El_Hardy | 29.05.2017 06:26 | Sollte ich den COde noch irgendwohin kopieren?
Fixlog: Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 28-05-2017
durchgeführt von Hardy (29-05-2017 07:03:42) Run:1
Gestartet von C:\Users\Hardy\Desktop\NÜTZLICH\Antivir-Zeug
Geladene Profile: Hardy (Verfügbare Profile: Hardy & Administrator)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
closeprocesses:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\Run: [background_fault] => C:\Users\Hardy\AppData\Local\background_fault\aswRD.exe [1419576 2017-05-27] (AVAST Software) <===== ACHTUNG
IFEO\GoogleUpdate.exe: [Debugger] 324095823984.exe
IFEO\GoogleUpdaterService.exe: [Debugger] 8736459873644.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Keine Datei
Toolbar: HKU\S-1-5-21-2570889560-1274126736-4133381010-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\lxdrst7r.default -> Search
FF Extension: (TLS 1.3 A/B Test Experiment) - C:\Users\Hardy\AppData\Roaming\Mozilla\Firefox\Profiles\lxdrst7r.default\features\{3d15c9f6-c448-4e7d-953a-bfc7814ca1c3}\tls13-comparison-all-v1@mozilla.org.xpi [2017-03-27]
FF HKLM-x32\...\Firefox\Extensions: [dnshelp@dnshelp.com] - C:\Users\Hardy\AppData\Roaming\Helper
FF Extension: (Helper) - C:\Users\Hardy\AppData\Roaming\Helper [2014-08-15] [ist nicht signiert]
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.mystarting123.com/search/index.php?z=c6b1474d1208226a98e6fabg1z0tew2q0o0o1c7e8c&q={searchTerms}
CHR DefaultSearchKeyword: ChromeDefaultData -> mystarting123
CHR Profile: C:\Users\Hardy\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-05-28] <==== ACHTUNG
R2 BIT; C:\ProgramData\BIT\BIT.dll [1812992 2017-05-27] (TODO: <公司名>) [Datei ist nicht signiert] <==== ACHTUNG
S2 terana; C:\Users\Hardy\AppData\Local\terana\terana.dll [908288 2017-05-27] (IntertSect Alliance Pty Ltd) [Datei ist nicht signiert] <==== ACHTUNG
R2 WinSAPSvc; C:\Users\Hardy\AppData\Roaming\WinSAPSvc\WinSAP.dll [1932800 2017-05-27] () [Datei ist nicht signiert] <==== ACHTUNG
2017-05-28 14:56 - 2017-05-28 14:57 - 00000000 _____ C:\end
2017-05-27 18:39 - 2017-05-28 19:39 - 00000000 _____ C:\WINDOWS\SysWOW64\1
2017-05-27 13:57 - 2017-05-27 13:57 - 00000000 ____D C:\Users\Hardy\AppData\Local\background_fault
2017-05-27 13:57 - 2017-05-27 13:57 - 00000000 ____D C:\ProgramData\BIT
2017-05-27 13:56 - 2017-05-27 13:57 - 00000000 ____D C:\Program Files (x86)\MIO
2017-05-27 13:56 - 2017-05-27 13:56 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\WinSAPSvc
2017-05-27 13:56 - 2017-05-27 13:56 - 00000000 ____D C:\Users\Hardy\AppData\Local\terana
2017-05-27 13:56 - 2017-05-27 13:56 - 00000000 ____D C:\Pipisy
2017-05-24 14:35 - 2017-05-24 14:35 - 00000000 _____ C:\WINDOWS\SysWOW64\1111
2017-05-26 01:54 - 2015-12-02 02:08 - 00000000 ____D C:\Users\Hardy\Downloads\Pepakura.Designer.v3.0.3b.Incl.Keymaker-CORE
2017-04-28 14:11 - 2017-04-27 13:31 - 00000000 _____ C:\WINDOWS\SysWOW64\22
2017-04-28 14:11 - 2017-04-27 13:31 - 00000000 _____ C:\WINDOWS\SysWOW64\11
Task: {4F476EA5-407C-4B1D-B88E-B3699D1B5004} - System32\Tasks\{E299C8C9-0B72-457B-8A9C-90007BD552AA} => pcalua.exe -a E:\X3.exe -d E:\
Task: {6CB48E4C-761F-4C73-A762-EFB3CA811A06} - System32\Tasks\Milimili => C:\Program Files (x86)\MIO\MIO.exe [2017-05-27] () <==== ACHTUNG
Task: {793733B3-85F0-46D8-87A2-B6E1B7F3D5B3} - \ASC10_SkipUac_Hardy -> Keine Datei <==== ACHTUNG
Task: {FA691F52-FF4C-408B-AC18-58616239038E} - \Jogosh -> Keine Datei <==== ACHTUNG
HKLM\...\StartupApproved\Run: => "SaiMfd"
HKLM\...\StartupApproved\Run: => "ProfilerU"
HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8"
HKLM\...\StartupApproved\Run32: => "AvastUI.exe"
HKLM\...\StartupApproved\Run32: => "EsternTimesMouseExRun"
HKLM\...\StartupApproved\Run32: => "ABNotify"
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\StartupApproved\Run: => "CAHeadless"
FirewallRules: [TCP Query User{50DC1D1C-BB8A-4B54-812F-DB29419A1CF2}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [UDP Query User{22E4CCDA-0CAF-42C8-8C33-6C9F2380C501}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [{6D7CDBD9-B779-4290-9153-3A48D2CF6A70}] => (Allow) C:\Program Files (x86)\Setleaf\Application\chrome.exe
emptytemp:
*****************
Prozesse erfolgreich geschlossen.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\Software\Microsoft\Windows\CurrentVersion\Run\\background_fault => Wert erfolgreich entfernt
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\GoogleUpdate.exe => Schlüssel erfolgreich entfernt
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\GoogleUpdaterService.exe => Schlüssel erfolgreich entfernt
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => Schlüssel erfolgreich entfernt
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Schlüssel nicht gefunden.
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wert erfolgreich entfernt
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Schlüssel nicht gefunden.
Firefox SelectedSearchEngine erfolgreich entfernt
C:\Users\Hardy\AppData\Roaming\Mozilla\Firefox\Profiles\lxdrst7r.default\features\{3d15c9f6-c448-4e7d-953a-bfc7814ca1c3}\tls13-comparison-all-v1@mozilla.org.xpi => erfolgreich verschoben
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\dnshelp@dnshelp.com => Wert erfolgreich entfernt
C:\Users\Hardy\AppData\Roaming\Helper => erfolgreich verschoben
Chrome DefaultSearchURL => erfolgreich entfernt
Chrome DefaultSearchKeyword => erfolgreich entfernt
C:\Users\Hardy\AppData\Local\Google\Chrome\User Data\ChromeDefaultData => erfolgreich verschoben
BIT => Dienst konnte nicht gestoppt werden.
HKLM\System\CurrentControlSet\Services\BIT => Schlüssel erfolgreich entfernt
BIT => Dienst erfolgreich entfernt
HKLM\System\CurrentControlSet\Services\terana => Schlüssel erfolgreich entfernt
terana => Dienst erfolgreich entfernt
WinSAPSvc => Dienst konnte nicht gestoppt werden.
HKLM\System\CurrentControlSet\Services\WinSAPSvc => Schlüssel erfolgreich entfernt
WinSAPSvc => Dienst erfolgreich entfernt
C:\end => erfolgreich verschoben
C:\WINDOWS\SysWOW64\1 => erfolgreich verschoben
C:\Users\Hardy\AppData\Local\background_fault => erfolgreich verschoben
C:\ProgramData\BIT => erfolgreich verschoben
C:\Program Files (x86)\MIO => erfolgreich verschoben
C:\Users\Hardy\AppData\Roaming\WinSAPSvc => erfolgreich verschoben
C:\Users\Hardy\AppData\Local\terana => erfolgreich verschoben
C:\Pipisy => erfolgreich verschoben
C:\WINDOWS\SysWOW64\1111 => erfolgreich verschoben
C:\Users\Hardy\Downloads\Pepakura.Designer.v3.0.3b.Incl.Keymaker-CORE => erfolgreich verschoben
C:\WINDOWS\SysWOW64\22 => erfolgreich verschoben
C:\WINDOWS\SysWOW64\11 => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4F476EA5-407C-4B1D-B88E-B3699D1B5004} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F476EA5-407C-4B1D-B88E-B3699D1B5004} => Schlüssel erfolgreich entfernt
C:\WINDOWS\System32\Tasks\{E299C8C9-0B72-457B-8A9C-90007BD552AA} => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E299C8C9-0B72-457B-8A9C-90007BD552AA} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6CB48E4C-761F-4C73-A762-EFB3CA811A06} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6CB48E4C-761F-4C73-A762-EFB3CA811A06} => Schlüssel erfolgreich entfernt
C:\WINDOWS\System32\Tasks\Milimili => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Milimili => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{793733B3-85F0-46D8-87A2-B6E1B7F3D5B3} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{793733B3-85F0-46D8-87A2-B6E1B7F3D5B3} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC10_SkipUac_Hardy => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA691F52-FF4C-408B-AC18-58616239038E} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA691F52-FF4C-408B-AC18-58616239038E} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Jogosh => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\SaiMfd => Wert erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SaiMfd => Wert nicht gefunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\ProfilerU => Wert erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ProfilerU => Wert nicht gefunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\CLMLServer_For_P2G8 => Wert erfolgreich entfernt
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\CLMLServer_For_P2G8 => Wert nicht gefunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\AvastUI.exe => Wert erfolgreich entfernt
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AvastUI.exe => Wert nicht gefunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\EsternTimesMouseExRun => Wert erfolgreich entfernt
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\EsternTimesMouseExRun => Wert nicht gefunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\ABNotify => Wert erfolgreich entfernt
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ABNotify => Wert nicht gefunden.
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\CAHeadless => Wert erfolgreich entfernt
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CAHeadless => Wert nicht gefunden.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{50DC1D1C-BB8A-4B54-812F-DB29419A1CF2}C:\windows\syswow64\dplaysvr.exe => Wert erfolgreich entfernt
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{22E4CCDA-0CAF-42C8-8C33-6C9F2380C501}C:\windows\syswow64\dplaysvr.exe => Wert erfolgreich entfernt
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6D7CDBD9-B779-4290-9153-3A48D2CF6A70} => Wert erfolgreich entfernt
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 17064895 B
Java, Flash, Steam htmlcache => 619209744 B
Windows/system/drivers => 121622 B
Edge => 0 B
Chrome => 0 B
Firefox => 12488493 B
Opera => 436340236 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 10811038 B
LocalService => 6546 B
NetworkService => 0 B
Hardy => 97380567 B
Administrator => 4503501 B
RecycleBin => 0 B
EmptyTemp: => 1.1 GB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 07:08:04 ==== FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 28-05-2017
durchgeführt von Hardy (Administrator) auf JAMES (29-05-2017 07:16:37)
Gestartet von C:\Users\Hardy\Desktop\NÜTZLICH\Antivir-Zeug
Geladene Profile: Hardy (Verfügbare Profile: Hardy & Administrator)
Platform: Windows 8.1 (Update) (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Opera)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe
(Microsoft) C:\Program Files (x86)\GIGABYTE\CloudStation_Server\HomeCloud\GCloud.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft) C:\Program Files (x86)\GIGABYTE\CloudStation_Server\HomeCloud\HCLOUD.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
() C:\Program Files (x86)\GIGABYTE\CloudStation_Server\RemoteControl\grckm.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Program Files (x86)\GIGABYTE\CloudStation_Server\RemoteOC\ubssrv_oc_only.exe
(Mr. John aka japamd) C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe
(GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngine.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\SIV\thermald.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\livecomm.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Rapoo) C:\Program Files (x86)\Rapoo\V700\V700Config.exe
() C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe
(Opera Software) C:\Program Files (x86)\Opera\45.0.2552.812\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\45.0.2552.812\opera_crashreporter.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
(Opera Software) C:\Program Files (x86)\Opera\45.0.2552.812\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\45.0.2552.812\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\45.0.2552.812\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\45.0.2552.812\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\45.0.2552.812\opera.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [478984 2012-12-15] (Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15033976 2015-11-20] (Logitech Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-11-20] (IDT, Inc.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2013-11-20] (Hewlett-Packard )
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9197568 2017-05-22] (Realtek Semiconductor)
HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-05-23] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14522512 2017-04-03] (Copyright 2017.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-05-23] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2016-11-04] (Razer Inc.)
HKLM-x32\...\Run: [Rapoo V700] => C:\Program Files (x86)\Rapoo\V700\load.exe [808760 2014-04-30] ()
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58584 2016-09-29] (Raptr, Inc)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-05-23] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [6153128 2017-05-22] (LogMeIn Inc.)
HKLM-x32\...\RunOnce: [EasyTuneEngineService] => C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EngineRunOnce.exe [8192 2015-08-05] (GIGA-BYTE TECHNOLOGY CO., LTD.)
HKLM-x32\...\RunOnce: [SIV] => C:\Program Files (x86)\GIGABYTE\SIV\sivro.exe [12096 2015-08-11] (GIGA-BYTE TECHNOLOGY CO., LTD.)
HKLM-x32\...\RunOnce: [EasyTune] => C:\Program Files (x86)\GIGABYTE\EasyTune\etro.exe [5632 2015-08-05] (GIGA-BYTE TECHNOLOGY CO., LTD.)
HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe [8192 2013-04-29] ()
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9772248 2017-05-05] (Piriform Ltd)
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\MountPoints2: {182bb6d7-7546-11e3-bf81-b4b52fd91f16} - "H:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\MountPoints2: {292e2fcd-3875-11e6-80d8-b4b52fd91f16} - "I:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\MountPoints2: {858bc1f3-5612-11e5-bfcd-b4b52fd91f16} - "I:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\MountPoints2: {882e6f95-ead9-11e6-81b3-b4b52fd91f16} - "E:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\MountPoints2: {a0968113-b115-11e4-bf1d-b4b52fd91f16} - "H:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\MountPoints2: {bce95545-5557-11e5-bfcc-b4b52fd91f16} - "I:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\MountPoints2: {bce95547-5557-11e5-bfcc-b4b52fd91f16} - "I:\HTC_Sync_Manager_PC.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-08-20]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{7A68117C-CA3D-4CD2-93E3-92CA12B9A7C3}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{7A68117C-CA3D-4CD2-93E3-92CA12B9A7C3}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{C155D1A7-613D-45C6-9A05-87C4F655EEA6}: [DhcpNameServer] 192.168.0.1
ManualProxies:
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKLM -> {43F6ABD5-68C5-4060-A10F-AEAA1B6C98A7} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-2570889560-1274126736-4133381010-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2570889560-1274126736-4133381010-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKU\S-1-5-21-2570889560-1274126736-4133381010-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-17] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-17] (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Hardy\AppData\Roaming\Mozilla\Firefox\Profiles\lxdrst7r.default [2017-05-29]
FF NewTab: Mozilla\Firefox\Profiles\lxdrst7r.default -> about:newtab
FF Homepage: Mozilla\Firefox\Profiles\lxdrst7r.default -> www.google.de/
FF Extension: (AVG Web TuneUp) - C:\Users\Hardy\AppData\Roaming\Mozilla\Firefox\Profiles\lxdrst7r.default\Extensions\avg@toolbar.xpi [2017-05-09]
FF Extension: (MEGA) - C:\Users\Hardy\AppData\Roaming\Mozilla\Firefox\Profiles\lxdrst7r.default\Extensions\firefox@mega.co.nz.xpi [2017-05-04]
FF Extension: (Adblock Plus) - C:\Users\Hardy\AppData\Roaming\Mozilla\Firefox\Profiles\lxdrst7r.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24]
FF HKU\S-1-5-21-2570889560-1274126736-4133381010-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: (McAfee Security Scan Plus) - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-09] ()
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-17] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-12-15] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-09] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 -> C:\WINDOWS\SysWOW64\npDeployJava1.dll [2014-12-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - Chrome.exe
Opera:
=======
OPR Extension: (Video Downloader Pro) - C:\Users\Hardy\AppData\Roaming\Opera Software\Opera Stable\Extensions\ibehiiilehaakkhkigckfjfknboalpbe [2017-02-03]
StartMenuInternet: (HKLM) OperaStable - Opera.exe
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 AppleChargerSrv; C:\WINDOWS\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [1002552 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5334432 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-05-23] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [729048 2017-04-11] (AVG Technologies CZ, s.r.o.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1486344 2017-02-07] ()
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2017-05-28] (BitRaider, LLC)
R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [138240 2015-08-05] (GIGA-BYTE TECHNOLOGY CO., LTD.) [Datei ist nicht signiert]
R2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [Datei ist nicht signiert]
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [284736 2017-02-23] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6625856 2016-12-04] (GOG.com)
R2 GCloud; C:\Program Files (x86)\GIGABYTE\CloudStation_Server\HomeCloud\GCloud.exe [19776 2015-03-23] (Microsoft)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3760040 2017-05-22] (LogMeIn Inc.)
S4 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35232 2012-08-29] (Hewlett-Packard)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [33640 2017-04-07] (HP Inc.)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-06-27] (Nero AG)
S3 HwmRecordService; C:\Program Files (x86)\GIGABYTE\SIV\HwmRecordService.exe [62784 2015-08-11] (GIGA-BYTE TECHNOLOGY CO., LTD.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2015-11-20] (Logitech Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S2 OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [117760 2015-08-05] (GIGA-BYTE TECHNOLOGY CO., LTD.) [Datei ist nicht signiert]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2145288 2017-04-04] (Electronic Arts)
S3 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3114512 2017-04-04] (Electronic Arts)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [Datei ist nicht signiert]
S3 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2016-10-04] ()
S3 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2017-03-07] ()
R2 RadeonPro Support Service; C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe [20608 2013-11-04] (Mr. John aka japamd) [Datei ist nicht signiert]
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [69744 2016-10-18] (Razer Inc.)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] ()
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) [Datei ist nicht signiert]
S2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-11-20] (IDT, Inc.) [Datei ist nicht signiert]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14522512 2017-04-03] (Copyright 2017.)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 amdacpksd; C:\WINDOWS\system32\drivers\amdacpksd.sys [305544 2017-05-22] (Advanced Micro Devices)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R1 AppleCharger; C:\WINDOWS\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] ()
S3 ASPI; C:\WINDOWS\SysWOW64\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [Datei ist nicht signiert]
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWB6.sys [118848 2016-08-09] (Advanced Micro Devices)
S2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [303616 2014-09-28] () [Datei ist nicht signiert]
S0 Avgboota; C:\WINDOWS\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\WINDOWS\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdrivera.sys [313088 2017-02-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\WINDOWS\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\WINDOWS\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\WINDOWS\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\WINDOWS\System32\DRIVERS\avgmfx64.sys [253184 2017-04-11] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\WINDOWS\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 avguniva; C:\WINDOWS\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys [313096 2016-08-04] (AVG Technologies CZ, s.r.o.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2017-05-28] (BitRaider)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283064 2014-09-22] (Disc Soft Ltd)
R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-03-22] ()
S3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2017-05-22] (LogMeIn Inc.)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [54736 2017-04-22] ()
S3 HtcVCom32; C:\WINDOWS\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) [Datei ist nicht signiert]
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-05-22] (REALiX(tm))
R3 iusb3adp; C:\WINDOWS\System32\drivers\iusb3adp.sys [37472 2017-05-22] (Intel)
S3 ladfGSS; C:\WINDOWS\system32\drivers\ladfGSS.sys [45208 2017-05-22] (Logitech Inc.)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.)
S3 lgLowAudio; C:\WINDOWS\system32\drivers\lgLowAudio.sys [26264 2015-11-20] (Logitech Inc.)
S2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [35328 2014-09-28] () [Datei ist nicht signiert]
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [186304 2017-05-04] (Malwarebytes)
S3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [111544 2017-05-04] (Malwarebytes)
S3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-05-04] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [251832 2017-05-29] (Malwarebytes)
S3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [92096 2017-05-04] (Malwarebytes)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rpvmsd; C:\WINDOWS\system32\drivers\rpvmsd.sys [22016 2013-07-05] (RAPOO)
R3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [51736 2016-06-22] (Razer Inc)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.)
R3 SaiMini; C:\WINDOWS\System32\drivers\SaiMini.sys [24152 2016-07-18] (Saitek)
R3 SaiNtBus; C:\WINDOWS\system32\drivers\SaiBus.sys [59736 2016-07-18] (Saitek)
S3 STHDA; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [551936 2013-11-20] (IDT, Inc.) [Datei ist nicht signiert]
S1 UsbCharger; C:\WINDOWS\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2017-04-22] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-04-22] (Zemana Ltd.)
S3 _hid_0738_1703; C:\WINDOWS\system32\DRIVERS\_hid_0738_1703.sys [210408 2016-07-18] (Saitek)
S3 _usb_0738_1703; C:\WINDOWS\System32\drivers\_usb_0738_1703.sys [46824 2016-07-18] (Saitek)
S3 dcdbas; \SystemRoot\System32\drivers\dcdbas64.sys [X]
S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-05-28 18:28 - 2017-05-28 18:28 - 02870984 _____ (ESET) C:\Users\Hardy\Desktop\esetsmartinstaller_deu.exe
2017-05-28 16:18 - 2017-05-28 16:26 - 00000000 ____D C:\Users\Hardy\Documents\Stronghold
2017-05-28 15:12 - 2017-05-28 15:12 - 00000000 ____D C:\ProgramData\BitRaider
2017-05-28 14:57 - 2017-05-28 14:57 - 00000852 _____ C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2017-05-27 14:12 - 2017-05-27 14:12 - 00000000 ____D C:\Users\Hardy\AppData\Local\The Lord of the Rings Online
2017-05-27 06:27 - 2017-05-27 07:13 - 00000000 ____D C:\Users\Hardy\AppData\Local\Turbine
2017-05-27 06:27 - 2017-05-27 06:27 - 00000093 _____ C:\Users\Hardy\AppData\Local\fusioncache.dat
2017-05-27 06:27 - 2017-05-27 06:27 - 00000000 ____D C:\Users\Hardy\AppData\Local\ApplicationHistory
2017-05-27 06:23 - 2017-05-27 06:23 - 00000000 ____D C:\WINDOWS\SysWOW64\URTTEMP
2017-05-26 22:57 - 2017-05-26 23:25 - 00000000 ____D C:\Users\Hardy\Documents\NCSOFT
2017-05-26 21:08 - 2017-05-28 04:28 - 00000000 ____D C:\Users\Hardy\Documents\Stronghold Crusader
2017-05-26 21:06 - 2017-05-26 21:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefly Studios
2017-05-26 21:05 - 2017-05-26 21:05 - 00001922 _____ C:\Users\Public\Desktop\Stronghold.lnk
2017-05-26 21:02 - 2017-05-26 21:03 - 116773320 _____ (Acresso Software Inc. ) C:\Users\Hardy\Downloads\Stronghold_HD_Update.exe
2017-05-26 20:58 - 2017-05-26 20:58 - 00002120 _____ C:\Users\Public\Desktop\Stronghold Crusader Extreme.lnk
2017-05-26 20:58 - 2017-05-26 20:58 - 00002064 _____ C:\Users\Public\Desktop\Stronghold Crusader.lnk
2017-05-26 20:56 - 2017-05-26 21:03 - 00000000 ____D C:\Program Files (x86)\Firefly Studios
2017-05-26 20:45 - 2017-05-26 21:01 - 150844400 _____ (Acresso Software Inc. ) C:\Users\Hardy\Downloads\Stronghold_Crusader_HD_Update.exe
2017-05-26 20:05 - 2017-05-26 23:25 - 00000000 ____D C:\Program Files (x86)\NCSOFT
2017-05-26 20:04 - 2017-05-26 23:25 - 00000000 ____D C:\Users\Hardy\AppData\Local\NCSOFT
2017-05-26 20:04 - 2017-05-26 20:04 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\NCSOFT
2017-05-26 20:03 - 2017-05-26 20:04 - 02428616 _____ (NCSOFT) C:\Users\Hardy\Downloads\Wildstar.exe
2017-05-26 18:02 - 2017-05-26 18:02 - 00493127 _____ C:\Users\Hardy\Desktop\Malwarebytes.txt
2017-05-26 02:11 - 2017-05-26 02:14 - 00074425 _____ C:\Users\Hardy\Downloads\Addition.txt
2017-05-26 02:06 - 2017-05-26 02:14 - 00068646 _____ C:\Users\Hardy\Downloads\FRST.txt
2017-05-26 02:05 - 2017-05-29 07:16 - 00000000 ____D C:\FRST
2017-05-26 02:02 - 2017-05-29 07:12 - 00000176 _____ C:\Users\Hardy\BullseyeCoverageError.txt
2017-05-26 02:02 - 2017-05-26 02:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2017-05-26 02:02 - 2017-05-26 02:02 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2017-05-26 02:01 - 2017-05-26 02:02 - 00000176 _____ C:\Users\Default\BullseyeCoverageError.txt
2017-05-26 01:54 - 2017-05-26 01:54 - 00184136 _____ (Emsisoft Ltd) C:\WINDOWS\system32\eamclean.exe
2017-05-26 01:54 - 2017-05-26 01:54 - 00000300 _____ C:\WINDOWS\system32\eamclean.dat
2017-05-25 22:21 - 2017-05-25 22:21 - 00000000 ____D C:\ProgramData\Emsisoft
2017-05-25 22:20 - 2017-05-26 01:53 - 00000000 ____D C:\EEK
2017-05-25 22:11 - 2017-05-25 22:11 - 00005726 _____ C:\Users\Hardy\Desktop\JRT.txt
2017-05-25 14:41 - 2017-05-25 15:16 - 00000000 ____D C:\Users\Hardy\Desktop\SICHERUNG
2017-05-25 13:50 - 2017-05-26 17:12 - 00000000 ____D C:\AdwCleaner
2017-05-25 12:44 - 2017-05-25 12:44 - 00000000 ____D C:\Cosusp
2017-05-25 00:06 - 2017-05-25 00:07 - 149781056 _____ (Zenimax Online Studios) C:\Users\Hardy\Downloads\Install_ESO.exe
2017-05-24 17:42 - 2017-05-24 17:42 - 00000939 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk
2017-05-24 17:42 - 2017-05-24 17:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2
2017-05-24 17:42 - 2017-05-24 17:42 - 00000000 ____D C:\Program Files\Guild Wars 2
2017-05-24 16:34 - 2017-05-24 16:34 - 00000000 ____D C:\Users\Hardy\Downloads\totalRP3-1.2.8
2017-05-24 16:33 - 2017-05-24 16:33 - 00661440 _____ C:\Users\Hardy\Downloads\totalRP3-1.2.8.zip
2017-05-24 14:36 - 2017-05-25 11:39 - 00002018 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-05-22 19:15 - 2017-05-22 19:16 - 112206656 _____ (SQUARE ENIX CO., LTD.) C:\Users\Hardy\Downloads\ffxivsetup_ft.exe
2017-05-22 16:12 - 2017-05-22 16:12 - 00045680 ____H (LogMeIn Inc.) C:\WINDOWS\system32\Drivers\Hamdrv.sys
2017-05-22 13:31 - 2017-05-22 13:31 - 00957440 _____ (Realtek ) C:\WINDOWS\system32\Drivers\Rt630x64.sys
2017-05-22 13:31 - 2017-05-22 13:31 - 00082536 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 59237256 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 46456712 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 36547976 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmdag.sys
2017-05-22 13:29 - 2017-05-22 13:29 - 32732552 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atio6axx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 28797832 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl12cl64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 26826120 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atioglxx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 22739336 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl12cl.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 15728008 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticaldd64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 14318984 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticaldd.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 10311560 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdvlk64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 09899912 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmantle64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 09446336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 08470408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdvlk32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 07955848 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmantle32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 03471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2017-05-22 13:29 - 2017-05-22 13:29 - 03437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2017-05-22 13:29 - 2017-05-22 13:29 - 02527624 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 02189704 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 01032072 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00942858 _____ C:\WINDOWS\system32\amdicdxx.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00915848 _____ (AMD) C:\WINDOWS\system32\coinst_17.10.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00855432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00791456 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2017-05-22 13:29 - 2017-05-22 13:29 - 00791456 _____ C:\WINDOWS\system32\atiapfxx.blb
2017-05-22 13:29 - 2017-05-22 13:29 - 00687496 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00559984 _____ C:\WINDOWS\system32\amdmiracast.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00544136 _____ (AMD) C:\WINDOWS\system32\atitmm64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00543112 _____ C:\WINDOWS\system32\dgtrayicon.exe
2017-05-22 13:29 - 2017-05-22 13:29 - 00537992 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00522632 _____ C:\WINDOWS\system32\GameManager64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00520072 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmpag.sys
2017-05-22 13:29 - 2017-05-22 13:29 - 00505736 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00475016 _____ C:\WINDOWS\system32\atieah64.exe
2017-05-22 13:29 - 2017-05-22 13:29 - 00469384 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00458632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00456584 _____ C:\WINDOWS\system32\amdhdl64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00402312 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
2017-05-22 13:29 - 2017-05-22 13:29 - 00369792 _____ C:\WINDOWS\system32\ativvaxy_gl_nd.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00368832 _____ C:\WINDOWS\system32\ativvaxy_el_nd.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00356744 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00351624 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00349064 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe
2017-05-22 13:29 - 2017-05-22 13:29 - 00325512 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2017-05-22 13:29 - 2017-05-22 13:29 - 00325316 _____ C:\WINDOWS\system32\ativvaxy_vi.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00325056 _____ C:\WINDOWS\system32\ativvaxy_vi_nd.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00311176 _____ C:\WINDOWS\SysWOW64\amdhdl32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00305544 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\amdacpksd.sys
2017-05-22 13:29 - 2017-05-22 13:29 - 00276960 _____ C:\WINDOWS\system32\ativvaxy_stn_nd.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00271456 _____ C:\WINDOWS\system32\ativvaxy_cz_nd.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00269704 _____ C:\WINDOWS\system32\clinfo.exe
2017-05-22 13:29 - 2017-05-22 13:29 - 00266772 _____ C:\WINDOWS\system32\ativvaxy_FJ.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00266512 _____ C:\WINDOWS\system32\ativvaxy_FJ_nd.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00236424 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00234292 _____ C:\WINDOWS\system32\ativvaxy_cik.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00234032 _____ C:\WINDOWS\system32\ativvaxy_cik_nd.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00194952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00185600 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00185088 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiu9p64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00182664 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00166560 _____ C:\WINDOWS\system32\amde34b.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00166560 _____ C:\WINDOWS\system32\amde34a.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00166280 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amduve64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00164960 _____ C:\WINDOWS\system32\amde40a.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00161160 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00160768 _____ C:\WINDOWS\system32\ativce03.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00159112 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00159072 _____ C:\WINDOWS\system32\amde31a.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00155528 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6pxx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00154152 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00142216 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00135560 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amduve32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00128968 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00126344 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00124808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00124808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiglpxx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00124808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiglpxx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00121240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00121240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00120368 _____ C:\WINDOWS\system32\kapp_ci.sbin
2017-05-22 13:29 - 2017-05-22 13:29 - 00114056 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00112520 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00106248 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00103304 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00100832 _____ C:\WINDOWS\system32\ativce02.dat
2017-05-22 13:29 - 2017-05-22 13:29 - 00092840 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00092840 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00082824 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00078728 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalrt64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00072072 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalcl64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00068488 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalrt.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00067464 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe
2017-05-22 13:29 - 2017-05-22 13:29 - 00066952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmmcl6.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00066440 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00065416 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalcl.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00060296 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\ati2erec.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00054664 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmmcl.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00036232 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00033672 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00020360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2017-05-22 13:29 - 2017-05-22 13:29 - 00020360 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2017-05-22 13:28 - 2017-05-22 13:28 - 00891392 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iaStorA.sys
2017-05-22 13:27 - 2017-05-22 13:27 - 72520712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2017-05-22 13:27 - 2017-05-22 13:27 - 09124224 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2017-05-22 13:27 - 2017-05-22 13:27 - 07172912 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 07096184 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 05545512 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2017-05-22 13:27 - 2017-05-22 13:27 - 03503048 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 03203584 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 03203424 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 03014144 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2017-05-22 13:27 - 2017-05-22 13:27 - 02201600 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 01965808 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 01780616 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 01591056 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 01508928 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 01353824 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00743960 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00727432 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00708312 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00689880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00504304 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00447720 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00445400 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00441264 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00343704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00327456 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00272712 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00253896 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00253864 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00252872 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00192976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00151784 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00134200 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00118592 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00105304 _____ C:\WINDOWS\system32\audioLibVc.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00084616 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2017-05-22 13:27 - 2017-05-22 13:27 - 00037472 _____ (Intel) C:\WINDOWS\system32\Drivers\iusb3adp.sys
2017-05-22 13:27 - 2017-05-22 13:27 - 00023688 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2017-05-22 13:26 - 2017-05-22 13:26 - 03569816 _____ (Logitech Inc.) C:\WINDOWS\system32\RenderAPO.dll
2017-05-22 13:26 - 2017-05-22 13:26 - 02121056 _____ (Logitech Inc.) C:\WINDOWS\system32\CaptureAPO.dll
2017-05-22 13:26 - 2017-05-22 13:26 - 00045208 _____ (Logitech Inc.) C:\WINDOWS\system32\Drivers\ladfGSS.sys
2017-05-22 13:25 - 2017-05-22 13:25 - 00204920 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2017-05-22 13:14 - 2017-05-22 13:14 - 00000000 ____D C:\WINDOWS\IObit
2017-05-22 13:13 - 2017-05-22 13:13 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2017-05-22 13:12 - 2017-05-22 13:12 - 15721672 _____ (IObit ) C:\Users\Hardy\Downloads\driver_booster_setup(4.4.0.512).exe
2017-05-20 23:24 - 2017-05-20 23:24 - 30871208 _____ (ArenaNet) C:\Users\Hardy\Downloads\Gw2Setup-64.tmp
2017-05-20 23:24 - 2017-05-20 23:24 - 00000000 ____D C:\Users\Hardy\Downloads\bin64
2017-05-20 23:24 - 2017-05-20 23:24 - 00000000 _____ C:\Users\Hardy\Downloads\Gw2.tmp
2017-05-20 23:24 - 2017-05-20 23:24 - 00000000 _____ C:\Users\Hardy\Downloads\Gw2.dat
2017-05-20 22:41 - 2017-05-20 23:24 - 30871208 _____ (ArenaNet) C:\Users\Hardy\Downloads\Gw2Setup-64.exe
2017-05-20 19:39 - 2017-05-20 19:39 - 29719936 _____ C:\Users\Hardy\Downloads\SWTOR_setup.exe
2017-05-20 01:38 - 2017-05-20 01:38 - 00000000 ____D C:\WINDOWS\Tasks\ImCleanDisabled
2017-05-20 01:38 - 2017-05-20 01:38 - 00000000 ____D C:\Users\Hardy\AppData\LocalLow\IObit
2017-05-20 01:38 - 2017-05-20 01:38 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A}
2017-05-20 01:37 - 2017-05-25 13:59 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\IObit
2017-05-20 01:35 - 2017-05-20 01:36 - 39658392 _____ (IObit ) C:\Users\Hardy\Downloads\advanced-systemcare-setup(10.3.0.745).exe
2017-05-20 01:31 - 2017-05-25 14:30 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\GlarySoft
2017-05-20 01:31 - 2017-05-20 01:31 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\DiskDefrag
2017-05-20 01:29 - 2017-05-20 01:29 - 16788744 _____ C:\Users\Hardy\Downloads\gu5setup.exe
2017-05-20 01:28 - 2017-05-20 01:28 - 00000000 ____D C:\Users\Hardy\Downloads\geek-1.4.4.115
2017-05-20 01:26 - 2017-05-26 17:07 - 00000000 ____D C:\Users\Hardy\Desktop\NÜTZLICH
2017-05-20 01:25 - 2017-05-20 01:25 - 02777872 _____ C:\Users\Hardy\Downloads\geek-1.4.4.115.zip
2017-05-20 01:15 - 2017-05-20 01:15 - 00002784 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-05-20 01:15 - 2017-05-20 01:15 - 00000000 ____D C:\Program Files\CCleaner
2017-05-20 01:14 - 2017-05-20 01:14 - 09548112 _____ (Piriform Ltd) C:\Users\Hardy\Downloads\ccsetup530.exe
2017-05-19 18:49 - 2017-05-19 18:49 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\com.playa-games.sfgame
2017-05-11 02:14 - 2017-05-11 02:18 - 00000000 ____D C:\Users\Hardy\Downloads\Xenoblade Chronicles X
2017-05-11 02:12 - 2017-05-11 02:12 - 02735233 _____ C:\Users\Hardy\Downloads\Xenoblade Chronicles X.7z
2017-05-08 13:16 - 2017-05-08 13:16 - 00000000 ____D C:\Program Files (x86)\5910538D_jumpeasy
2017-05-05 20:00 - 2017-05-05 20:00 - 00044528 _____ C:\Users\Hardy\Downloads\Sildurs Vibrant Shaders v1.141 Extreme.zip
2017-05-05 19:52 - 2017-05-05 19:52 - 00044530 _____ C:\Users\Hardy\Downloads\Sildurs Vibrant Shaders v1.141 Medium.zip
2017-05-04 14:46 - 2017-05-05 15:39 - 00000000 ____D C:\Users\Hardy\Downloads\The Legend of Zelda Breath of the Wild
2017-05-04 14:45 - 2017-05-04 14:45 - 00043963 _____ C:\Users\Hardy\Downloads\The-legend-of-zelda-breath-of-the-wild-Update-v1-1-2-EUR-Loadiine-GX2.rar
2017-05-04 14:36 - 2017-05-04 14:36 - 00028354 _____ C:\Users\Hardy\Downloads\11780F9C79BB903471A7A96E4F8D2A973E604FD0.torrent
2017-05-04 10:40 - 2017-05-04 10:40 - 00000000 ____D C:\Users\Public\Documents\Google
2017-05-04 08:52 - 2017-05-04 08:52 - 00000000 ____D C:\Users\Hardy\Desktop\2912eb2f
2017-05-04 08:51 - 2017-05-04 08:51 - 06572885 _____ C:\Users\Hardy\Desktop\2912eb2f.7z
2017-05-03 20:25 - 2017-05-03 20:25 - 00002272 _____ C:\Users\Hardy\Desktop\Andi-Circus_anküdnigung.wlmp
2017-05-03 20:20 - 2017-05-03 14:24 - 32413449 ____N C:\Users\Hardy\Desktop\VID-20170503-WA0004.mp4
2017-05-03 15:32 - 2017-05-03 15:32 - 00000000 ____D C:\Users\Hardy\Desktop\BOTW STUFF
2017-05-03 15:31 - 2017-05-03 15:32 - 11333777 _____ C:\Users\Hardy\Desktop\BOTW STUFF.rar
2017-05-03 15:19 - 2017-05-03 15:19 - 04966218 _____ C:\Users\Hardy\Downloads\cemuhook_174d_0410.zip
2017-05-03 15:19 - 2017-05-03 15:19 - 00000000 ____D C:\Users\Hardy\Downloads\cemuhook_174d_0410
2017-05-02 17:10 - 2017-05-05 11:28 - 00001028 _____ C:\Users\Public\Desktop\AVG.lnk
2017-04-30 21:24 - 2017-04-30 21:24 - 05731656 _____ C:\Users\Hardy\Downloads\BotW.7z
2017-04-30 21:24 - 2017-04-30 21:24 - 00000000 ____D C:\Users\Hardy\Downloads\BotW
2017-04-30 19:09 - 2017-05-08 17:42 - 00000000 ____D C:\Users\Hardy\Desktop\cemu_1.7.5
2017-04-30 19:08 - 2017-04-30 19:08 - 02309750 _____ C:\Users\Hardy\Downloads\cemu_1.7.5.zip
2017-04-30 18:25 - 2017-05-26 16:57 - 00002300 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-30 18:25 - 2017-05-25 11:44 - 00002258 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-30 18:25 - 2017-04-30 18:25 - 01130328 _____ (Google Inc.) C:\Users\Hardy\Downloads\ChromeSetup.exe
2017-04-30 16:14 - 2017-04-30 16:14 - 00000000 ____D C:\Users\Hardy\Downloads\cemu_1.7.5
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-05-29 07:20 - 2017-04-22 00:47 - 00055708 _____ C:\WINDOWS\ZAM.krnl.trace
2017-05-29 07:20 - 2017-04-22 00:47 - 00026240 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-05-29 07:15 - 2014-09-19 04:40 - 00000000 ___DO C:\Users\Hardy\OneDrive.old
2017-05-29 07:14 - 2015-01-02 04:14 - 00000000 ____D C:\Users\Hardy\AppData\Local\LogMeIn Hamachi
2017-05-29 07:13 - 2017-02-24 13:59 - 00026192 _____ (Windows (R) Server 2003 DDK provider) C:\WINDOWS\gdrv.sys
2017-05-29 07:12 - 2017-04-22 00:49 - 00251832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-05-29 07:12 - 2015-06-28 14:20 - 00000000 ____D C:\ProgramData\MFAData
2017-05-29 07:12 - 2014-12-21 16:18 - 00000000 ____D C:\Users\Hardy\AppData\Local\HTC MediaHub
2017-05-29 07:09 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-29 07:08 - 2016-09-25 21:14 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-05-29 07:08 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2017-05-29 07:00 - 2014-09-25 20:25 - 00000000 ____D C:\Users\Hardy\AppData\Local\Adobe
2017-05-28 22:06 - 2014-08-15 22:39 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2570889560-1274126736-4133381010-1001
2017-05-28 17:03 - 2016-12-09 10:01 - 00003600 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2017-05-28 14:57 - 2014-11-14 00:14 - 00000000 ____D C:\Games
2017-05-28 14:40 - 2014-08-18 02:50 - 00000000 ____D C:\Program Files (x86)\Steam
2017-05-28 12:02 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2017-05-28 01:37 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf
2017-05-27 22:47 - 2014-08-16 13:27 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\TS3Client
2017-05-27 21:20 - 2015-09-20 17:50 - 00003158 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForHardy
2017-05-27 21:20 - 2015-09-20 17:50 - 00000344 _____ C:\WINDOWS\Tasks\HPCeeScheduleForHardy.job
2017-05-27 13:56 - 2017-04-26 09:03 - 00000000 ____D C:\Program Files\MK
2017-05-27 13:56 - 2017-04-21 11:44 - 00000000 ____D C:\Program Files (x86)\Cludeing
2017-05-27 06:32 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\Registration
2017-05-27 06:26 - 2014-09-19 03:58 - 02008488 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-05-27 06:26 - 2014-03-18 11:25 - 00851332 _____ C:\WINDOWS\system32\perfh007.dat
2017-05-27 06:26 - 2014-03-18 11:25 - 00195966 _____ C:\WINDOWS\system32\perfc007.dat
2017-05-27 00:52 - 2014-09-03 17:38 - 00000000 ____D C:\Users\Hardy\AppData\Local\Battle.net
2017-05-27 00:36 - 2014-09-03 17:39 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2017-05-26 23:47 - 2014-09-03 17:38 - 00000000 ____D C:\Program Files (x86)\Battle.net
2017-05-26 23:39 - 2016-12-18 23:58 - 00000000 ____D C:\Program Files (x86)\Zenimax Online
2017-05-26 23:39 - 2014-09-19 04:00 - 00000000 ____D C:\Users\Hardy
2017-05-26 21:03 - 2012-11-19 17:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-05-26 16:59 - 2016-07-19 13:01 - 00000000 ____D C:\Users\Default\AppData\Local\LogMeIn Hamachi
2017-05-26 16:59 - 2016-07-19 13:01 - 00000000 ____D C:\Users\Default User\AppData\Local\LogMeIn Hamachi
2017-05-26 02:02 - 2017-03-11 14:38 - 00000940 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2017-05-26 01:54 - 2017-04-26 09:03 - 00000000 ____D C:\Insist
2017-05-25 14:50 - 2016-11-21 14:12 - 00000000 ____D C:\Program Files (x86)\Uplink
2017-05-25 14:47 - 2015-08-22 00:15 - 00000000 ____D C:\Users\Hardy\AppData\Local\Unity
2017-05-25 14:42 - 2015-05-30 17:08 - 00000000 ____D C:\GOG Games
2017-05-25 14:32 - 2016-11-22 05:30 - 00000000 ____D C:\Program Files (x86)\Onlink
2017-05-25 14:29 - 2014-09-26 03:57 - 00000000 ____D C:\Program Files (x86)\FreeTime
2017-05-25 14:28 - 2012-11-19 17:56 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2017-05-25 14:28 - 2012-11-19 17:56 - 00000000 ____D C:\Program Files (x86)\CyberLink
2017-05-25 14:25 - 2014-08-18 23:42 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-05-25 14:24 - 2012-11-19 17:58 - 00000000 ____D C:\ProgramData\Apple
2017-05-25 14:20 - 2017-02-23 18:08 - 00000082 _____ C:\WINDOWS\SysWOW64\winsevr.dat
2017-05-25 14:20 - 2016-01-30 17:27 - 00000000 ____D C:\Program Files (x86)\Anker Precision Laser Gaming Mouse
2017-05-25 14:18 - 2014-09-25 20:29 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-05-25 14:18 - 2014-08-15 22:33 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\Adobe
2017-05-25 14:17 - 2015-08-03 14:40 - 00000000 ____D C:\Program Files (x86)\4Musics OGG to MP3 Converter
2017-05-25 14:09 - 2014-12-28 21:24 - 00000000 ____D C:\Program Files (x86)\IObit
2017-05-25 14:06 - 2017-04-22 02:32 - 00000000 ____D C:\WINDOWS\Update
2017-05-25 13:59 - 2014-12-28 21:24 - 00000000 ____D C:\ProgramData\IObit
2017-05-25 11:40 - 2016-09-23 12:01 - 00000000 ____D C:\Users\Hardy\AppData\LocalLow\Mozilla
2017-05-24 15:11 - 2014-09-19 04:37 - 00001456 _____ C:\Users\Hardy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-05-24 14:37 - 2014-09-19 03:54 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-24 02:41 - 2015-06-11 21:31 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2017-05-22 19:16 - 2013-04-08 22:25 - 00000000 ____D C:\Users\Hardy\Documents\My Games
2017-05-22 18:06 - 2014-03-18 12:03 - 01980934 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-22 17:58 - 2017-03-18 15:31 - 00000000 ____D C:\WINDOWS\LastGood
2017-05-22 13:29 - 2017-03-10 23:34 - 00161344 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll
2017-05-22 13:29 - 2017-03-10 23:33 - 00768392 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2017-05-22 13:29 - 2017-03-10 23:33 - 00543112 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
2017-05-22 13:29 - 2017-03-10 23:32 - 14413536 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd6a.dll
2017-05-22 13:29 - 2017-03-10 23:32 - 10088520 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2017-05-22 13:29 - 2017-03-10 23:32 - 01507720 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2017-05-22 13:29 - 2017-03-10 23:32 - 01032072 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2017-05-22 13:29 - 2017-02-10 16:23 - 07663888 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdag.dll
2017-05-22 13:29 - 2017-02-10 16:23 - 01342784 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2017-05-22 13:29 - 2017-02-10 16:23 - 00143864 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiu9pag.dll
2017-05-22 13:29 - 2017-02-10 16:22 - 13254256 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdva.dll
2017-05-22 13:29 - 2016-10-05 04:20 - 00207760 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiuxp64.dll
2017-05-22 13:29 - 2016-10-05 04:19 - 12139760 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
2017-05-22 13:29 - 2016-10-05 04:19 - 01649736 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2017-05-22 13:28 - 2017-02-24 10:23 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-05-22 13:09 - 2016-10-08 13:55 - 00000000 ____D C:\Users\Hardy\Desktop\DESKTOP-LAN2
2017-05-22 13:09 - 2016-05-05 02:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch
2017-05-22 13:09 - 2016-03-21 20:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Life Is Strange
2017-05-22 13:09 - 2015-06-11 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2017-05-22 13:09 - 2015-03-17 03:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westwood Online
2017-05-22 13:09 - 2014-09-19 04:50 - 00000000 ___DC C:\WINDOWS\Panther
2017-05-21 18:37 - 2017-04-23 16:45 - 00000000 ____D C:\Users\Hardy\.litwrl
2017-05-20 23:31 - 2014-08-24 00:24 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\Skype
2017-05-20 20:11 - 2014-08-18 01:58 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\vlc
2017-05-20 01:52 - 2015-05-30 03:21 - 00000000 ____D C:\Users\Hardy\AppData\Local\Ubisoft Game Launcher
2017-05-20 01:51 - 2014-09-22 19:38 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\DAEMON Tools Lite
2017-05-20 01:49 - 2015-01-13 16:33 - 00000000 ____D C:\WINDOWS\Minidump
2017-05-19 16:18 - 2014-08-15 22:28 - 00000000 ____D C:\Users\Hardy\AppData\Local\Packages
2017-05-19 16:18 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-19 15:57 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-19 15:34 - 2015-02-06 10:18 - 00003862 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1423210713
2017-05-19 15:34 - 2015-02-06 10:18 - 00000000 ____D C:\Program Files (x86)\Opera
2017-05-19 15:28 - 2014-09-19 04:00 - 00000000 ____D C:\Users\Administrator
2017-05-11 11:19 - 2016-09-23 07:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-05-11 11:19 - 2014-08-15 01:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-05-09 21:54 - 2016-04-08 03:54 - 00004474 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-05-09 21:54 - 2014-12-12 02:37 - 00004342 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-05-09 21:54 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-05-09 21:54 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-05-09 17:02 - 2015-09-11 15:08 - 00000000 ____D C:\Users\Hardy\AppData\Local\ElevatedDiagnostics
2017-05-08 21:24 - 2017-04-21 13:51 - 00001267 _____ C:\Users\Hardy\Desktop\nativelog.txt
2017-05-08 21:24 - 2017-04-21 09:30 - 00000000 ____D C:\Users\Hardy\AppData\Roaming\.minecraft
2017-05-08 17:42 - 2017-01-16 14:31 - 00000000 ____D C:\Users\Hardy\Desktop\cemu_1.7.2
2017-05-05 11:28 - 2015-06-28 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-05-04 08:23 - 2017-04-22 00:50 - 00186304 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-05-04 08:20 - 2017-04-22 00:50 - 00111544 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-05-04 08:20 - 2017-04-22 00:50 - 00092096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-05-04 08:20 - 2017-04-22 00:50 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2017-05-27 06:27 - 2017-05-27 06:27 - 0000093 _____ () C:\Users\Hardy\AppData\Local\fusioncache.dat
2014-09-25 21:23 - 2014-12-21 19:22 - 0001480 _____ () C:\Users\Hardy\AppData\Local\RecConfig.xml
2017-02-24 10:23 - 2017-02-24 10:23 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-08-15 22:32 - 2014-08-15 22:32 - 0000141 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2015-03-04 04:29 - 2015-03-04 04:29 - 0000040 _____ () C:\ProgramData\ra3.ini
Einige Dateien in TEMP:
====================
2017-05-29 07:12 - 2017-05-29 07:12 - 0010520 _____ () C:\Users\Hardy\AppData\Local\Temp\BullseyeCoverage-x86-3.dll
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-05-26 18:20
==================== Ende von FRST.txt ============================ |