Amicelli11 | 13.08.2017 01:07 | Vielen Dank für die schnelle Antwort!
Ich muss wegen der Zeichenlänge die Logfiles in mehrere Antworten packen.
Anmerkung: alle Dateien vom 09.07.2017 sind potenziell schadhaft, da an diesem Datum die Adware eingefangen wurde. Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-08-2017
durchgeführt von Paustian (13-08-2017 01:28:05) Run:1
Gestartet von C:\Users\Paustian\Downloads
Geladene Profile: Paustian (Verfügbare Profile: defaultuser0 & Paustian)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG
CMD: dir "%ProgramFiles%"
CMD: dir "%ProgramFiles(x86)%"
CMD: dir "%ProgramData%"
CMD: dir "%Appdata%"
CMD: dir "%LocalAppdata%"
CMD: dir "%CommonProgramFiles(x86)%"
CMD: dir "%CommonProgramW6432%"
CMD: dir "%UserProfile%"
CMD: dir "C:\"
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
Hosts:
RemoveProxy:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
EmptyTemp:
*****************
Prozesse erfolgreich geschlossen.
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => Schlüssel erfolgreich entfernt
========= dir "%ProgramFiles%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\Program Files
08.07.2017 01:55 <DIR> .
08.07.2017 01:55 <DIR> ..
17.05.2017 17:32 <DIR> Adobe
29.05.2017 18:58 <DIR> Common Files
08.07.2017 01:55 <DIR> CPUID
17.05.2017 23:50 <DIR> Epic Games
29.05.2017 18:58 <DIR> IIS
06.05.2017 22:25 <DIR> Image-Line
27.03.2017 13:32 <DIR> Inkscape
29.05.2017 19:43 <DIR> Internet Explorer
26.03.2017 22:58 <DIR> Logitech Gaming Software
08.05.2017 02:26 <DIR> Malwarebytes
27.07.2017 07:59 <DIR> Microsoft Office 15
27.03.2017 13:34 <DIR> Microsoft SQL Server
27.03.2017 13:34 <DIR> Microsoft SQL Server Compact Edition
27.03.2017 13:29 <DIR> Microsoft Visual Studio 12.0
29.05.2017 19:35 <DIR> MSBuild
01.06.2017 13:27 <DIR> NVIDIA Corporation
27.03.2017 12:57 <DIR> PDF Architect 5
27.03.2017 13:01 <DIR> PDFCreator
29.05.2017 19:35 <DIR> Reference Assemblies
08.04.2017 16:53 <DIR> Tablet
27.03.2017 14:14 <DIR> TabletPlugins
27.03.2017 13:12 <DIR> Unity
11.05.2017 20:34 <DIR> UNP
11.07.2017 23:24 <DIR> Windows Defender
20.03.2017 06:35 <DIR> Windows Mail
20.03.2017 06:36 <DIR> Windows Media Player
18.03.2017 23:03 <DIR> Windows Multimedia Platform
29.05.2017 19:19 <DIR> Windows NT
09.08.2017 23:30 <DIR> Windows Photo Viewer
18.03.2017 23:03 <DIR> Windows Portable Devices
18.03.2017 23:03 <DIR> Windows Security
18.03.2017 23:03 <DIR> WindowsPowerShell
27.03.2017 00:25 <DIR> WinRAR
0 Datei(en), 0 Bytes
35 Verzeichnis(se), 163.046.092.800 Bytes frei
========= Ende von CMD: =========
========= dir "%ProgramFiles(x86)%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\Program Files (x86)
17.07.2017 21:47 <DIR> .
17.07.2017 21:47 <DIR> ..
12.06.2017 22:02 <DIR> Activision
01.04.2017 16:38 <DIR> Adobe
27.03.2017 13:39 <DIR> AppInsights
06.05.2017 22:26 <DIR> ASIO4ALL v2
12.06.2017 21:31 <DIR> Aspyr
12.08.2017 19:29 <DIR> Blizzard App
29.05.2017 18:59 <DIR> Common Files
10.08.2017 23:27 <DIR> Dropbox
17.05.2017 23:42 <DIR> Epic Games
27.03.2017 13:10 <DIR> epson
27.03.2017 13:12 <DIR> GtkSharp
08.08.2017 21:08 <DIR> Hearthstone
17.07.2017 22:33 <DIR> Heroes of the Storm
27.03.2017 13:37 <DIR> IIS
06.05.2017 22:26 <DIR> Image-Line
29.05.2017 19:43 <DIR> Internet Explorer
31.03.2017 19:54 <DIR> Java
27.03.2017 13:28 <DIR> Microsoft Help Viewer
16.06.2017 17:05 <DIR> Microsoft Office
27.03.2017 13:31 <DIR> Microsoft Office365 Tools
27.03.2017 13:37 <DIR> Microsoft SDKs
27.03.2017 13:35 <DIR> Microsoft Silverlight
27.03.2017 13:34 <DIR> Microsoft SQL Server
27.03.2017 13:34 <DIR> Microsoft SQL Server Compact Edition
29.05.2017 17:10 <DIR> Microsoft Visual Studio 11.0
29.05.2017 17:10 <DIR> Microsoft Visual Studio 12.0
29.05.2017 17:10 <DIR> Microsoft Visual Studio 14.0
27.03.2017 13:46 <DIR> Microsoft Visual Studio Tools for Unity
27.03.2017 13:30 <DIR> Microsoft WCF Data Services
29.05.2017 18:59 <DIR> Microsoft.NET
08.07.2017 01:54 <DIR> Mozilla Firefox
08.07.2017 12:04 <DIR> Mozilla Maintenance Service
29.05.2017 18:59 <DIR> MSBuild
18.06.2017 21:02 <DIR> NCSOFT
18.06.2017 21:01 <DIR> NCWest
27.03.2017 13:30 <DIR> NuGet
29.05.2017 18:59 <DIR> NVIDIA Corporation
17.05.2017 18:21 <DIR> obs-studio
27.03.2017 12:41 <DIR> OpenOffice 4
27.03.2017 12:38 <DIR> OpenOffice 4.1.3
10.08.2017 20:30 <DIR> Overwatch
12.08.2017 02:49 <DIR> Overwatch Test
27.03.2017 12:57 <DIR> PDF Architect 5
29.05.2017 19:35 <DIR> Reference Assemblies
27.03.2017 13:33 <DIR> ShellDir
27.03.2017 00:28 <DIR> SplitmediaLabs
05.04.2017 18:47 <DIR> SquareEnix
01.08.2017 10:28 <DIR> Steam
27.03.2017 14:14 <DIR> TabletPlugins
18.05.2017 03:24 <DIR> Ubisoft
27.03.2017 00:24 <DIR> VideoLAN
06.05.2017 22:26 <DIR> VstPlugins
08.07.2017 00:04 <DIR> VulkanRT
11.07.2017 23:24 <DIR> Windows Defender
27.03.2017 13:28 <DIR> Windows Kits
20.03.2017 06:35 <DIR> Windows Mail
20.03.2017 06:36 <DIR> Windows Media Player
18.03.2017 23:03 <DIR> Windows Multimedia Platform
18.03.2017 23:03 <DIR> Windows NT
09.08.2017 23:30 <DIR> Windows Photo Viewer
18.03.2017 23:03 <DIR> Windows Portable Devices
18.03.2017 23:03 <DIR> WindowsPowerShell
27.03.2017 12:42 <DIR> WinRoll
12.08.2017 02:45 <DIR> World of Warcraft
0 Datei(en), 0 Bytes
66 Verzeichnis(se), 163.046.092.800 Bytes frei
========= Ende von CMD: =========
========= dir "%ProgramData%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\ProgramData
09.05.2017 20:54 <DIR> .mono
17.05.2017 16:12 <DIR> Adobe
27.03.2017 00:26 <DIR> Battle.net
01.05.2017 15:40 <DIR> Blizzard Entertainment
17.05.2017 15:57 <DIR> boost_interprocess
16.07.2016 13:47 <DIR> Comms
27.03.2017 12:31 <DIR> Dropbox
17.05.2017 23:49 <DIR> Epic
27.04.2017 11:18 <DIR> EPSON
26.03.2017 22:59 <DIR> LogiShrd
08.05.2017 02:26 <DIR> Malwarebytes
10.06.2017 21:11 <DIR> ManiaPlanet
29.05.2017 21:14 <DIR> Microsoft Help
29.05.2017 19:50 <DIR> Microsoft OneDrive
27.03.2017 13:30 <DIR> NuGet
13.08.2017 01:28 <DIR> NVIDIA
08.07.2017 00:04 <DIR> NVIDIA Corporation
31.03.2017 19:54 <DIR> Oracle
27.03.2017 00:14 <DIR> Origin
18.05.2017 01:07 <DIR> Package Cache
27.03.2017 14:36 <DIR> PDF Architect 5
27.03.2017 12:58 <DIR> pdfforge
15.05.2017 15:43 <DIR> PixelPlanet
27.03.2017 13:33 <DIR> PreEmptive Solutions
29.05.2017 19:06 <DIR> regid.1986-12.com.adobe
27.07.2017 08:00 <DIR> regid.1991-06.com.microsoft
18.03.2017 23:03 <DIR> SoftwareDistribution
27.03.2017 00:28 <DIR> SplitMediaLabs
29.05.2017 18:59 <DIR> USOPrivate
29.05.2017 18:59 <DIR> USOShared
20.03.2017 06:37 <DIR> WindowsHolographicDevices
0 Datei(en), 0 Bytes
31 Verzeichnis(se), 163.046.088.704 Bytes frei
========= Ende von CMD: =========
========= dir "%Appdata%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\Users\Paustian\AppData\Roaming
09.07.2017 16:43 <DIR> .
09.07.2017 16:43 <DIR> ..
24.06.2017 18:48 <DIR> .minecraft
09.05.2017 20:54 <DIR> .mono
17.05.2017 18:08 <DIR> Adobe
08.06.2017 19:14 33 AdobeWLCMCache.dat
27.03.2017 00:29 <DIR> Battle.net
27.03.2017 12:31 <DIR> Dropbox
06.05.2017 22:25 <DIR> Image-Line
17.05.2017 15:38 <DIR> inkscape
26.03.2017 22:54 <DIR> Logishrd
26.03.2017 22:54 <DIR> Logitech
31.03.2017 19:53 <DIR> Macromedia
26.03.2017 22:26 <DIR> Mozilla
01.04.2017 16:52 <DIR> NVIDIA
17.05.2017 23:56 <DIR> obs-studio
27.03.2017 14:38 <DIR> OpenOffice
27.03.2017 14:36 <DIR> PDF Architect 5
15.05.2017 16:01 <DIR> PixelPlanet
26.03.2017 22:11 <DIR> Skype
27.03.2017 00:26 <DIR> SplitmediaLabs
13.08.2017 01:17 <DIR> Spotify
31.03.2017 19:51 <DIR> Sun
13.08.2017 01:22 <DIR> TS3Client
12.08.2017 04:08 <DIR> Twitch
24.06.2017 17:58 <DIR> Twitch Setup
18.05.2017 03:40 <DIR> Ubisoft
07.08.2017 19:59 <DIR> vlc
27.03.2017 14:38 <DIR> WinRAR
08.04.2017 16:41 <DIR> WTablet
1 Datei(en), 33 Bytes
29 Verzeichnis(se), 163.046.084.608 Bytes frei
========= Ende von CMD: =========
========= dir "%LocalAppdata%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\Users\Paustian\AppData\Local
12.08.2017 01:08 <DIR> .
12.08.2017 01:08 <DIR> ..
12.08.2017 02:00 <DIR> Adobe
13.08.2017 00:40 <DIR> Battle.net
17.07.2017 21:52 <DIR> Blizzard
07.07.2017 19:44 <DIR> Blizzard Entertainment
27.03.2017 00:28 <DIR> CEF
29.05.2017 19:54 <DIR> Comms
08.07.2017 01:34 <DIR> ConnectedDevicesPlatform
29.05.2017 17:16 <DIR> CrashDumps
29.05.2017 19:51 <DIR> DBG
15.05.2017 15:43 <DIR> Downloaded Installations
14.06.2017 22:07 <DIR> Dropbox
17.05.2017 23:44 <DIR> EpicGamesLauncher
17.05.2017 15:39 <DIR> fontconfig
09.07.2017 16:20 140.800 installer.dat
07.08.2017 19:18 <DIR> JDownloader 2.0
26.03.2017 22:59 <DIR> Logitech
14.04.2017 23:43 <DIR> Macromedia
16.06.2017 17:21 <DIR> Microsoft
29.05.2017 17:26 <DIR> Microsoft Help
26.03.2017 22:25 <DIR> MicrosoftEdge
26.03.2017 22:31 <DIR> Mozilla
27.03.2017 13:55 <DIR> NVIDIA
28.03.2017 12:56 <DIR> NVIDIA Corporation
27.03.2017 00:14 <DIR> Origin
09.08.2017 12:56 <DIR> Packages
27.03.2017 12:58 <DIR> PDFCreator
27.03.2017 12:56 <DIR> Programs
26.03.2017 22:09 <DIR> Publishers
01.08.2017 16:24 2.365 recently-used.xbel
08.07.2017 03:17 7.655 Resmon.ResmonCfg
12.08.2017 16:31 <DIR> Spotify
27.03.2017 00:39 <DIR> Steam
26.03.2017 22:35 <DIR> TeamSpeak 3
21.07.2017 01:33 <DIR> TeamSpeak 3 Client
13.08.2017 01:26 <DIR> Temp
03.04.2017 22:40 <DIR> Tempzxpsign02834643cbb00a01
01.08.2017 10:18 <DIR> Tempzxpsign037c669b50ec6d43
28.07.2017 09:54 <DIR> Tempzxpsign05fb69ed10880fe1
02.06.2017 12:37 <DIR> Tempzxpsign0680004327190e13
17.05.2017 18:40 <DIR> Tempzxpsign075bc6f56fdde4dc
17.05.2017 16:56 <DIR> Tempzxpsign0c4bbdf8ebde3b68
15.06.2017 21:51 <DIR> Tempzxpsign1085b5aead91fca4
03.04.2017 22:40 <DIR> Tempzxpsign137a5b1f94249715
10.04.2017 17:35 <DIR> Tempzxpsign1509f3af3b2c6b2c
17.05.2017 18:52 <DIR> Tempzxpsign171ef18669ddbfbf
02.06.2017 12:35 <DIR> Tempzxpsign199c28b8d81ef543
08.05.2017 10:15 <DIR> Tempzxpsign1a32af66fe73f4b4
17.05.2017 18:47 <DIR> Tempzxpsign1c653b61ae9790ae
10.08.2017 15:23 <DIR> Tempzxpsign1dba350bab4ad878
01.08.2017 12:07 <DIR> Tempzxpsign220de6f8fb9e4108
01.08.2017 09:54 <DIR> Tempzxpsign22a2580f00affdc2
08.04.2017 16:43 <DIR> Tempzxpsign25094613886aaceb
31.07.2017 17:16 <DIR> Tempzxpsign27f1030247c2e24b
10.08.2017 15:23 <DIR> Tempzxpsign2ab947999353cd00
08.05.2017 13:37 <DIR> Tempzxpsign2bb119e4641003d5
15.04.2017 23:52 <DIR> Tempzxpsign2c3b930876efb3ad
10.04.2017 17:37 <DIR> Tempzxpsign301a14c707332b26
01.08.2017 09:54 <DIR> Tempzxpsign359c84d784f777b0
31.07.2017 17:17 <DIR> Tempzxpsign385019027971ffd9
03.04.2017 22:41 <DIR> Tempzxpsign38a78e6c1dba80c1
17.05.2017 16:43 <DIR> Tempzxpsign3a817e6981453d5c
09.08.2017 19:42 <DIR> Tempzxpsign3c97aaa7eea8428a
01.04.2017 16:53 <DIR> Tempzxpsign4296e3061c3c3b4b
01.08.2017 10:33 <DIR> Tempzxpsign44e7000a3d27fd6f
17.05.2017 19:57 <DIR> Tempzxpsign4693c5403c0606e9
04.04.2017 15:58 <DIR> Tempzxpsign4ab63c4ba6eb199e
08.06.2017 20:19 <DIR> Tempzxpsign4bb5b27461320738
15.06.2017 21:52 <DIR> Tempzxpsign4c5eabf625a26d11
16.04.2017 04:57 <DIR> Tempzxpsign5286b9a95bfae294
01.08.2017 12:01 <DIR> Tempzxpsign52a1910445f145b6
17.05.2017 18:47 <DIR> Tempzxpsign54b3e1678a750e03
01.04.2017 16:52 <DIR> Tempzxpsign54d4e85918f506d1
15.04.2017 23:24 <DIR> Tempzxpsign598f4e69a58b1443
31.07.2017 17:16 <DIR> Tempzxpsign5bdb9571a7c0fde6
17.05.2017 18:51 <DIR> Tempzxpsign5c38e917ae74d2e7
08.04.2017 17:14 <DIR> Tempzxpsign5fdabc3506008f44
17.05.2017 19:57 <DIR> Tempzxpsign6173a455edcb064b
08.05.2017 02:47 <DIR> Tempzxpsign63d892bd02233a7a
17.05.2017 18:07 <DIR> Tempzxpsign660c9d3360a33952
17.05.2017 18:52 <DIR> Tempzxpsign68701831c894c67a
15.04.2017 23:23 <DIR> Tempzxpsign6a37b5071a2d1108
04.04.2017 15:58 <DIR> Tempzxpsign6a414753c41a1e78
08.06.2017 20:15 <DIR> Tempzxpsign6cce6fa36f392503
28.07.2017 09:56 <DIR> Tempzxpsign6d68e398ae0ed38b
08.04.2017 16:43 <DIR> Tempzxpsign6f1e05f68069e08f
10.08.2017 19:14 <DIR> Tempzxpsign71beb850eb3601be
01.08.2017 12:01 <DIR> Tempzxpsign7449ac600c0c832c
18.05.2017 00:59 <DIR> Tempzxpsign7574134cc74743a8
09.08.2017 19:42 <DIR> Tempzxpsign764dda9344e155e0
11.08.2017 16:49 <DIR> Tempzxpsign7908eaead9a21f93
01.06.2017 23:42 <DIR> Tempzxpsign7a190d4808780bc2
17.05.2017 19:57 <DIR> Tempzxpsign7e2241cfd2be44d8
08.04.2017 17:03 <DIR> Tempzxpsign91e46fd3b165d422
09.08.2017 19:42 <DIR> Tempzxpsign9615c3457d1b63bb
08.05.2017 02:47 <DIR> Tempzxpsign9a65262ddb69c967
08.05.2017 02:50 <DIR> Tempzxpsign9beb800145761fe8
08.04.2017 16:44 <DIR> Tempzxpsign9cb690c2b7da441c
08.06.2017 20:15 <DIR> Tempzxpsign9e51d45ef2738e11
08.05.2017 10:46 <DIR> Tempzxpsign9f243864383abcf0
17.05.2017 18:40 <DIR> Tempzxpsigna7ac845d264d1144
28.07.2017 09:58 <DIR> Tempzxpsigna89232716f7b0a27
01.08.2017 10:33 <DIR> Tempzxpsignad445edd83177901
02.06.2017 12:35 <DIR> Tempzxpsignadacb00f5e322efa
17.05.2017 16:43 <DIR> Tempzxpsignae366aa96ad85fa1
08.05.2017 10:15 <DIR> Tempzxpsignb0e259e70a32af41
17.05.2017 18:47 <DIR> Tempzxpsignb28121c7c366c04d
15.04.2017 23:23 <DIR> Tempzxpsignb49233db73f9894e
11.08.2017 16:49 <DIR> Tempzxpsignb5f3b4c1933708cd
08.04.2017 17:04 <DIR> Tempzxpsignba374f3f3cb1fa7d
02.06.2017 12:36 <DIR> Tempzxpsignbd52de24ea9c5cc1
31.07.2017 17:16 <DIR> Tempzxpsignbd88cb794746890e
03.04.2017 22:41 <DIR> Tempzxpsignc23e982100986977
15.06.2017 21:51 <DIR> Tempzxpsignc886893e5cb98a40
01.04.2017 16:52 <DIR> Tempzxpsigncfc94c7e5e99ff0e
17.05.2017 16:43 <DIR> Tempzxpsignd2497c2b06adb8dd
18.05.2017 00:53 <DIR> Tempzxpsignd4486612bc899887
17.05.2017 18:51 <DIR> Tempzxpsignd8b0cc088119c508
28.07.2017 09:54 <DIR> Tempzxpsignd9d182d6bac33600
17.05.2017 18:08 <DIR> Tempzxpsigndce2999b74f64bc9
10.04.2017 17:35 <DIR> Tempzxpsignde86fe5a9fbd84c0
10.08.2017 19:14 <DIR> Tempzxpsigndeb5b40ea1eb2b4f
10.04.2017 17:35 <DIR> Tempzxpsigne2720d22b7f132d9
01.08.2017 09:55 <DIR> Tempzxpsigne3419bf049d1d756
08.05.2017 10:15 <DIR> Tempzxpsignea88860afc561e1e
01.08.2017 10:37 <DIR> Tempzxpsigneaccd478d245dbad
08.05.2017 10:15 <DIR> Tempzxpsigneb5d861c4ebba951
16.04.2017 04:57 <DIR> Tempzxpsignec14d9b09d9b7fc8
04.04.2017 15:58 <DIR> Tempzxpsignec253b0a9d74510e
08.04.2017 17:03 <DIR> Tempzxpsignede1e4777da2cf50
10.08.2017 15:23 <DIR> Tempzxpsignf2ebd09ab856f7b9
01.06.2017 23:33 <DIR> Tempzxpsignf6f46e70a20923a5
17.05.2017 18:40 <DIR> Tempzxpsignf6fd7e9ec85f2ba0
01.06.2017 23:33 <DIR> Tempzxpsignf8538f4185443d4c
15.04.2017 23:23 <DIR> Tempzxpsignf9c417ecbe84fb87
16.04.2017 04:57 <DIR> Tempzxpsignf9dab9c0f65e51cb
04.04.2017 16:39 <DIR> Tempzxpsignfe7e76d8a355c2f3
01.06.2017 23:33 <DIR> Tempzxpsignfe94ad59403b54cd
17.05.2017 18:52 <DIR> Tempzxpsignffb8dcfba9e4bad5
09.07.2017 16:20 930.816 test_db_cara.db
26.03.2017 22:08 <DIR> TileDataLayer
18.05.2017 07:25 <DIR> Ubisoft Game Launcher
11.05.2017 22:45 <DIR> UNP
18.05.2017 01:09 <DIR> UnrealEngine
17.05.2017 23:44 <DIR> UnrealEngineLauncher
08.05.2017 16:31 <DIR> VirtualStore
08.04.2017 16:42 <DIR> Wacom
4 Datei(en), 1.081.636 Bytes
144 Verzeichnis(se), 163.046.072.320 Bytes frei
========= Ende von CMD: =========
========= dir "%CommonProgramFiles(x86)%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\Program Files (x86)\Common Files
29.05.2017 18:59 <DIR> .
29.05.2017 18:59 <DIR> ..
17.05.2017 16:15 <DIR> Adobe
16.06.2017 17:07 <DIR> Designer
17.05.2017 17:27 <DIR> Intel
31.03.2017 19:54 <DIR> Java
27.03.2017 13:27 <DIR> Merge Modules
16.06.2017 17:07 <DIR> Microsoft Shared
27.03.2017 12:57 <DIR> PDF Software
06.05.2017 22:26 <DIR> Propellerhead Software
18.03.2017 23:03 <DIR> Services
01.08.2017 10:28 <DIR> Steam
29.05.2017 21:14 <DIR> System
15.05.2017 16:01 <DIR> XpressUpdate
0 Datei(en), 0 Bytes
14 Verzeichnis(se), 163.046.109.184 Bytes frei
========= Ende von CMD: =========
========= dir "%CommonProgramW6432%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\Program Files\Common Files
29.05.2017 18:58 <DIR> .
29.05.2017 18:58 <DIR> ..
17.05.2017 17:26 <DIR> Adobe
27.03.2017 13:08 <DIR> EPSON
29.05.2017 18:58 <DIR> microsoft shared
06.05.2017 22:26 <DIR> Propellerhead Software
18.03.2017 23:03 <DIR> Services
20.03.2017 06:35 <DIR> System
06.05.2017 22:26 <DIR> VST2
0 Datei(en), 0 Bytes
9 Verzeichnis(se), 163.046.109.184 Bytes frei
========= Ende von CMD: =========
========= dir "%UserProfile%" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\Users\Paustian
12.08.2017 19:30 <DIR> .
12.08.2017 19:30 <DIR> ..
08.04.2017 16:42 <DIR> .android
24.06.2017 18:19 <DIR> .mputils
10.08.2017 13:10 <DIR> Contacts
17.05.2017 15:57 <DIR> Creative Cloud Files
12.08.2017 17:07 <DIR> Desktop
10.08.2017 13:11 <DIR> Documents
13.08.2017 01:28 <DIR> Downloads
19.06.2017 02:12 <DIR> Dropbox
10.08.2017 13:10 <DIR> Favorites
10.08.2017 13:11 <DIR> Links
10.08.2017 13:10 <DIR> Music
16.06.2017 23:29 <DIR> ODBA
27.07.2017 09:24 <DIR> OneDrive
28.07.2017 08:22 <DIR> OneDrive - smail.fh-koeln.de
10.08.2017 13:10 <DIR> Pictures
28.04.2017 16:14 <DIR> private Dokumente
10.08.2017 13:11 <DIR> Saved Games
10.08.2017 13:10 <DIR> Searches
12.08.2017 15:03 <DIR> Videos
0 Datei(en), 0 Bytes
21 Verzeichnis(se), 163.046.105.088 Bytes frei
========= Ende von CMD: =========
========= dir "C:\" =========
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 5042-FE71
Verzeichnis von C:\
12.08.2017 16:53 <DIR> AdwCleaner
13.08.2017 01:28 <DIR> FRST
27.03.2017 13:33 <DIR> NVIDIA
18.03.2017 23:03 <DIR> PerfLogs
08.07.2017 01:55 <DIR> Program Files
17.07.2017 21:47 <DIR> Program Files (x86)
29.05.2017 18:53 <DIR> Users
12.08.2017 16:34 <DIR> Windows
0 Datei(en), 0 Bytes
8 Verzeichnis(se), 163.046.109.184 Bytes frei
========= Ende von CMD: =========
================== ExportKey: ===================
[HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions]
[HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Extensions]
[HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths]
[HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes]
[HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\TemporaryPaths]
=== Ende von ExportKey ===
C:\Windows\System32\Drivers\etc\hosts => erfolgreich verschoben
Hosts erfolgreich wiederhergestellt.
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1081556182-481547222-1970898152-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1081556182-481547222-1970898152-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
========= Ende von RemoveProxy: =========
========= ipconfig /flushdns =========
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
========= Ende von CMD: =========
========= netsh winsock reset =========
Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.
========= Ende von CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 9461760 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 265175788 B
Java, Flash, Steam htmlcache => 346446536 B
Windows/system/drivers => 27728831 B
Edge => 3121449 B
Chrome => 0 B
Firefox => 400293666 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 128 B
LocalService => 27010 B
NetworkService => 245222 B
defaultuser0 => 7168 B
Paustian => 738857216 B
RecycleBin => 26591768373 B
EmptyTemp: => 26.4 GB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 01:29:18 ==== Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 13.08.17
Scan-Zeit: 01:34
Protokolldatei: mbam.txt
Administrator: Ja
-Softwaredaten-
Version: 3.1.2.1733
Komponentenversion: 1.0.160
Version des Aktualisierungspakets: 1.0.2572
Lizenz: Kostenlos
-Systemdaten-
Betriebssystem: Windows 10 (Build 15063.540)
CPU: x64
Dateisystem: NTFS
Benutzer: DESKTOP-LJE2TQQ\Paustian
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 411278
Erkannte Bedrohungen: 9
In die Quarantäne verschobene Bedrohungen: 9
Abgelaufene Zeit: 7 Min., 46 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 5
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1081556182-481547222-1970898152-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE, In Quarantäne, [5311], [425124],1.0.2572
PUP.Optional.PSScriptLoad.ACMB3, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7D040D47-790B-040B-7811-7A057F0B110C}, In Quarantäne, [5311], [-1],0.0.0
PUP.Optional.PSScriptLoad.ACMB3, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99B2373C-F778-41A2-94E7-69C253BF7D25}, In Quarantäne, [5311], [-1],0.0.0
PUP.Optional.PSScriptLoad.ACMB3, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99B2373C-F778-41A2-94E7-69C253BF7D25}, In Quarantäne, [5311], [-1],0.0.0
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1081556182-481547222-1970898152-1001\CONSOLE\TASKENG.EXE, In Quarantäne, [5311], [425125],1.0.2572
Registrierungswert: 3
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1081556182-481547222-1970898152-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE|WINDOWPOSITION, In Quarantäne, [5311], [425124],1.0.2572
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1081556182-481547222-1970898152-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_WINDOWSPOWERSHELL_V1.0_POWERSHELL.EXE|WINDOWPOSITION, In Quarantäne, [5311], [425126],1.0.2572
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1081556182-481547222-1970898152-1001\CONSOLE\TASKENG.EXE|WINDOWPOSITION, In Quarantäne, [5311], [425125],1.0.2572
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 1
Generic.Malware/Suspicious, C:\USERS\PAUSTIAN\DOWNLOADS\WINDOWS+LOADER+V2.2.2.ZIP, In Quarantäne, [0], [392686],1.0.2572
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end) Anmerkung: Die FRST-Datei ist mit mind. 150.000 Zeichen deutlich zu lang, mit 140kb aber auch zu groß, um hochgeladen zu werden! Ich unterteile diesen Log also in zwei Posts. Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-08-2017
durchgeführt von Paustian (Administrator) auf DESKTOP-LJE2TQQ (13-08-2017 01:49:49)
Gestartet von C:\Users\Paustian\Downloads
Geladene Profile: Paustian (Verfügbare Profile: defaultuser0 & Paustian)
Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17406072 2017-01-24] (Logitech Inc.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3487032 2017-08-10] (Dropbox, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2404952 2017-03-27] (Adobe Systems Incorporated)
HKU\S-1-5-21-1081556182-481547222-1970898152-1001\...\Run: [WinRoll] => C:\Program Files (x86)\WinRoll\winroll.exe [15360 2004-04-06] ()
HKU\S-1-5-21-1081556182-481547222-1970898152-1001\...\Run: [Spotify] => C:\Users\Paustian\AppData\Roaming\Spotify\Spotify.exe [15866480 2017-08-04] (Spotify Ltd)
HKU\S-1-5-21-1081556182-481547222-1970898152-1001\...\Run: [Spotify Web Helper] => C:\Users\Paustian\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1580144 2017-08-04] (Spotify Ltd)
HKU\S-1-5-21-1081556182-481547222-1970898152-1001\...\MountPoints2: {b8d5793c-12f5-11e7-b47a-806e6f6e6963} - "F:\setup.exe"
SSODL: EldosMountNotificator-cbfs6 - {40D1E7FC-F449-4D95-9FC1-BF6F60B2A518} - C:\Windows\system32\cbfsMntNtf6.dll (/n software, Inc.)
SSODL-x32: EldosMountNotificator-cbfs6 - {40D1E7FC-F449-4D95-9FC1-BF6F60B2A518} - C:\Windows\SysWOW64\cbfsMntNtf6.dll (/n software, Inc.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{1ae22881-d583-4f3b-a6dc-9f61d817f80b}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{99e0b5a8-7d25-4dc2-af2e-f83e827f64de}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-06-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-06-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-31] (Oracle Corporation)
BHO-x32: PDF Architect 5 Helper -> {AEA429F3-D2D4-4BD7-A03E-5357DA017733} -> C:\Program Files (x86)\PDF Architect 5\creator-ie-helper.dll [2017-02-10] (pdfforge GmbH)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2017-06-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-31] (Oracle Corporation)
Toolbar: HKLM-x32 - PDF Architect 5 Toolbar - {84F23192-A475-4038-B5C0-8584777F2DF4} - C:\Program Files (x86)\PDF Architect 5\creator-ie-plugin.dll [2017-02-10] (pdfforge GmbH)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-06-16] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 3ngho49z.default
FF ProfilePath: C:\Users\Paustian\AppData\Roaming\Mozilla\Firefox\Profiles\3ngho49z.default [2017-08-13]
FF Session Restore: Mozilla\Firefox\Profiles\3ngho49z.default -> ist aktiviert.
FF Extension: (Stylish) - C:\Users\Paustian\AppData\Roaming\Mozilla\Firefox\Profiles\3ngho49z.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2017-05-04]
FF Extension: (Adblock Plus) - C:\Users\Paustian\AppData\Roaming\Mozilla\Firefox\Profiles\3ngho49z.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-08]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_137.dll [2017-07-11] ()
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-03-27] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll [2017-07-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-31] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-31] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2017-06-16] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-03-27] (Adobe Systems)
FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [2017-02-10] (pdfforge GmbH)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [771672 2017-03-14] (Adobe Systems Incorporated)
S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-02-27] (Adobe Systems, Incorporated)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-03-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-03-27] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [49992 2017-08-10] (Dropbox, Inc.)
S4 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [225400 2017-01-24] (Logitech Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [492480 2017-04-26] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [492480 2017-04-26] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-04-26] (NVIDIA Corporation)
S4 PDF Architect 5; C:\Program Files\PDF Architect 5\ws.exe [2706824 2017-02-10] (pdfforge GmbH)
S4 PDF Architect 5 CrashHandler; C:\Program Files\PDF Architect 5\crash-handler-ws.exe [1048976 2017-02-10] (pdfforge GmbH)
S4 PDF Architect 5 Creator; C:\Program Files\PDF Architect 5\creator-ws.exe [856976 2017-02-10] (pdfforge GmbH)
S4 PDF Architect 5 Manager; C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe [985904 2017-02-28] (© pdfforge GmbH.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [672208 2017-04-05] (Wacom Technology, Corp.)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 cbfs6; C:\Windows\system32\drivers\cbfs6.sys [460992 2016-09-21] (/n software, Inc.)
R3 ladfGSS; C:\Windows\system32\drivers\ladfGSS.sys [54552 2017-01-23] (Logitech Inc.)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\Windows\system32\drivers\LGJoyXlCore.sys [67736 2017-01-24] (Logitech Inc.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [253856 2017-08-13] (Malwarebytes)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_f9309145156afb40\nvlddmkm.sys [14456912 2017-05-19] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-04-26] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47552 2017-03-28] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57792 2017-04-26] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R3 SensorsSimulatorDriver; C:\Windows\System32\drivers\WUDFRd.sys [220672 2017-03-18] (Microsoft Corporation)
R3 vpnpbus; C:\Windows\System32\drivers\vpnpbus.sys [18624 2016-09-21] (/n software, Inc.)
R3 WacHidRouterPro; C:\Windows\System32\drivers\wachidrouter.sys [120976 2017-03-27] (Wacom Technology)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 XSplit_Dummy; C:\Windows\system32\drivers\xspltspk.sys [26200 2016-06-15] (SplitmediaLabs Limited)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Drei Monate: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-08-13 01:49 - 2017-08-13 01:49 - 000002807 _____ C:\Users\Paustian\Desktop\mbam.txt
2017-08-13 01:28 - 2017-08-13 01:29 - 000025595 _____ C:\Users\Paustian\Downloads\Fixlog.txt
2017-08-13 01:28 - 2017-08-13 01:28 - 000253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\220342B5.sys
2017-08-12 17:07 - 2017-08-12 17:07 - 000030891 _____ C:\Users\Paustian\Desktop\logfiles.zip
2017-08-12 17:07 - 2017-08-12 16:34 - 000069643 _____ C:\Users\Paustian\Desktop\FRST-log.txt
2017-08-12 17:06 - 2017-08-12 16:53 - 000001284 _____ C:\Users\Paustian\Desktop\AdwCleaner[S4]-log.txt
2017-08-12 17:05 - 2017-08-12 16:34 - 000067051 _____ C:\Users\Paustian\Desktop\FRST_Addition-log.txt
2017-08-12 17:01 - 2017-08-12 17:01 - 000002970 _____ C:\Users\Paustian\Desktop\mbam-log.txt
2017-08-12 16:51 - 2017-08-12 16:51 - 008185288 _____ (Malwarebytes) C:\Users\Paustian\Downloads\adwcleaner_7.0.1.0.exe
2017-08-12 16:34 - 2017-08-12 16:34 - 000067051 _____ C:\Users\Paustian\Downloads\Addition.txt
2017-08-12 16:29 - 2017-08-13 01:50 - 000015878 _____ C:\Users\Paustian\Downloads\FRST.txt
2017-08-12 16:29 - 2017-08-13 01:49 - 000000000 ____D C:\FRST
2017-08-12 16:29 - 2017-08-12 16:29 - 002395648 _____ (Farbar) C:\Users\Paustian\Downloads\FRST64.exe
2017-08-11 16:49 - 2017-08-11 16:49 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsignb5f3b4c1933708cd
2017-08-11 16:49 - 2017-08-11 16:49 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign7908eaead9a21f93
2017-08-10 23:25 - 2017-08-10 23:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-08-10 19:14 - 2017-08-10 19:14 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsigndeb5b40ea1eb2b4f
2017-08-10 19:14 - 2017-08-10 19:14 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign71beb850eb3601be
2017-08-10 19:03 - 2017-08-10 19:03 - 000049992 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-08-10 19:03 - 2017-08-10 19:03 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-08-10 19:03 - 2017-08-10 19:03 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-08-10 19:03 - 2017-08-10 19:03 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-08-10 15:23 - 2017-08-10 15:23 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsignf2ebd09ab856f7b9
2017-08-10 15:23 - 2017-08-10 15:23 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign2ab947999353cd00
2017-08-10 15:23 - 2017-08-10 15:23 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign1dba350bab4ad878
2017-08-09 19:42 - 2017-08-09 19:42 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign9615c3457d1b63bb
2017-08-09 19:42 - 2017-08-09 19:42 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign764dda9344e155e0
2017-08-09 19:42 - 2017-08-09 19:42 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign3c97aaa7eea8428a
2017-08-09 16:12 - 2017-08-01 04:38 - 000406544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2017-08-09 16:12 - 2017-08-01 04:36 - 002165752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-08-09 16:12 - 2017-08-01 04:36 - 000750496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-08-09 16:12 - 2017-08-01 04:36 - 000119712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-08-09 16:12 - 2017-08-01 04:35 - 000280472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2017-08-09 16:12 - 2017-08-01 04:35 - 000133904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2017-08-09 16:12 - 2017-08-01 04:34 - 000610584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-08-09 16:12 - 2017-08-01 04:34 - 000359552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2017-08-09 16:12 - 2017-08-01 04:34 - 000349600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-08-09 16:12 - 2017-08-01 04:34 - 000168864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2017-08-09 16:12 - 2017-08-01 04:31 - 000176024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2017-08-09 16:12 - 2017-08-01 04:20 - 002956288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-08-09 16:12 - 2017-08-01 04:20 - 000404480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2017-08-09 16:12 - 2017-08-01 04:20 - 000154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
2017-08-09 16:12 - 2017-08-01 04:18 - 013841408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-08-09 16:12 - 2017-08-01 04:18 - 002199552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-08-09 16:12 - 2017-08-01 04:17 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tokenbinding.dll
2017-08-09 16:12 - 2017-08-01 04:14 - 000035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2017-08-09 16:12 - 2017-08-01 04:13 - 000364032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2017-08-09 16:12 - 2017-08-01 04:13 - 000127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdeploy.dll
2017-08-09 16:12 - 2017-08-01 04:12 - 000229888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2017-08-09 16:12 - 2017-08-01 04:09 - 000394240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-08-09 16:12 - 2017-08-01 04:08 - 000267264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptprov.dll
2017-08-09 16:12 - 2017-08-01 04:07 - 005961728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-08-09 16:12 - 2017-08-01 04:07 - 002671616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-08-09 16:12 - 2017-08-01 04:06 - 000798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2017-08-09 16:12 - 2017-08-01 04:03 - 001627136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-08-09 16:12 - 2017-08-01 03:30 - 003377664 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-08-09 16:12 - 2017-08-01 03:28 - 002516480 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000144896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-08-09 16:12 - 2017-08-01 00:45 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll
2017-08-09 16:12 - 2017-07-28 07:23 - 000723360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2017-08-09 16:12 - 2017-07-28 07:20 - 000279968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2017-08-09 16:12 - 2017-07-28 07:15 - 000554400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2017-08-09 16:12 - 2017-07-28 07:10 - 002679200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-08-09 16:12 - 2017-07-28 07:07 - 000805816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2017-08-09 16:12 - 2017-07-28 06:48 - 001839872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-08-09 16:12 - 2017-07-28 06:48 - 000096648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmcmnutils.dll
2017-08-09 16:12 - 2017-07-28 06:47 - 002259768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreUIComponents.dll
2017-08-09 16:12 - 2017-07-28 06:40 - 005820984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-08-09 16:12 - 2017-07-28 06:40 - 000551200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-08-09 16:12 - 2017-07-28 06:38 - 004213656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2017-08-09 16:12 - 2017-07-28 06:37 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 020373408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 006761568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 005808640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 002424024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 001195760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 000866808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DolbyDecMFT.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 000864248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 000173104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsensorgroup.dll
2017-08-09 16:12 - 2017-07-28 06:36 - 000090464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msacm32.dll
2017-08-09 16:12 - 2017-07-28 06:35 - 000988168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-08-09 16:12 - 2017-07-28 06:35 - 000277432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shlwapi.dll
2017-08-09 16:12 - 2017-07-28 06:33 - 000967584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2017-08-09 16:12 - 2017-07-28 06:33 - 000583160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-08-09 16:12 - 2017-07-28 06:33 - 000414296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2017-08-09 16:12 - 2017-07-28 06:27 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UcmUcsi.sys
2017-08-09 16:12 - 2017-07-28 06:26 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\cmintegrator.dll
2017-08-09 16:12 - 2017-07-28 06:21 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll
2017-08-09 16:12 - 2017-07-28 06:20 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-08-09 16:12 - 2017-07-28 06:20 - 000018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IpNatHlpClient.dll
2017-08-09 16:12 - 2017-07-28 06:19 - 000942592 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2017-08-09 16:12 - 2017-07-28 06:19 - 000147456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll
2017-08-09 16:12 - 2017-07-28 06:19 - 000117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryUpgrade.dll
2017-08-09 16:12 - 2017-07-28 06:18 - 004544000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VsGraphicsDesktopEngine.exe
2017-08-09 16:12 - 2017-07-28 06:18 - 000139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BluetoothApis.dll
2017-08-09 16:12 - 2017-07-28 06:17 - 006728192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-08-09 16:12 - 2017-07-28 06:16 - 001291776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2017-08-09 16:12 - 2017-07-28 06:16 - 000470016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TpmCoreProvisioning.dll
2017-08-09 16:12 - 2017-07-28 06:16 - 000135680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
2017-08-09 16:12 - 2017-07-28 06:15 - 005721600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2017-08-09 16:12 - 2017-07-28 06:15 - 000586752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-08-09 16:12 - 2017-07-28 06:14 - 000368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-08-09 16:12 - 2017-07-28 06:14 - 000357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
2017-08-09 16:12 - 2017-07-28 06:14 - 000331264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastlsext.dll
2017-08-09 16:12 - 2017-07-28 06:13 - 000932352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GamePanel.exe
2017-08-09 16:12 - 2017-07-28 06:13 - 000665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2017-08-09 16:12 - 2017-07-28 06:13 - 000636416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2017-08-09 16:12 - 2017-07-28 06:12 - 000952832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2017-08-09 16:12 - 2017-07-28 06:12 - 000587776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll
2017-08-09 16:12 - 2017-07-28 06:12 - 000446464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-08-09 16:12 - 2017-07-28 06:12 - 000337920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-08-09 16:12 - 2017-07-28 06:11 - 003667456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-08-09 16:12 - 2017-07-28 06:11 - 001248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-08-09 16:12 - 2017-07-28 06:10 - 001019904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2017-08-09 16:12 - 2017-07-28 06:10 - 000787456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-08-09 16:12 - 2017-07-28 06:10 - 000564224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsvcs.dll
2017-08-09 16:12 - 2017-07-28 06:09 - 005225984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-08-09 16:12 - 2017-07-28 06:08 - 004559360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2017-08-09 16:12 - 2017-07-28 06:08 - 004417024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-08-09 16:12 - 2017-07-28 06:08 - 004056064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-08-09 16:12 - 2017-07-28 06:08 - 000760832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2017-08-09 16:12 - 2017-07-28 06:08 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2017-08-09 16:12 - 2017-07-28 06:07 - 002211840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2017-08-09 16:12 - 2017-07-28 06:05 - 001536512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2017-08-09 16:12 - 2017-07-28 06:05 - 000892928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2017-08-09 16:12 - 2017-07-28 06:05 - 000538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2017-08-09 16:12 - 2017-07-28 06:02 - 000877056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2017-08-09 16:12 - 2017-07-28 06:02 - 000853504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2017-08-09 16:12 - 2017-07-28 06:02 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2017-08-09 16:11 - 2017-08-01 04:39 - 008319392 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-08-09 16:11 - 2017-08-01 04:38 - 000382368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2017-08-09 16:11 - 2017-08-01 04:33 - 000473240 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2017-08-09 16:11 - 2017-08-01 04:32 - 002444704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-08-09 16:11 - 2017-08-01 04:32 - 000820128 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2017-08-09 16:11 - 2017-08-01 04:32 - 000712600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2017-08-09 16:11 - 2017-08-01 04:31 - 005477088 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
2017-08-09 16:11 - 2017-08-01 04:31 - 002645680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-08-09 16:11 - 2017-08-01 04:31 - 000212384 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2017-08-09 16:11 - 2017-08-01 04:30 - 000723680 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-08-09 16:11 - 2017-08-01 04:30 - 000411040 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-08-09 16:11 - 2017-08-01 04:30 - 000410160 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2017-08-09 16:11 - 2017-08-01 04:30 - 000315288 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2017-08-09 16:11 - 2017-08-01 04:30 - 000182688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-08-09 16:11 - 2017-08-01 04:30 - 000143736 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2017-08-09 16:11 - 2017-08-01 04:30 - 000082336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmcl.sys
2017-08-09 16:11 - 2017-08-01 04:26 - 000204192 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2017-08-09 16:11 - 2017-08-01 04:16 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2017-08-09 16:11 - 2017-08-01 04:13 - 020504064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-08-09 16:11 - 2017-08-01 04:12 - 019336192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-08-09 16:11 - 2017-08-01 04:10 - 000358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2017-08-09 16:11 - 2017-08-01 04:07 - 011870208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-08-09 16:11 - 2017-08-01 04:04 - 006269440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-08-09 16:11 - 2017-08-01 04:04 - 003656192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-08-09 16:11 - 2017-08-01 03:57 - 023677952 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-08-09 16:11 - 2017-08-01 03:45 - 003670016 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2017-08-09 16:11 - 2017-08-01 03:45 - 001275392 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2017-08-09 16:11 - 2017-08-01 03:45 - 000462848 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2017-08-09 16:11 - 2017-08-01 03:45 - 000092672 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
2017-08-09 16:11 - 2017-08-01 03:44 - 000184320 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
2017-08-09 16:11 - 2017-08-01 03:44 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmclr.sys
2017-08-09 16:11 - 2017-08-01 03:44 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2017-08-09 16:11 - 2017-08-01 03:42 - 002199552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-08-09 16:11 - 2017-08-01 03:41 - 000130560 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll
2017-08-09 16:11 - 2017-08-01 03:41 - 000110592 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2017-08-09 16:11 - 2017-08-01 03:41 - 000042496 _____ (Microsoft Corporation) C:\Windows\system32\tokenbinding.dll
2017-08-09 16:11 - 2017-08-01 03:40 - 017366528 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2017-08-09 16:11 - 2017-08-01 03:40 - 000290816 _____ (Microsoft Corporation) C:\Windows\system32\dmenterprisediagnostics.dll
2017-08-09 16:11 - 2017-08-01 03:39 - 000046592 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2017-08-09 16:11 - 2017-08-01 03:38 - 000153088 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll
2017-08-09 16:11 - 2017-08-01 03:38 - 000143872 _____ (Microsoft Corporation) C:\Windows\system32\profsvcext.dll
2017-08-09 16:11 - 2017-08-01 03:37 - 000582656 _____ (Microsoft Corporation) C:\Windows\system32\SmsRouterSvc.dll
2017-08-09 16:11 - 2017-08-01 03:37 - 000433664 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll
2017-08-09 16:11 - 2017-08-01 03:37 - 000255488 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2017-08-09 16:11 - 2017-08-01 03:36 - 023681536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-08-09 16:11 - 2017-08-01 03:35 - 000692736 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-08-09 16:11 - 2017-08-01 03:34 - 000805888 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2017-08-09 16:11 - 2017-08-01 03:33 - 001269760 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2017-08-09 16:11 - 2017-08-01 03:33 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\ncryptprov.dll
2017-08-09 16:11 - 2017-08-01 03:32 - 007336960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-08-09 16:11 - 2017-08-01 03:32 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
2017-08-09 16:11 - 2017-08-01 03:31 - 012786176 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-08-09 16:11 - 2017-08-01 03:31 - 004445696 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2017-08-09 16:11 - 2017-08-01 03:31 - 001396736 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2017-08-09 16:11 - 2017-08-01 03:30 - 008209920 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2017-08-09 16:11 - 2017-08-01 03:30 - 002055168 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2017-08-09 16:11 - 2017-08-01 03:30 - 001052160 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2017-08-09 16:11 - 2017-08-01 03:30 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2017-08-09 16:11 - 2017-08-01 03:28 - 004730368 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-08-09 16:11 - 2017-08-01 03:27 - 001802752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-08-09 16:11 - 2017-08-01 03:27 - 000574464 _____ (Microsoft Corporation) C:\Windows\system32\configmanager2.dll
2017-08-09 16:11 - 2017-08-01 03:27 - 000482816 _____ (Microsoft Corporation) C:\Windows\system32\dmenrollengine.dll
2017-08-09 16:11 - 2017-08-01 03:26 - 000323584 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe
2017-08-09 16:11 - 2017-08-01 03:25 - 000249344 _____ (Microsoft Corporation) C:\Windows\system32\coredpus.dll
2017-08-09 16:11 - 2017-08-01 03:25 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll
2017-08-09 16:11 - 2017-08-01 03:25 - 000140800 _____ (Microsoft Corporation) C:\Windows\system32\dmcsps.dll
2017-08-09 16:11 - 2017-07-28 07:30 - 001068720 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2017-08-09 16:11 - 2017-07-28 07:25 - 002399728 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-08-09 16:11 - 2017-07-28 07:24 - 002327456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-08-09 16:11 - 2017-07-28 07:24 - 000455584 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2017-08-09 16:11 - 2017-07-28 07:24 - 000119904 _____ (Microsoft Corporation) C:\Windows\system32\dmcmnutils.dll
2017-08-09 16:11 - 2017-07-28 07:24 - 000116280 _____ (Microsoft Corporation) C:\Windows\system32\bcd.dll
2017-08-09 16:11 - 2017-07-28 07:23 - 002969888 _____ (Microsoft Corporation) C:\Windows\system32\CoreUIComponents.dll
2017-08-09 16:11 - 2017-07-28 07:22 - 000923048 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2017-08-09 16:11 - 2017-07-28 07:17 - 000660680 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2017-08-09 16:11 - 2017-07-28 07:16 - 007326128 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2017-08-09 16:11 - 2017-07-28 07:16 - 000961952 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2017-08-09 16:11 - 2017-07-28 07:15 - 005302968 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2017-08-09 16:11 - 2017-07-28 07:15 - 000872472 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2017-08-09 16:11 - 2017-07-28 07:15 - 000715168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2017-08-09 16:11 - 2017-07-28 07:14 - 000654976 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2017-08-09 16:11 - 2017-07-28 07:14 - 000318232 _____ (Microsoft Corporation) C:\Windows\system32\wininit.exe
2017-08-09 16:11 - 2017-07-28 07:13 - 007907344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-08-09 16:11 - 2017-07-28 07:13 - 006557520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2017-08-09 16:11 - 2017-07-28 07:13 - 002604248 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2017-08-09 16:11 - 2017-07-28 07:13 - 001054280 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2017-08-09 16:11 - 2017-07-28 07:13 - 001033544 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll
2017-08-09 16:11 - 2017-07-28 07:13 - 000192264 _____ (Microsoft Corporation) C:\Windows\system32\mfsensorgroup.dll
2017-08-09 16:11 - 2017-07-28 07:13 - 000104432 _____ (Microsoft Corporation) C:\Windows\system32\msacm32.dll
2017-08-09 16:11 - 2017-07-28 07:12 - 021353208 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-08-09 16:11 - 2017-07-28 07:12 - 001337856 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2017-08-09 16:11 - 2017-07-28 07:12 - 001325968 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-08-09 16:11 - 2017-07-28 07:12 - 000323936 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2017-08-09 16:11 - 2017-07-28 07:10 - 001114528 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2017-08-09 16:11 - 2017-07-28 07:09 - 000529992 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
2017-08-09 16:11 - 2017-07-28 07:09 - 000527976 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2017-08-09 16:11 - 2017-07-28 07:09 - 000387928 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2017-08-09 16:11 - 2017-07-28 06:48 - 000100232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcd.dll
2017-08-09 16:11 - 2017-07-28 06:31 - 003995136 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2017-08-09 16:11 - 2017-07-28 06:30 - 001722880 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2017-08-09 16:11 - 2017-07-28 06:29 - 000584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2017-08-09 16:11 - 2017-07-28 06:29 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2017-08-09 16:11 - 2017-07-28 06:26 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\officecsp.dll
2017-08-09 16:11 - 2017-07-28 06:26 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-08-09 16:11 - 2017-07-28 06:26 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\ofdeploy.exe
2017-08-09 16:11 - 2017-07-28 06:26 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\IpNatHlpClient.dll
2017-08-09 16:11 - 2017-07-28 06:25 - 003464704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2017-08-09 16:11 - 2017-07-28 06:25 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\DolbyMATEnc.dll
2017-08-09 16:11 - 2017-07-28 06:25 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2017-08-09 16:11 - 2017-07-28 06:25 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2017-08-09 16:11 - 2017-07-28 06:24 - 000584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2017-08-09 16:11 - 2017-07-28 06:24 - 000184832 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll
2017-08-09 16:11 - 2017-07-28 06:24 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryUpgrade.dll
2017-08-09 16:11 - 2017-07-28 06:24 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-08-09 16:11 - 2017-07-28 06:24 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2017-08-09 16:11 - 2017-07-28 06:23 - 007931392 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-08-09 16:11 - 2017-07-28 06:23 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\DolbyHrtfEnc.dll
2017-08-09 16:11 - 2017-07-28 06:23 - 000189440 _____ (Microsoft Corporation) C:\Windows\system32\BluetoothApis.dll
2017-08-09 16:11 - 2017-07-28 06:22 - 000778240 _____ C:\Windows\system32\MBR2GPT.EXE
2017-08-09 16:11 - 2017-07-28 06:22 - 000555008 _____ (Microsoft Corporation) C:\Windows\system32\TpmCoreProvisioning.dll
2017-08-09 16:11 - 2017-07-28 06:22 - 000500224 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.BlueLightReduction.dll
2017-08-09 16:11 - 2017-07-28 06:22 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Display.dll
2017-08-09 16:11 - 2017-07-28 06:22 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2017-08-09 16:11 - 2017-07-28 06:22 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Flights.dll
2017-08-09 16:11 - 2017-07-28 06:22 - 000209408 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2017-08-09 16:11 - 2017-07-28 06:22 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2017-08-09 16:11 - 2017-07-28 06:21 - 008333312 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2017-08-09 16:11 - 2017-07-28 06:21 - 000699904 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll
2017-08-09 16:11 - 2017-07-28 06:21 - 000527360 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2017-08-09 16:11 - 2017-07-28 06:21 - 000365056 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Notifications.dll
2017-08-09 16:11 - 2017-07-28 06:21 - 000165888 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2017-08-09 16:11 - 2017-07-28 06:21 - 000150528 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2017-08-09 16:11 - 2017-07-28 06:20 - 001015296 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManager.dll
2017-08-09 16:11 - 2017-07-28 06:20 - 000524800 _____ (Microsoft Corporation) C:\Windows\system32\TileDataRepository.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 001878016 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 000847360 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 000687616 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 000566784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2017-08-09 16:11 - 2017-07-28 06:19 - 000412160 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 000370688 _____ (Microsoft Corporation) C:\Windows\system32\rastlsext.dll
2017-08-09 16:11 - 2017-07-28 06:19 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\SIHClient.exe
2017-08-09 16:11 - 2017-07-28 06:18 - 005776384 _____ (Microsoft Corporation) C:\Windows\system32\VsGraphicsDesktopEngine.exe
2017-08-09 16:11 - 2017-07-28 06:18 - 001468416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2017-08-09 16:11 - 2017-07-28 06:18 - 001298432 _____ (Microsoft Corporation) C:\Windows\system32\lpasvc.dll
2017-08-09 16:11 - 2017-07-28 06:18 - 001260544 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2017-08-09 16:11 - 2017-07-28 06:18 - 000925696 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2017-08-09 16:11 - 2017-07-28 06:18 - 000777216 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2017-08-09 16:11 - 2017-07-28 06:18 - 000586240 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2017-08-09 16:11 - 2017-07-28 06:18 - 000536064 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2017-08-09 16:11 - 2017-07-28 06:17 - 002805248 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2017-08-09 16:11 - 2017-07-28 06:17 - 001886208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-08-09 16:11 - 2017-07-28 06:17 - 000770048 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll
2017-08-09 16:11 - 2017-07-28 06:17 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2017-08-09 16:11 - 2017-07-28 06:17 - 000420864 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll
2017-08-09 16:11 - 2017-07-28 06:16 - 001046016 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2017-08-09 16:11 - 2017-07-28 06:16 - 000383488 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2017-08-09 16:11 - 2017-07-28 06:15 - 003204608 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-08-09 16:11 - 2017-07-28 06:15 - 000986112 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-08-09 16:11 - 2017-07-28 06:15 - 000612864 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2017-08-09 16:11 - 2017-07-28 06:14 - 004396032 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-08-09 16:11 - 2017-07-28 06:14 - 001305088 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2017-08-09 16:11 - 2017-07-28 06:13 - 004535296 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2017-08-09 16:11 - 2017-07-28 06:13 - 001293824 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2017-08-09 16:11 - 2017-07-28 06:13 - 000972288 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2017-08-09 16:11 - 2017-07-28 06:13 - 000809984 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2017-08-09 16:11 - 2017-07-28 06:12 - 005557760 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2017-08-09 16:11 - 2017-07-28 06:12 - 004707840 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-08-09 16:11 - 2017-07-28 06:12 - 002939392 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2017-08-09 16:11 - 2017-07-28 06:12 - 002444288 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-08-09 16:11 - 2017-07-28 06:12 - 000406528 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2017-08-09 16:11 - 2017-07-28 06:11 - 001357312 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-08-09 16:11 - 2017-07-28 06:10 - 001706496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2017-08-09 16:11 - 2017-07-28 06:10 - 000625152 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2017-08-09 16:11 - 2017-07-28 06:09 - 000971264 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2017-08-09 16:11 - 2017-07-28 06:09 - 000579072 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2017-08-09 16:11 - 2017-07-28 06:08 - 000600576 _____ (Microsoft Corporation) C:\Windows\system32\FrameServer.dll
2017-08-09 16:11 - 2017-07-28 06:07 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe
2017-08-09 16:11 - 2017-07-28 06:07 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\RjvMDMConfig.dll
2017-08-09 16:11 - 2017-07-28 06:07 - 000074240 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2017-08-09 16:11 - 2017-07-28 06:07 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\DmApiSetExtImplDesktop.dll
2017-08-09 16:11 - 2017-07-28 06:06 - 001833984 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
2017-08-09 16:11 - 2017-07-28 06:06 - 000593408 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2017-08-09 16:11 - 2017-07-28 06:06 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2017-08-09 16:11 - 2017-07-28 06:05 - 001525760 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2017-08-09 16:11 - 2017-07-28 06:05 - 001087488 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2017-08-09 16:11 - 2017-07-28 06:05 - 000954368 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2017-08-09 16:11 - 2017-07-28 06:05 - 000926208 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2017-08-09 16:11 - 2017-07-28 06:05 - 000078848 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-08-09 13:11 - 2017-08-09 13:11 - 000139865 _____ C:\Users\Paustian\Downloads\Groupon-D8D9D9FA07.pdf
2017-08-09 13:11 - 2017-08-09 13:11 - 000139762 _____ C:\Users\Paustian\Downloads\Groupon-3866478E9C.pdf
2017-08-09 13:11 - 2017-08-09 13:11 - 000139613 _____ C:\Users\Paustian\Downloads\Groupon-765142A2D7.pdf
2017-08-01 16:24 - 2017-08-01 16:24 - 000002365 _____ C:\Users\Paustian\AppData\Local\recently-used.xbel
2017-08-01 12:07 - 2017-08-01 12:07 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign220de6f8fb9e4108
2017-08-01 12:01 - 2017-08-01 12:01 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign7449ac600c0c832c
2017-08-01 12:01 - 2017-08-01 12:01 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign52a1910445f145b6
2017-08-01 10:37 - 2017-08-01 10:37 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsigneaccd478d245dbad
2017-08-01 10:33 - 2017-08-01 10:33 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsignad445edd83177901
2017-08-01 10:33 - 2017-08-01 10:33 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign44e7000a3d27fd6f
2017-08-01 10:18 - 2017-08-01 10:18 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign037c669b50ec6d43
2017-08-01 09:55 - 2017-08-01 09:55 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsigne3419bf049d1d756
2017-08-01 09:54 - 2017-08-01 09:54 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign359c84d784f777b0
2017-08-01 09:54 - 2017-08-01 09:54 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign22a2580f00affdc2
2017-07-31 20:26 - 2017-08-01 10:18 - 008103415 _____ C:\Users\Paustian\Desktop\Unbenannt-1.psd
2017-07-31 17:17 - 2017-07-31 17:17 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign385019027971ffd9
2017-07-31 17:16 - 2017-07-31 17:16 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsignbd88cb794746890e
2017-07-31 17:16 - 2017-07-31 17:16 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign5bdb9571a7c0fde6
2017-07-31 17:16 - 2017-07-31 17:16 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign27f1030247c2e24b
2017-07-31 16:33 - 2017-07-31 16:34 - 000051007 _____ C:\Users\Paustian\Downloads\amtlib.zip
2017-07-31 14:45 - 2017-07-31 14:45 - 002227895 _____ C:\Users\Paustian\Desktop\UF I-Bericht_Team 1_Spritzfest.pdf
2017-07-30 16:35 - 2017-07-30 16:35 - 002164867 _____ C:\Users\Paustian\Downloads\Download File(2).pdf
2017-07-30 16:34 - 2017-07-31 14:45 - 001740361 _____ C:\Users\Paustian\Desktop\Spritzfest_neu.pdf
2017-07-30 16:34 - 2017-07-30 16:34 - 000182946 _____ C:\Users\Paustian\Downloads\Download File(1).pdf
2017-07-30 16:33 - 2017-07-30 16:33 - 002164461 _____ C:\Users\Paustian\Downloads\Download File.pdf
2017-07-30 16:33 - 2017-07-30 16:33 - 000306539 _____ C:\Users\Paustian\Desktop\Protokolle.pdf
2017-07-30 16:32 - 2017-07-30 16:32 - 000182865 _____ C:\Users\Paustian\Desktop\Deckblatt.pdf
2017-07-30 16:31 - 2017-07-30 16:31 - 000012388 _____ C:\Users\Paustian\Desktop\Deckblatt.odt
2017-07-30 16:02 - 2017-07-30 16:13 - 000555721 _____ C:\Users\Paustian\Desktop\Protokolle U1.odt
2017-07-30 15:45 - 2017-08-13 01:28 - 000000000 ____D C:\Users\Paustian\AppData\LocalLow\Temp
2017-07-30 14:41 - 2017-07-30 14:41 - 000061784 _____ C:\Users\Paustian\Downloads\Liquiditätsplan (Abbildung).pdf
2017-07-30 14:28 - 2017-07-30 14:49 - 000000000 ____D C:\Users\Paustian\Desktop\Bilder
2017-07-30 09:43 - 2017-07-30 09:43 - 000026712 _____ C:\Users\Paustian\Desktop\Organisation.odt
2017-07-28 09:58 - 2017-07-28 09:58 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsigna89232716f7b0a27
2017-07-28 09:56 - 2017-07-28 09:56 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign6d68e398ae0ed38b
2017-07-28 09:54 - 2017-07-28 09:54 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsignd9d182d6bac33600
2017-07-28 09:54 - 2017-07-28 09:54 - 000000000 ____D C:\Users\Paustian\AppData\Local\Tempzxpsign05fb69ed10880fe1
2017-07-28 09:11 - 2017-07-31 14:45 - 002470393 _____ C:\Users\Paustian\Desktop\Spritzfest_Bericht_WIP.odt
2017-07-28 09:11 - 2017-07-30 11:46 - 000033479 _____ C:\Users\Paustian\Desktop\Spritzfest_Bericht_OLD.odt
2017-07-27 09:24 - 2017-07-27 09:24 - 000003382 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1081556182-481547222-1970898152-1001
2017-07-21 01:30 - 2017-07-21 01:30 - 001790024 _____ (Malwarebytes) C:\Users\Paustian\Downloads\JRT.exe
2017-07-21 01:26 - 2017-07-21 01:26 - 008162248 _____ (Malwarebytes) C:\Users\Paustian\Downloads\adwcleaner_7.0.0.0.exe
2017-07-17 21:52 - 2017-07-17 21:52 - 000000000 ____D C:\Users\Paustian\AppData\LocalLow\Blizzard Entertainment
2017-07-17 21:52 - 2017-07-17 21:52 - 000000000 ____D C:\Users\Paustian\AppData\Local\Blizzard
2017-07-17 21:51 - 2017-07-17 21:51 - 000000948 _____ C:\Users\Public\Desktop\Hearthstone.lnk
2017-07-17 21:51 - 2017-07-17 21:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2017-07-17 21:47 - 2017-08-08 21:08 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2017-07-14 21:39 - 2017-07-14 21:39 - 000001048 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
2017-07-14 21:39 - 2017-07-14 21:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2017-07-14 21:37 - 2017-08-12 02:45 - 000000000 ____D C:\Program Files (x86)\World of Warcraft
2017-07-14 16:38 - 2017-07-14 16:38 - 000253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\40EB532E.sys
2017-07-14 16:32 - 2017-08-12 16:53 - 000000000 ____D C:\AdwCleaner
2017-07-11 19:17 - 2017-07-07 09:13 - 000336320 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe
2017-07-11 19:17 - 2017-07-07 08:57 - 000626528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2017-07-11 19:17 - 2017-07-07 08:57 - 000125344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2017-07-11 19:17 - 2017-07-07 08:31 - 001518088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-07-11 19:17 - 2017-07-07 08:31 - 000129184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-07-11 19:17 - 2017-07-07 08:30 - 000949920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2017-07-11 19:17 - 2017-07-07 08:29 - 000123520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Clipc.dll
2017-07-11 19:17 - 2017-07-07 08:26 - 001529384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2017-07-11 19:17 - 2017-07-07 08:25 - 000035232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininitext.dll
2017-07-11 19:17 - 2017-07-07 08:14 - 001448960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2017-07-11 19:17 - 2017-07-07 08:10 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapprovp.dll
2017-07-11 19:17 - 2017-07-07 08:09 - 000365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2017-07-11 19:17 - 2017-07-07 08:07 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\raschap.dll
2017-07-11 19:17 - 2017-07-07 08:06 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2017-07-11 19:17 - 2017-07-07 08:05 - 000502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
2017-07-11 19:17 - 2017-07-07 08:05 - 000312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-07-11 19:17 - 2017-07-07 08:04 - 000754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-07-11 19:17 - 2017-07-07 08:04 - 000506368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-07-11 19:17 - 2017-07-07 08:03 - 006123520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2017-07-11 19:17 - 2017-07-07 08:03 - 000430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1debug3.dll
2017-07-11 19:17 - 2017-07-07 08:01 - 002859520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-07-11 19:17 - 2017-07-07 08:00 - 007596544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-07-11 19:17 - 2017-07-07 08:00 - 002588160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapRouter.dll
2017-07-11 19:17 - 2017-07-07 08:00 - 001565184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-07-11 19:17 - 2017-07-07 07:59 - 001494016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActiveSyncProvider.dll
2017-07-11 19:17 - 2017-07-07 07:59 - 001355264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2017-07-11 19:17 - 2017-07-07 07:58 - 002782720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2017-07-11 19:17 - 2017-07-07 07:58 - 002298368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2017-07-11 19:17 - 2017-07-07 07:58 - 001237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-07-11 19:17 - 2017-07-07 07:55 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2017-07-11 19:17 - 2017-07-07 07:55 - 000329216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2017-07-11 19:17 - 2017-07-07 07:53 - 001301504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-07-11 19:17 - 2017-07-07 07:53 - 000338432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-07-11 19:17 - 2017-06-20 08:02 - 001055648 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2017-07-11 19:17 - 2017-06-20 07:34 - 000192416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll
2017-07-11 19:17 - 2017-06-20 07:15 - 000455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2017-07-11 19:17 - 2017-06-20 07:13 - 000787712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-07-11 19:17 - 2017-06-20 07:12 - 000264192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2017-07-11 19:17 - 2017-06-20 07:12 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2017-07-11 19:17 - 2017-06-20 07:08 - 004469840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-07-11 19:17 - 2017-06-20 07:07 - 002475136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-07-11 19:17 - 2017-06-20 07:07 - 000346016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2017-07-11 19:17 - 2017-06-20 07:07 - 000138656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostUser.dll
2017-07-11 19:17 - 2017-06-20 07:06 - 000754592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2017-07-11 19:17 - 2017-06-20 07:06 - 000278944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2017-07-11 19:17 - 2017-06-20 07:05 - 000438096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
2017-07-11 19:17 - 2017-06-20 07:05 - 000364032 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-07-11 19:17 - 2017-06-20 07:04 - 002330520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-07-11 19:17 - 2017-06-20 07:04 - 001178528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll
2017-07-11 19:17 - 2017-06-20 07:04 - 001077496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2017-07-11 19:17 - 2017-06-20 07:04 - 000181656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2017-07-11 19:17 - 2017-06-20 07:04 - 000049656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2017-07-11 19:17 - 2017-06-20 07:03 - 000443728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2017-07-11 19:17 - 2017-06-20 07:02 - 001121928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2017-07-11 19:17 - 2017-06-20 07:02 - 000354400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2017-07-11 19:17 - 2017-06-20 07:00 - 002597888 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-07-11 19:17 - 2017-06-20 06:49 - 000899072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfuimanager.dll
2017-07-11 19:17 - 2017-06-20 06:49 - 000331776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2017-07-11 19:17 - 2017-06-20 06:46 - 000132096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll
2017-07-11 19:17 - 2017-06-20 06:45 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Profile.RetailInfo.dll
2017-07-11 19:17 - 2017-06-20 06:43 - 000173568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ClipboardServer.dll
2017-07-11 19:17 - 2017-06-20 06:43 - 000151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredui.dll
2017-07-11 19:17 - 2017-06-20 06:43 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dataclen.dll
2017-07-11 19:17 - 2017-06-20 06:42 - 000641024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certca.dll
2017-07-11 19:17 - 2017-06-20 06:42 - 000387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Payments.dll
2017-07-11 19:17 - 2017-06-20 06:42 - 000121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sendmail.dll
2017-07-11 19:17 - 2017-06-20 06:41 - 000734208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2017-07-11 19:17 - 2017-06-20 06:41 - 000646656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll
2017-07-11 19:17 - 2017-06-20 06:41 - 000601088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVolSSO.dll
2017-07-11 19:17 - 2017-06-20 06:41 - 000433152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2017-07-11 19:17 - 2017-06-20 06:41 - 000201216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovhost.dll
2017-07-11 19:17 - 2017-06-20 06:40 - 000342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-07-11 19:17 - 2017-06-20 06:40 - 000247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
2017-07-11 19:17 - 2017-06-20 06:40 - 000230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edputil.dll
2017-07-11 19:17 - 2017-06-20 06:40 - 000038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerUI.dll
2017-07-11 19:17 - 2017-06-20 06:39 - 002814464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2017-07-11 19:17 - 2017-06-20 06:39 - 000969728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2017-07-11 19:17 - 2017-06-20 06:39 - 000646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2017-07-11 19:17 - 2017-06-20 06:39 - 000471040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VAN.dll
2017-07-11 19:17 - 2017-06-20 06:39 - 000312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-07-11 19:17 - 2017-06-20 06:38 - 001451008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2017-07-11 19:17 - 2017-06-20 06:38 - 001285120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2017-07-11 19:17 - 2017-06-20 06:38 - 001171968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2017-07-11 19:17 - 2017-06-20 06:38 - 000648192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2017-07-11 19:17 - 2017-06-20 06:35 - 005141504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d12warp.dll
2017-07-11 19:17 - 2017-06-20 06:35 - 002679296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2017-07-11 19:17 - 2017-06-20 06:35 - 002132480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-11 19:17 - 2017-06-20 06:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cldapi.dll
2017-07-11 19:17 - 2017-06-20 06:34 - 002750464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2017-07-11 19:17 - 2017-06-20 06:34 - 001492480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2017-07-11 19:17 - 2017-06-20 06:31 - 000334848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2017-07-11 19:17 - 2017-06-20 06:30 - 000209920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdmaud.drv
2017-07-11 19:17 - 2017-06-20 06:30 - 000157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-07-11 19:17 - 2017-06-20 06:30 - 000089088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-07-11 19:17 - 2017-06-20 06:28 - 000584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2017-07-11 19:16 - 2017-07-07 16:00 - 000947712 _____ (Microsoft Corporation) C:\Windows\system32\HoloSI.PCShell.dll
2017-07-11 19:16 - 2017-07-07 09:27 - 001147288 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2017-07-11 19:16 - 2017-07-07 09:27 - 001024928 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2017-07-11 19:16 - 2017-07-07 09:27 - 000965024 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
2017-07-11 19:16 - 2017-07-07 09:27 - 000821664 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
2017-07-11 19:16 - 2017-07-07 09:27 - 000750560 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2017-07-11 19:16 - 2017-07-07 09:26 - 001065104 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-07-11 19:16 - 2017-07-07 09:25 - 000899824 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2017-07-11 19:16 - 2017-07-07 09:24 - 000117664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2017-07-11 19:16 - 2017-07-07 09:22 - 001186464 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2017-07-11 19:16 - 2017-07-07 09:21 - 032688336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsRaw.dll
2017-07-11 19:16 - 2017-07-07 09:20 - 002021680 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2017-07-11 19:16 - 2017-07-07 09:20 - 000519584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-07-11 19:16 - 2017-07-07 09:17 - 001017760 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2017-07-11 19:16 - 2017-07-07 09:14 - 001760264 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-07-11 19:16 - 2017-07-07 09:14 - 001171032 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2017-07-11 19:16 - 2017-07-07 09:13 - 000147800 _____ (Microsoft Corporation) C:\Windows\system32\Clipc.dll
2017-07-11 19:16 - 2017-07-07 09:12 - 000228256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-07-11 19:16 - 2017-07-07 09:11 - 000094624 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-07-11 19:16 - 2017-07-07 09:10 - 001670496 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2017-07-11 19:16 - 2017-07-07 09:10 - 000372128 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-07-11 19:16 - 2017-07-07 09:10 - 000254168 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-07-11 19:16 - 2017-07-07 09:09 - 000041376 _____ (Microsoft Corporation) C:\Windows\system32\wininitext.dll
2017-07-11 19:16 - 2017-07-07 09:07 - 001106848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-07-11 19:16 - 2017-07-07 09:07 - 000058488 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-07-11 19:16 - 2017-07-07 08:37 - 031652264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsRaw.dll
2017-07-11 19:16 - 2017-07-07 08:37 - 001339352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2017-07-11 19:16 - 2017-07-07 08:27 - 001640448 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2017-07-11 19:16 - 2017-07-07 08:27 - 000859136 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2017-07-11 19:16 - 2017-07-07 08:27 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\duser.dll
2017-07-11 19:16 - 2017-07-07 08:27 - 000557568 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-07-11 19:16 - 2017-07-07 08:27 - 000443392 _____ (Microsoft Corporation) C:\Windows\system32\PerceptionSimulationExtensions.dll
2017-07-11 19:16 - 2017-07-07 08:27 - 000360960 _____ (Microsoft Corporation) C:\Windows\system32\ConhostV2.dll
2017-07-11 19:16 - 2017-07-07 08:23 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\eapprovp.dll
2017-07-11 19:16 - 2017-07-07 08:22 - 000520704 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2017-07-11 19:16 - 2017-07-07 08:21 - 000096256 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncCsp.dll
2017-07-11 19:16 - 2017-07-07 08:20 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\prntvpt.dll
2017-07-11 19:16 - 2017-07-07 08:19 - 007149056 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2017-07-11 19:16 - 2017-07-07 08:19 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2017-07-11 19:16 - 2017-07-07 08:19 - 000137216 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2017-07-11 19:16 - 2017-07-07 08:18 - 000563712 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2017-07-11 19:16 - 2017-07-07 08:18 - 000548864 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2017-07-11 19:16 - 2017-07-07 08:18 - 000353280 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-07-11 19:16 - 2017-07-07 08:18 - 000274944 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2017-07-11 19:16 - 2017-07-07 08:17 - 000588800 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-07-11 19:16 - 2017-07-07 08:17 - 000422400 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll
2017-07-11 19:16 - 2017-07-07 08:16 - 000545792 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2017-07-11 19:16 - 2017-07-07 08:15 - 000922112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-07-11 19:16 - 2017-07-07 08:15 - 000498176 _____ (Microsoft Corporation) C:\Windows\system32\d2d1debug3.dll
2017-07-11 19:16 - 2017-07-07 08:14 - 008211968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-07-11 19:16 - 2017-07-07 08:14 - 003784704 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll
2017-07-11 19:16 - 2017-07-07 08:14 - 000570880 _____ (Microsoft Corporation)C:\Windows\system32\PhotoScreensaver.scr
2017-07-11 19:16 - 2017-07-07 08:13 - 005892096 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-07-11 19:16 - 2017-07-07 08:13 - 000840192 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2017-07-11 19:16 - 2017-07-07 08:12 - 003307008 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-07-11 19:16 - 2017-07-07 08:12 - 002499584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2017-07-11 19:16 - 2017-07-07 08:12 - 001713664 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2017-07-11 19:16 - 2017-07-07 08:12 - 001420800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Maps.dll
2017-07-11 19:16 - 2017-07-07 08:12 - 001142272 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-07-11 19:16 - 2017-07-07 08:12 - 000706560 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2017-07-11 19:16 - 2017-07-07 08:11 - 003139584 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2017-07-11 19:16 - 2017-07-07 08:11 - 002829824 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-07-11 19:16 - 2017-07-07 08:11 - 002649600 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2017-07-11 19:16 - 2017-07-07 08:11 - 002177024 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2017-07-11 19:16 - 2017-07-07 08:11 - 001888256 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-07-11 19:16 - 2017-07-07 08:11 - 001812480 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-07-11 19:16 - 2017-07-07 08:08 - 000285696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-07-11 19:16 - 2017-07-07 08:07 - 000430080 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2017-07-11 19:16 - 2017-07-07 08:07 - 000391168 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2017-07-11 19:16 - 2017-07-07 08:07 - 000272896 _____ (Microsoft Corporation) C:\Windows\system32\PlayToReceiver.dll
2017-07-11 19:16 - 2017-07-07 08:06 - 000412160 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2017-07-11 19:16 - 2017-07-07 08:06 - 000205824 _____ (Microsoft Corporation) C:\Windows\system32\sensrsvc.dll
2017-07-11 19:16 - 2017-07-07 08:05 - 000370176 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2017-07-11 19:16 - 2017-07-07 08:04 - 001703424 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2017-07-11 19:16 - 2017-07-07 08:04 - 001403392 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-07-11 19:16 - 2017-07-07 08:04 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-07-11 19:16 - 2017-07-07 08:02 - 000508416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr
2017-07-11 19:16 - 2017-07-02 00:52 - 000031932 _____ C:\Windows\system32\edgehtmlpluginpolicy.bin
2017-07-11 19:16 - 2017-06-20 08:18 - 001564576 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-07-11 19:16 - 2017-06-20 08:18 - 000096672 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-07-11 19:16 - 2017-06-20 08:17 - 000629152 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-07-11 19:16 - 2017-06-20 08:17 - 000544160 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-07-11 19:16 - 2017-06-20 08:17 - 000334240 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-07-11 19:16 - 2017-06-20 08:17 - 000136096 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-07-11 19:16 - 2017-06-20 08:17 - 000034720 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2017-07-11 19:16 - 2017-06-20 08:16 - 001214880 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-07-11 19:16 - 2017-06-20 08:16 - 000335776 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2017-07-11 19:16 - 2017-06-20 08:15 - 000233376 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-07-11 19:16 - 2017-06-20 08:11 - 001395152 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-07-11 19:16 - 2017-06-20 08:11 - 000411992 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2017-07-11 19:16 - 2017-06-20 08:10 - 001930320 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-07-11 19:16 - 2017-06-20 08:08 - 001242528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2017-07-11 19:16 - 2017-06-20 08:05 - 001057832 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2017-07-11 19:16 - 2017-06-20 08:04 - 004847424 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-07-11 19:16 - 2017-06-20 08:03 - 000179608 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostUser.dll
2017-07-11 19:16 - 2017-06-20 08:03 - 000102312 _____ (Microsoft Corporation) C:\Windows\system32\CredentialUIBroker.exe
2017-07-11 19:16 - 2017-06-20 08:02 - 000426912 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
2017-07-11 19:16 - 2017-06-20 08:00 - 000558920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll
2017-07-11 19:16 - 2017-06-20 08:00 - 000255904 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2017-07-11 19:16 - 2017-06-20 08:00 - 000142752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcifs.sys
2017-07-11 19:16 - 2017-06-20 07:59 - 001220072 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2017-07-11 19:16 - 2017-06-20 07:59 - 000583304 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2017-07-11 19:16 - 2017-06-20 07:59 - 000467504 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2017-07-11 19:16 - 2017-06-20 07:58 - 000833160 _____ (Microsoft Corporation) C:\Windows\system32\EditionUpgradeManagerObj.dll
2017-07-11 19:16 - 2017-06-20 07:58 - 000406072 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2017-07-11 19:16 - 2017-06-20 07:58 - 000203168 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.dll
2017-07-11 19:16 - 2017-06-20 07:16 - 000970752 _____ (Microsoft Corporation) C:\Windows\system32\msctfuimanager.dll
2017-07-11 19:16 - 2017-06-20 07:16 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2017-07-11 19:16 - 2017-06-20 07:15 - 001620368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-07-11 19:16 - 2017-06-20 07:14 - 001150784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-07-11 19:16 - 2017-06-20 07:14 - 000032768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mskssrv.sys
2017-07-11 19:16 - 2017-06-20 07:13 - 000216064 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll
2017-07-11 19:16 - 2017-06-20 07:13 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2017-07-11 19:16 - 2017-06-20 07:13 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\WFDSConMgr.dll
2017-07-11 19:16 - 2017-06-20 07:13 - 000056832 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModelOOBE.exe
2017-07-11 19:16 - 2017-06-20 07:12 - 000293376 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe |