Glaringsoul | 12.03.2017 00:03 | Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 11-03-2017 01
durchgeführt von Henselmann (Administrator) auf FATAL-CRYPT-ERR (12-03-2017 00:01:44)
Gestartet von C:\Users\Henselmann\Downloads
Geladene Profile: Henselmann (Verfügbare Profile: defaultuser0 & Henselmann)
Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Electronic Arts) D:\Origin\OriginWebHelperService.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Apple Inc.) D:\iTunes\iTunesHelper.exe
(Flux Software LLC) C:\Users\Henselmann\AppData\Local\FluxSoftware\Flux\flux.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.5459\Agent.exe
(Blizzard Entertainment) D:\Blizzard\Battle.net\Battle.net.8423\Battle.net.exe
(Akamai Technologies, Inc.) C:\Users\Henselmann\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Henselmann\AppData\Local\Akamai\netsession_win.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(SPEEDLINK) C:\Program Files (x86)\SPEEDLINK\ACCUSOR Advanced Gaming Keyboard\Monitor.EXE
() C:\Program Files (x86)\Drakonia Configurator\hid.exe
() C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
() D:\Blizzard\Battle.net\Battle.net.8423\Battle.net Helper.exe
() C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\Henselmann\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe
() D:\Blizzard\Battle.net\Battle.net.8423\Battle.net Helper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(TODO: <Company name>) C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ASLED.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(TODO: <Company name>) C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ledcontrolservice.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-27] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => D:\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES/MALWAREBYTES/ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-04] (AVAST Software)
HKLM-x32\...\Run: [ACCUSOR Advanced Gaming Keyboard Driver] => C:\Program Files (x86)\SPEEDLINK\ACCUSOR Advanced Gaming Keyboard\Monitor.exe [1972736 2016-10-10] (SPEEDLINK)
HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc)
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [248832 2013-10-29] ()
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2017-03-02] (Razer Inc.)
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27427808 2017-02-08] (Skype Technologies S.A.)
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9539800 2016-12-15] (Piriform Ltd)
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\...\Run: [f.lux] => C:\Users\Henselmann\AppData\Local\FluxSoftware\Flux\flux.exe [1024240 2016-12-06] (Flux Software LLC)
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-03-09] (Valve Corporation)
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\...\Run: [Discord] => C:\Users\Henselmann\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\...\Run: [Battle.net] => D:\Blizzard\Battle.net\Battle.net Launcher.exe [3122152 2017-01-26] (Blizzard Entertainment)
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Henselmann\AppData\Local\Akamai\netsession_win.exe [4490200 2017-01-03] (Akamai Technologies, Inc.)
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ledcontrolservice.exe [2111488 2016-06-06] (TODO: <Company name>)
SSODL: EldosMountNotificator-cbfs6 - {2BDE6E34-89F1-4989-8908-582D4DAB9A1E} - C:\Windows\system32\cbfsMntNtf6.dll (/n software, Inc.)
SSODL-x32: EldosMountNotificator-cbfs6 - {2BDE6E34-89F1-4989-8908-582D4DAB9A1E} - C:\Windows\SysWOW64\cbfsMntNtf6.dll (/n software, Inc.)
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Henselmann\AppData\Local\MEGAsync\ShellExtX64.dll [2016-10-31] ()
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Henselmann\AppData\Local\MEGAsync\ShellExtX64.dll [2016-10-31] ()
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Henselmann\AppData\Local\MEGAsync\ShellExtX64.dll [2016-10-31] ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-04] (AVAST Software)
ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs6] -> {0C9DD067-B805-44B0-ADF1-4DC31E9C35E5} => C:\Windows\system32\cbfsMntNtf6.dll [2016-08-03] (/n software, Inc.)
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Henselmann\AppData\Local\MEGAsync\ShellExtX32.dll [2016-10-31] ()
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Henselmann\AppData\Local\MEGAsync\ShellExtX32.dll [2016-10-31] ()
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Henselmann\AppData\Local\MEGAsync\ShellExtX32.dll [2016-10-31] ()
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs6] -> {0C9DD067-B805-44B0-ADF1-4DC31E9C35E5} => C:\Windows\SysWOW64\cbfsMntNtf6.dll [2016-08-03] (/n software, Inc.)
Startup: C:\Users\Henselmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2017-01-15]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Henselmann\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{2fca545b-e1d8-474e-8e16-93c937e8e135}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?bcutc=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
HKU\S-1-5-21-2565043127-2691430490-4239563169-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?bcutc=sp-006
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2565043127-2691430490-4239563169-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2565043127-2691430490-4239563169-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2565043127-2691430490-4239563169-1001 -> hxxp://www.google.com
FireFox:
========
FF ProfilePath: C:\Users\Henselmann\AppData\Roaming\Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 [2017-03-11]
FF NewTab: Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 -> about:newtab
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 -> Google
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 -> hxxps://www.google.com/search?bcutc=sp-006
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 -> Google
FF Homepage: Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 -> hxxps://www.google.com/?bcutc=sp-006
FF Keyword.URL: Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583 -> hxxps://www.google.com/search?bcutc=sp-006
FF Extension: (Test Pilot) - C:\Users\Henselmann\AppData\Roaming\Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583\Extensions\@testpilot-addon.xpi [2017-03-07]
FF Extension: (Ghostery) - C:\Users\Henselmann\AppData\Roaming\Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583\Extensions\firefox@ghostery.com.xpi [2017-02-26]
FF Extension: (uBlock Origin) - C:\Users\Henselmann\AppData\Roaming\Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583\Extensions\uBlock0@raymondhill.net.xpi [2017-03-04]
FF SearchPlugin: C:\Users\Henselmann\AppData\Roaming\Mozilla\Firefox\Profiles\641m7xt6.default-1488061479583\searchplugins\google-avast.xml [2017-03-10]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-03-04]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-03-04]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-14] ()
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-14] ()
FF Plugin-x32: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll [2017-01-02] (Nexon)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-23] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 ASLED; C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ASLED.exe [49664 2016-06-14] (TODO: <Company name>) [Datei ist nicht signiert]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-04] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-04] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [278784 2017-03-04] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1445384 2016-10-22] ()
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2017-01-10] (BitRaider, LLC)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-12-09] (Hi-Rez Studios) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [7847256 2016-10-18] (INCA Internet Co., Ltd.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-23] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-02-23] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-02-23] (NVIDIA Corporation)
S3 Origin Client Service; D:\Origin\OriginClientService.exe [2124296 2017-03-07] (Electronic Arts)
R2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [2185232 2017-03-07] (Electronic Arts)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [133376 2016-09-28] (Razer Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [672208 2017-02-03] (Wacom Technology, Corp.)
S2 chip1click; "C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [309272 2017-03-04] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-04] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334600 2017-03-04] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-04] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-04] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32088 2017-03-04] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [126600 2017-03-04] (AVAST Software)
R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [461640 2017-03-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [100640 2017-03-04] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-04] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [993608 2017-03-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [548928 2017-03-10] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162528 2017-03-04] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [337592 2017-03-04] (AVAST Software)
R1 cbfs6; C:\Windows\system32\drivers\cbfs6.sys [460992 2016-08-03] (/n software, Inc.)
S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2017-02-18] (Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2017-02-18] (Disc Soft Ltd)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [102856 2017-01-14] (Malwarebytes)
S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-01-14] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [250816 2017-03-11] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [91584 2017-01-14] (Malwarebytes)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_2a6e383a1adc0e24\nvlddmkm.sys [14569528 2017-02-24] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-02-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47672 2017-01-06] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [59448 2017-02-23] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2015-10-10] (Realtek )
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.)
R3 vpnpbus; C:\Windows\System32\drivers\vpnpbus.sys [18624 2016-08-03] (/n software, Inc.)
S3 WacHidRouterPro; C:\Windows\System32\drivers\wachidrouter.sys [119952 2017-01-25] (Wacom Technology)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 xhunter1; C:\Windows\xhunter1.sys [36808 2017-03-11] (Wellbia.com Co., Ltd.)
U1 aswbdisk; kein ImagePath
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
S3 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-03-12 00:01 - 2017-03-12 00:01 - 00023630 _____ C:\Users\Henselmann\Downloads\FRST.txt
2017-03-12 00:00 - 2017-03-12 00:01 - 2005164028 _____ C:\Users\Henselmann\Desktop\Kram.zip
2017-03-11 23:59 - 2017-03-11 23:59 - 29389413 _____ C:\Users\Henselmann\Downloads\Hentai_Pictures_Pack_45_(www.hentairules.net) (2).zip
2017-03-11 23:59 - 2017-03-11 23:59 - 05858628 _____ C:\Users\Henselmann\Downloads\Ino Yamanaka Hentai Pics (2).zip
2017-03-11 23:56 - 2017-03-12 00:01 - 00000000 ____D C:\FRST
2017-03-11 23:55 - 2017-03-11 23:55 - 02424320 _____ (Farbar) C:\Users\Henselmann\Downloads\FRST64.exe
2017-03-11 19:11 - 2017-03-11 19:11 - 00000000 ____D C:\Users\Henselmann\AppData\LocalLow\Sun
2017-03-11 19:11 - 2017-03-11 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WAIS-IV
2017-03-11 18:57 - 2017-03-11 19:06 - 00000000 ____D C:\Users\Henselmann\Desktop\mbar
2017-03-11 18:55 - 2017-03-11 18:55 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Henselmann\Downloads\mbar-1.09.3.1001(1).exe
2017-03-10 15:29 - 2017-03-11 10:39 - 00290304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\subinacl.exe
2017-03-10 15:29 - 2017-03-10 15:44 - 00000000 ____D C:\Program Files (x86)\Adware Removal Tool by TSA
2017-03-10 15:28 - 2017-03-10 15:28 - 00752296 _____ C:\Users\Henselmann\Downloads\Adware Removal Tool by TSA.exe
2017-03-10 15:26 - 2017-03-10 15:26 - 00000386 _____ C:\Windows\SysWOW64\data.bin
2017-03-10 15:26 - 2017-03-10 15:26 - 00000000 _____ C:\Windows\SysWOW64\4
2017-03-10 15:26 - 2017-03-10 15:26 - 00000000 _____ C:\Windows\SysWOW64\3
2017-03-10 15:22 - 2017-03-10 15:22 - 00000000 ____D C:\Program Files (x86)\Ckosushdekey
2017-03-09 16:30 - 2017-03-09 16:30 - 00000000 ____D C:\Temp
2017-03-09 16:30 - 2017-03-09 16:30 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-03-09 16:30 - 2017-02-23 09:17 - 00136064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-03-09 16:30 - 2017-01-26 01:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-03-09 16:30 - 2017-01-26 01:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-03-09 16:30 - 2017-01-26 01:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll
2017-03-09 16:30 - 2017-01-26 01:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe
2017-03-09 16:29 - 2017-03-09 16:30 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-03-09 16:28 - 2017-02-23 23:55 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 40192056 _____ C:\Windows\system32\nvcompiler.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 34992184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 28252608 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 19007528 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 14674896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 11122728 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 03168192 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 02717752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 01985080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437878.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437878.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 01052096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00989632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00946456 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFTH264.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00944224 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFThevc.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00910784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00721768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00719856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFThevc.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00618416 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00605120 _____ (NVIDIA Corporation) C:\Windows\system32\nvDecMFTMjpeg.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00576008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00573632 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00499136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00483384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvDecMFTMjpeg.dll
2017-03-09 16:28 - 2017-02-23 11:32 - 00447984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-03-08 01:00 - 2017-03-10 15:25 - 00000000 ____D C:\Program Files (x86)\MK
2017-03-07 18:03 - 2017-03-07 18:03 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-03-07 17:58 - 2017-03-07 21:17 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-03-07 17:58 - 2017-03-07 17:58 - 00002096 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2017-03-07 17:58 - 2017-03-07 17:58 - 00000000 ____D C:\Users\Henselmann\AppData\LocalLow\Adobe
2017-03-07 17:57 - 2017-03-07 17:59 - 00000000 ____D C:\ProgramData\Adobe
2017-03-07 17:57 - 2017-03-07 17:57 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-03-07 17:56 - 2017-03-07 17:58 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Adobe
2017-03-07 17:25 - 2017-03-07 17:25 - 00001159 _____ C:\Users\Public\Desktop\Mass Effect 3.lnk
2017-03-06 21:11 - 2017-03-06 21:11 - 00000000 ____D C:\Users\Henselmann\Desktop\saveedit_rev25
2017-03-06 21:10 - 2017-03-06 21:10 - 00055487 _____ C:\Users\Henselmann\Downloads\saveedit_rev25.zip
2017-03-06 21:10 - 2017-03-06 21:10 - 00000000 ____D C:\ProgramData\Estsoft
2017-03-04 21:21 - 2017-03-04 21:21 - 03086696 _____ C:\Users\Henselmann\Downloads\instspeedfan452(1).exe
2017-03-04 21:21 - 2017-03-04 21:21 - 00001080 _____ C:\Users\Henselmann\Desktop\SpeedFan.lnk
2017-03-04 21:21 - 2017-03-04 21:21 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2017-03-04 19:38 - 2017-03-04 19:38 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Internet Security.lnk
2017-03-04 19:38 - 2017-03-04 19:38 - 00001967 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2017-03-04 19:38 - 2017-03-04 19:37 - 00461640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetSec.sys
2017-03-04 19:38 - 2017-03-04 19:31 - 00398408 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-03-04 19:34 - 2017-03-10 16:11 - 00004044 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1488652479
2017-03-04 19:34 - 2017-03-10 16:11 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-03-04 19:34 - 2017-03-04 19:34 - 00032088 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-03-04 19:34 - 2017-03-04 19:34 - 00001088 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2017-03-04 19:32 - 2017-03-04 19:32 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\AVAST Software
2017-03-04 19:31 - 2017-03-10 15:49 - 00548928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2017-03-04 19:31 - 2017-03-04 19:38 - 00003994 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-03-04 19:31 - 2017-03-04 19:31 - 00993608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00496896 _____ C:\Users\Henselmann\Downloads\flux-setup.exe
2017-03-04 19:31 - 2017-03-04 19:31 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00334600 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00309272 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00162528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00126600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00100640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-03-04 19:31 - 2017-03-04 19:31 - 00002185 _____ C:\Users\Henselmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk
2017-03-04 19:31 - 2017-03-04 19:31 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2017-03-04 19:31 - 2017-03-04 19:31 - 00000000 ____D C:\Users\Henselmann\AppData\Local\FluxSoftware
2017-03-04 19:30 - 2017-03-04 19:34 - 00000000 ____D C:\Program Files\AVAST Software
2017-03-04 19:29 - 2017-03-04 23:54 - 00000000 ____D C:\ProgramData\AVAST Software
2017-03-04 19:29 - 2017-03-04 19:29 - 06654960 _____ (AVAST Software) C:\Users\Henselmann\Downloads\avast_free_antivirus_setup_online.exe
2017-03-04 10:23 - 2017-03-04 10:24 - 04121760 _____ (Husdawg, LLC) C:\Users\Henselmann\Downloads\Detection(1).exe
2017-03-03 18:13 - 2017-03-03 18:13 - 00000000 ____D C:\Windows\System32\Tasks\Avira
2017-03-01 18:21 - 2017-03-01 18:21 - 00000000 ____D C:\Users\Henselmann\Desktop\1408077412919_transistor
2017-03-01 18:19 - 2017-03-01 18:19 - 04031440 _____ C:\Users\Henselmann\Desktop\adwcleaner_6.044.exe
2017-03-01 17:44 - 2017-03-01 17:44 - 15220605 _____ C:\Users\Henselmann\Downloads\1408077412919_transistor.zip
2017-02-28 13:00 - 2017-02-28 13:00 - 01191352 _____ ( ) C:\Users\Henselmann\Downloads\hwmonitor_1.30.exe
2017-02-28 13:00 - 2017-02-28 13:00 - 00000975 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2017-02-28 13:00 - 2017-02-28 13:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-02-28 13:00 - 2017-02-28 13:00 - 00000000 ____D C:\Program Files\CPUID
2017-02-28 01:55 - 2017-03-05 10:40 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2017-02-28 01:55 - 2017-03-04 21:21 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2017-02-28 01:55 - 2017-02-28 01:55 - 03086696 _____ C:\Users\Henselmann\Downloads\instspeedfan452.exe
2017-02-27 22:32 - 2017-02-27 22:32 - 02212462 _____ C:\Users\Henselmann\Downloads\TMACv6.0.7_Setup.zip
2017-02-27 22:32 - 2017-02-27 22:32 - 01070232 ___RS (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2017-02-27 22:32 - 2017-02-27 22:32 - 01010720 ___RS (Microsoft Corporation) C:\Windows\SysWOW64\MSCHRT20.OCX
2017-02-27 22:32 - 2017-02-27 22:32 - 00224016 ___RS (Microsoft Corporation) C:\Windows\SysWOW64\TABCTL32.OCX
2017-02-27 22:32 - 2017-02-27 22:32 - 00140488 ___RS (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX
2017-02-27 22:32 - 2017-02-27 22:32 - 00001273 _____ C:\Users\Public\Desktop\TMAC v6.lnk
2017-02-27 22:32 - 2017-02-27 22:32 - 00000000 ____D C:\Program Files (x86)\Technitium
2017-02-26 18:54 - 2017-02-26 18:54 - 00000000 ____D C:\Program Files (x86)\Origin Games
2017-02-26 17:24 - 2017-02-26 17:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablett
2017-02-26 17:19 - 2017-02-26 17:20 - 82101304 _____ C:\Users\Henselmann\Downloads\WacomTablet_6.3.15-3.exe
2017-02-26 17:17 - 2017-02-26 17:17 - 00001951 _____ C:\Users\Henselmann\Desktop\Wacom Tablett-Eigenschaften.lnk
2017-02-26 16:17 - 2017-02-26 17:21 - 00000016 _____ C:\Users\Henselmann\Desktop\BDO.txt
2017-02-26 15:55 - 2017-03-11 18:52 - 00000000 ____D C:\AdwCleaner
2017-02-26 12:10 - 2017-02-26 12:11 - 00000000 ____D C:\Users\Henselmann\Desktop\SCHULE
2017-02-26 10:08 - 2017-02-26 10:08 - 04581024 _____ (Avira Operations GmbH & Co. KG) C:\Users\Henselmann\Downloads\avira_de_fass0_58b29474b3687__ws.exe
2017-02-25 23:24 - 2017-03-10 15:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-25 23:24 - 2017-03-10 15:28 - 00001208 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-02-25 23:24 - 2017-03-10 15:28 - 00001208 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-25 23:24 - 2017-02-25 23:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-02-25 23:22 - 2017-02-25 23:22 - 00245600 _____ C:\Users\Henselmann\Downloads\Firefox Setup Stub 51.0.1.exe
2017-02-25 23:11 - 2017-02-25 23:11 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Pmuthercoudole
2017-02-25 16:51 - 2017-02-25 16:51 - 00000000 ____D C:\Users\Henselmann\Desktop\WhatsApp Chat - Mama
2017-02-25 16:51 - 2017-02-25 13:16 - 15712860 _____ C:\Users\Henselmann\Desktop\WhatsApp Chat - Mama.zip
2017-02-25 00:27 - 2017-02-25 00:27 - 00066608 _____ C:\Users\Henselmann\Downloads\saveedit_rev23.zip
2017-02-24 19:48 - 2017-02-24 19:48 - 00000000 ____D C:\Users\Henselmann\Documents\BioWare
2017-02-24 19:48 - 2017-02-24 19:48 - 00000000 ____D C:\ProgramData\Electronic Arts
2017-02-24 14:39 - 2017-02-24 14:39 - 00001061 _____ C:\Users\Public\Desktop\Mass Effect 2.lnk
2017-02-24 14:39 - 2017-02-24 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mass Effect 2
2017-02-24 12:28 - 2017-03-10 15:36 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\Origin
2017-02-24 12:28 - 2017-02-24 12:28 - 00000575 _____ C:\Users\Public\Desktop\Origin.lnk
2017-02-24 12:28 - 2017-02-24 12:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2017-02-24 12:26 - 2017-03-09 22:57 - 00000000 ____D C:\ProgramData\Origin
2017-02-24 12:26 - 2017-02-24 12:28 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Origin
2017-02-24 12:26 - 2017-02-24 12:26 - 00000000 ____D C:\Users\Henselmann\.Origin
2017-02-24 12:15 - 2017-02-24 12:15 - 00001358 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
2017-02-23 20:59 - 2017-02-23 20:59 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Wacom
2017-02-23 20:59 - 2017-02-23 20:59 - 00000000 ____D C:\Users\Henselmann\.android
2017-02-23 20:02 - 2017-02-26 17:23 - 00000000 ____D C:\Program Files\Tablet
2017-02-23 20:02 - 2017-02-23 20:59 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\WTablet
2017-02-23 20:02 - 2017-02-23 20:02 - 00000000 ____D C:\Program Files\TabletPlugins
2017-02-23 20:02 - 2017-02-23 20:02 - 00000000 ____D C:\Program Files (x86)\TabletPlugins
2017-02-23 20:02 - 2017-02-03 01:01 - 02274256 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.dll
2017-02-23 20:02 - 2017-02-03 01:01 - 02267600 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Touch_Tablet.dll
2017-02-23 20:02 - 2017-02-03 01:01 - 02173392 _____ (Wacom Technology, Corp.) C:\Windows\system32\WacomMT.dll
2017-02-23 20:02 - 2017-02-03 01:01 - 02111952 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wintab32.dll
2017-02-23 20:02 - 2017-02-03 01:01 - 01787856 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Tablet.dll
2017-02-23 20:02 - 2017-02-03 01:01 - 01781200 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Touch_Tablet.dll
2017-02-23 20:02 - 2017-02-03 01:01 - 01673168 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll
2017-02-23 20:02 - 2017-02-03 01:01 - 01632720 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll
2017-02-23 20:02 - 2017-01-25 18:52 - 00119952 _____ (Wacom Technology) C:\Windows\system32\Drivers\wachidrouter.sys
2017-02-23 20:02 - 2016-11-15 22:43 - 00033960 _____ (Wacom Technology) C:\Windows\system32\Drivers\wacomrouterfilter.sys
2017-02-23 20:02 - 2016-08-03 16:01 - 00018848 _____ (/n software, Inc.) C:\Windows\system32\elevtmsg.dll
2017-02-23 20:02 - 2016-08-03 16:00 - 00235424 _____ (/n software, Inc.) C:\Windows\SysWOW64\cbfsNetRdr6.dll
2017-02-23 20:02 - 2016-08-03 16:00 - 00134560 _____ (/n software, Inc.) C:\Windows\system32\cbfsNetRdr6.dll
2017-02-23 20:02 - 2016-08-03 15:59 - 00196000 _____ (/n software, Inc.) C:\Windows\system32\cbfsMntNtf6.dll
2017-02-23 20:02 - 2016-08-03 15:59 - 00170400 _____ (/n software, Inc.) C:\Windows\SysWOW64\cbfsMntNtf6.dll
2017-02-23 20:02 - 2016-08-03 15:48 - 00460992 _____ (/n software, Inc.) C:\Windows\system32\Drivers\cbfs6.sys
2017-02-23 20:02 - 2016-08-03 15:48 - 00018624 _____ (/n software, Inc.) C:\Windows\system32\Drivers\vpnpbus.sys
2017-02-23 20:02 - 2012-12-11 23:12 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\wdfcoinstaller01009.dll
2017-02-23 20:02 - 2012-12-11 23:12 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wdfcoinstaller01009.dll
2017-02-22 16:57 - 2017-02-22 16:58 - 00000000 ____D C:\Program Files\Common Files\logishrd
2017-02-21 19:33 - 2017-02-21 19:33 - 00000000 ____D C:\ProgramData\Screaming Bee
2017-02-21 19:29 - 2017-02-21 19:29 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\Screaming Bee
2017-02-20 00:32 - 2017-02-20 00:32 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\RenPy
2017-02-19 22:30 - 2017-02-19 23:17 - 02870984 _____ (ESET) C:\Users\Henselmann\Desktop\esetsmartinstaller_deu.exe
2017-02-19 22:16 - 2017-02-19 22:16 - 00000000 ____D C:\Users\Henselmann\Desktop\IGG-SunrideAcademy
2017-02-18 02:20 - 2017-02-18 02:20 - 00047672 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtliteusbbus.sys
2017-02-18 02:20 - 2017-02-18 02:20 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2017-02-18 02:20 - 2017-02-18 02:20 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Disc_Soft_Ltd
2017-02-18 02:19 - 2017-02-22 17:03 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\DAEMON Tools Lite
2017-02-18 02:19 - 2017-02-18 02:27 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2017-02-18 02:19 - 2017-02-18 02:19 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2017-02-18 02:19 - 2017-02-18 02:19 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2017-02-16 16:45 - 2017-02-16 16:45 - 00000000 ____D C:\Users\Henselmann\ansel
2017-02-14 22:20 - 2017-02-10 03:33 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437866.dll
2017-02-14 22:20 - 2017-02-10 03:33 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437866.dll
2017-02-13 15:46 - 2017-02-13 15:46 - 00000000 ____D C:\Users\Henselmann\AppData\LocalLow\square_enix
2017-02-10 17:54 - 2017-02-10 17:54 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\.mono
2017-02-10 17:54 - 2017-02-10 17:54 - 00000000 ____D C:\Users\Henselmann\AppData\LocalLow\Blizzard Entertainment
2017-02-10 17:54 - 2017-02-10 17:54 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Blizzard
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-03-11 23:59 - 2017-01-26 16:27 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Battle.net
2017-03-11 22:31 - 2016-12-23 10:46 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-03-11 20:21 - 2016-12-31 14:21 - 00000000 ____D C:\Users\Henselmann\AppData\LocalLow\Mozilla
2017-03-11 19:16 - 2017-01-04 19:28 - 00036808 _____ (Wellbia.com Co., Ltd.) C:\Windows\xhunter1.sys
2017-03-11 19:16 - 2017-01-03 17:53 - 00000000 ____D C:\Users\Henselmann\AppData\Local\BlackDesertOnline
2017-03-11 19:16 - 2016-12-23 10:48 - 00000000 ____D C:\Users\Henselmann
2017-03-11 19:13 - 2016-12-31 14:28 - 00000000 ____D C:\Program Files (x86)\Steam
2017-03-11 19:06 - 2017-01-17 00:24 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-03-11 18:58 - 2016-12-23 10:52 - 03310556 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-11 18:58 - 2016-07-16 23:51 - 01485866 _____ C:\Windows\system32\perfh007.dat
2017-03-11 18:58 - 2016-07-16 23:51 - 00373616 _____ C:\Windows\system32\perfc007.dat
2017-03-11 18:57 - 2016-12-31 14:26 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-03-11 18:54 - 2017-01-07 18:12 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2017-03-11 18:54 - 2016-12-23 11:03 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-11 18:52 - 2016-12-31 14:26 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-03-11 18:52 - 2016-12-23 10:46 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-11 18:52 - 2016-07-16 07:04 - 00262144 _____ C:\Windows\system32\config\BBI
2017-03-11 18:31 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\AppReadiness
2017-03-11 18:23 - 2017-01-02 20:10 - 00004182 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{564F6E84-C00A-4C0A-BC99-D7AB81F118FD}
2017-03-09 22:41 - 2016-12-31 14:20 - 00000000 ____D C:\Users\Henselmann\AppData\Local\CrashDumps
2017-03-09 16:30 - 2016-12-23 11:03 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-03-09 16:30 - 2016-12-23 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-03-09 16:30 - 2016-07-16 12:45 - 00000000 ____D C:\Windows\INF
2017-03-09 16:25 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-07 17:58 - 2016-12-23 10:48 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\Adobe
2017-03-04 19:43 - 2016-12-23 10:51 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-04 19:41 - 2016-12-31 14:43 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\discord
2017-03-04 19:35 - 2017-01-13 20:27 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-03-04 19:35 - 2017-01-13 20:27 - 00000000 ____D C:\ProgramData\Skype
2017-03-04 19:31 - 2017-01-15 02:23 - 00000000 ____D C:\Program Files\Common Files\AV
2017-03-04 19:08 - 2016-12-31 14:43 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Discord
2017-03-04 10:26 - 2016-12-31 18:14 - 00004308 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-03-04 10:26 - 2016-12-31 18:14 - 00001489 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-03-04 10:26 - 2016-12-23 11:04 - 00003994 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-03-04 10:26 - 2016-12-23 11:03 - 00003894 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-03-04 10:26 - 2016-12-23 11:03 - 00003866 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-03-04 10:26 - 2016-12-23 11:03 - 00003858 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-03-04 10:26 - 2016-12-23 11:03 - 00003696 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-03-04 10:26 - 2016-12-23 11:03 - 00003654 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-03-04 10:26 - 2016-12-23 11:03 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-03-04 10:26 - 2016-12-23 11:00 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-03-03 19:10 - 2016-12-29 14:00 - 00003300 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-03-03 19:10 - 2016-12-23 10:49 - 00002402 _____ C:\Users\Henselmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-03-03 19:10 - 2016-12-23 10:49 - 00000000 ___RD C:\Users\Henselmann\OneDrive
2017-03-01 21:40 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\LiveKernelReports
2017-03-01 16:02 - 2017-01-03 17:54 - 00000000 ____D C:\Users\Henselmann\Documents\Black Desert
2017-02-28 17:32 - 2016-12-31 14:47 - 00000000 ____D C:\Users\Henselmann\AppData\Roaming\TS3Client
2017-02-28 12:54 - 2016-12-23 10:47 - 00000000 ____D C:\Users\defaultuser0
2017-02-27 13:05 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\system32\NDF
2017-02-27 12:52 - 2017-01-23 22:27 - 00000000 ____D C:\Users\Henselmann\AppData\Local\ElevatedDiagnostics
2017-02-26 17:58 - 2017-01-07 13:41 - 00000000 ____D C:\Users\Henselmann\AppData\Local\osu!
2017-02-25 23:11 - 2017-01-15 00:54 - 00000000 ____D C:\Windows\system32\SSL
2017-02-24 12:15 - 2016-12-31 14:50 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Razer
2017-02-24 12:15 - 2016-12-31 14:50 - 00000000 ____D C:\ProgramData\Razer
2017-02-24 12:15 - 2016-12-31 14:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2017-02-24 12:15 - 2016-12-31 14:50 - 00000000 ____D C:\Program Files (x86)\Razer
2017-02-23 23:55 - 2016-12-23 11:02 - 01600056 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2017-02-23 23:55 - 2016-12-23 11:02 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-02-23 21:48 - 2016-12-31 14:44 - 00000000 ____D C:\Users\Henselmann\AppData\Local\TeamSpeak 3 Client
2017-02-23 19:35 - 2016-12-23 11:04 - 01880512 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-02-23 19:35 - 2016-12-23 11:04 - 01755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2017-02-23 19:35 - 2016-12-23 11:04 - 01468864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-02-23 19:35 - 2016-12-23 11:04 - 01317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2017-02-23 19:35 - 2016-12-23 11:04 - 00120256 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2017-02-23 19:34 - 2017-01-11 17:36 - 00059448 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2017-02-23 17:17 - 2016-12-31 14:09 - 00000000 ____D C:\Windows\system32\MRT
2017-02-23 17:16 - 2016-12-31 14:09 - 138020592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-02-23 15:30 - 2016-12-31 18:14 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-02-23 11:32 - 2016-12-23 11:02 - 04078008 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2017-02-23 11:32 - 2016-12-23 11:02 - 03596616 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-02-23 11:32 - 2016-12-23 11:02 - 00043566 _____ C:\Windows\system32\nvinfo.pb
2017-02-23 09:43 - 2016-12-23 11:03 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-02-23 09:28 - 2016-12-23 11:03 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2017-02-23 09:28 - 2016-12-23 11:03 - 02479160 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2017-02-23 09:28 - 2016-12-23 11:03 - 01764408 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2017-02-23 09:28 - 2016-12-23 11:03 - 00548288 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2017-02-23 09:28 - 2016-12-23 11:03 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2017-02-23 09:28 - 2016-12-23 11:03 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2017-02-23 09:28 - 2016-12-23 11:03 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2017-02-23 07:38 - 2016-12-23 11:03 - 07807027 _____ C:\Windows\system32\nvcoproc.bin
2017-02-22 17:14 - 2016-07-16 12:36 - 00000000 ____D C:\Windows\CbsTemp
2017-02-22 16:57 - 2017-01-02 13:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-19 00:57 - 2016-12-31 14:30 - 00000000 ____D C:\Users\Henselmann\AppData\Local\Steam
2017-02-16 16:47 - 2017-01-05 00:33 - 00000000 ____D C:\Users\Henselmann\AppData\Local\MEGAsync
2017-02-14 16:00 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-02-14 16:00 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\system32\Macromed
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2017-01-08 04:12 - 2017-01-14 20:47 - 0007597 _____ () C:\Users\Henselmann\AppData\Local\Resmon.ResmonCfg
2016-12-23 10:54 - 2016-12-23 10:54 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-01-01 14:03 - 2017-01-01 14:03 - 0000016 _____ () C:\ProgramData\mntemp
2016-12-31 18:14 - 2017-01-11 17:36 - 0007609 _____ () C:\ProgramData\NvTelemetryContainer.log
2016-12-31 18:14 - 2017-01-10 19:32 - 0010108 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1
Einige Dateien in TEMP:
====================
2017-03-03 18:28 - 2017-03-03 18:28 - 0000512 _____ () C:\Users\Henselmann\AppData\Local\Temp\6699d3ee8dd9cf775caae782c8f44f03.dll
2017-03-03 18:28 - 2017-03-11 19:16 - 0000069 _____ () C:\Users\Henselmann\AppData\Local\Temp\e3a0f8dd4837fff176547bdbd39cbe30.dll
2017-02-14 22:22 - 2017-02-09 23:39 - 0754168 _____ (NVIDIA Corporation) C:\Users\Henselmann\AppData\Local\Temp\nvSCPAPI.dll
2017-02-14 22:22 - 2017-02-09 23:39 - 0868152 _____ (NVIDIA Corporation) C:\Users\Henselmann\AppData\Local\Temp\nvSCPAPI64.dll
2017-03-09 16:28 - 2017-02-09 23:39 - 0352704 _____ (NVIDIA Corporation) C:\Users\Henselmann\AppData\Local\Temp\nvStInst.exe
2017-03-04 21:22 - 2017-03-05 10:39 - 0192512 _____ () C:\Users\Henselmann\AppData\Local\Temp\sfamcc00001.dll
2015-02-10 18:56 - 2015-02-10 18:56 - 0105984 _____ () C:\Users\Henselmann\AppData\Local\Temp\sfextra.dll
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-03-05 11:01
==================== Ende von FRST.txt ============================ |