Splasher | 01.12.2015 15:04 | Erstmal vielen Dank schonmal für die schnelle Antwort
FRST.txt
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:30-11-2015
durchgeführt von Simeon (Administrator) auf PC-192-168-2-11 (01-12-2015 14:42:13)
Gestartet von C:\Users\Simeon\Downloads
Geladene Profile: Simeon (Verfügbare Profile: Simeon)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\mcsvchost\McSvHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Ruiware LLC) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.15361.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1120.13270.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.23.23.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\mfpmp.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-13] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191528 2014-06-04] (Geek Software GmbH)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7004376 2015-11-04] (AVAST Software)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [Spotify Web Helper] => C:\Users\Simeon\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2030912 2015-10-23] (Spotify Ltd)
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3098424 2015-08-19] (Nota Inc.)
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1154112 2014-07-21] (Ruiware LLC)
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [{517CC397-B22F-4593-8DCB-DE72CC541E9A}] => C:\Users\Simeon\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe [30668968 2015-05-23] (Riot Games)
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [Dropbox Update] => C:\Users\Simeon\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-18] (Dropbox, Inc.)
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50143872 2015-11-17] (Skype Technologies S.A.)
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\...\Run: [GoogleChromeAutoLaunch_D0278164EA89A1039D7EE87582DA94F0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [811848 2015-11-07] (Google Inc.)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation)
AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-11-04] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Simeon\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Simeon\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Simeon\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Simeon\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Simeon\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-11-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Simeon\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-11-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Simeon\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-11-05] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2015-09-29]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS)
Startup: C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-09-29]
ShortcutTarget: Dropbox.lnk -> C:\Users\Simeon\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{1601235c-8be2-42ad-a516-95a4b5503b4b}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{6010b956-984b-4a82-b08a-0da6920722a6}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2194020832-3275982821-4177272209-1002 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2194020832-3275982821-4177272209-1002 -> {25ED8489-9D47-4ADD-AD9B-F4074B21DD47} URL =
SearchScopes: HKU\S-1-5-21-2194020832-3275982821-4177272209-1002 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-18] (Oracle Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll [2013-02-28] (Qualcomm Atheros Commnucations)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-04] (AVAST Software)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-18] (Oracle Corporation)
BHO-x32: Kein Name -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> Keine Datei
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-10-20] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-04] (AVAST Software)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-13] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-08-12] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2014-04-25] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
FireFox:
========
FF ProfilePath: C:\Users\Simeon\AppData\Roaming\Mozilla\Firefox\Profiles\rd6us1fq.default
FF Homepage: hxxps://www.malwarebytes.org/restorebrowser//?type=hp&ts=1443542688&z=7624780dbd56ba9eba34037gez8z5c8wbz0ofz8t2b&from=cor&uid=TOSHIBAXMQ01ABF050_Y368SDOISXXY368SDOIS
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-18] (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.20 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-20] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-20] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-06-25] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2014-05-25] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2014-05-25] ()
FF Plugin HKU\S-1-5-21-2194020832-3275982821-4177272209-1002: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2014-05-25] (Pando Networks)
FF Plugin HKU\S-1-5-21-2194020832-3275982821-4177272209-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2014-11-23] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-06-25] (Microsoft Corporation)
FF Extension: WOT - C:\Users\Simeon\AppData\Roaming\Mozilla\Firefox\Profiles\rd6us1fq.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-07-20]
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-11-04]
FF Extension: NoScript - C:\Users\Simeon\AppData\Roaming\Mozilla\Firefox\Profiles\rd6us1fq.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-11-01]
FF Extension: Video DownloadHelper - C:\Users\Simeon\AppData\Roaming\Mozilla\Firefox\Profiles\rd6us1fq.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-08-18]
FF Extension: Adblock Plus - C:\Users\Simeon\AppData\Roaming\Mozilla\Firefox\Profiles\rd6us1fq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-27]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-11-04]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-05-26] [ist nicht signiert]
Chrome:
=======
CHR StartupUrls: Default -> "","hxxps://www.google.de/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8","hxxp://search.gboxapp.com/?aff=p","hxxp://www.istartsurf.com/?type=hp&ts=1437339063&z=0b86e84ee58059b9942a498gbzfc4m2c9c1t8e8c3m&from=cor&uid=TOSHIBAXMQ01ABF050_Y368SDOISXXY368SDOIS","hxxp://www.istartsurf.com/?type=hppp&ts=1437339121&z=bbf8572756d2628d0332518g7zec7mdcfcetde8t7w&from=cor&uid=TOSHIBAXMQ01ABF050_Y368SDOISXXY368SDOIS","hxxp://www.istartsurf.com/?type=hp&ts=1443542688&z=7624780dbd56ba9eba34037gez8z5c8wbz0ofz8t2b&from=cor&uid=TOSHIBAXMQ01ABF050_Y368SDOISXXY368SDOIS"
CHR Session Restore: Default -> ist aktiviert.
CHR Profile: C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-11-11]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-11-20]
CHR Extension: (Adblock Plus) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-11-25]
CHR Extension: (Steam inventory helper) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2015-11-23]
CHR Extension: (LoungeDestroyer) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2015-11-26]
CHR Extension: (Avast Online Security) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-03]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2015-08-20]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Simeon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-25]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Simeon\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx <nicht gefunden>
CHR HKU\S-1-5-21-2194020832-3275982821-4177272209-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-04]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [174416 2015-11-04] (AVAST Software)
S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [63968 2015-05-21] (CyberGhost S.R.L)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated)
S2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-13] (ELAN Microelectronics Corp.)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation)
U2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [370064 2015-10-15] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-20] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-20] (Intel Corporation)
S2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-04-26] (Acer Incorporate)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [334760 2012-12-21] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
U2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
U2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-06-18] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-02-20] (Electronic Arts)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-11-04] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-11-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-11-04] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-11-04] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [154256 2015-11-04] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-11-04] (AVAST Software)
R4 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-03-30] (LogMeIn Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [444720 2014-06-18] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-06-18] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [751632 2015-05-14] (Realsil Semiconductor Corporation)
S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-01-27] (SteelSeries ApS)
S3 sshid; C:\Windows\System32\drivers\sshid.sys [51392 2015-10-27] (SteelSeries ApS)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-12-01 14:42 - 2015-12-01 14:43 - 00029096 _____ C:\Users\Simeon\Downloads\FRST.txt
2015-12-01 14:41 - 2015-12-01 14:42 - 00000000 ____D C:\FRST
2015-12-01 14:41 - 2015-12-01 14:41 - 02350080 _____ (Farbar) C:\Users\Simeon\Downloads\FRST64.exe
2015-11-30 21:05 - 2015-11-30 21:06 - 00000000 ____D C:\Program Files (x86)\Opera
2015-11-30 21:05 - 2015-11-30 21:05 - 00717288 _____ (Opera Software) C:\Users\Simeon\Downloads\Opera_NI_stable (3).exe
2015-11-30 21:05 - 2015-11-30 21:05 - 00003968 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1448913947
2015-11-30 21:05 - 2015-11-30 21:05 - 00001212 _____ C:\Users\Public\Desktop\Opera.lnk
2015-11-30 21:05 - 2015-11-30 21:05 - 00001212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-11-30 20:28 - 2015-11-30 20:29 - 00717288 _____ (Opera Software) C:\Users\Simeon\Downloads\Opera_NI_stable (2).exe
2015-11-30 20:16 - 2015-11-30 20:16 - 00003968 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1448910958
2015-11-30 20:15 - 2015-11-30 20:15 - 00717288 _____ (Opera Software) C:\Users\Simeon\Downloads\Opera_NI_stable (1).exe
2015-11-30 17:56 - 2015-11-30 17:56 - 00000000 _____ C:\WINDOWS\SysWOW64\REN7F89.tmp
2015-11-29 15:44 - 2015-11-29 15:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-11-29 00:20 - 2015-11-29 00:22 - 41943979 _____ C:\Users\Simeon\Downloads\Izrail_-_1994_EP_MP3_Format.zip
2015-11-27 22:54 - 2015-11-27 22:54 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-11-27 16:30 - 2015-11-28 14:43 - 00250104 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2015-11-26 20:54 - 2015-11-26 20:54 - 00000000 ____D C:\Users\Simeon\AppData\Local\ActiveSync
2015-11-26 20:52 - 2015-11-26 20:52 - 00000020 ___SH C:\Users\Simeon\ntuser.ini
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Vorlagen
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Startmenü
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2015-11-26 20:50 - 2015-11-26 20:50 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2015-11-26 20:40 - 2015-11-29 17:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-26 20:23 - 2015-11-26 20:23 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-11-26 20:23 - 2015-11-26 20:23 - 00000000 ____D C:\Users\Default\AppData\Local\Pokki
2015-11-26 20:23 - 2015-11-26 20:23 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2015-11-26 20:23 - 2015-11-26 20:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Pokki
2015-11-26 20:23 - 2015-11-26 20:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2015-11-26 20:15 - 2015-11-26 20:27 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2015-11-26 20:10 - 2015-11-29 18:22 - 00000000 ____D C:\Users\Simeon
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Vorlagen
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Startmenü
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Netzwerkumgebung
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Lokale Einstellungen
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Eigene Dateien
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Druckumgebung
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Documents\Eigene Videos
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Documents\Eigene Musik
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Documents\Eigene Bilder
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\AppData\Local\Verlauf
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\AppData\Local\Anwendungsdaten
2015-11-26 20:10 - 2015-11-26 20:10 - 00000000 _SHDL C:\Users\Simeon\Anwendungsdaten
2015-11-26 20:06 - 2015-11-26 20:16 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-26 20:06 - 2015-11-26 20:06 - 00646947 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2015-11-26 20:06 - 2015-11-26 20:06 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-11-26 20:06 - 2015-11-26 20:06 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2015-11-26 20:06 - 2015-11-26 20:06 - 00000000 ____D C:\Program Files\Realtek
2015-11-26 20:06 - 2015-11-26 20:06 - 00000000 ____D C:\Program Files\Common Files\Atheros
2015-11-26 20:06 - 2015-07-23 02:10 - 06873928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-11-26 20:06 - 2015-07-23 02:10 - 03493008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-11-26 20:06 - 2015-07-23 02:10 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-11-26 20:06 - 2015-07-23 02:10 - 01059984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2015-11-26 20:06 - 2015-07-23 02:10 - 00937800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-11-26 20:06 - 2015-07-23 02:10 - 00385168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-11-26 20:06 - 2015-07-23 02:10 - 00074896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2015-11-26 20:06 - 2015-07-23 02:10 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-11-26 20:06 - 2015-07-22 05:29 - 05121613 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-11-26 20:05 - 2015-11-30 17:10 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-26 20:05 - 2015-11-26 20:16 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-26 20:05 - 2015-11-26 20:16 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-11-26 20:05 - 2015-11-26 20:16 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-11-26 20:05 - 2015-11-26 20:05 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2015-11-26 20:05 - 2015-11-26 20:05 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2015-11-26 20:05 - 2015-10-15 00:22 - 00105472 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2015-11-26 20:05 - 2015-10-15 00:22 - 00099856 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2015-11-26 20:04 - 2015-11-26 20:27 - 00000000 ____D C:\Program Files\Elantech
2015-11-26 20:04 - 2015-11-26 20:16 - 00000000 ____D C:\Program Files\Intel
2015-11-26 20:04 - 2015-11-26 20:04 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2015-11-26 20:03 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-11-26 19:59 - 2015-11-26 20:28 - 00359656 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-26 19:58 - 2015-11-30 18:39 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-26 19:54 - 2015-11-26 19:54 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 13376512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 13017088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 12120064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-26 19:54 - 2015-11-26 19:54 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2015-11-26 19:54 - 2015-11-26 19:54 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2015-11-26 19:54 - 2015-11-26 19:54 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 01998848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 01707008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-26 19:54 - 2015-11-26 19:54 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-26 19:54 - 2015-11-26 19:54 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-11-26 19:54 - 2015-11-26 19:54 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-11-26 19:54 - 2015-11-26 19:54 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-26 19:54 - 2015-11-26 19:54 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-11-26 19:54 - 2015-11-26 19:54 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2015-11-26 19:54 - 2015-11-26 19:54 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-11-26 19:54 - 2015-11-26 19:54 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2015-11-26 19:54 - 2015-11-26 19:54 - 00000000 ____D C:\Windows.old
2015-11-26 19:52 - 2015-10-29 19:43 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2015-11-26 19:52 - 2015-10-29 19:43 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-11-26 19:52 - 2015-10-29 19:41 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-11-26 19:52 - 2015-10-29 19:25 - 06359040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-11-26 19:52 - 2015-10-29 19:24 - 04847616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2015-11-26 19:51 - 2015-11-26 19:51 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-11-26 19:47 - 2015-11-26 19:47 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2015-11-26 19:47 - 2015-11-26 19:47 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-11-26 19:47 - 2015-11-26 19:47 - 00000000 ____D C:\Program Files\MSBuild
2015-11-26 19:47 - 2015-11-26 19:47 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-11-26 19:47 - 2015-11-26 19:47 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-11-26 19:47 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-11-26 19:47 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-26 19:47 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-11-26 19:47 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-11-26 19:47 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-11-26 19:47 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-23 12:46 - 2015-11-23 12:47 - 50202832 _____ C:\Users\Simeon\Downloads\luth-1x01.part6.rar
2015-11-23 12:46 - 2015-11-23 12:47 - 105000000 _____ C:\Users\Simeon\Downloads\luth-1x01.part5.rar
2015-11-23 12:45 - 2015-11-23 12:46 - 105000000 _____ C:\Users\Simeon\Downloads\luth-1x01.part4.rar
2015-11-23 12:44 - 2015-11-23 12:45 - 105000000 _____ C:\Users\Simeon\Downloads\luth-1x01.part3.rar
2015-11-23 12:44 - 2015-11-23 12:44 - 105000000 _____ C:\Users\Simeon\Downloads\luth-1x01.part2.rar
2015-11-23 12:43 - 2015-11-23 12:43 - 105000000 _____ C:\Users\Simeon\Downloads\luth-1x01.part1.rar
2015-11-14 13:55 - 2015-11-14 13:55 - 00001055 _____ C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2015-11-13 19:18 - 2015-11-26 20:27 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-11-12 23:50 - 2015-11-12 23:53 - 91149892 _____ C:\Users\Simeon\Downloads\Arrow.S04E06.720p.HDTV.x-DIMENSION.part6.rar
2015-11-12 23:49 - 2015-11-12 23:54 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E06.720p.HDTV.x-DIMENSION.part5.rar
2015-11-12 23:49 - 2015-11-12 23:53 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E06.720p.HDTV.x-DIMENSION.part4.rar
2015-11-12 23:48 - 2015-11-12 23:53 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E06.720p.HDTV.x-DIMENSION.part3.rar
2015-11-12 23:47 - 2015-11-12 23:52 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E06.720p.HDTV.x-DIMENSION.part2.rar
2015-11-12 23:47 - 2015-11-12 23:49 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E06.720p.HDTV.x-DIMENSION.part1.rar
2015-11-12 23:42 - 2015-11-12 23:43 - 154073668 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part6 (1).rar
2015-11-12 23:39 - 2015-11-12 23:42 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part5 (1).rar
2015-11-12 23:38 - 2015-11-12 23:42 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part4 (1).rar
2015-11-12 23:37 - 2015-11-12 23:42 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part3 (1).rar
2015-11-12 23:37 - 2015-11-12 23:41 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part2 (1).rar
2015-11-12 23:36 - 2015-11-12 23:39 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part1 (2).rar
2015-11-12 23:33 - 2015-11-12 23:35 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part1 (1).rar
2015-11-12 23:20 - 2015-11-12 23:23 - 154073668 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part6.rar
2015-11-12 23:18 - 2015-11-12 23:23 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part5.rar
2015-11-12 23:17 - 2015-11-12 23:23 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part4.rar
2015-11-12 23:10 - 2015-11-12 23:12 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part3.rar
2015-11-12 23:09 - 2015-11-12 23:11 - 209715200 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part2.rar
2015-11-12 22:34 - 2015-11-12 22:38 - 85243611 _____ C:\Users\Simeon\Downloads\Arrow.S04E05.720p.HDTV.x-DIMENSION.part1.rar
2015-11-10 15:43 - 2015-11-10 15:45 - 173351164 _____ C:\Users\Simeon\Downloads\hw_final.zip
2015-11-05 01:37 - 2015-11-05 01:37 - 00006228 _____ C:\Users\Simeon\Downloads\friberg.rar
2015-11-05 01:37 - 2015-11-05 01:37 - 00003846 _____ C:\Users\Simeon\Downloads\Get_right.rar
2015-11-05 01:37 - 2015-11-05 01:37 - 00003719 _____ C:\Users\Simeon\Downloads\dupreeh.cfg
2015-11-05 01:36 - 2015-11-05 01:36 - 00032633 _____ C:\Users\Simeon\Downloads\[navi-gaming.com]guardian_new_config_2014.rar
2015-11-05 01:33 - 2015-11-05 01:33 - 00067889 _____ C:\Users\Simeon\Downloads\shox.rar
2015-11-05 01:33 - 2015-11-05 01:33 - 00067889 _____ C:\Users\Simeon\Downloads\shox (1).rar
2015-11-05 01:33 - 2015-11-05 01:33 - 00006408 _____ C:\Users\Simeon\Downloads\ScreaM_cfg_2015-09-23.zip
2015-11-05 00:22 - 2015-11-05 00:22 - 00000219 _____ C:\Users\Simeon\Desktop\Counter-Strike Global Offensive.url
2015-11-05 00:13 - 2015-11-26 20:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-11-05 00:13 - 2015-11-05 00:13 - 00001040 _____ C:\Users\Public\Desktop\Steam.lnk
2015-11-05 00:12 - 2015-11-05 00:12 - 01476720 _____ C:\Users\Simeon\Downloads\SteamSetup (11).exe
2015-11-04 18:48 - 2015-11-04 18:48 - 00386096 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-11-04 18:47 - 2015-11-04 18:47 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-11-04 14:00 - 2015-11-04 14:00 - 01476720 _____ C:\Users\Simeon\Downloads\SteamSetup (10).exe
2015-11-03 14:16 - 2015-11-03 14:16 - 01476720 _____ C:\Users\Simeon\Downloads\SteamSetup (9).exe
2015-11-03 14:15 - 2015-11-03 14:16 - 01476720 _____ C:\Users\Simeon\Downloads\SteamSetup (8).exe
2015-11-01 23:12 - 2015-11-01 23:13 - 01476720 _____ C:\Users\Simeon\Downloads\SteamSetup (7).exe
2015-11-01 23:12 - 2015-11-01 23:12 - 01476720 _____ C:\Users\Simeon\Downloads\SteamSetup (6).exe
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-12-01 14:42 - 2015-10-30 07:28 - 00000000 ____D C:\Windows
2015-12-01 14:40 - 2014-05-25 18:55 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Skype
2015-12-01 14:15 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-01 14:15 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-01 14:09 - 2014-07-24 17:07 - 00004174 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{84A861DF-DBA4-44D4-A2E4-B064A3A08795}
2015-12-01 14:08 - 2015-01-05 18:27 - 00001150 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-01 14:07 - 2015-05-06 18:58 - 00000000 ____D C:\Program Files (x86)\Steam
2015-12-01 14:07 - 2015-01-05 18:27 - 00001146 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-01 00:36 - 2014-09-26 21:50 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\TS3Client
2015-12-01 00:05 - 2015-07-19 21:13 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-30 23:54 - 2015-06-18 15:43 - 00001260 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2194020832-3275982821-4177272209-1002UA.job
2015-11-30 21:42 - 2015-04-13 15:10 - 00000422 _____ C:\WINDOWS\Tasks\update-sys.job
2015-11-30 21:05 - 2015-10-30 19:35 - 00776766 _____ C:\WINDOWS\system32\perfh007.dat
2015-11-30 21:05 - 2015-10-30 19:35 - 00155544 _____ C:\WINDOWS\system32\perfc007.dat
2015-11-30 21:05 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2015-11-30 21:05 - 2015-09-15 19:51 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Opera Software
2015-11-30 21:05 - 2015-09-15 19:51 - 00000000 ____D C:\Users\Simeon\AppData\Local\Opera Software
2015-11-30 21:05 - 2015-08-01 14:23 - 01799166 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-30 20:51 - 2015-04-13 15:10 - 00000422 _____ C:\WINDOWS\Tasks\update-S-1-5-21-2194020832-3275982821-4177272209-1002.job
2015-11-30 20:03 - 2015-08-01 17:40 - 00000000 ____D C:\Users\Simeon\AppData\Local\MicrosoftEdge
2015-11-30 18:54 - 2015-01-09 21:08 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2015-11-30 18:54 - 2013-11-20 18:40 - 00000000 ____D C:\ProgramData\Temp
2015-11-30 18:52 - 2013-08-02 16:04 - 00000000 ____D C:\WINDOWS\oem
2015-11-30 18:52 - 2013-08-02 16:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2015-11-30 18:52 - 2013-08-02 16:04 - 00000000 ____D C:\ProgramData\Acer
2015-11-30 18:52 - 2013-08-02 16:04 - 00000000 ____D C:\Program Files (x86)\Acer
2015-11-30 18:48 - 2014-05-27 17:54 - 00000000 ____D C:\ProgramData\Apple
2015-11-30 18:34 - 2014-09-03 22:23 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-30 18:28 - 2013-11-20 18:36 - 00000000 ____D C:\ProgramData\NortonInstaller
2015-11-30 18:28 - 2013-11-20 18:36 - 00000000 ____D C:\Program Files (x86)\Norton Online Backup ARA
2015-11-30 18:09 - 2014-08-14 23:46 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-11-30 18:09 - 2014-08-14 23:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-11-30 18:00 - 2015-07-20 22:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-30 17:57 - 2014-08-09 00:08 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-30 17:10 - 2014-07-18 16:22 - 00000000 __SHD C:\Users\Simeon\IntelGraphicsProfiles
2015-11-30 00:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-11-29 20:50 - 2014-05-25 18:55 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-11-29 20:02 - 2015-07-28 19:12 - 00001017 _____ C:\Users\Simeon\Desktop\Start Tor Browser.lnk
2015-11-29 17:47 - 2013-11-20 18:37 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-11-29 17:37 - 2015-10-30 07:28 - 00008192 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-29 13:54 - 2015-06-18 15:42 - 00001208 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2194020832-3275982821-4177272209-1002Core.job
2015-11-29 03:42 - 2015-10-23 16:01 - 00000000 ____D C:\Users\Simeon\AppData\Local\JDownloader 2.0
2015-11-29 01:19 - 2015-09-15 19:59 - 00000946 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-11-29 00:29 - 2014-06-13 21:07 - 00000000 ___RD C:\Users\Simeon\Desktop\blah
2015-11-29 00:28 - 2015-01-05 19:16 - 00000000 ____D C:\Users\Simeon\Desktop\Simeon Musik
2015-11-27 21:36 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-27 13:46 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\appcompat
2015-11-26 21:17 - 2014-05-25 18:03 - 00000000 ____D C:\Users\Simeon\AppData\Local\Packages
2015-11-26 21:12 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2015-11-26 21:04 - 2015-08-01 17:28 - 00002410 _____ C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-11-26 21:04 - 2014-07-18 15:35 - 00000000 __RDO C:\Users\Simeon\OneDrive
2015-11-26 20:56 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2015-11-26 20:53 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-11-26 20:53 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-11-26 20:53 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-11-26 20:52 - 2014-05-08 13:39 - 00000000 __RHD C:\Users\Public\AccountPictures
2015-11-26 20:50 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows NT
2015-11-26 20:49 - 2014-07-18 14:57 - 00041913 _____ C:\WINDOWS\diagwrn.xml
2015-11-26 20:49 - 2014-07-18 14:57 - 00041913 _____ C:\WINDOWS\diagerr.xml
2015-11-26 20:46 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-11-26 20:46 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration
2015-11-26 20:41 - 2014-07-18 15:21 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-11-26 20:40 - 2015-09-15 19:59 - 00003404 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2015-11-26 20:40 - 2015-07-19 21:13 - 00003098 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-26 20:40 - 2015-07-08 15:37 - 00002668 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachineDaily
2015-11-26 20:40 - 2015-06-18 15:43 - 00003876 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2194020832-3275982821-4177272209-1002UA
2015-11-26 20:40 - 2015-06-18 15:42 - 00003604 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2194020832-3275982821-4177272209-1002Core
2015-11-26 20:40 - 2015-04-13 15:10 - 00003058 _____ C:\WINDOWS\System32\Tasks\update-S-1-5-21-2194020832-3275982821-4177272209-1002
2015-11-26 20:40 - 2015-04-13 15:10 - 00002856 _____ C:\WINDOWS\System32\Tasks\update-sys
2015-11-26 20:40 - 2015-01-14 22:31 - 00002300 _____ C:\WINDOWS\System32\Tasks\{92FF06CD-8D86-4E45-96E7-1BE9BB85AA3D}
2015-11-26 20:40 - 2015-01-14 22:31 - 00002300 _____ C:\WINDOWS\System32\Tasks\{4B1CD73C-F434-4C00-B979-BD691703A46C}
2015-11-26 20:40 - 2015-01-05 18:27 - 00003662 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-11-26 20:40 - 2015-01-05 18:27 - 00003438 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-11-26 20:40 - 2014-11-19 23:50 - 00002676 _____ C:\WINDOWS\System32\Tasks\{FE37CCD8-5799-4A7D-9B0B-C9BB5E5B9E97}
2015-11-26 20:40 - 2014-09-17 12:54 - 00002260 _____ C:\WINDOWS\System32\Tasks\{BC94A892-74D7-420D-BF66-58B8F5654AF6}
2015-11-26 20:40 - 2014-09-03 22:44 - 00002954 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-11-26 20:40 - 2014-06-02 12:35 - 00002528 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachine
2015-11-26 20:40 - 2014-05-25 18:12 - 00002940 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2194020832-3275982821-4177272209-1002
2015-11-26 20:40 - 2013-11-20 18:33 - 00002248 _____ C:\WINDOWS\System32\Tasks\Power Management
2015-11-26 20:40 - 2013-11-20 18:17 - 00001848 _____ C:\WINDOWS\System32\Tasks\Dolby Selector
2015-11-26 20:40 - 2013-08-02 16:04 - 00002238 _____ C:\WINDOWS\System32\Tasks\Launch Manager
2015-11-26 20:39 - 2015-10-30 08:24 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-26 20:27 - 2015-10-30 19:44 - 00000000 ____D C:\WINDOWS\ShellNew
2015-11-26 20:27 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Help
2015-11-26 20:27 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-11-26 20:27 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-11-26 20:27 - 2015-10-23 16:31 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2015-11-26 20:27 - 2015-10-02 23:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2015-11-26 20:27 - 2015-09-30 21:12 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-11-26 20:27 - 2015-06-13 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
2015-11-26 20:27 - 2015-02-17 20:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-11-26 20:27 - 2015-01-15 21:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2015-11-26 20:27 - 2015-01-14 22:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2015-11-26 20:27 - 2015-01-10 14:41 - 00000000 ____D C:\WINDOWS\SysWOW64\vbox
2015-11-26 20:27 - 2015-01-10 14:41 - 00000000 ____D C:\WINDOWS\system32\vbox
2015-11-26 20:27 - 2015-01-09 21:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2015-11-26 20:27 - 2015-01-09 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
2015-11-26 20:27 - 2015-01-06 18:53 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2015-11-26 20:27 - 2015-01-05 18:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-26 20:27 - 2014-09-03 22:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-26 20:27 - 2014-08-15 17:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
2015-11-26 20:27 - 2014-07-18 16:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-26 20:27 - 2014-07-11 17:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-11-26 20:27 - 2014-06-20 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2015-11-26 20:27 - 2014-06-14 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-26 20:27 - 2014-06-07 15:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-11-26 20:27 - 2014-06-02 12:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
2015-11-26 20:27 - 2014-06-01 00:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2015-11-26 20:27 - 2014-05-29 15:21 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2015-11-26 20:27 - 2014-05-29 02:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-11-26 20:27 - 2014-05-25 20:08 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-26 20:27 - 2014-05-25 20:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-26 20:27 - 2013-08-02 16:01 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-11-26 20:23 - 2015-07-10 10:05 - 00000000 ____D C:\Users\Default.migrated
2015-11-26 20:19 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spool
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\IME
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\et-EE
2015-11-26 20:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\en-GB
2015-11-26 20:19 - 2014-05-25 20:26 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2015-11-26 20:19 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2015-11-26 20:19 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2015-11-26 20:17 - 2015-10-30 19:36 - 00000000 ____D C:\WINDOWS\OCR
2015-11-26 20:17 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-11-26 20:17 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-11-26 20:16 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2015-11-26 20:16 - 2015-10-30 08:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-11-26 20:16 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InputMethod
2015-11-26 20:16 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\USOPrivate
2015-11-26 20:16 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\System
2015-11-26 20:16 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-11-26 20:16 - 2015-08-28 13:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-11-26 20:16 - 2015-04-28 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries
2015-11-26 20:16 - 2014-06-12 14:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaHuman
2015-11-26 20:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\ADFS
2015-11-26 20:14 - 2014-11-22 18:16 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-11-26 20:09 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-11-26 20:06 - 2014-10-06 22:29 - 00000000 ____D C:\Temp
2015-11-26 19:59 - 2015-10-30 19:55 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2015-11-26 19:58 - 2015-10-30 08:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-11-26 19:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-11-26 19:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-26 19:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Provisioning
2015-11-26 19:54 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-11-26 19:54 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-11-26 19:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2015-11-26 19:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MUI
2015-11-26 19:47 - 2015-10-30 08:17 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2015-11-26 19:47 - 2015-10-30 08:17 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2015-11-26 19:47 - 2015-10-30 08:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2015-11-26 19:47 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2015-11-26 19:47 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2015-11-26 19:03 - 2015-10-30 20:27 - 00000000 ___HD C:\$WINDOWS.~BT
2015-11-26 01:23 - 2014-05-30 20:12 - 00000000 ____D C:\Users\Simeon\AppData\Local\Spotify
2015-11-26 01:19 - 2014-05-30 20:12 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Spotify
2015-11-25 21:50 - 2014-09-03 22:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-20 13:29 - 2014-05-25 18:55 - 00000000 ____D C:\ProgramData\Skype
2015-11-13 19:19 - 2014-09-03 22:57 - 00000000 ____D C:\Users\Simeon\AppData\Roaming\Dropbox
2015-11-11 23:40 - 2015-06-13 15:51 - 00000000 ____D C:\Users\Simeon\AppData\Local\CyberGhost
2015-11-11 23:10 - 2015-01-05 18:28 - 00002256 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-11-10 23:27 - 2015-09-30 21:02 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-10 23:13 - 2014-05-27 20:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-10 23:13 - 2012-07-26 06:26 - 00000199 _____ C:\WINDOWS\win.ini
2015-11-10 23:03 - 2014-05-27 20:30 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-04 18:48 - 2014-09-03 22:42 - 00449992 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-11-04 18:48 - 2014-09-03 22:42 - 00273784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-11-04 18:48 - 2014-09-03 22:42 - 00154256 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-11-04 18:48 - 2014-09-03 22:42 - 00097648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-11-04 18:48 - 2014-09-03 22:42 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-11-04 18:48 - 2014-09-03 22:42 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-11-04 18:48 - 2014-09-03 22:42 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-11-04 18:47 - 2014-09-03 22:42 - 01059656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-11-03 01:12 - 2015-10-30 08:26 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-03 01:12 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2014-09-22 22:47 - 2014-12-20 14:42 - 0000004 _____ () C:\Users\Simeon\AppData\Roaming\appdataFr2.bin
2015-04-13 15:10 - 2015-04-13 15:10 - 0000003 _____ () C:\Users\Simeon\AppData\Local\updater.log
2015-04-13 15:10 - 2015-10-02 23:38 - 0000424 _____ () C:\Users\Simeon\AppData\Local\UserProducts.xml
2015-11-26 20:06 - 2015-11-26 20:06 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-09-29 17:05 - 2015-09-29 17:05 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Einige Dateien in TEMP:
====================
C:\Users\Simeon\AppData\Local\Temp\{311739EB-5C94-4EE1-B911-2D1F005060F4}_NARA_9953.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-11-26 19:59
==================== Ende von FRST.txt ============================ --- --- --- |