 - 00706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2017-07-13 11:08 - 2017-07-07 08:11 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2017-07-13 11:08 - 2017-07-07 08:10 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2017-07-13 11:08 - 2017-07-07 08:10 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapprovp.dll 2017-07-13 11:08 - 2017-07-07 08:09 - 20504576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-07-13 11:08 - 2017-07-07 08:09 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2017-07-13 11:08 - 2017-07-07 08:08 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2017-07-13 11:08 - 2017-07-07 08:07 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll 2017-07-13 11:08 - 2017-07-07 08:07 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\raschap.dll 2017-07-13 11:08 - 2017-07-07 08:06 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 2017-07-13 11:08 - 2017-07-07 08:06 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsExt.dll 2017-07-13 11:08 - 2017-07-07 08:06 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll 2017-07-13 11:08 - 2017-07-07 08:05 - 19335168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-07-13 11:08 - 2017-07-07 08:05 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-07-13 11:08 - 2017-07-07 08:05 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-07-13 11:08 - 2017-07-07 08:05 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-07-13 11:08 - 2017-07-07 08:05 - 00502784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2017-07-13 11:08 - 2017-07-07 08:05 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll 2017-07-13 11:08 - 2017-07-07 08:04 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-07-13 11:08 - 2017-07-07 08:04 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-07-13 11:08 - 2017-07-07 08:04 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2017-07-13 11:08 - 2017-07-07 08:04 - 00506368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-07-13 11:08 - 2017-07-07 08:04 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2017-07-13 11:08 - 2017-07-07 08:03 - 06123520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2017-07-13 11:08 - 2017-07-07 08:03 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2017-07-13 11:08 - 2017-07-07 08:03 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll 2017-07-13 11:08 - 2017-07-07 08:02 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-07-13 11:08 - 2017-07-07 08:02 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr 2017-07-13 11:08 - 2017-07-07 08:01 - 06287360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-07-13 11:08 - 2017-07-07 08:01 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-07-13 11:08 - 2017-07-07 08:00 - 07596544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2017-07-13 11:08 - 2017-07-07 08:00 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-07-13 11:08 - 2017-07-07 08:00 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2017-07-13 11:08 - 2017-07-07 08:00 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-07-13 11:08 - 2017-07-07 08:00 - 01565184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2017-07-13 11:08 - 2017-07-07 08:00 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-07-13 11:08 - 2017-07-07 07:59 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-07-13 11:08 - 2017-07-07 07:59 - 03656704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-07-13 11:08 - 2017-07-07 07:59 - 01494016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2017-07-13 11:08 - 2017-07-07 07:59 - 01355264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll 2017-07-13 11:08 - 2017-07-07 07:59 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2017-07-13 11:08 - 2017-07-07 07:58 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2017-07-13 11:08 - 2017-07-07 07:58 - 02782720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2017-07-13 11:08 - 2017-07-07 07:58 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-07-13 11:08 - 2017-07-07 07:58 - 01237504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll 2017-07-13 11:08 - 2017-07-07 07:55 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll 2017-07-13 11:08 - 2017-07-07 07:55 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll 2017-07-13 11:08 - 2017-07-07 07:53 - 01301504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll 2017-07-13 11:08 - 2017-07-07 07:53 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinfo32.exe 2017-07-13 11:08 - 2017-06-20 08:11 - 00411992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll 2017-07-13 11:08 - 2017-06-20 08:08 - 01242528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2017-07-13 11:08 - 2017-06-20 08:06 - 00279968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys 2017-07-13 11:08 - 2017-06-20 08:03 - 00820128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2017-07-13 11:08 - 2017-06-20 08:02 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-07-13 11:08 - 2017-06-20 07:59 - 06554928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-07-13 11:08 - 2017-06-20 07:59 - 01220072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-07-13 11:08 - 2017-06-20 07:59 - 00467504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 2017-07-13 11:08 - 2017-06-20 07:57 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-07-13 11:08 - 2017-06-20 07:34 - 00192416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll 2017-07-13 11:08 - 2017-06-20 07:15 - 00455104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll 2017-07-13 11:08 - 2017-06-20 07:13 - 00787712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2017-07-13 11:08 - 2017-06-20 07:13 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe 2017-07-13 11:08 - 2017-06-20 07:12 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-07-13 11:08 - 2017-06-20 07:12 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys 2017-07-13 11:08 - 2017-06-20 07:12 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 2017-07-13 11:08 - 2017-06-20 07:11 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2017-07-13 11:08 - 2017-06-20 07:10 - 00722432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2017-07-13 11:08 - 2017-06-20 07:10 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2017-07-13 11:08 - 2017-06-20 07:09 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll 2017-07-13 11:08 - 2017-06-20 07:09 - 00406032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2017-07-13 11:08 - 2017-06-20 07:09 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe 2017-07-13 11:08 - 2017-06-20 07:09 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2017-07-13 11:08 - 2017-06-20 07:08 - 04469840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-07-13 11:08 - 2017-06-20 07:08 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll 2017-07-13 11:08 - 2017-06-20 07:08 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2017-07-13 11:08 - 2017-06-20 07:08 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2017-07-13 11:08 - 2017-06-20 07:08 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll 2017-07-13 11:08 - 2017-06-20 07:08 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2017-07-13 11:08 - 2017-06-20 07:07 - 02475136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2017-07-13 11:08 - 2017-06-20 07:07 - 00823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll 2017-07-13 11:08 - 2017-06-20 07:07 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2017-07-13 11:08 - 2017-06-20 07:07 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2017-07-13 11:08 - 2017-06-20 07:07 - 00346016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll 2017-07-13 11:08 - 2017-06-20 07:07 - 00138656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll 2017-07-13 11:08 - 2017-06-20 07:06 - 00942592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll 2017-07-13 11:08 - 2017-06-20 07:06 - 00847872 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2017-07-13 11:08 - 2017-06-20 07:06 - 00754592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-07-13 11:08 - 2017-06-20 07:06 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2017-07-13 11:08 - 2017-06-20 07:06 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-07-13 11:08 - 2017-06-20 07:06 - 00278944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll 2017-07-13 11:08 - 2017-06-20 07:05 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-07-13 11:08 - 2017-06-20 07:05 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-07-13 11:08 - 2017-06-20 07:05 - 00438096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll 2017-07-13 11:08 - 2017-06-20 07:05 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-07-13 11:08 - 2017-06-20 07:05 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-07-13 11:08 - 2017-06-20 07:05 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2017-07-13 11:08 - 2017-06-20 07:04 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2017-07-13 11:08 - 2017-06-20 07:04 - 01178528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll 2017-07-13 11:08 - 2017-06-20 07:04 - 01177600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2017-07-13 11:08 - 2017-06-20 07:04 - 01077496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll 2017-07-13 11:08 - 2017-06-20 07:04 - 00181656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2017-07-13 11:08 - 2017-06-20 07:04 - 00049656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msasn1.dll 2017-07-13 11:08 - 2017-06-20 07:03 - 05806048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-07-13 11:08 - 2017-06-20 07:03 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2017-07-13 11:08 - 2017-06-20 07:03 - 00864240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2017-07-13 11:08 - 2017-06-20 07:03 - 00443728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2017-07-13 11:08 - 2017-06-20 07:02 - 03377664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-07-13 11:08 - 2017-06-20 07:02 - 01121928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-07-13 11:08 - 2017-06-20 07:02 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2017-07-13 11:08 - 2017-06-20 07:01 - 04536320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-07-13 11:08 - 2017-06-20 07:01 - 00176032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll 2017-07-13 11:08 - 2017-06-20 07:00 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-07-13 11:08 - 2017-06-20 06:59 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-07-13 11:08 - 2017-06-20 06:59 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-07-13 11:08 - 2017-06-20 06:56 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2017-07-13 11:08 - 2017-06-20 06:49 - 00899072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll 2017-07-13 11:08 - 2017-06-20 06:49 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll 2017-07-13 11:08 - 2017-06-20 06:46 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll 2017-07-13 11:08 - 2017-06-20 06:45 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Profile.RetailInfo.dll 2017-07-13 11:08 - 2017-06-20 06:45 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2017-07-13 11:08 - 2017-06-20 06:43 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2017-07-13 11:08 - 2017-06-20 06:43 - 00173568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll 2017-07-13 11:08 - 2017-06-20 06:43 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll 2017-07-13 11:08 - 2017-06-20 06:43 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll 2017-07-13 11:08 - 2017-06-20 06:43 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2017-07-13 11:08 - 2017-06-20 06:43 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2017-07-13 11:08 - 2017-06-20 06:43 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dataclen.dll 2017-07-13 11:08 - 2017-06-20 06:42 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll 2017-07-13 11:08 - 2017-06-20 06:42 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll 2017-07-13 11:08 - 2017-06-20 06:42 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2017-07-13 11:08 - 2017-06-20 06:42 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2017-07-13 11:08 - 2017-06-20 06:42 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll 2017-07-13 11:08 - 2017-06-20 06:42 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2017-07-13 11:08 - 2017-06-20 06:41 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2017-07-13 11:08 - 2017-06-20 06:41 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll 2017-07-13 11:08 - 2017-06-20 06:41 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll 2017-07-13 11:08 - 2017-06-20 06:41 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2017-07-13 11:08 - 2017-06-20 06:41 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll 2017-07-13 11:08 - 2017-06-20 06:40 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-07-13 11:08 - 2017-06-20 06:40 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2017-07-13 11:08 - 2017-06-20 06:40 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2017-07-13 11:08 - 2017-06-20 06:40 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2017-07-13 11:08 - 2017-06-20 06:40 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll 2017-07-13 11:08 - 2017-06-20 06:40 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll 2017-07-13 11:08 - 2017-06-20 06:39 - 02814464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll 2017-07-13 11:08 - 2017-06-20 06:39 - 02671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-07-13 11:08 - 2017-06-20 06:39 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2017-07-13 11:08 - 2017-06-20 06:39 - 00646144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl 2017-07-13 11:08 - 2017-06-20 06:39 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll 2017-07-13 11:08 - 2017-06-20 06:39 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2017-07-13 11:08 - 2017-06-20 06:38 - 01451008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-07-13 11:08 - 2017-06-20 06:38 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2017-07-13 11:08 - 2017-06-20 06:38 - 01171968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe 2017-07-13 11:08 - 2017-06-20 06:38 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2017-07-13 11:08 - 2017-06-20 06:38 - 00648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll 2017-07-13 11:08 - 2017-06-20 06:38 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-07-13 11:08 - 2017-06-20 06:37 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2017-07-13 11:08 - 2017-06-20 06:36 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-07-13 11:08 - 2017-06-20 06:35 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2017-07-13 11:08 - 2017-06-20 06:35 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-07-13 11:08 - 2017-06-20 06:35 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll 2017-07-13 11:08 - 2017-06-20 06:34 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-07-13 11:08 - 2017-06-20 06:34 - 02750464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2017-07-13 11:08 - 2017-06-20 06:34 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-07-13 11:08 - 2017-06-20 06:34 - 01492480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2017-07-13 11:08 - 2017-06-20 06:34 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2017-07-13 11:08 - 2017-06-20 06:31 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll 2017-07-13 11:08 - 2017-06-20 06:30 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdmaud.drv 2017-07-13 11:08 - 2017-06-20 06:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll 2017-07-13 11:08 - 2017-06-20 06:30 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2017-07-13 11:08 - 2017-06-20 06:28 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll 2017-07-13 11:07 - 2017-07-07 09:27 - 01147288 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-07-13 11:07 - 2017-07-07 09:27 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-07-13 11:07 - 2017-07-07 09:27 - 00965024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi 2017-07-13 11:07 - 2017-07-07 09:27 - 00821664 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe 2017-07-13 11:07 - 2017-07-07 09:27 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-07-13 11:07 - 2017-07-07 09:26 - 01065104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2017-07-13 11:07 - 2017-07-07 09:25 - 00899824 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2017-07-13 11:07 - 2017-07-07 09:22 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-07-13 11:07 - 2017-07-07 09:22 - 01186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2017-07-13 11:07 - 2017-07-07 09:22 - 00119384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll 2017-07-13 11:07 - 2017-07-07 09:20 - 00923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-07-13 11:07 - 2017-07-07 09:20 - 00382368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2017-07-13 11:07 - 2017-07-07 09:17 - 01017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2017-07-13 11:07 - 2017-07-07 09:15 - 02444696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-07-13 11:07 - 2017-07-07 09:14 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-07-13 11:07 - 2017-07-07 09:14 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-07-13 11:07 - 2017-07-07 09:14 - 01171032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2017-07-13 11:07 - 2017-07-07 09:13 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-07-13 11:07 - 2017-07-07 09:13 - 00147800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Clipc.dll 2017-07-13 11:07 - 2017-07-07 09:12 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-07-13 11:07 - 2017-07-07 09:12 - 00318232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe 2017-07-13 11:07 - 2017-07-07 09:12 - 00228256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2017-07-13 11:07 - 2017-07-07 09:11 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-07-13 11:07 - 2017-07-07 09:10 - 21353208 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-07-13 11:07 - 2017-07-07 09:10 - 01337848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2017-07-13 11:07 - 2017-07-07 09:10 - 00372128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-07-13 11:07 - 2017-07-07 09:09 - 00041376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininitext.dll 2017-07-13 11:07 - 2017-07-07 08:27 - 03670016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-07-13 11:07 - 2017-07-07 08:27 - 01640448 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2017-07-13 11:07 - 2017-07-07 08:27 - 01050624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2017-07-13 11:07 - 2017-07-07 08:27 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2017-07-13 11:07 - 2017-07-07 08:27 - 00577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\duser.dll 2017-07-13 11:07 - 2017-07-07 08:27 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll 2017-07-13 11:07 - 2017-07-07 08:27 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2017-07-13 11:07 - 2017-07-07 08:26 - 17364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-07-13 11:07 - 2017-07-07 08:25 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-07-13 11:07 - 2017-07-07 08:24 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\officecsp.dll 2017-07-13 11:07 - 2017-07-07 08:23 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll 2017-07-13 11:07 - 2017-07-07 08:23 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapprovp.dll 2017-07-13 11:07 - 2017-07-07 08:22 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-07-13 11:07 - 2017-07-07 08:22 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-07-13 11:07 - 2017-07-07 08:21 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncCsp.dll 2017-07-13 11:07 - 2017-07-07 08:21 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-07-13 11:07 - 2017-07-07 08:19 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-07-13 11:07 - 2017-07-07 08:19 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-07-13 11:07 - 2017-07-07 08:19 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\raschap.dll 2017-07-13 11:07 - 2017-07-07 08:18 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-07-13 11:07 - 2017-07-07 08:18 - 00563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2017-07-13 11:07 - 2017-07-07 08:18 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll 2017-07-13 11:07 - 2017-07-07 08:18 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsExt.dll 2017-07-13 11:07 - 2017-07-07 08:17 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-07-13 11:07 - 2017-07-07 08:17 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2017-07-13 11:07 - 2017-07-07 08:17 - 00536064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2017-07-13 11:07 - 2017-07-07 08:17 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe 2017-07-13 11:07 - 2017-07-07 08:16 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-07-13 11:07 - 2017-07-07 08:15 - 00922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2017-07-13 11:07 - 2017-07-07 08:14 - 01802240 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-07-13 11:07 - 2017-07-07 08:14 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll 2017-07-13 11:07 - 2017-07-07 08:13 - 05892096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2017-07-13 11:07 - 2017-07-07 08:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2017-07-13 11:07 - 2017-07-07 08:12 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-07-13 11:07 - 2017-07-07 08:12 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2017-07-13 11:07 - 2017-07-07 08:12 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-07-13 11:07 - 2017-07-07 08:12 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2017-07-13 11:07 - 2017-07-07 08:12 - 01420800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll 2017-07-13 11:07 - 2017-07-07 08:12 - 01305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-07-13 11:07 - 2017-07-07 08:12 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-07-13 11:07 - 2017-07-07 08:11 - 03139584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2017-07-13 11:07 - 2017-07-07 08:11 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2017-07-13 11:07 - 2017-07-07 08:11 - 02649600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-07-13 11:07 - 2017-07-07 08:11 - 02177024 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll 2017-07-13 11:07 - 2017-07-07 08:11 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2017-07-13 11:07 - 2017-07-07 08:11 - 00986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2017-07-13 11:07 - 2017-07-07 08:11 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2017-07-13 11:07 - 2017-07-07 08:10 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-07-13 11:07 - 2017-07-07 08:10 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-07-13 11:07 - 2017-07-07 08:10 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-07-13 11:07 - 2017-07-07 08:07 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll 2017-07-13 11:07 - 2017-07-07 08:07 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll 2017-07-13 11:07 - 2017-07-07 08:05 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe 2017-07-13 11:07 - 2017-07-07 08:04 - 01703424 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2017-07-13 11:07 - 2017-07-07 08:04 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll 2017-07-13 11:07 - 2017-07-07 08:04 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll 2017-07-13 11:07 - 2017-07-02 00:52 - 00031932 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin 2017-07-13 11:07 - 2017-06-20 08:18 - 01564576 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2017-07-13 11:07 - 2017-06-20 08:18 - 00096672 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2017-07-13 11:07 - 2017-06-20 08:17 - 00629152 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2017-07-13 11:07 - 2017-06-20 08:17 - 00544160 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2017-07-13 11:07 - 2017-06-20 08:17 - 00334240 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2017-07-13 11:07 - 2017-06-20 08:17 - 00136096 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2017-07-13 11:07 - 2017-06-20 08:17 - 00034720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2017-07-13 11:07 - 2017-06-20 08:16 - 01214880 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2017-07-13 11:07 - 2017-06-20 08:16 - 00335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll 2017-07-13 11:07 - 2017-06-20 08:15 - 00233376 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2017-07-13 11:07 - 2017-06-20 08:11 - 01395152 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2017-07-13 11:07 - 2017-06-20 08:10 - 02327456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2017-07-13 11:07 - 2017-06-20 08:10 - 01930320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2017-07-13 11:07 - 2017-06-20 08:05 - 01057832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2017-07-13 11:07 - 2017-06-20 08:04 - 04847424 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-07-13 11:07 - 2017-06-20 08:04 - 00472728 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2017-07-13 11:07 - 2017-06-20 08:03 - 00179608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll 2017-07-13 11:07 - 2017-06-20 08:03 - 00102312 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialUIBroker.exe 2017-07-13 11:07 - 2017-06-20 08:02 - 02645688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2017-07-13 11:07 - 2017-06-20 08:02 - 00426912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll 2017-07-13 11:07 - 2017-06-20 08:00 - 00558920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll 2017-07-13 11:07 - 2017-06-20 08:00 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2017-07-13 11:07 - 2017-06-20 08:00 - 00142752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys 2017-07-13 11:07 - 2017-06-20 07:59 - 01054280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2017-07-13 11:07 - 2017-06-20 07:59 - 00583304 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2017-07-13 11:07 - 2017-06-20 07:58 - 00833160 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2017-07-13 11:07 - 2017-06-20 07:58 - 00406072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2017-07-13 11:07 - 2017-06-20 07:58 - 00203168 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll 2017-07-13 11:07 - 2017-06-20 07:57 - 00204192 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll 2017-07-13 11:07 - 2017-06-20 07:16 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll 2017-07-13 11:07 - 2017-06-20 07:16 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll 2017-07-13 11:07 - 2017-06-20 07:15 - 01620368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2017-07-13 11:07 - 2017-06-20 07:14 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2017-07-13 11:07 - 2017-06-20 07:14 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys 2017-07-13 11:07 - 2017-06-20 07:13 - 00216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll 2017-07-13 11:07 - 2017-06-20 07:13 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll 2017-07-13 11:07 - 2017-06-20 07:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgr.dll 2017-07-13 11:07 - 2017-06-20 07:12 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll 2017-07-13 11:07 - 2017-06-20 07:12 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll 2017-07-13 11:07 - 2017-06-20 07:11 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll 2017-07-13 11:07 - 2017-06-20 07:10 - 00778240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll 2017-07-13 11:07 - 2017-06-20 07:10 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2017-07-13 11:07 - 2017-06-20 07:10 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll 2017-07-13 11:07 - 2017-06-20 07:10 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgrSvc.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2017-07-13 11:07 - 2017-06-20 07:09 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dataclen.dll 2017-07-13 11:07 - 2017-06-20 07:08 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll 2017-07-13 11:07 - 2017-06-20 07:08 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll 2017-07-13 11:07 - 2017-06-20 07:08 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll 2017-07-13 11:07 - 2017-06-20 07:07 - 00916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2017-07-13 11:07 - 2017-06-20 07:07 - 00757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2017-07-13 11:07 - 2017-06-20 07:07 - 00626176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2017-07-13 11:07 - 2017-06-20 07:07 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll 2017-07-13 11:07 - 2017-06-20 07:07 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-07-13 11:07 - 2017-06-20 07:06 - 00455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2017-07-13 11:07 - 2017-06-20 07:06 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll 2017-07-13 11:07 - 2017-06-20 07:06 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-07-13 11:07 - 2017-06-20 07:06 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll 2017-07-13 11:07 - 2017-06-20 07:06 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll 2017-07-13 11:07 - 2017-06-20 07:05 - 04447744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-07-13 11:07 - 2017-06-20 07:05 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll 2017-07-13 11:07 - 2017-06-20 07:05 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-07-13 11:07 - 2017-06-20 07:05 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2017-07-13 11:07 - 2017-06-20 07:05 - 00696320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl 2017-07-13 11:07 - 2017-06-20 07:05 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll 2017-07-13 11:07 - 2017-06-20 07:05 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll 2017-07-13 11:07 - 2017-06-20 07:04 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-07-13 11:07 - 2017-06-20 07:04 - 01425920 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe 2017-07-13 11:07 - 2017-06-20 07:04 - 00899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll 2017-07-13 11:07 - 2017-06-20 07:04 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2017-07-13 11:07 - 2017-06-20 07:04 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2017-07-13 11:07 - 2017-06-20 07:04 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2017-07-13 11:07 - 2017-06-20 07:03 - 01396224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2017-07-13 11:07 - 2017-06-20 07:02 - 03204096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll 2017-07-13 11:07 - 2017-06-20 07:02 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-07-13 11:07 - 2017-06-20 07:02 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-07-13 11:07 - 2017-06-20 07:02 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-07-13 11:07 - 2017-06-20 07:02 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll 2017-07-13 11:07 - 2017-06-20 07:01 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-07-13 11:07 - 2017-06-20 07:01 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-07-13 11:07 - 2017-06-20 07:01 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-07-13 11:07 - 2017-06-20 07:01 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2017-07-13 11:07 - 2017-06-20 07:01 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-07-13 11:07 - 2017-06-20 07:01 - 00809984 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2017-07-13 11:07 - 2017-06-20 07:01 - 00397312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2017-07-13 11:07 - 2017-06-20 07:00 - 03057664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2017-07-13 11:07 - 2017-06-20 07:00 - 02171392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll 2017-07-13 11:07 - 2017-06-20 06:59 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-07-13 11:07 - 2017-06-20 06:58 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-07-13 11:07 - 2017-06-20 06:57 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2017-07-13 11:07 - 2017-06-20 06:57 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMPushRouterCore.dll 2017-07-13 11:07 - 2017-06-20 06:56 - 00600064 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll 2017-07-13 11:07 - 2017-06-20 06:56 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdmaud.drv 2017-07-13 11:07 - 2017-06-20 06:54 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\DmApiSetExtImplDesktop.dll 2017-07-13 10:59 - 2017-07-13 10:59 - 00001462 _____ C:\Users\Raphael\Desktop\AdwCleaner[C2].txt 2017-07-11 17:55 - 2017-07-13 11:05 - 00000549 _____ C:\Users\Raphael\Desktop\JRT.txt 2017-07-11 17:47 - 2017-07-11 17:47 - 00000000 ____D C:\WINDOWS\Panther 2017-07-11 17:37 - 2017-07-13 11:09 - 00000000 ____D C:\AdwCleaner 2017-07-08 20:50 - 2017-07-13 20:35 - 00000000 ____D C:\Users\Raphael\AppData\LocalLow\Mozilla 2017-07-08 20:07 - 2017-07-08 20:40 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-07-08 19:29 - 2017-07-08 20:40 - 00000000 ____D C:\Users\Raphael\Desktop\mbar 2017-07-08 19:28 - 2017-07-08 19:28 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Raphael\Desktop\mbar-1.09.3.1001.exe 2017-07-05 21:13 - 2017-07-05 21:13 - 00128813 _____ C:\Users\Raphael\Desktop\Addition.zip 2017-07-05 20:34 - 2017-07-05 20:34 - 00079661 _____ C:\Users\Raphael\Desktop\FRST.txt 2017-07-05 20:33 - 2017-07-05 20:33 - 00128655 _____ C:\Users\Raphael\Desktop\Addition.txt 2017-07-05 20:31 - 2017-07-13 20:35 - 00000000 ____D C:\FRST 2017-07-04 19:39 - 2017-07-05 21:16 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2017-07-02 23:14 - 2017-07-11 17:46 - 00000008 __RSH C:\ProgramData\ntuser.pol 2017-07-02 23:08 - 2017-07-13 20:31 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-07-02 23:08 - 2017-07-13 20:31 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-07-02 23:08 - 2017-07-13 20:31 - 00044960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-07-02 23:08 - 2017-07-11 20:01 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-07-02 23:08 - 2017-07-02 23:09 - 00188312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-07-02 23:08 - 2017-07-02 23:08 - 00001915 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-07-02 23:08 - 2017-07-02 23:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-07-02 23:08 - 2017-07-02 23:08 - 00000000 ____D C:\Program Files\Malwarebytes 2017-07-02 22:58 - 2017-07-11 17:47 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\k1zwksbzduz 2017-07-02 22:58 - 2017-07-11 17:47 - 00000000 ____D C:\Program Files\UXW6ZEE8PL 2017-07-02 22:50 - 2017-07-02 23:13 - 00000000 ____D C:\Program Files (x86)\fL3y0Saiyu 2017-07-02 22:50 - 2017-07-02 22:50 - 00930816 _____ C:\Users\Raphael\AppData\Local\test_db_cara.db 2017-07-02 22:50 - 2017-07-02 22:50 - 00140800 _____ C:\Users\Raphael\AppData\Local\installer.dat 2017-07-02 22:50 - 2017-07-02 22:50 - 00016838 _____ C:\WINDOWS\System32\Tasks\CooRink Portable 2017-07-02 22:50 - 2017-07-02 22:50 - 00016788 _____ C:\WINDOWS\System32\Tasks\SwapHome 2017-07-02 22:50 - 2017-07-02 01:40 - 02001920 ___SH (Micrasaft Carparation) C:\WINDOWS\C_02iu47.dat 2017-07-02 22:49 - 2017-07-11 17:47 - 00000000 ____D C:\Program Files (x86)\jena5f2tmwt 2017-07-02 22:49 - 2017-07-02 23:13 - 00000000 ____D C:\Program Files\TH3XPQP0V1 2017-07-02 22:49 - 2017-07-02 23:13 - 00000000 ____D C:\Program Files\R3MCTN2THA 2017-07-02 22:49 - 2017-07-02 22:50 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\2y2slneb2xm 2017-07-02 22:49 - 2017-07-02 22:50 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\2xwswhtv2rl 2017-07-02 22:49 - 2017-07-02 22:49 - 00000000 ____D C:\Users\Raphael\AppData\Local\CrashRpt 2017-07-02 22:24 - 2017-07-02 22:26 - 00000000 ____D C:\ProgramData\MegaTrainerUltimate 2017-07-02 22:24 - 2017-07-02 22:24 - 00001443 _____ C:\Users\Public\Desktop\MegaTrainer.lnk 2017-07-02 22:24 - 2017-07-02 22:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MegaTrainerUltimate 2017-07-02 22:24 - 2017-07-02 22:24 - 00000000 ____D C:\Program Files (x86)\MegaDev 2017-07-02 21:41 - 2017-07-02 21:41 - 00000000 ____D C:\Users\Raphael\Documents\screens 2017-07-02 21:41 - 2017-07-02 21:41 - 00000000 ____D C:\Users\Raphael\Documents\fmdata 2017-07-02 21:41 - 2017-07-02 21:41 - 00000000 ____D C:\Users\Raphael\Documents\desk_objects 2017-07-02 21:40 - 2017-07-02 21:40 - 00000000 ____D C:\Users\Raphael\Documents\art_fm 2017-07-02 21:39 - 2017-07-02 21:40 - 00000000 ____D C:\Users\Raphael\Documents\art 2017-07-02 21:33 - 2017-07-02 21:33 - 01207319 _____ C:\WINDOWS\unins000.exe 2017-07-02 21:33 - 2017-07-02 21:33 - 00010826 _____ C:\WINDOWS\unins000.dat 2017-07-02 21:33 - 2017-07-02 21:33 - 00001998 _____ C:\AiOLog.txt 2017-07-02 21:33 - 2017-04-01 20:44 - 03450616 _____ (Red Hat) C:\WINDOWS\system32\cygwin1.dll 2017-07-02 21:33 - 2017-01-26 07:25 - 01265664 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\libeay32.dll 2017-07-02 21:33 - 2017-01-26 07:25 - 00274944 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\ssleay32.dll 2017-07-02 21:33 - 2017-01-26 07:25 - 00274944 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\libssl32.dll 2017-07-02 21:33 - 2015-07-10 11:51 - 00456008 _____ (AutoIt Team) C:\WINDOWS\system32\autoitx3.dll 2017-07-02 21:33 - 2014-01-31 03:14 - 01055676 _____ (Free Software Foundation) C:\WINDOWS\system32\libiconv2.dll 2017-07-02 21:33 - 2014-01-25 14:30 - 00131072 _____ (Sereby Corporation) C:\WINDOWS\system32\AiORuntimes.dll 2017-07-02 21:33 - 2013-12-23 15:44 - 00163480 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 01070232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscomctl.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00660120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscomct2.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00617896 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00444328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshflxgd.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00416408 _____ (Microsoft Corporation ) C:\WINDOWS\system32\comct332.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00279192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdatgrd.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00259736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msflxgrd.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00253080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdatlst.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00222360 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabctl32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00219288 _____ (Microsoft Corporation) C:\WINDOWS\system32\richtx32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00218776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dblist32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00212112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mci32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00179352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmask32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00170920 _____ (Microsoft Corporation) C:\WINDOWS\system32\comct232.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00131728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinet.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00130712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msstdfmt.dll 2017-07-02 21:33 - 2013-12-20 01:48 - 00127640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswinsck.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00119960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscomm32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00108696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msstkprp.dll 2017-07-02 21:33 - 2013-12-20 01:48 - 00104088 _____ (Microsoft Corporation) C:\WINDOWS\system32\picclp32.ocx 2017-07-02 21:33 - 2013-12-20 01:48 - 00084624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysinfo.ocx 2017-07-02 21:33 - 2012-06-14 15:36 - 00107520 _____ C:\WINDOWS\system32\zlib1.dll 2017-07-02 21:33 - 2012-04-03 17:11 - 00138752 _____ C:\WINDOWS\system32\libpng15.dll 2017-07-02 21:33 - 2011-10-12 04:09 - 04033440 _____ (Intel Corporation) C:\WINDOWS\system32\libmmd.dll 2017-07-02 21:33 - 2011-01-12 14:36 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71u.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71DEU.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71ITA.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71FRA.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71ESP.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71ENU.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71KOR.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71JPN.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71CHT.dll 2017-07-02 21:33 - 2011-01-12 14:25 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71CHS.dll 2017-07-02 21:33 - 2011-01-12 14:19 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71.dll 2017-07-02 21:33 - 2011-01-12 13:53 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl71.dll 2017-07-02 21:33 - 2010-06-27 18:44 - 00053248 _____ (Adobe Systems, Incorporated) C:\WINDOWS\system\plugin.dll 2017-07-02 21:33 - 2010-03-18 21:21 - 00799568 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdia100.dll 2017-07-02 21:33 - 2008-08-26 07:40 - 00162304 _____ C:\WINDOWS\system32\libpng13.dll 2017-07-02 21:33 - 2007-02-01 23:13 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp71.dll 2017-07-02 21:33 - 2007-02-01 20:11 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr71.dll 2017-07-02 21:33 - 2007-01-30 23:04 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr70.dll 2017-07-02 21:33 - 2006-08-26 01:28 - 01017344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70u.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70ITA.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70FRA.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70ESP.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70DEU.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70ENU.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70KOR.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70JPN.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70CHT.dll 2017-07-02 21:33 - 2006-08-26 01:15 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70CHS.dll 2017-07-02 21:33 - 2006-08-26 01:07 - 01024000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70.dll 2017-07-02 21:33 - 2006-08-26 00:17 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl70.dll 2017-07-02 21:33 - 2005-05-06 14:52 - 00103424 _____ (GNU <www.gnu.org>) C:\WINDOWS\system32\libintl3.dll 2017-07-02 21:33 - 2005-01-20 20:25 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvci70.dll 2017-07-02 21:33 - 2002-01-05 06:40 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp70.dll 2017-07-02 21:33 - 1996-01-12 04:00 - 00935632 _____ (Microsoft Corporation) C:\WINDOWS\system\vb40016.dll 2017-07-02 21:33 - 1996-01-12 04:00 - 00722192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vb40032.dll 2017-07-02 21:33 - 1994-11-17 14:00 - 00210944 _____ C:\WINDOWS\system\msvcrt10.dll 2017-07-02 21:33 - 1993-05-11 20:00 - 00398416 _____ (Microsoft Corporation) C:\WINDOWS\system\vbrun300.dll 2017-07-02 21:33 - 1992-10-21 01:00 - 00356992 _____ (Microsoft Corporation) C:\WINDOWS\system\vbrun200.dll 2017-07-02 21:33 - 1991-05-10 02:00 - 00271264 _____ C:\WINDOWS\system\vbrun100.dll 2017-07-02 21:31 - 2017-07-02 21:31 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2017-07-02 21:31 - 2017-07-02 21:31 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2017-07-02 21:31 - 2017-07-02 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-07-02 19:20 - 2017-07-02 19:20 - 00001179 _____ C:\Users\Raphael\Desktop\MEGAsync.lnk 2017-07-02 19:20 - 2017-07-02 19:20 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync 2017-07-02 19:20 - 2017-07-02 19:20 - 00000000 ____D C:\Users\Raphael\AppData\Local\MEGAsync 2017-07-02 19:20 - 2017-07-02 19:20 - 00000000 ____D C:\Users\Raphael\AppData\Local\Mega Limited 2017-07-02 19:11 - 2017-07-02 21:42 - 00000000 ____D C:\Users\Raphael\Documents\FUSSBALL MANAGER 16-17 2017-06-27 22:31 - 2017-06-27 22:31 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-06-15 18:44 - 2017-06-15 18:44 - 00000000 ____D C:\Users\Raphael\.mputils 2017-06-15 18:33 - 2017-06-15 18:33 - 00030263 _____ C:\Users\Raphael\Documents\Hochzeit Isabell u. Gabriel.pdf 2017-06-15 17:59 - 2017-06-15 17:59 - 00001036 _____ C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk 2017-06-15 17:59 - 2017-06-15 17:59 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Twitch 2017-06-15 16:52 - 2017-06-15 16:52 - 00000000 ____D C:\Users\Raphael\AppData\Local\DBG 2017-06-15 12:49 - 2017-06-15 18:28 - 00039566 _____ C:\Users\Raphael\Documents\Hochzeit Isabell u. Gabriel.odg 2017-06-15 11:24 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-06-15 11:24 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-06-15 11:24 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2017-06-15 11:24 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2017-06-15 11:24 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2017-06-15 11:24 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll 2017-06-15 11:24 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-06-15 11:24 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-06-15 11:24 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-06-15 11:24 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2017-06-15 11:24 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2017-06-15 11:24 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll 2017-06-15 11:24 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2017-06-15 11:24 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2017-06-15 11:24 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2017-06-15 11:24 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-06-15 11:24 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-06-15 11:24 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-06-15 11:24 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-06-15 11:24 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-06-15 11:24 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe 2017-06-15 11:24 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll 2017-06-15 11:24 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll 2017-06-15 11:24 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-06-15 11:24 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2017-06-15 11:24 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe 2017-06-15 11:24 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2017-06-15 11:24 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2017-06-15 11:24 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll 2017-06-15 11:24 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll 2017-06-15 11:24 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-06-15 11:24 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2017-06-15 11:24 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-06-15 11:24 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-06-15 11:24 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-06-15 11:24 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2017-06-15 11:24 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-06-15 11:24 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2017-06-15 11:24 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-06-15 11:24 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-06-15 11:24 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2017-06-15 11:24 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe 2017-06-15 11:24 - 2017-05-20 11:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-06-15 11:24 - 2017-05-20 10:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2017-06-15 11:24 - 2017-05-20 10:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-06-15 11:24 - 2017-05-20 10:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2017-06-15 11:24 - 2017-05-20 10:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-06-15 11:24 - 2017-05-20 10:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-06-15 11:24 - 2017-05-20 10:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2017-06-15 11:24 - 2017-05-20 10:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll 2017-06-15 11:24 - 2017-05-20 10:26 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll 2017-06-15 11:24 - 2017-05-20 10:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll 2017-06-15 11:24 - 2017-05-20 10:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2017-06-15 11:24 - 2017-05-20 10:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll 2017-06-15 11:24 - 2017-05-20 10:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-06-15 11:24 - 2017-05-20 10:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2017-06-15 11:24 - 2017-05-20 10:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2017-06-15 11:24 - 2017-05-20 10:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2017-06-15 11:24 - 2017-05-20 10:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2017-06-15 11:24 - 2017-05-20 10:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2017-06-15 11:24 - 2017-05-20 10:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-06-15 11:24 - 2017-05-20 10:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-06-15 11:24 - 2017-05-20 10:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-06-15 11:24 - 2017-05-20 10:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2017-06-15 11:24 - 2017-05-20 10:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-06-15 11:24 - 2017-05-20 10:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-06-15 11:24 - 2017-05-20 10:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll 2017-06-15 11:24 - 2017-05-20 10:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2017-06-15 11:24 - 2017-05-20 10:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll 2017-06-15 11:24 - 2017-05-20 09:08 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-06-15 11:24 - 2017-05-20 09:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-06-15 11:24 - 2017-05-20 09:07 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2017-06-15 11:24 - 2017-05-20 09:03 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2017-06-15 11:24 - 2017-05-20 08:59 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2017-06-15 11:24 - 2017-05-20 08:58 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2017-06-15 11:24 - 2017-05-20 08:56 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-06-15 11:24 - 2017-05-20 08:56 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-06-15 11:24 - 2017-05-20 08:55 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2017-06-15 11:24 - 2017-05-20 08:55 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-06-15 11:24 - 2017-05-20 08:54 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-06-15 11:24 - 2017-05-20 08:54 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-06-15 11:24 - 2017-05-20 08:54 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys 2017-06-15 11:24 - 2017-05-20 08:53 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-06-15 11:24 - 2017-05-20 08:53 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-06-15 11:24 - 2017-05-20 08:52 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-06-15 11:24 - 2017-05-20 08:52 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-06-15 11:24 - 2017-05-20 08:51 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-06-15 11:24 - 2017-05-20 08:48 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll 2017-06-15 11:24 - 2017-05-20 08:10 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys 2017-06-15 11:24 - 2017-05-20 08:09 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll 2017-06-15 11:24 - 2017-05-20 08:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll 2017-06-15 11:24 - 2017-05-20 08:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-06-15 11:24 - 2017-05-20 08:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys 2017-06-15 11:24 - 2017-05-20 08:07 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2017-06-15 11:24 - 2017-05-20 08:07 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll 2017-06-15 11:24 - 2017-05-20 08:07 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe 2017-06-15 11:24 - 2017-05-20 08:06 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2017-06-15 11:24 - 2017-05-20 08:06 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll 2017-06-15 11:24 - 2017-05-20 08:06 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2017-06-15 11:24 - 2017-05-20 08:03 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll 2017-06-15 11:24 - 2017-05-20 08:02 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2017-06-15 11:24 - 2017-05-20 08:02 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2017-06-15 11:24 - 2017-05-20 08:01 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll 2017-06-15 11:24 - 2017-05-20 08:00 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-06-15 11:24 - 2017-05-20 08:00 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-06-15 11:24 - 2017-05-20 07:59 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-06-15 11:24 - 2017-05-20 07:58 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2017-06-15 11:24 - 2017-05-20 07:56 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe 2017-06-15 11:24 - 2017-05-20 07:55 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-06-15 11:24 - 2017-05-20 07:54 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-06-15 11:24 - 2017-05-20 07:52 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2017-06-15 11:24 - 2017-05-20 07:52 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-06-15 11:24 - 2017-05-20 07:51 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-06-15 11:24 - 2017-05-20 07:51 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2017-06-15 11:24 - 2017-05-20 07:50 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll 2017-06-15 11:24 - 2017-05-20 07:50 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2017-06-15 11:24 - 2017-05-20 07:48 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2017-06-15 11:24 - 2017-05-20 07:48 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll 2017-06-15 11:24 - 2017-05-20 07:47 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2017-06-15 11:24 - 2017-05-20 07:47 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll Code:
ATTFilter ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-07-13 20:35 - 2017-05-30 19:21 - 02643258 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-07-13 20:35 - 2017-03-20 06:35 - 01150850 _____ C:\WINDOWS\system32\perfh007.dat 2017-07-13 20:35 - 2017-03-20 06:35 - 00279270 _____ C:\WINDOWS\system32\perfc007.dat 2017-07-13 20:34 - 2017-02-22 01:18 - 00000000 ____D C:\ProgramData\aquasuite-data 2017-07-13 20:34 - 2017-01-26 23:06 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\PersBackup5 2017-07-13 20:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-07-13 20:33 - 2016-06-17 10:37 - 00000000 __SHD C:\Users\Raphael\IntelGraphicsProfiles 2017-07-13 20:33 - 2016-04-27 07:56 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-07-13 20:31 - 2017-05-30 19:30 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-07-13 20:31 - 2017-05-30 19:20 - 00377624 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-07-13 20:31 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-07-13 20:31 - 2016-11-24 23:38 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-07-13 11:17 - 2017-05-30 19:20 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin 2017-07-13 11:17 - 2017-03-18 13:40 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\migwiz 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-07-13 11:16 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2017-07-13 11:12 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-07-13 11:10 - 2013-08-15 09:30 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-07-13 11:09 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-07-13 11:08 - 2012-09-10 16:21 - 135225752 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-07-13 11:00 - 2016-08-21 08:10 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-07-13 10:53 - 2017-01-26 23:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Personal Backup 2017-07-13 10:53 - 2017-01-26 23:05 - 00000000 ____D C:\Program Files\Personal Backup 5 2017-07-13 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-07-13 10:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-07-11 22:16 - 2017-05-30 19:20 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-07-11 17:47 - 2015-07-03 13:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-07-11 17:47 - 2012-09-07 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-07-08 20:49 - 2012-09-07 20:49 - 00001235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-07-08 20:07 - 2016-11-24 23:38 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-07-05 21:16 - 2015-10-30 08:28 - 00000000 ____D C:\Users\Default.migrated 2017-07-02 23:15 - 2017-05-30 19:21 - 00000000 ____D C:\Users\Raphael 2017-07-02 23:13 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\SwapHome 2017-07-02 23:13 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\CooRink Portable 2017-07-02 23:13 - 2015-12-07 00:14 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.4 2017-07-02 22:50 - 2017-05-30 19:30 - 00003616 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-07-02 22:50 - 2017-05-30 19:30 - 00003392 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-07-02 22:26 - 2013-03-23 20:41 - 00000000 ____D C:\ProgramData\Origin 2017-07-02 21:46 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-07-02 21:46 - 2013-03-23 20:45 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Origin 2017-07-02 21:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\System 2017-07-02 21:32 - 2017-05-30 19:21 - 00000000 ____D C:\ProgramData\Package Cache 2017-07-02 21:31 - 2015-01-26 14:13 - 00000000 ____D C:\Program Files\Java 2017-07-02 21:30 - 2012-09-24 21:32 - 00000000 ____D C:\Program Files (x86)\Java 2017-07-02 19:56 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-06-30 16:47 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-06-30 16:47 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-06-29 19:35 - 2017-01-22 23:41 - 00002267 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-06-29 19:35 - 2017-01-22 23:41 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-06-27 22:32 - 2013-05-20 10:34 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Dropbox 2017-06-21 20:13 - 2016-12-21 22:01 - 00000000 ____D C:\Users\Raphael\AppData\Roaming\Curse Client 2017-06-18 19:55 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-06-16 10:40 - 2013-03-07 19:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-06-16 10:40 - 2013-03-07 19:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-06-15 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-06-15 19:43 - 2013-03-07 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-06-14 21:30 - 2015-06-16 11:08 - 00000000 ____D C:\Users\Raphael\AppData\Local\Dropbox 2017-06-14 20:34 - 2017-05-30 19:30 - 00004428 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2017-06-14 20:29 - 2017-02-22 01:17 - 00000000 ____D C:\Program Files\aquasuite ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2012-12-25 16:51 - 2017-01-05 15:01 - 0000161 _____ () C:\Users\Raphael\AppData\Roaming\default.rss 2013-08-11 10:24 - 2013-08-11 10:24 - 0000000 _____ () C:\Users\Raphael\AppData\Roaming\downloads.m3u 2013-12-27 01:10 - 2016-04-15 22:21 - 0004031 _____ () C:\Users\Raphael\AppData\Roaming\LTspiceIV.ini 2013-12-21 20:12 - 2016-04-15 22:19 - 0000363 _____ () C:\Users\Raphael\AppData\Roaming\Solve Elec 2.5 Prefs 2016-10-11 21:44 - 2017-03-03 16:08 - 1307648 _____ () C:\Users\Raphael\AppData\Local\file__0.localstorage 2017-07-02 22:50 - 2017-07-02 22:50 - 0140800 _____ () C:\Users\Raphael\AppData\Local\installer.dat 2014-03-04 02:48 - 2014-03-04 02:48 - 0002742 _____ () C:\Users\Raphael\AppData\Local\recently-used.xbel 2015-05-15 21:09 - 2015-09-12 21:03 - 0007604 _____ () C:\Users\Raphael\AppData\Local\Resmon.ResmonCfg 2017-07-02 22:50 - 2017-07-02 22:50 - 0930816 _____ () C:\Users\Raphael\AppData\Local\test_db_cara.db 2012-09-08 14:54 - 2012-09-08 14:54 - 0010719 _____ () C:\ProgramData\xml39BA.tmp 2012-09-08 14:54 - 2012-09-08 14:54 - 0013814 _____ () C:\ProgramData\xml456F.tmp 2012-09-08 14:54 - 2012-09-08 14:54 - 0000000 _____ () C:\ProgramData\xml49A4.tmp 2012-09-08 14:54 - 2012-09-08 14:54 - 0000000 _____ () C:\ProgramData\xml4DAB.tmp Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Raphael\pb-setup-x64-5.8.0602.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-07-06 20:01 ==================== Ende von FRST.txt ============================ |
Themen zu Malware verhindert MBAM/Windows Defender |
adware, bonjour, computer, desktop, firefox, flash player, google, home, homepage, kaspersky, malware, mozilla, prozesse, realtek, registry, rundll, scan, security, sekunden, software, starten, system, usb, werbung, windows, windowsapps |