Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Thema geschlossen
Alt 02.12.2016, 05:07   #1
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Frage

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



hi,
hab das gefühl, dass mal wieder irgendwas mit meinem laptop nicht stimmt.
heißt meine maus bewegt sich teilweise nicht wie sie soll, vor allem wenn ich zocke, meine festplatte ist teilweise zu 100% ausgelastet, auch wenn ich absolut nichts mache, mein lüfter arbeitet durchgehend auf hochtouren einige programme funktionieren nicht richtig, u.a. frooty loops und ich habe einiege anwendungen die mir suspekt ercheinen. weiß allerdings nicht sicher, ob ich nicht mal wieder nur paranoia hab^^
mein antivirenprogramm findet nichts, aber ich hab FRST ausgeführt. hab schon öfter versucht damit meinen pc wieder auf vordermann zu bringen. selbst mit anleitung und vielen stunden zeitaufwand, hat beim letzten mal nur system komplett platt machen mit DBAN geholfen. da aber das kostenlose win 10 update nicht mehr verfügbar ist, muss dieses mal fast eine andere lösung her.

Anhang 79427
Anhang 79428
Anhang 79428

Alt 02.12.2016, 09:43   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



+++ WICHTIGER HINWEIS +++


Während der Analyse und Bereinigung nimmst du KEINERLEI Änderungen auf eigene Faust vor, d.h. du installierst oder deinstallierst keine Software ohne Absprache.
Auch veränderst du keine Systemeinstellungen, solange wir deinen Fall bearbeiten. Änderungen, Installationen oder Deinstallationen machst du AUSSCHLIESSLICH nur auf Anweisung!
Es wird erforderlich sein, deinen Virenscanner zu deaktivieren und in bestimmten Fällen auch zu deinstallieren, damit vernünftig bereinigt werden kann. Dein System ist daher erst wenn wir hier fertig sind wieder für den alltäglichen Gebrauch wie surfen oder mailen von mir freigegeben.

Gelesen und verstanden?




Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 02.12.2016, 21:12   #3
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



ok verstanden. danke für die schnelle antwort.
__________________

Alt 02.12.2016, 23:12   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Gut. Poste bitte die Logs in CODE-Tags. Weil als Anhang ist das zu umständlich für uns. Danke.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 17.12.2016, 18:55   #5
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 17-12-2016
durchgeführt von Dragonfly (17-12-2016 18:50:23)
Gestartet von C:\Users\Dragonfly\Desktop
Windows 10 Home Version 1511 (X64) (2016-07-29 23:35:10)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-614321186-1851163967-905647231-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-614321186-1851163967-905647231-503 - Limited - Disabled)
Dragonfly (S-1-5-21-614321186-1851163967-905647231-1000 - Administrator - Enabled) => C:\Users\Dragonfly
Gast (S-1-5-21-614321186-1851163967-905647231-501 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov)
Adblock Plus für IE (32-Bit- und 64-Bit) (HKLM\...\{588B7DD2-3480-4A89-A8F6-C6781CBFAD56}) (Version: 1.5 - Eyeo GmbH)
Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated)
Ansel (Version: 376.33 - NVIDIA Corporation) Hidden
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.13 - Michael Tippach)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.24.146 - Avira Operations GmbH & Co. KG)
Avira Browser Safety (HKLM-x32\...\{9E10EA90-5E97-43B7-A246-FC7B4F5E9493}) (Version: 1.4.5.509 - Avira Operations GmbH & Co KG)
Avira Connect (HKLM-x32\...\{707e8edf-9482-4417-ae39-c9b5fe605e87}) (Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG)
Avira Connect (x32 Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Hidden
CyberGhost 6 (HKLM\...\CyberGhost 6_is1) (Version:  - CyberGhost S.R.L.)
Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel® PROSet/Wireless WiFi-Software (HKLM\...\{181BBF43-CA17-4E1A-A78D-81E67A57B8A4}) (Version: 15.02.0000.1258 - Intel Corporation)
League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 3.15.0414.1 - Vimicro)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
NVIDIA GeForce Experience 3.2.0.96 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.2.0.96 - NVIDIA Corporation)
NVIDIA Grafiktreiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.33 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.2.0.96 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 2.0.0.0 - NVIDIA Corporation) Hidden
OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation)
paint.net (HKLM\...\{A1D05314-DC32-4668-A97E-51060EC8BCCE}) (Version: 4.0.12 - dotPDN LLC)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.54.309.2012 - Realtek)
SHIELD Streaming (Version: 7.1.0350 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.2.0.96 - NVIDIA Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.9.5 - Synaptics Incorporated)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Windows 10-Upgrade-Assistent (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17332 - Microsoft Corporation)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll => Kein (Der Dateneintrag hat 7 mehr Zeichen).
CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncApi64.dll => Keine  (Der Dateneintrag hat 5 mehr Zeichen).

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03E3805D-70CA-4B7A-88FE-B0A7ECB79FA0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {05E29CAC-D387-45CE-AE18-876241F8A74B} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation)
Task: {05FD0347-5C60-4CE5-8A7F-B13732DA5194} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {06DB1599-D4C7-4B21-AA32-2E8AFE0B60AA} - \Microsoft\Windows\Setup\gwx\rundetector -> Keine Datei <==== ACHTUNG
Task: {07A62BCD-1B29-4E4E-910C-9C1FF254C0B6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-12-13] (NVIDIA Corporation)
Task: {0848D22A-6161-4F11-A372-96D326C7D0BC} - System32\Tasks\Avira Browser Safety Updater Task => C:\Program Files (x86)\Avira\Browser Safety\AviraBrowserSafetyUpdater.exe [2015-03-11] (Avira Operations GmbH & Co. KG)
Task: {1C2F7D9C-9FB4-4994-A225-EB858F74F810} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1C60354A-D04E-4B4D-A8BE-2B2311FE4CBA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {217D3CCF-9F2D-4AD6-9EFF-6CEB68DE2301} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {248A8323-DA31-4222-96A2-5C6E6951F619} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG
Task: {360EB739-EB12-49D4-BED1-E2021BDCA7C8} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {40EB871D-0140-44C8-9E7B-525645048C0D} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {40EF86BA-63C8-47D9-92DD-EB62496BCA26} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {41B5F213-92D6-4DFE-BECF-387CB2885869} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {4EB4A967-6105-45ED-B825-629CB423DE43} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {5A33D8D1-EC9E-41A2-BBB6-2420356CD89C} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation)
Task: {5B76CB83-A5F9-4E43-A63B-CBF8F67C41A5} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {62D21782-9F4C-4347-AAAF-5B1584328DBB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {6C2C580E-AB30-4A56-BDE3-4A963668C9F7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6F0FA1DC-6A61-40FF-8E48-E2E6D9D1EC5B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {73EAD0A0-D4D3-42F2-AB00-158104EE5FD7} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {743B6204-186E-4EFE-B6D3-CBBAB15C84BE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {76A0339D-DA5E-4811-8264-0A64B9BD2138} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation)
Task: {80CC415F-3D85-42A5-85C4-DB80FCBBA889} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8AE3FC4C-B5A2-47FE-B764-2FDC7CF41766} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {9029FA70-4FC2-41D9-869D-42A60F4662E4} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG
Task: {97DFCF79-D4C3-48A8-AF2F-66F28E6A5A88} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {9E48F49C-D889-4CCC-9F07-C83816CEAB70} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A551C101-F597-4E55-BF05-A5B30B685C6D} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Keine Datei <==== ACHTUNG
Task: {A9CB0F2A-7B83-4E5F-B717-2F669157731D} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG
Task: {AAE922AD-510D-48AA-B0DD-3EF0C60C967D} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B1146A5D-8566-4172-8D39-F826DA990E8D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-12-13] (NVIDIA Corporation)
Task: {B4905C69-C0BC-47D8-BF0A-8CDFE0E01150} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {BA55B185-6F05-44EC-B7C8-1EA0D065D486} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation)
Task: {BBF13E3A-451D-4AD4-8A81-DEB0933E1D5F} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BDF6FE28-C910-4FDB-8906-5D062A256641} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C6B39C71-78D8-40D7-B9B0-36C543724A9A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CA269936-C128-4BB7-A0E2-3D7E955C4A5F} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {CF619372-64D8-4ECB-9782-7FDE3D0F7FB6} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-12-13] (NVIDIA Corporation)
Task: {DADC79E6-4947-4B1C-85F5-C40EC1D7560D} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DD1D530A-1547-4E97-A2EC-C16E96BCC0D9} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E454C27B-586C-4D8C-830C-459442B08B45} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {E9E6F3AA-93E4-4497-B237-0D4F75BC228E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {F4D8ABA4-EF6C-4378-A09F-5C0662B919E1} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F4F793B4-DA06-4683-BAA0-A6108BB1BFD7} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)


==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2016-10-07 14:20 - 2016-12-13 00:36 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
2016-10-07 14:20 - 2016-12-13 00:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-11-09 01:24 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-11-09 01:24 - 2016-10-25 10:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-04-27 06:17 - 2016-04-27 06:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-30 00:41 - 2016-07-30 00:41 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-11-09 01:25 - 2016-10-25 08:01 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-11-09 01:24 - 2016-10-25 05:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-09 01:24 - 2016-10-25 05:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-11-09 01:24 - 2016-10-25 05:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-09 01:24 - 2016-10-25 05:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-10-07 14:20 - 2016-12-13 00:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-10-07 14:20 - 2016-12-13 00:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll
2016-10-07 14:20 - 2016-12-13 00:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-10-07 14:20 - 2016-12-12 15:36 - 00525760 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
2016-10-07 14:20 - 2016-12-12 15:36 - 00254008 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
2016-10-07 14:20 - 2016-12-12 15:36 - 02808888 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
2016-10-07 14:20 - 2016-12-12 15:36 - 00384568 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
2016-10-07 14:20 - 2016-12-12 15:36 - 00447424 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
2016-10-07 14:20 - 2016-12-12 15:36 - 00336832 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
2016-10-07 14:20 - 2016-12-12 15:36 - 01003456 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node
2016-12-17 12:22 - 2016-12-12 15:36 - 00956472 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSDKAPINode.node

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-614321186-1851163967-905647231-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

MSCONFIG\Services: AMPPALR3 => 2
MSCONFIG\Services: Avira.ServiceHost => 2
MSCONFIG\Services: CG6Service => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: EvtEng => 2
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: MyWiFiDHCPDNS => 3
MSCONFIG\Services: NvContainerLocalSystem => 2
MSCONFIG\Services: NvContainerNetworkService => 3
MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2
MSCONFIG\Services: NVIDIA Wireless Controller Service => 2
MSCONFIG\Services: RegSrvc => 2
MSCONFIG\Services: SynTPEnhService => 2
MSCONFIG\Services: TapiSrv => 3
MSCONFIG\Services: ZeroConfigService => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Update Benachrichtigungsdienst.lnk => C:\Windows\pss\Update Benachrichtigungsdienst.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Preloader.lnk => C:\Windows\pss\WinZip Preloader.lnk.CommonStartup
MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 6\CyberGhost.exe" /autostart /min
MSCONFIG\startupreg: IntelPROSet => "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless
HKLM\...\StartupApproved\StartupFolder: => "FAH.lnk"
HKLM\...\StartupApproved\Run: => "SynLenovoGestureMgr"
HKLM\...\StartupApproved\Run32: => "331BigDog"
HKLM\...\StartupApproved\Run32: => "IAStorIcon"
HKU\S-1-5-21-614321186-1851163967-905647231-1000\...\StartupApproved\Run: => "OneDrive"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [MSMQ-In-TCP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => LPort=808
FirewallRules: [{C42E09EE-544C-4058-B937-1E1C214C3179}] => C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{C13FCC8E-EA7C-4CF3-A00E-B34183437A33}] => C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{60B6505E-646C-49A7-AED9-61624970AD3A}] => C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{DDA3AE79-ADE7-4908-8334-C9DA3F39B5B1}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9C9D448E-E0C6-4AB9-BDB5-B501BA9707ED}] => %systemroot%\system32\mqsvc.exe
FirewallRules: [{3EB2F7F5-4D9C-4CC4-ABF8-4B5239F07BB4}] => %systemroot%\system32\mqsvc.exe
FirewallRules: [{E07F3B24-CA0A-4C07-9E7B-AD478A9A1BCF}] => %systemroot%\system32\mqsvc.exe
FirewallRules: [{66237BE3-1D77-47EA-AFD0-64530BFBE380}] => %systemroot%\system32\mqsvc.exe
FirewallRules: [{EC4463D8-0CDF-4C6E-A8F3-ED1AECD22E7A}] => LPort=808
FirewallRules: [{AEB7ABE0-DE10-4AE4-8C08-394F31414C3A}] => C:\Fruity Loops Studio 8\FL_3GB.exe
FirewallRules: [{A8A6276D-B39F-4DD2-9B64-5D280508E2D7}] => C:\Fruity Loops Studio 8\FL_3GB.exe
FirewallRules: [{9A47A000-1124-4309-B74A-11D80A8C9F4D}] => C:\Fruity Loops Studio 8\FL_3GB.exe
FirewallRules: [{20824275-6B98-4756-8CF8-4E37B4FABE0A}] => C:\Fruity Loops Studio 8\FL_3GB.exe
FirewallRules: [{50977907-6F8B-483C-A95A-AC054B7F83B4}] => C:\Fruity Loops Studio 8\FL.exe
FirewallRules: [{5439A04F-8DA4-4FBE-85AB-F1F50F10CE07}] => C:\Fruity Loops Studio 8\FL.exe
FirewallRules: [{8043D186-EF79-453E-B207-B1C0304910A2}] => C:\Fruity Loops Studio 8\FL.exe
FirewallRules: [{5133CF13-31A7-4A88-A181-89D2E1F3A29F}] => C:\Fruity Loops Studio 8\FL.exe
FirewallRules: [{0921E149-3077-41B7-8F31-09C8F36CE06E}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{8C0DBFD5-D27C-4B56-BD72-D58BDC1C1516}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{CB643C00-DDAE-4619-9558-0BC84F1667E4}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{2B7A0D01-EA76-49D8-8281-243149DE9D24}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B7A429B8-C176-4617-A67B-5D0F59DA53A3}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe

==================== Wiederherstellungspunkte =========================

ACHTUNG: Systemwiederherstellung ist deaktiviert

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (12/17/2016 12:37:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x1678
Startzeit der fehlerhaften Anwendung: 0x01d25859f3e47dad
Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll
Berichtskennung: a36d47d5-9f60-4e33-af47-ed7fcda8c113
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (12/17/2016 12:36:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x1354
Startzeit der fehlerhaften Anwendung: 0x01d25859deef5288
Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll
Berichtskennung: 0ea1f4ad-8817-4168-ae1f-fd70af18d25e
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (12/17/2016 12:16:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x1448
Startzeit der fehlerhaften Anwendung: 0x01d2585700195c8d
Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll
Berichtskennung: 41d347ad-0001-488b-9852-9f2885c8213c
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (12/17/2016 12:14:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.9193, Zeitstempel: 0x560489c4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x1728
Startzeit der fehlerhaften Anwendung: 0x01d25856ab785d8b
Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_d09188224426efcd\MSVCR80.dll
Berichtskennung: e309e262-cd45-4f67-9915-15b403e29093
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (12/16/2016 10:32:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC)
Description: Bei der Aktivierung der App „Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (12/16/2016 10:32:22 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm LockApp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 13d8

Startzeit: 01d2573779f06a60

Beendigungszeit: 4294967295

Anwendungspfad: C:\WINDOWS\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe

Berichts-ID: 7ff06158-c372-11e6-aef7-208984e59db3

Vollständiger Name des fehlerhaften Pakets: Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy

Auf das fehlerhafte Paket bezogene Anwendungs-ID: WindowsDefaultLockScreen

Error: (12/13/2016 12:03:39 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC)
Description: Bei der Aktivierung der App „Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (12/11/2016 07:31:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ShellExperienceHost.exe, Version: 10.0.10586.494, Zeitstempel: 0x5775e94c
Name des fehlerhaften Moduls: twinapi.appcore.dll, Version: 10.0.10586.672, Zeitstempel: 0x580ef283
Ausnahmecode: 0xc000027b
Fehleroffset: 0x000000000004b1c9
ID des fehlerhaften Prozesses: 0x318
Startzeit der fehlerhaften Anwendung: 0x01d253dc7a71494a
Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
Pfad des fehlerhaften Moduls: C:\Windows\System32\twinapi.appcore.dll
Berichtskennung: 899a1405-ce81-403e-8920-787ca73c9839
Vollständiger Name des fehlerhaften Pakets: Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App

Error: (12/11/2016 05:08:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm LockApp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1900

Startzeit: 01d2534b12d37acc

Beendigungszeit: 4294967295

Anwendungspfad: C:\WINDOWS\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe

Berichts-ID: 50dec74a-bf3e-11e6-aef5-208984e59db3

Vollständiger Name des fehlerhaften Pakets: Microsoft.LockApp_10.0.10586.0_neutral__cw5n1h2txyewy

Auf das fehlerhafte Paket bezogene Anwendungs-ID: WindowsDefaultLockScreen

Error: (12/07/2016 11:12:26 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.


Systemfehler:
=============
Error: (12/17/2016 05:51:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenspeicher _3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kontaktdaten_3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/17/2016 04:27:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_3d1cc" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/17/2016 12:34:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "CG6Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (12/17/2016 12:34:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst CG6Service erreicht.

Error: (12/17/2016 12:34:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira.ServiceHost erreicht.

Error: (12/17/2016 12:34:11 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden.

Error: (12/17/2016 12:33:00 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Benutzerdatenspeicher _3de5d erreicht.


CodeIntegrity:
===================================
  Date: 2016-12-15 21:52:02.547
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-14 13:00:08.180
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-14 03:41:15.867
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-11-11 11:36:35.733
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-11-09 13:06:47.157
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-11-09 08:22:05.757
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-11-09 03:44:07.044
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-10-30 12:47:21.004
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-10-29 04:39:02.108
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-10-15 10:29:41.341
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\WINDOWS\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Prozentuale Nutzung des RAM: 23%
Installierter physikalischer RAM: 8053.6 MB
Verfügbarer physikalischer RAM: 6156.52 MB
Summe virtueller Speicher: 16245.6 MB
Verfügbarer virtueller Speicher: 14176.04 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:930.91 GB) (Free:847.2 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 9BCA118F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=930.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=511 MB) - (Type=27)

==================== Ende von Addition.txt ===========================
         
Code:
ATTFilter
Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 17-12-2016
durchgeführt von Dragonfly (17-12-2016 18:51:19)
Gestartet von C:\Users\Dragonfly\Desktop
Start-Modus: Normal

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)





Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\Dragonfly\Documents ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\Dragonfly\Downloads ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\Dragonfly\Music ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\Dragonfly\Pictures ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\Dragonfly\Videos ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk -> Microsoft.Windows.Homegroup
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk -> Microsoft.Windows.Network
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\Dragonfly ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk -> C:\WINDOWS\DevicesFlow\DevicesFlow.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk -> C:\WINDOWS\MiracastView\MiracastView.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (dotPDN LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk -> C:\WINDOWS\PrintDialog\PrintDialog.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10-Upgrade-Assistent.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Uninstall Winamp.lnk -> C:\Program Files (x86)\Winamp\UninstWA.exe (Nullsoft, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\What's New.lnk -> C:\Program Files (x86)\Winamp\whatsnew.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel(R) Rapid Storage Technology.lnk -> C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUI.exe (Intel Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 6\CyberGhost 6 deinstallieren.lnk -> C:\Program Files\CyberGhost 6\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 6\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Avira Antivirus Hilfe.lnk -> C:\Program Files (x86)\Avira\Antivirus\57\avwin.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Avira Antivirus starten.lnk -> C:\Program Files (x86)\Avira\Antivirus\avcenter.exe (Avira Operations GmbH & Co. KG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Avira im Internet.lnk -> C:\Program Files (x86)\Avira\Antivirus\weblink.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\WINDOWS\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\WINDOWS\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\WINDOWS\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\WINDOWS\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\WINDOWS\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\WINDOWS\SysWOW64\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\WINDOWS\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\WINDOWS\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\WINDOWS\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\WINDOWS\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\WINDOWS\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Bluetooth File Transfer Wizard.lnk -> C:\WINDOWS\System32\fsquirt.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\WINDOWS\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\WINDOWS\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\WINDOWS\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\WINDOWS\System32\psr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\WINDOWS\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\WINDOWS\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\WINDOWS\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm ()
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\WINDOWS\explorer.exe,-304
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\System32\diskmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\WINDOWS\explorer.exe,-304
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc ()
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\System32\diskmgmt.msc ()
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\Links\Desktop.lnk -> C:\Users\Dragonfly\Desktop ()
Shortcut: C:\Users\Dragonfly\Links\Downloads.lnk -> C:\Users\Dragonfly\Downloads ()
Shortcut: C:\Users\Dragonfly\Links\RecentPlaces.lnk -> L ᐁ  À  䘀                         耟穭⊇㞡䘚낑�깚馼 ć 	ꀀz 匱卐뜥䟯ယ怂麌곫1 
 ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ   
 Systemordner     匱卐檦⡣锽ᇒ횵쀀�퀘e  ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀        
Shortcut: C:\Users\Dragonfly\Desktop\ASIO4ALL v2 Anleitung.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Anleitung.pdf ()
Shortcut: C:\Users\Dragonfly\Desktop\-\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.)
Shortcut: C:\Users\Dragonfly\Desktop\-\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation)
Shortcut: C:\Users\Dragonfly\Desktop\-\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe ()
Shortcut: C:\Users\Dragonfly\Desktop\-\McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\McUICnt.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\OpenOffice 4.1.2.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\Desktop\-\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (dotPDN LLC)
Shortcut: C:\Users\Dragonfly\Desktop\-\Security Task Manager.lnk -> C:\Program Files (x86)\Security Task Manager\TaskMan.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Dragonfly\Desktop\-\True Key.lnk -> C:\Program Files\Intel Security\True Key\application\truekey.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.)
Shortcut: C:\Users\Dragonfly\Desktop\-\Windows 10-Upgrade-Assistent.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\Desktop\-\WinZip.lnk -> C:\Program Files\WinZip\WINZIP64.EXE (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Tor Browser\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\firefox (2).lnk -> C:\Users\Dragonfly\Desktop\firefox.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk -> C:\WINDOWS\System32\fodhelper.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\WINDOWS\explorer.exe,-304
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Base.lnk -> C:\Program Files (x86)\OpenOffice 4\program\sbase.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Calc.lnk -> C:\Program Files (x86)\OpenOffice 4\program\scalc.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Draw.lnk -> C:\Program Files (x86)\OpenOffice 4\program\sdraw.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Impress.lnk -> C:\Program Files (x86)\OpenOffice 4\program\simpress.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Math.lnk -> C:\Program Files (x86)\OpenOffice 4\program\smath.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice Writer.lnk -> C:\Program Files (x86)\OpenOffice 4\program\swriter.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2\OpenOffice.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2\ASIO4ALL v2 Anleitung.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Anleitung.pdf ()
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2\ASIO4ALL Web Site.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL Web Site.url ()
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2\Uninstall.lnk -> C:\Program Files (x86)\ASIO4ALL v2\uninstall.exe ()
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\WINDOWS\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\WINDOWS\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\WINDOWS\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth-Dateiübertragung.LNK -> C:\WINDOWS\System32\fsquirt.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (CyberGhost S.R.L.)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\WINDOWS\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc ()
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\WINDOWS\System32\diskmgmt.msc ()
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation)




ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\WINDOWS\System32\rundll32.exe (Microsoft Corporation) -> -sta {C90FB8CA-3295-4462-A721-2935E83694BA}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Winamp (Safe Mode).lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.) -> /SAFE=1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /7
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Administrator-Toolkit.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\itFrmwrk.exe (Intel(R) Corporation) -> /af Administrator Tool /class IT Admin Class
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Ereignisanzeige für WiFi.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\imFrmwrk.exe (Intel(R) Corporation) -> /sf Wireless Event Viewer
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Erweiterte Statistik für WiFi.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\imFrmwrk.exe (Intel(R) Corporation) -> /sf Advanced Statistics
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\Manuelles Diagnose-Tool für WiFi.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\imFrmwrk.exe (Intel(R) Corporation) -> /sf Wireless Diagnostics
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless\WiFi Connection Utility.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation) -> /af Intel PROSet/Wireless
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Connect.lnk -> C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\WINDOWS\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\WINDOWS\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\WINDOWS\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\WINDOWS\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\WINDOWS\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\WINDOWS\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\WINDOWS\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\Dragonfly\Desktop\-\Avira Launcher.lnk -> C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\WINDOWS\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\WINDOWS\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\WINDOWS\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\WINDOWS\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}


InternetURL: C:\Users\Dragonfly\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
InternetURL: C:\Users\Dragonfly\Favorites\Teen Babysitter Sydney Cole Fucks for Job - Pornhub.com.url -> BASEURL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4 URL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=70742
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Ideas.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72700
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Mail.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72681
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Spaces.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72682
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Auto.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72680
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Fernsehen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72659
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Money.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72640
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Nachrichten.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72636
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Sport.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72635
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72630
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\IE-Site auf Microsoft.com.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72186
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Deutschland GmbH.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72520
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Store.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Windows - Start.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72629
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft zu Hause.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72406
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft.com durchsuchen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72893
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Site für IE Add-Ons.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Users\Dragonfly\Favorites\Links\Vorgeschlagene Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice
InternetURL: C:\Users\Dragonfly\Favorites\Links\Web Slice-Katalog.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\Dragonfly\AppData\Local\Microsoft\Internet Explorer\Pinned Sites\Family Guy (7) - Burning Series Serien online sehen.website -> URL: hxxps://bs.to/serie/Family-Guy/7

==================== Ende von Shortcut.txt =============================
         
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-12-2016
durchgeführt von Dragonfly (Administrator) auf DRAGONFLY-PC (17-12-2016 18:59:13)
Gestartet von C:\Users\Dragonfly\Desktop
Geladene Profile: Dragonfly (Verfügbare Profile: Dragonfly & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\WINDOWS\System32\InstallAgent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynLenovoGestureMgr] => %ProgramFiles%\Synaptics\SynTP\SynLenovoGestureMgr.exe
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61640 2016-11-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-13] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [571928 2015-09-03] (Vimicro)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-614321186-1851163967-905647231-1000\...\RunOnce: [Uninstall C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [172736 2016-12-12] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll Keine Datei

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{532a19c3-72f7-44e7-9dd6-29ffc5f32635}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{710a9cfb-03be-40ab-86c0-bcc56c490da4}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8db06c7b-14a1-4d88-b57a-c536e881adc4}: [DhcpNameServer] 194.187.251.67 185.93.180.131 38.132.106.139

Internet Explorer:
==================
HKU\S-1-5-21-614321186-1851163967-905647231-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\Windows\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default [2016-12-17]
FF Extension: (Avira Browser Safety) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default\Extensions\abs@avira.com.xpi [2016-11-21]
FF Extension: (Video DownloadHelper) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-10-11]
FF Extension: (Adblock Plus) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\WZyZFQzB.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-22] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-22] ()

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-13] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-13] (Avira Operations GmbH & Co. KG)
S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [350528 2016-11-24] (Avira Operations GmbH & Co. KG)
S2 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [76336 2016-11-28] (CyberGhost S.R.L)
S4 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-06-25] ()
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-13] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-13] (NVIDIA Corporation)
S3 PrintNotify; C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll [3337728 2016-09-07] (Microsoft Corporation) [Datei ist nicht signiert]
S4 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation)
S4 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3325232 2012-06-25] (Intel® Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [151352 2016-12-13] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [153904 2016-12-13] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [35488 2016-07-30] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [78208 2016-07-30] (Avira Operations GmbH & Co. KG)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [422656 2016-03-09] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
R3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [648872 2015-09-03] (Vimicro Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 WUDFWpdComp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath
U3 wpcsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-12-17 18:51 - 2016-12-17 18:59 - 00013144 _____ C:\Users\Dragonfly\Desktop\FRST.txt
2016-12-17 18:51 - 2016-12-17 18:51 - 00042436 _____ C:\Users\Dragonfly\Desktop\Shortcut.txt
2016-12-17 18:50 - 2016-12-17 18:51 - 00040991 _____ C:\Users\Dragonfly\Desktop\Addition.txt
2016-12-17 12:32 - 2016-09-09 19:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2016-12-17 12:32 - 2016-09-09 19:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll
2016-12-17 12:32 - 2016-09-09 19:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2016-12-17 12:32 - 2016-09-09 19:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2016-12-17 12:30 - 2016-12-12 22:27 - 00047032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2016-12-17 12:30 - 2016-12-12 04:03 - 40125496 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 35222976 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 34710584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 28201408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 24389160 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 17586992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 14529624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 10912744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 10803880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 10353960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 09158616 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 08913328 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 08761560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 02950200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 02587704 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 01953336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437633.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437633.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 01038392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00974784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00942528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00894400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00802768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00683640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00643928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00572888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00470400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00438208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00394888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00388544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00327408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00153368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00150784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-12-17 12:30 - 2016-12-12 04:03 - 00131536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-12-17 12:22 - 2016-12-17 12:33 - 00005110 _____ C:\ProgramData\NvTelemetryContainer.log_backup1
2016-12-17 12:22 - 2016-12-17 12:22 - 00004418 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-17 12:22 - 2016-12-17 12:22 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Chromium
2016-12-17 12:22 - 2016-12-12 15:36 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2016-12-17 12:21 - 2016-12-17 12:31 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-12-17 12:21 - 2016-12-13 00:36 - 00156096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-12-17 12:21 - 2016-12-13 00:36 - 00123840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-12-14 00:46 - 2016-11-22 12:42 - 00384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2016-12-14 00:46 - 2016-11-22 11:43 - 03692040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-12-14 00:46 - 2016-11-22 11:38 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-12-14 00:46 - 2016-11-22 11:38 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-12-14 00:46 - 2016-11-22 11:36 - 00159640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2016-12-14 00:46 - 2016-11-22 11:35 - 00609056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-12-14 00:46 - 2016-11-22 11:35 - 00075448 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2016-12-14 00:46 - 2016-11-22 11:04 - 02549456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2016-12-14 00:46 - 2016-11-22 11:03 - 01777280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-12-14 00:46 - 2016-11-22 11:02 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-12-14 00:46 - 2016-11-22 11:02 - 01399216 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-12-14 00:46 - 2016-11-22 10:32 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-12-14 00:46 - 2016-11-22 10:24 - 02938408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-12-14 00:46 - 2016-11-22 10:21 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
2016-12-14 00:46 - 2016-11-22 10:17 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2016-12-14 00:46 - 2016-11-22 10:16 - 00064072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2016-12-14 00:46 - 2016-11-22 10:13 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2016-12-14 00:46 - 2016-11-22 10:00 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe
2016-12-14 00:46 - 2016-11-22 09:59 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-12-14 00:46 - 2016-11-22 09:55 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-12-14 00:46 - 2016-11-22 09:54 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-12-14 00:46 - 2016-11-22 09:50 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-12-14 00:46 - 2016-11-22 09:49 - 02195640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2016-12-14 00:46 - 2016-11-22 09:48 - 01522672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-12-14 00:46 - 2016-11-22 09:47 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-12-14 00:46 - 2016-11-22 09:47 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-12-14 00:46 - 2016-11-22 09:35 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-12-14 00:46 - 2016-11-22 09:32 - 01386496 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-12-14 00:46 - 2016-11-22 09:27 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-12-14 00:46 - 2016-11-22 09:20 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-12-14 00:46 - 2016-11-22 09:12 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-12-14 00:46 - 2016-11-22 09:04 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-12-14 00:46 - 2016-11-22 08:57 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-12-14 00:46 - 2016-11-22 08:54 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2016-12-14 00:46 - 2016-11-22 08:53 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-12-14 00:46 - 2016-11-22 08:41 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-12-14 00:46 - 2016-11-22 08:38 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2016-12-14 00:46 - 2016-11-22 08:36 - 00766464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-12-14 00:46 - 2016-11-22 08:26 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-12-14 00:46 - 2016-11-22 08:26 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-12-14 00:46 - 2016-11-22 08:21 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-12-14 00:46 - 2016-11-22 08:15 - 22373376 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-12-14 00:46 - 2016-11-22 08:14 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-12-14 00:46 - 2016-11-22 08:02 - 24610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-12-14 00:46 - 2016-11-22 08:01 - 13392384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-12-14 00:46 - 2016-11-22 07:59 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-12-14 00:46 - 2016-11-22 07:55 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-12-14 00:46 - 2016-11-22 07:49 - 07839232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-12-14 00:46 - 2016-11-22 07:35 - 19350016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-12-14 00:46 - 2016-11-22 07:34 - 18670080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-12-14 00:46 - 2016-11-22 07:34 - 12134400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-12-14 00:46 - 2016-11-22 07:32 - 03663872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-12-14 00:46 - 2016-11-22 07:17 - 05658624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-12-04 00:53 - 2016-12-04 00:53 - 00213053 _____ C:\Users\Dragonfly\Desktop\frenchcore_9.flp
2016-12-04 00:38 - 2016-12-04 00:38 - 00212230 _____ C:\Users\Dragonfly\Desktop\frenchcore_8.flp
2016-12-03 21:44 - 2016-12-03 21:44 - 00211869 _____ C:\Users\Dragonfly\Desktop\frenchcore_7.flp
2016-12-03 21:18 - 2016-12-03 21:18 - 00207810 _____ C:\Users\Dragonfly\Desktop\frenchcore_6.flp
2016-12-03 18:51 - 2016-12-03 18:51 - 00202861 _____ C:\Users\Dragonfly\Desktop\frenchcore_5.flp
2016-12-03 18:38 - 2016-12-03 18:38 - 00156550 _____ C:\Users\Dragonfly\Desktop\frenchcore_4.flp
2016-12-03 18:25 - 2016-12-03 18:25 - 00156753 _____ C:\Users\Dragonfly\Desktop\frenchcore_3.flp
2016-12-03 17:34 - 2016-12-03 17:34 - 00145338 _____ C:\Users\Dragonfly\Desktop\frenchcore_2.flp
2016-12-02 21:51 - 2016-12-03 15:08 - 00145351 _____ C:\Users\Dragonfly\Desktop\frenchcore.flp
2016-12-02 08:21 - 2016-12-03 19:13 - 00000000 ____D C:\Users\Dragonfly\Desktop\speadhead
2016-12-02 03:47 - 2016-12-17 18:48 - 00000000 ____D C:\Users\Dragonfly\Desktop\FRST-OlderVersion
2016-12-01 16:37 - 2016-12-12 04:03 - 20748080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-12-01 16:37 - 2016-12-12 04:03 - 00572584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-12-01 16:37 - 2016-11-24 21:53 - 01951680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437609.dll
2016-12-01 16:37 - 2016-11-24 21:53 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437609.dll
2016-11-30 14:54 - 2016-11-30 14:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-11-30 14:54 - 2016-11-30 14:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_wpdcomp_01_11_00.Wdf
2016-11-22 03:16 - 2016-12-17 18:48 - 02420224 _____ (Farbar) C:\Users\Dragonfly\Desktop\FRST64.exe
2016-11-21 04:41 - 2016-11-17 03:06 - 01953336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437595.dll
2016-11-21 04:41 - 2016-11-17 03:06 - 01585088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437595.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 06384576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 02475968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 01764408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 00548408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 00145344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-11-21 04:33 - 2016-12-11 19:47 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-11-21 04:33 - 2016-12-09 09:52 - 07639617 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-11-21 04:32 - 2016-12-11 19:47 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2016-11-19 21:55 - 2016-11-19 21:55 - 00106714 _____ C:\Users\Dragonfly\Desktop\hummel_gut.flp
2016-11-19 21:49 - 2016-11-19 21:49 - 00106714 _____ C:\Users\Dragonfly\Desktop\hummel_3.flp
2016-11-19 21:47 - 2016-11-19 21:47 - 00106716 _____ C:\Users\Dragonfly\Desktop\hummel_2.flp
2016-11-19 13:57 - 2016-11-19 21:52 - 00105720 _____ C:\Users\Dragonfly\Desktop\hummel.flp
2016-11-18 17:23 - 2016-12-17 18:50 - 00000000 ____D C:\Users\Dragonfly\AppData\LocalLow\Mozilla
2016-11-18 16:02 - 2016-12-17 14:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-11-18 14:17 - 2016-12-12 22:26 - 14200880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-11-18 14:17 - 2016-12-12 04:03 - 03934504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-11-18 14:17 - 2016-12-12 04:03 - 03474392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-11-18 14:17 - 2016-12-12 04:03 - 00172736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-11-18 14:17 - 2016-12-12 04:03 - 00042286 _____ C:\WINDOWS\system32\nvinfo.pb
2016-11-18 14:17 - 2016-11-11 00:51 - 01951680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437586.dll
2016-11-18 14:17 - 2016-11-11 00:51 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437586.dll
2016-11-18 14:17 - 2016-11-11 00:51 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-11-18 14:17 - 2016-11-11 00:51 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2016-11-18 14:11 - 2016-12-17 12:22 - 00001485 _____ C:\Users\Public\Desktop\GeForce Experience.lnk

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-12-17 18:59 - 2016-07-04 21:54 - 00000000 ____D C:\FRST
2016-12-17 17:54 - 2016-07-17 12:15 - 00007634 _____ C:\Users\Dragonfly\AppData\Local\Resmon.ResmonCfg
2016-12-17 17:05 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-12-17 17:05 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-12-17 17:00 - 2016-07-29 23:51 - 00000000 ____D C:\ProgramData\NVIDIA
2016-12-17 14:23 - 2016-09-30 00:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-17 12:37 - 2016-07-14 19:27 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\CrashDumps
2016-12-17 12:33 - 2016-04-27 06:48 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-12-17 12:33 - 2015-10-30 07:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-12-17 12:32 - 2016-07-13 22:03 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-12-17 12:31 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-12-17 12:22 - 2016-10-07 14:21 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-17 12:22 - 2016-10-07 14:20 - 00004004 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-17 12:22 - 2016-10-07 14:20 - 00003976 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-17 12:22 - 2016-10-07 14:20 - 00003968 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-17 12:22 - 2016-10-07 14:20 - 00003806 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-17 12:22 - 2016-10-07 14:20 - 00003764 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-17 12:22 - 2016-07-29 23:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-12-17 12:22 - 2016-07-29 23:50 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-12-17 12:22 - 2016-07-29 23:50 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-12-17 12:22 - 2016-07-13 22:08 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA Corporation
2016-12-17 12:21 - 2016-07-13 22:07 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA
2016-12-16 13:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2016-12-15 11:26 - 2016-07-29 23:53 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-12-15 11:26 - 2016-04-27 06:13 - 00889250 _____ C:\WINDOWS\system32\perfh007.dat
2016-12-15 11:26 - 2016-04-27 06:13 - 00197298 _____ C:\WINDOWS\system32\perfc007.dat
2016-12-14 12:58 - 2016-04-26 21:44 - 00224368 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-12-14 12:56 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-12-14 02:55 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-12-14 02:53 - 2016-07-17 12:16 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-12-14 02:51 - 2016-07-17 12:16 - 135632432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-12-13 01:30 - 2016-07-04 20:21 - 00000000 ____D C:\ProgramData\Package Cache
2016-12-13 01:30 - 2016-07-04 20:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-12-13 01:27 - 2016-10-11 10:32 - 00028272 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2016-12-13 01:27 - 2016-07-04 20:22 - 00153904 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2016-12-13 01:27 - 2016-07-04 20:22 - 00151352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2016-12-13 00:37 - 2016-10-07 14:21 - 01853376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-12-13 00:37 - 2016-10-07 14:21 - 01755072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-12-13 00:37 - 2016-10-07 14:21 - 01452480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-12-13 00:37 - 2016-10-07 14:21 - 01317312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-12-13 00:37 - 2016-10-07 14:21 - 00120256 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-12-13 00:36 - 2016-07-13 22:00 - 00046016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2016-12-12 15:27 - 2016-10-07 14:14 - 00000000 ____D C:\Users\Dragonfly\dwhelper
2016-12-12 00:03 - 2015-10-30 08:26 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-12-12 00:03 - 2015-10-30 08:26 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-12-02 22:53 - 2016-09-29 20:54 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\ElevatedDiagnostics
2016-12-02 07:14 - 2016-07-30 00:35 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Packages
2016-11-22 23:37 - 2016-08-11 00:43 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Adobe
2016-11-22 23:37 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-11-22 23:37 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-11-22 03:59 - 2016-07-25 18:44 - 00000000 __SHD C:\Users\Dragonfly\IntelGraphicsProfiles
2016-11-22 03:14 - 2016-07-17 23:35 - 01741824 _____ (Farbar) C:\Users\Dragonfly\Downloads\FRST.exe
2016-11-21 21:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration
2016-11-21 04:33 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Help
2016-11-21 04:00 - 2016-10-04 11:27 - 00000000 ___HD C:\$SysReset
2016-11-18 20:57 - 2016-07-29 23:50 - 00000000 ____D C:\Program Files\Intel
2016-11-18 20:56 - 2016-08-11 00:52 - 00000000 ____D C:\Program Files\Common Files\McAfee
2016-11-18 20:38 - 2016-08-11 00:43 - 00000000 ____D C:\ProgramData\McAfee

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2016-07-17 12:15 - 2016-12-17 17:54 - 0007634 _____ () C:\Users\Dragonfly\AppData\Local\Resmon.ResmonCfg
2016-12-17 12:22 - 2016-12-17 16:56 - 0003771 _____ () C:\ProgramData\NvTelemetryContainer.log
2016-12-17 12:22 - 2016-12-17 12:33 - 0005110 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1

Einige Dateien in TEMP:
====================
C:\Users\Dragonfly\AppData\Local\Temp\avgnt.exe
C:\Users\Dragonfly\AppData\Local\Temp\NvTelemetry.dll
C:\Users\Dragonfly\AppData\Local\Temp\NvTelemetryAPI32.dll
C:\Users\Dragonfly\AppData\Local\Temp\NvTelemetryAPI64.dll


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2016-12-14 07:01

==================== Ende von FRST.txt ============================
         


Geändert von izockdi (17.12.2016 um 19:17 Uhr)

Alt 20.12.2016, 10:15   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Bitte Avira deinstallieren. Das Teil empfehlen wir schon seit Jahren aus mehreren Gründen nicht mehr. Ein Grund ist ne rel. hohe Fehlalarmquote, der zweite Hauptgrund ist, dass die immer noch mit ASK zusammenarbeiten (Avira Suchfunktion geht über ASK). Auch andere Freewareanbieter wie AVG, Avast oder Panda sprangen auf diesen Zug auf; so was ist bei Sicherheitssoftware einfach inakzeptabel. Vgl. Antivirensoftware: Schutz Für Ihre Dateien, Aber Auf Kosten Ihrer Privatsphäre? | Emsisoft Blog

Gib Bescheid wenn Avira weg ist; wenn wir hier durch sind, kannst du auf einen anderen Virenscanner umsteigen, Infos folgen dann im Abschlussposting. Bitte JETZT nix mehr ohne Absprache installieren!
__________________
--> rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......

Alt 20.01.2017, 05:03   #7
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



ok danke. der rest passt?

Alt 20.01.2017, 10:20   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Was soll das heißen, der Rest passt, lies mein Posting doch mal bis zum Ende - wir sind hier nämlich nicht fertig.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 24.01.2017, 09:52   #9
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



schade dass wir noch nicht fertig sind...
sorry ich hatte wenig zeit die tage und muss gestehen mich auch nicht großartig mit dem thema auseinander gesetzt zu haben. leider häufen sich aber die probleme und dank gebrochenem arm hab ich auch gut zeit.
ich hab emisoft installiert und danach noch mal frst asgeführt.

hier die neuen berichte:


Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2017
durchgeführt von Dragonfly (Administrator) auf DRAGONFLY-PC (24-01-2017 09:38:53)
Gestartet von C:\Users\Dragonfly\Desktop
Geladene Profile: Dragonfly &  (Verfügbare Profile: Dragonfly)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation) C:\Windows\syswow64\IntelCpHeciSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2start.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\Dragonfly\Desktop\FRST64 (1).exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1812544 2016-09-12] (NVIDIA Corporation)
HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [8140696 2016-12-29] (Emsisoft Ltd)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [571928 2015-09-03] (Vimicro)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Keine Datei

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================

FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-23] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-23] (Google Inc.)

Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default [2017-01-24]
CHR Extension: (Google Docs) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-24]
CHR Extension: (Google Drive) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-24]
CHR Extension: (YouTube) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-24]
CHR Extension: (Google Docs Offline) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-24]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-23]
CHR Extension: (Google Mail) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-24]
CHR Extension: (Chrome Media Router) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-24]

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [9461280 2016-12-29] (Emsisoft Ltd)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2017-01-23] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2017-01-23] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R1 epp; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [422656 2016-03-09] (Realsil Semiconductor Corporation)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [42184 2015-06-03] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [648872 2015-09-03] (Vimicro Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-24 08:05 - 2017-01-24 08:05 - 00042168 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2017-01-24 07:50 - 2017-01-24 07:50 - 01932769 _____ C:\Users\Dragonfly\Downloads\processexplorer (1).zip
2017-01-24 06:32 - 2017-01-24 06:32 - 00036409 _____ C:\Users\Dragonfly\Desktop\Shortcut.txt
2017-01-24 06:32 - 2017-01-24 06:32 - 00023299 _____ C:\Users\Dragonfly\Desktop\Addition.txt
2017-01-24 06:31 - 2017-01-24 09:38 - 00007525 _____ C:\Users\Dragonfly\Desktop\FRST.txt
2017-01-24 06:31 - 2017-01-24 06:31 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Desktop\FRST64 (1).exe
2017-01-24 06:30 - 2017-01-24 06:30 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Desktop\FRST64.exe
2017-01-24 01:56 - 2017-01-24 03:41 - 00000000 ____D C:\ProgramData\Emsisoft
2017-01-24 01:55 - 2017-01-24 01:55 - 00000937 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2017-01-24 01:55 - 2017-01-24 01:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2017-01-24 01:54 - 2017-01-24 09:09 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2017-01-24 01:53 - 2017-01-24 01:54 - 241881560 _____ (Emsisoft Ltd. ) C:\Users\Dragonfly\Desktop\EmsisoftAntiMalwareSetup (1).exe
2017-01-24 01:52 - 2017-01-24 01:53 - 241881560 _____ (Emsisoft Ltd. ) C:\Users\Dragonfly\Desktop\EmsisoftAntiMalwareSetup.exe
2017-01-24 01:47 - 2017-01-24 01:47 - 00000000 ____D C:\EEK
2017-01-24 01:45 - 2017-01-24 01:46 - 283519832 _____ C:\Users\Dragonfly\Downloads\EmsisoftEmergencyKit.exe
2017-01-24 01:37 - 2017-01-24 01:37 - 00000000 ____D C:\Users\Dragonfly\Desktop\Neuer Ordner
2017-01-24 01:31 - 2016-10-28 02:22 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-01-24 01:16 - 2017-01-24 06:28 - 00007616 _____ C:\Users\Dragonfly\AppData\Local\resmon.resmoncfg
2017-01-24 00:46 - 2017-01-24 00:46 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Downloads\FRST64 (1).exe
2017-01-24 00:44 - 2017-01-24 00:45 - 02420736 _____ (Farbar) C:\Users\Dragonfly\Downloads\FRST64.exe
2017-01-23 23:22 - 2017-01-23 23:22 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA
2017-01-23 23:17 - 2017-01-23 23:17 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-23 23:17 - 2017-01-23 23:17 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-23 23:17 - 2016-05-04 03:23 - 00129824 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-01-23 23:17 - 2016-05-04 03:22 - 00130848 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-01-23 23:17 - 2016-05-04 03:22 - 00045344 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-01-23 23:17 - 2016-05-04 03:22 - 00040224 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-01-23 22:19 - 2017-01-23 22:19 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Comms
2017-01-23 22:15 - 2017-01-23 22:15 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\LolClient
2017-01-23 22:12 - 2017-01-23 22:12 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk
2017-01-23 22:12 - 2017-01-23 22:12 - 00000000 ____D C:\ProgramData\Riot Games
2017-01-23 22:12 - 2017-01-23 22:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2017-01-23 22:12 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2017-01-23 22:12 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2017-01-23 22:12 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2017-01-23 22:12 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2017-01-23 22:12 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2017-01-23 22:09 - 2017-01-23 22:12 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\Riot Games
2017-01-23 21:57 - 2017-01-23 21:57 - 00000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-01-23 21:53 - 2017-01-23 22:09 - 31876824 _____ (Riot Games) C:\Users\Dragonfly\Downloads\LeagueofLegends_EUW_Installer_2016_11_10.exe
2017-01-23 21:53 - 2017-01-23 21:53 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\Macromedia
2017-01-23 21:48 - 2017-01-23 21:48 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-23 21:48 - 2017-01-23 21:48 - 00002324 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-01-23 21:39 - 2017-01-23 22:58 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-01-23 21:39 - 2017-01-23 22:58 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-01-23 21:39 - 2017-01-23 21:52 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgsnx.sys.148520484293701
2017-01-23 21:39 - 2017-01-23 21:48 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Google
2017-01-23 21:39 - 2017-01-23 21:48 - 00000000 ____D C:\Program Files (x86)\Google
2017-01-23 21:38 - 2017-01-23 21:38 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-01-23 21:38 - 2017-01-23 21:38 - 00000000 ____D C:\Program Files (x86)\USB Camera
2017-01-23 21:36 - 2017-01-23 21:36 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\CEF
2017-01-23 21:35 - 2017-01-24 02:53 - 00000000 ____D C:\ProgramData\Avg
2017-01-23 21:35 - 2017-01-24 02:09 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\AvgSetupLog
2017-01-23 21:35 - 2017-01-23 21:35 - 03449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Dragonfly\Downloads\AVG_Protection_Free_1606.exe
2017-01-23 21:35 - 2017-01-23 21:35 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Avg
2017-01-23 21:33 - 2017-01-23 21:33 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\MicrosoftEdge
2017-01-23 21:31 - 2017-01-23 21:31 - 00015664 _____ C:\Users\Dragonfly\Desktop\Entfernte Anwendungen.html
2017-01-23 21:31 - 2017-01-23 21:31 - 00002366 _____ C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-01-23 21:31 - 2017-01-23 21:31 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\ActiveSync
2017-01-23 21:31 - 2017-01-23 21:31 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2017-01-23 21:30 - 2017-01-24 01:40 - 01799166 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-01-23 21:29 - 2017-01-24 02:03 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Packages
2017-01-23 21:29 - 2017-01-23 21:29 - 00000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2017-01-23 21:29 - 2017-01-23 21:29 - 00000020 ___SH C:\Users\Dragonfly\ntuser.ini
2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\Adobe
2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\VirtualStore
2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\TileDataLayer
2017-01-23 21:29 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Publishers
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Vorlagen
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Startmenü
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\Default User
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Users\All Users
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Vorlagen
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Startmenü
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Favoriten
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Dokumente
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2017-01-23 21:25 - 2017-01-23 21:25 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2017-01-23 21:23 - 2017-01-24 01:25 - 00000000 ____D C:\Users\Dragonfly
2017-01-23 21:23 - 2017-01-23 21:24 - 00000000 ____D C:\Users\DefaultAppPool
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Vorlagen
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Startmenü
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Netzwerkumgebung
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Lokale Einstellungen
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Eigene Dateien
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Druckumgebung
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Documents\Eigene Videos
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Documents\Eigene Musik
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Documents\Eigene Bilder
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\AppData\Local\Verlauf
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\AppData\Local\Anwendungsdaten
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\Dragonfly\Anwendungsdaten
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-01-23 21:23 - 2017-01-23 21:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-01-23 21:17 - 2017-01-23 23:19 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-23 21:17 - 2017-01-23 23:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-01-23 21:17 - 2017-01-23 23:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-01-23 21:17 - 2017-01-23 21:17 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-01-23 21:17 - 2017-01-23 21:17 - 00000000 ____D C:\Program Files\Common Files\Atheros
2017-01-23 21:17 - 2016-08-01 13:54 - 06386744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 02466360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 01365048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2017-01-23 21:17 - 2016-08-01 13:54 - 00547896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 00139712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-01-23 21:17 - 2016-07-28 14:02 - 07242545 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-01-23 21:17 - 2016-05-03 22:30 - 00081416 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2017-01-23 21:17 - 2016-05-03 22:30 - 00077832 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____D C:\ProgramData\USOShared
2017-01-23 21:16 - 2017-01-23 21:16 - 00000000 ____D C:\Program Files\Intel
2017-01-23 21:15 - 2017-01-23 20:52 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-01-23 21:13 - 2017-01-24 01:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-01-23 21:13 - 2017-01-23 21:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-01-23 21:12 - 2017-01-23 21:21 - 00194272 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-01-23 21:11 - 2017-01-23 21:26 - 00000000 ___DC C:\WINDOWS\Panther
2017-01-23 21:11 - 2017-01-23 21:11 - 00000000 ____D C:\WINDOWS\InfusedApps
2017-01-23 21:10 - 2017-01-24 05:24 - 00000000 ____D C:\Windows.old
2017-01-23 21:10 - 2017-01-23 21:10 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-01-23 21:08 - 2017-01-23 21:08 - 00000000 ____D C:\Program Files\Synaptics
2017-01-23 21:07 - 2017-01-23 21:07 - 00000000 ____D C:\WINDOWS\Setup
2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\OCR
2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files\MSBuild
2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-01-23 21:02 - 2017-01-23 21:02 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-01-23 21:01 - 2017-01-24 01:40 - 00776766 _____ C:\WINDOWS\system32\perfh007.dat
2017-01-23 21:01 - 2017-01-24 01:40 - 00155544 _____ C:\WINDOWS\system32\perfc007.dat
2017-01-23 21:01 - 2017-01-23 21:00 - 00305634 _____ C:\WINDOWS\system32\perfi007.dat
2017-01-23 21:01 - 2017-01-23 21:00 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\de
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\winrm
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\WCN
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\slmgr
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\de
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\0409
2017-01-23 21:00 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\DigitalLocker
2017-01-23 20:57 - 2017-01-23 20:52 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-01-23 20:57 - 2017-01-23 20:52 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-23 20:56 - 2017-01-23 20:53 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2017-01-23 20:56 - 2017-01-23 20:53 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-01-23 20:56 - 2017-01-23 20:53 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat
2017-01-23 20:56 - 2017-01-23 20:53 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat
2017-01-23 20:56 - 2017-01-23 20:53 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2017-01-23 20:55 - 2017-01-24 03:39 - 00000000 ____D C:\WINDOWS\appcompat
2017-01-23 20:55 - 2017-01-24 02:12 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-23 20:55 - 2017-01-24 02:12 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-01-23 20:55 - 2017-01-24 01:22 - 00000000 ____D C:\WINDOWS\Registration
2017-01-23 20:55 - 2017-01-23 21:46 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2017-01-23 20:55 - 2017-01-23 21:38 - 00000000 ____D C:\WINDOWS\System
2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\PrintDialog
2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\MiracastView
2017-01-23 20:55 - 2017-01-23 21:29 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-01-23 20:55 - 2017-01-23 21:27 - 00000000 ____D C:\WINDOWS\rescache
2017-01-23 20:55 - 2017-01-23 21:25 - 00000000 ____D C:\Program Files\Windows NT
2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 __RHD C:\Users\Public\Libraries
2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 ____D C:\WINDOWS\system32\spool
2017-01-23 20:55 - 2017-01-23 21:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2017-01-23 20:55 - 2017-01-23 21:20 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-01-23 20:55 - 2017-01-23 21:17 - 00000000 ____D C:\WINDOWS\Help
2017-01-23 20:55 - 2017-01-23 21:11 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 __RSD C:\WINDOWS\Media
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\Provisioning
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files\Windows Portable Devices
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-01-23 20:55 - 2017-01-23 21:06 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-01-23 20:55 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-01-23 20:55 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\SystemApps
2017-01-23 20:55 - 2017-01-23 21:02 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\system32\dsc
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\setup
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\system32\Com
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\IME
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Windows Defender
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Common Files\System
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-01-23 20:55 - 2017-01-23 21:00 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-01-23 20:55 - 2017-01-23 20:56 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 __SHD C:\Program Files\Windows Sidebar
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\system32\Nui
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Web
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Vss
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\tracing
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\TAPI
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SystemResources
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\winevt
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\ras
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\IME
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\icsxml
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\ias
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\downlevel
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SKB
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\security
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\schemas
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SchCache
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Resources
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\PLA
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Performance
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\ModemLogs
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\L2Schemas
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\InputMethod
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Globalization
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Cursors
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Branding
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\addins
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\ProgramData\USOPrivate
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\ProgramData\Comms
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\Program Files\Common Files\Services
2017-01-23 20:55 - 2017-01-23 20:55 - 00000000 ____D C:\Program Files (x86)\Windows NT
2017-01-23 20:55 - 2017-01-23 20:53 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-01-23 20:55 - 2017-01-23 20:53 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2017-01-23 20:55 - 2017-01-23 20:53 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
2017-01-23 20:55 - 2017-01-23 20:53 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-01-23 20:55 - 2017-01-23 20:53 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat
2017-01-23 20:55 - 2017-01-23 20:53 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2017-01-23 20:55 - 2017-01-23 20:53 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat
2017-01-23 20:55 - 2017-01-23 20:53 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2017-01-23 20:55 - 2017-01-23 20:53 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2017-01-23 20:55 - 2017-01-23 20:53 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2017-01-23 20:55 - 2017-01-23 20:53 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2017-01-23 20:55 - 2017-01-23 20:53 - 00000389 _____ C:\WINDOWS\system32\AutoWorkplace.exe.config
2017-01-23 20:55 - 2017-01-23 20:53 - 00000219 _____ C:\WINDOWS\system.ini
2017-01-23 20:55 - 2017-01-23 20:53 - 00000092 _____ C:\WINDOWS\win.ini
2017-01-23 20:54 - 2017-01-24 04:50 - 00000000 ____D C:\WINDOWS\INF
2017-01-23 20:43 - 2017-01-24 04:03 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-01-23 20:33 - 2017-01-24 01:32 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2017-01-23 20:33 - 2017-01-23 21:16 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2017-01-23 20:33 - 2017-01-23 21:00 - 00000000 ____D C:\WINDOWS\servicing
2017-01-23 20:33 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\SMI
2017-01-23 20:33 - 2015-10-30 07:33 - 00000164 _____ C:\WINDOWS\system32\config\FP
2017-01-22 16:50 - 2017-01-22 16:52 - 00000000 ____D C:\Users\Dragonfly\Desktop\Neuer Ordner (2)
2017-01-20 05:39 - 2017-01-20 05:39 - 00000000 ____D C:\Users\Dragonfly\AppData\Temp
2017-01-20 05:32 - 2017-01-23 20:32 - 00002362 _____ C:\bdlog.txt
2017-01-20 05:30 - 2017-01-20 05:30 - 00000684 ____H C:\bdr-cf01
2017-01-20 05:29 - 2017-01-20 05:30 - 00253404 ____H C:\bdr-ld01
2017-01-20 05:29 - 2017-01-20 05:30 - 00009216 ____H C:\bdr-ld01.mbr
2017-01-20 05:29 - 2016-10-18 11:51 - 49758588 ____H C:\bdr-im01.gz
2017-01-20 05:29 - 2013-08-13 13:38 - 03271472 ____H C:\bdr-bz01
2017-01-20 05:09 - 2017-01-20 05:11 - 11842672 _____ C:\Users\Dragonfly\Desktop\bitdefender_antivirus.exe
2017-01-15 00:00 - 2017-01-23 20:29 - 00000000 ____D C:\Users\Dragonfly\Documents\13 in one Session
2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\Sleepless & Destruction
2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\Projects3
2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\Projects in 2016
2017-01-15 00:00 - 2017-01-15 00:00 - 00000000 ____D C:\Users\Dragonfly\Documents\2016
2017-01-15 00:00 - 2017-01-14 23:59 - 00000068 _____ C:\Users\Dragonfly\Desktop\pmp_usb.ini
2017-01-15 00:00 - 2017-01-14 14:01 - 00000110 ____H C:\Users\Dragonfly\Desktop\.~lock.TOM  Bewerbung Krankenpfleger wbg.odt#
2017-01-15 00:00 - 2017-01-14 13:59 - 00017624 _____ C:\Users\Dragonfly\Desktop\TOM Lebenslauf.odt
2017-01-15 00:00 - 2017-01-05 11:32 - 00006869 _____ C:\Users\Dragonfly\Desktop\TOM  Bewerbung Krankenpfleger wbg.odt
2017-01-15 00:00 - 2016-10-26 17:46 - 00020499 _____ C:\Users\Dragonfly\Desktop\TOM  Bewerbung Krankenpfleger.odt
2017-01-15 00:00 - 2016-10-24 09:05 - 00082789 _____ C:\Users\Dragonfly\Desktop\winamp_metadata.dat
2017-01-15 00:00 - 2016-10-24 09:05 - 00004196 _____ C:\Users\Dragonfly\Desktop\winamp_metadata.idx
2017-01-15 00:00 - 2016-07-17 15:12 - 00185700 _____ C:\Users\Dragonfly\Documents\Daso_Version 2.flp
2017-01-15 00:00 - 2013-06-10 18:59 - 00015014 _____ C:\Users\Dragonfly\Desktop\TOM  Bewerbung Lehre Wasserburg.odt
2017-01-15 00:00 - 2013-06-03 20:43 - 00014689 _____ C:\Users\Dragonfly\Desktop\TOM  Bewerbung Lehre.odt
2017-01-15 00:00 - 2010-06-15 22:26 - 00102759 _____ C:\Users\Dragonfly\Documents\needspweed2.flp
2017-01-15 00:00 - 2010-06-10 16:09 - 00126729 _____ C:\Users\Dragonfly\Documents\wooly days neuer bass.flp
2017-01-15 00:00 - 2010-05-28 20:52 - 00100757 _____ C:\Users\Dragonfly\Documents\melodie.flp
2017-01-15 00:00 - 2010-02-10 19:58 - 00274250 _____ C:\Users\Dragonfly\Documents\Neustart4.flp
2017-01-14 23:59 - 2017-01-14 23:59 - 00000000 ____D C:\Users\Dragonfly\Documents\Acid Trumpet - becomming shroom
2017-01-14 23:59 - 2017-01-14 23:59 - 00000000 ____D C:\Users\Dragonfly\Desktop\Faithless
2017-01-14 14:09 - 2017-01-14 14:09 - 00018268 _____ C:\Users\Dragonfly\Documents\TOM  Bewerbung Krankenpfleger wbg.odt
2016-12-30 23:49 - 2017-01-09 13:26 - 00000000 ____D C:\Users\Dragonfly\Documents\hummel
2016-12-28 14:50 - 2016-12-28 14:51 - 00311294 _____ C:\Users\Dragonfly\Documents\goa drogen4 blue.png

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-24 09:38 - 2016-07-04 21:54 - 00000000 ____D C:\FRST
2017-01-24 09:09 - 2016-11-18 07:18 - 01457312 _____ (Sysinternals - www.sysinternals.com) C:\Users\Dragonfly\Desktop\procexp64.exe
2017-01-24 09:08 - 2016-07-25 18:44 - 00000000 __SHD C:\Users\Dragonfly\IntelGraphicsProfiles
2017-01-24 07:51 - 2016-11-18 07:26 - 02720928 _____ (Sysinternals - www.sysinternals.com) C:\Users\Dragonfly\Desktop\procexp.exe
2017-01-24 07:50 - 2016-11-18 07:10 - 00072154 _____ C:\Users\Dragonfly\Desktop\procexp.chm
2017-01-24 07:50 - 2016-03-03 21:44 - 00007490 _____ C:\Users\Dragonfly\Desktop\Eula.txt
2017-01-24 05:24 - 2016-10-04 11:27 - 00000000 ___HD C:\$SysReset
2017-01-23 21:31 - 2016-07-30 00:38 - 00000000 ___RD C:\Users\Dragonfly\OneDrive
2017-01-23 21:29 - 2016-04-27 06:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-01-23 21:24 - 2010-11-21 08:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2017-01-23 21:06 - 2016-04-27 06:17 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-01-23 21:06 - 2016-04-27 06:17 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-01-23 21:06 - 2016-04-27 06:17 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2017-01-23 20:53 - 2016-04-27 06:17 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-01-23 20:53 - 2016-04-27 06:17 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-01-23 20:53 - 2016-04-27 06:17 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2017-01-23 20:53 - 2016-04-27 06:17 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-01-23 20:53 - 2016-04-27 06:17 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2017-01-23 20:53 - 2016-04-27 06:17 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2017-01-23 20:53 - 2016-04-27 06:17 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-01-23 20:53 - 2016-04-27 06:17 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2017-01-23 20:53 - 2016-04-27 06:17 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-01-23 20:53 - 2016-04-27 06:17 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2017-01-23 20:53 - 2015-10-30 08:19 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2017-01-23 20:53 - 2015-10-30 08:19 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2017-01-23 20:53 - 2015-10-30 08:19 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll
2017-01-23 20:53 - 2015-10-30 08:19 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2017-01-23 20:53 - 2015-10-30 08:19 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPDShServiceObj.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 01123328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00965120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00824832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comuid.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00451072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUXHost.exe
2017-01-23 20:53 - 2015-10-30 08:18 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoipRT.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUX.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msobjs.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2017-01-23 20:53 - 2015-10-30 08:18 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2017-01-23 20:53 - 2015-10-30 08:17 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2017-01-23 20:53 - 2015-10-30 08:17 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2017-01-23 20:53 - 2015-10-30 08:17 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys
2017-01-23 20:53 - 2015-10-30 08:17 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsvc.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-01-23 20:52 - 2016-04-27 06:17 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-01-23 20:52 - 2016-04-27 06:17 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2017-01-23 20:52 - 2016-04-27 06:17 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-01-23 20:52 - 2016-04-27 06:17 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-01-23 20:52 - 2016-04-27 06:17 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-01-23 20:52 - 2016-04-27 06:17 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-01-23 20:52 - 2016-04-27 06:17 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
2017-01-23 20:52 - 2016-04-27 06:17 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2017-01-23 20:52 - 2016-04-27 06:17 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2017-01-23 20:52 - 2016-04-27 06:17 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2017-01-23 20:52 - 2016-04-27 06:17 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 28851224 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 01558528 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sbe.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartCardSimulator.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmsdk.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00495848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmdev.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dxpserver.exe
2017-01-23 20:52 - 2015-10-30 08:19 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiarpc.dll
2017-01-23 20:52 - 2015-10-30 08:19 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\vsstrace.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 04405248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 02771968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 02723840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 02519552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 02361856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 02102272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01987072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01187840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFramework.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01166848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Pimstore.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01085736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00885248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00835072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroles.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00759808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-01-23 20:52 - 2015-10-30 08:18 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2017-01-23 20:52 - 2015-10-30 08:18 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00707600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcsecproc_ssp.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00599040 _____ (Microsoft Corporation) C:\WINDOWS\system32\duser.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2017-01-23 20:52 - 2015-10-30 08:18 - 00504832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00442880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-01-23 20:52 - 2015-10-30 08:18 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00355680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00324448 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2017-01-23 20:52 - 2015-10-30 08:18 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2017-01-23 20:52 - 2015-10-30 08:18 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssphtb.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.ps.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2017-01-23 20:52 - 2015-10-30 08:18 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\spcompat.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\pngfilt.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-01-23 20:52 - 2015-10-30 08:18 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2017-01-23 20:52 - 2015-10-30 08:18 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\IconCodecService.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 04387680 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 03093504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 02573824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 02187408 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 02012672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmsipc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 01443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagperf.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 01424384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 01238584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcsecproc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 01113600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpedit.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00697344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00513024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00512512 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00511488 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00507904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcfile.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 00390656 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPSECSVC.DLL
2017-01-23 20:52 - 2015-10-30 08:17 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\polstore.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00317952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 00204048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2017-01-23 20:52 - 2015-10-30 08:17 - 00131424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufxsynopsys.sys
2017-01-23 20:52 - 2015-10-30 08:17 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapsvc.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecureTimeAggregator.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00080640 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpreference.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 00058208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwminit.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-01-23 20:52 - 2015-10-30 08:17 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe
2017-01-23 20:52 - 2015-10-30 08:17 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-01-23 20:51 - 2016-04-27 06:17 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-01-23 20:51 - 2016-04-27 06:17 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2017-01-23 20:51 - 2016-04-27 06:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-01-23 20:51 - 2016-04-27 06:17 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2017-01-23 20:51 - 2016-04-27 06:17 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-01-23 20:51 - 2016-04-27 06:17 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-01-23 20:51 - 2016-04-27 06:17 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-01-23 20:51 - 2016-04-27 06:17 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2017-01-23 20:51 - 2016-04-27 06:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2017-01-23 20:51 - 2016-04-27 06:17 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-01-23 20:51 - 2016-04-27 06:17 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2017-01-23 20:51 - 2016-04-27 06:17 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2017-01-23 20:51 - 2016-04-27 06:17 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 03415040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 02331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2017-01-23 20:51 - 2015-10-30 08:19 - 02217984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe
2017-01-23 20:51 - 2015-10-30 08:19 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00253080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-01-23 20:51 - 2015-10-30 08:19 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceConnectApi.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 06471168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-01-23 20:51 - 2015-10-30 08:18 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 04143104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 04078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 03577344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 02849792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 02632192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 02195128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 02106368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certmgr.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01676288 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01557504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01552104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01537024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pla.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01535024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01336832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01240064 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01228800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01194496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-01-23 20:51 - 2015-10-30 08:18 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00963072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-01-23 20:51 - 2015-10-30 08:18 - 00846080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00824832 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00726288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00638304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2017-01-23 20:51 - 2015-10-30 08:18 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00535088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00516608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00503600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00453464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DbgModel.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2017-01-23 20:51 - 2015-10-30 08:18 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2017-01-23 20:51 - 2015-10-30 08:18 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00322560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysdm.cpl
2017-01-23 20:51 - 2015-10-30 08:18 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WmpDui.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2017-01-23 20:51 - 2015-10-30 08:18 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2017-01-23 20:51 - 2015-10-30 08:18 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2017-01-23 20:51 - 2015-10-30 08:18 - 00256192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Maps.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe
2017-01-23 20:51 - 2015-10-30 08:18 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2017-01-23 20:51 - 2015-10-30 08:18 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10_1.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usbceip.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2017-01-23 20:51 - 2015-10-30 08:18 - 00116216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00097088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00064584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Clipc.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msobjs.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2017-01-23 20:51 - 2015-10-30 08:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2017-01-23 20:51 - 2015-10-30 08:18 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 03350528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 03079168 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 02745856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 02476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 02103296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01965568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01603224 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01568768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 01540216 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01447784 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01338368 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01337184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 01144320 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00897024 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppinst.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00742200 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00528736 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcbase.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskeng.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsExt.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmdskmgr.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00259840 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhengine.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00209760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cic.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00131248 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcshext.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoipRT.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvc.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00087904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdport.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\filecrypt.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2017-01-23 20:51 - 2015-10-30 08:17 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2017-01-23 20:51 - 2015-10-30 08:17 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2017-01-23 20:51 - 2015-10-30 08:17 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2017-01-23 20:50 - 2016-04-27 06:17 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-01-23 20:50 - 2016-04-27 06:17 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
         

Alt 24.01.2017, 09:53   #10
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Code:
ATTFilter
2017-01-23 20:50 - 2016-04-27 06:17 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-01-23 20:50 - 2016-04-27 06:17 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2017-01-23 20:50 - 2016-04-27 06:17 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-01-23 20:50 - 2016-04-27 06:17 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2017-01-23 20:50 - 2016-04-27 06:17 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2017-01-23 20:50 - 2016-04-27 06:17 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-01-23 20:50 - 2016-04-27 06:17 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2017-01-23 20:50 - 2016-04-27 06:17 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-01-23 20:50 - 2016-04-27 06:17 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2017-01-23 20:50 - 2016-04-27 06:17 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2017-01-23 20:50 - 2016-04-27 06:17 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2017-01-23 20:50 - 2015-10-30 08:19 - 03573248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 03555840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2017-01-23 20:50 - 2015-10-30 08:19 - 03459584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 01570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2017-01-23 20:50 - 2015-10-30 08:19 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00992256 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00918016 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmsdk.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00588320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmdev.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-01-23 20:50 - 2015-10-30 08:19 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2017-01-23 20:50 - 2015-10-30 08:19 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 03065344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2017-01-23 20:50 - 2015-10-30 08:18 - 03046400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 02563584 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-01-23 20:50 - 2015-10-30 08:18 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01865584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01537024 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01276928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01162144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01094656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 01033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00952320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2017-01-23 20:50 - 2015-10-30 08:18 - 00716640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-01-23 20:50 - 2015-10-30 08:18 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmIndexer.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00620176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00559616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00512816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnfldr.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2017-01-23 20:50 - 2015-10-30 08:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WLanConn.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00405856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2017-01-23 20:50 - 2015-10-30 08:18 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WmpDui.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authfwcfg.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\syncutil.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00312160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00268040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2017-01-23 20:50 - 2015-10-30 08:18 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2017-01-23 20:50 - 2015-10-30 08:18 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GnssAdapter.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00175120 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00170848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.exe
2017-01-23 20:50 - 2015-10-30 08:18 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00129888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2017-01-23 20:50 - 2015-10-30 08:18 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00107408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FingerprintEnrollment.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevDispItemProvider.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SCardDlg.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00064072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00057912 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2017-01-23 20:50 - 2015-10-30 08:18 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwcfg.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2017-01-23 20:50 - 2015-10-30 08:18 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CheckNetIsolation.exe
2017-01-23 20:50 - 2015-10-30 08:18 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 02874880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 02445312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 01465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2017-01-23 20:50 - 2015-10-30 08:17 - 01434112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 01098640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00904704 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipsecsnp.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\comuid.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00775344 _____ C:\WINDOWS\SysWOW64\locale.nls
2017-01-23 20:50 - 2015-10-30 08:17 - 00757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcsecproc_ssp.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00619520 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00600064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00465248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00422752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2017-01-23 20:50 - 2015-10-30 08:17 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00290856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2017-01-23 20:50 - 2015-10-30 08:17 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrokerLib.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpclean.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00124248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00100752 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthmodem.sys
2017-01-23 20:50 - 2015-10-30 08:17 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2017-01-23 20:50 - 2015-10-30 08:17 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-01-23 20:49 - 2016-04-27 06:17 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-01-23 20:49 - 2016-04-27 06:17 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2017-01-23 20:49 - 2016-04-27 06:17 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-01-23 20:49 - 2016-04-27 06:17 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2017-01-23 20:49 - 2016-04-27 06:17 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2017-01-23 20:49 - 2016-04-27 06:17 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-01-23 20:49 - 2016-04-27 06:17 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-01-23 20:49 - 2016-04-27 06:17 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
2017-01-23 20:49 - 2016-04-27 06:17 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-01-23 20:49 - 2016-04-27 06:17 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2017-01-23 20:49 - 2016-04-27 06:17 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-01-23 20:49 - 2016-04-27 06:17 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2017-01-23 20:49 - 2015-10-30 08:19 - 28083144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 09375232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2017-01-23 20:49 - 2015-10-30 08:19 - 04170240 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 02578432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 01976832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 01140224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00879616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00546816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2017-01-23 20:49 - 2015-10-30 08:19 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00305296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceConnectApi.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDShServiceObj.dll
2017-01-23 20:49 - 2015-10-30 08:19 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vsstrace.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 06675968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-01-23 20:49 - 2015-10-30 08:18 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 04170752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 03053568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 02902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 02679808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 02641928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2017-01-23 20:49 - 2015-10-30 08:18 - 02548432 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01582592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmsipc.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01297408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2017-01-23 20:49 - 2015-10-30 08:18 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01159168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpedit.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcsecproc.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2017-01-23 20:49 - 2015-10-30 08:18 - 00862720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00836208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2017-01-23 20:49 - 2015-10-30 08:18 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00753664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00706048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00686984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00629760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00523264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00486400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00482816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\duser.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00482816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe
2017-01-23 20:49 - 2015-10-30 08:18 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00430816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00405504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2017-01-23 20:49 - 2015-10-30 08:18 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wbemcomn.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe
2017-01-23 20:49 - 2015-10-30 08:18 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcfile.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00328520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
2017-01-23 20:49 - 2015-10-30 08:18 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\polstore.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00273752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00252064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2017-01-23 20:49 - 2015-10-30 08:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe
2017-01-23 20:49 - 2015-10-30 08:18 - 00183896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00129368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-01-23 20:49 - 2015-10-30 08:18 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00069224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
2017-01-23 20:49 - 2015-10-30 08:18 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Cortana.ProxyStub.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FwRemoteSvr.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe
2017-01-23 20:49 - 2015-10-30 08:18 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2017-01-23 20:49 - 2015-10-30 08:18 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IconCodecService.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 04212736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMM.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 02881536 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01951848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01847520 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01783808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01743872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01526784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\pla.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01479168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00958464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00871776 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00707424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00638816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00619296 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxApplicabilityEngine.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00550656 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00439128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2017-01-23 20:49 - 2015-10-30 08:17 - 00414559 _____ C:\WINDOWS\system32\ApnDatabase.xml
2017-01-23 20:49 - 2015-10-30 08:17 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-01-23 20:49 - 2015-10-30 08:17 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00337328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00254816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe
2017-01-23 20:49 - 2015-10-30 08:17 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00216408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00110552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevDispItemProvider.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Clipc.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2017-01-23 20:49 - 2015-10-30 08:17 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2017-01-23 20:49 - 2015-10-30 08:17 - 00030048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\genericusbfn.sys
2017-01-23 20:49 - 2015-10-30 08:17 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-01-23 20:48 - 2016-04-27 06:17 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2017-01-23 20:48 - 2016-04-27 06:17 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-01-23 20:48 - 2016-04-27 06:17 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-01-23 20:48 - 2016-04-27 06:17 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2017-01-23 20:48 - 2016-04-27 06:17 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2017-01-23 20:48 - 2016-04-27 06:17 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2017-01-23 20:48 - 2015-10-30 08:19 - 09375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2017-01-23 20:48 - 2015-10-30 08:19 - 04646400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2017-01-23 20:48 - 2015-10-30 08:19 - 03549184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 03301376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncCenter.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 01211392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 01186816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll
2017-01-23 20:48 - 2015-10-30 08:19 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 04268360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 03294208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 02527232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 02177024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 02144512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01915392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01562112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 01554152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01522152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01355344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01349128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 01083136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 00854016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00785920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00730352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00589856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00569744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00507904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnfldr.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 00431296 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00385376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-01-23 20:48 - 2015-10-30 08:18 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanui.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00357216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00306840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00300032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcbase.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsExt.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskeng.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2017-01-23 20:48 - 2015-10-30 08:18 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmdskmgr.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingMonitor.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cic.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcshext.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2017-01-23 20:48 - 2015-10-30 08:18 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2017-01-23 20:48 - 2015-10-30 08:18 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 01671168 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 01051136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagCpl.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 01040792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00994816 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-01-23 20:48 - 2015-10-30 08:17 - 00904704 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmIndexer.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00775344 _____ C:\WINDOWS\system32\locale.nls
2017-01-23 20:48 - 2015-10-30 08:17 - 00764976 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00705584 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2017-01-23 20:48 - 2015-10-30 08:17 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\filemgmt.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00527872 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanConn.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\authfwcfg.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbemcomn.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00458240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroleui.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00435712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00414232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00341944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00330080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2017-01-23 20:48 - 2015-10-30 08:17 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2017-01-23 20:48 - 2015-10-30 08:17 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe
2017-01-23 20:48 - 2015-10-30 08:17 - 00159648 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsutil.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00106928 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2017-01-23 20:48 - 2015-10-30 08:17 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00075448 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwcfg.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2017-01-23 20:48 - 2015-10-30 08:17 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys
2017-01-23 20:48 - 2015-10-30 08:17 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys
2017-01-23 20:48 - 2015-10-30 08:17 - 00033472 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-01-23 20:48 - 2015-10-30 08:17 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CheckNetIsolation.exe
2017-01-23 20:48 - 2015-10-30 08:17 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
2017-01-23 20:48 - 2015-10-30 08:17 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MTConfig.sys
2017-01-23 20:47 - 2016-04-27 06:17 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-01-23 20:47 - 2016-04-27 06:17 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2017-01-23 20:47 - 2015-10-30 08:19 - 02731008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2017-01-23 20:47 - 2015-10-30 08:18 - 03679232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2017-01-23 20:47 - 2015-10-30 08:18 - 00435200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-01-23 20:29 - 2016-08-09 18:42 - 00000000 ____D C:\Users\Dragonfly\Documents\Projects
2017-01-23 20:29 - 2016-07-30 23:04 - 00000000 ___RD C:\Users\Dragonfly\Desktop\-
2017-01-23 19:36 - 2016-11-18 17:23 - 00000000 ____D C:\Users\Dragonfly\AppData\LocalLow\Mozilla
2017-01-17 15:54 - 2016-10-07 14:14 - 00000000 ____D C:\Users\Dragonfly\dwhelper
2017-01-02 14:10 - 2016-07-14 15:21 - 10328598 _____ (Nullsoft, Inc.) C:\Users\Dragonfly\Downloads\winamp5666_full_en-us_redux.exe

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2017-01-24 01:16 - 2017-01-24 06:28 - 0007616 _____ () C:\Users\Dragonfly\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-01-23 21:42

==================== Ende von FRST.txt ============================
         
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 22-01-2017
durchgeführt von Dragonfly (24-01-2017 09:39:54)
Gestartet von C:\Users\Dragonfly\Desktop
Windows 10 Home Version 1511 (X64) (2017-01-23 20:26:00)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-614321186-1851163967-905647231-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-614321186-1851163967-905647231-503 - Limited - Disabled)
Dragonfly (S-1-5-21-614321186-1851163967-905647231-1000 - Administrator - Enabled) => C:\Users\Dragonfly
Gast (S-1-5-21-614321186-1851163967-905647231-501 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Emsisoft Anti-Malware (Enabled - Up to date) {701CB209-EBBC-AADC-11E6-DE73E7AF4C9D}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {CB7D53ED-CD86-A552-2B56-E5019C280620}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Emsisoft Anti-Malware (HKLM\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 12.2 - Emsisoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.123 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games)
League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 3.15.0414.1 - Vimicro)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
NVIDIA Grafiktreiber 369.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 369.09 - NVIDIA Corporation)
NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.9.5 - Synaptics Incorporated)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-614321186-1851163967-905647231-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {50EB80B4-0793-4AD7-880B-13CF2D3CE57A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-23] (Google Inc.)
Task: {FC35B7C5-F263-4BA7-B430-A22F1D73449E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-23] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)


==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 ____N () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-01-23 21:17 - 2016-08-01 13:54 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-04-27 06:17 - 2017-01-23 20:53 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-01-24 01:54 - 2017-01-24 01:55 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-04-27 06:17 - 2017-01-23 20:53 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-04-27 06:17 - 2016-04-27 06:17 - 00093696 ____N () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-27 06:17 - 2017-01-23 20:49 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-27 06:17 - 2017-01-23 20:52 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-27 06:17 - 2017-01-23 20:52 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-27 06:17 - 2017-01-23 20:52 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-27 06:17 - 2017-01-23 20:52 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-01-24 01:54 - 2017-01-24 01:55 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2017-01-24 01:54 - 2017-01-24 01:55 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2017-01-23 20:55 - 2017-01-23 20:53 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-614321186-1851163967-905647231-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper -> $(runtime.windows)\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

HKLM\...\StartupApproved\Run32: => "331BigDog"
HKU\S-1-5-21-614321186-1851163967-905647231-1000\...\StartupApproved\Run: => "OneDrive"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [{5F2A0CDB-43ED-4F23-87D2-5FCC23AB5538}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{BF250A34-5A24-49D6-8698-DF9993664B60}C:\windows\system32\mmc.exe] => C:\windows\system32\mmc.exe
FirewallRules: [UDP Query User{978339B8-8D4A-4EF1-BE90-837538EA8ADE}C:\windows\system32\mmc.exe] => C:\windows\system32\mmc.exe

==================== Wiederherstellungspunkte =========================

23-01-2017 22:09:56 Microsoft Visual C++ 2005 Redistributable (x64) wird installiert

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Lenovo EasyCamera
Description: Lenovo EasyCamera
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Chicony
Service: vm331avs
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Microsoft Device Association Root Enumerator
Description: Generisches Softwaregerät
Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
Manufacturer: Microsoft
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Qualcomm Atheros AR3012 Bluetooth 4.0
Description: Qualcomm Atheros AR3012 Bluetooth 4.0
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Qualcomm Atheros Communications
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Microsoft GS Wavetable Synthesizer
Description: Generisches Softwaregerät
Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
Manufacturer: Microsoft
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/24/2017 09:08:57 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (01/24/2017 09:08:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SearchUI.exe, Version: 10.0.10586.63, Zeitstempel: 0x568b1fdc
Name des fehlerhaften Moduls: Windows.UI.Xaml.dll, Version: 10.0.10586.71, Zeitstempel: 0x5699d8e0
Ausnahmecode: 0xc000027b
Fehleroffset: 0x00000000006fce8b
ID des fehlerhaften Prozesses: 0xdac
Startzeit der fehlerhaften Anwendung: 0x01d276191700dba4
Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
Pfad des fehlerhaften Moduls: C:\Windows\System32\Windows.UI.Xaml.dll
Berichtskennung: beee5f28-69a6-4673-94dd-567d6955e075
Vollständiger Name des fehlerhaften Pakets: Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: CortanaUI

Error: (01/24/2017 05:34:46 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: edgehtml.dll, Version: 11.0.10586.162, Zeitstempel: 0x56cd3d95
Ausnahmecode: 0xc0000602
Fehleroffset: 0x00000000004a5851
ID des fehlerhaften Prozesses: 0x15ec
Startzeit der fehlerhaften Anwendung: 0x01d275faf8b28cf1
Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\edgehtml.dll
Berichtskennung: 01245a2d-b6cb-4750-95f2-1b5fe855ca3f
Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge

Error: (01/24/2017 05:33:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: edgehtml.dll, Version: 11.0.10586.162, Zeitstempel: 0x56cd3d95
Ausnahmecode: 0xc0000602
Fehleroffset: 0x00000000004a5851
ID des fehlerhaften Prozesses: 0xcd4
Startzeit der fehlerhaften Anwendung: 0x01d275fac07488be
Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\edgehtml.dll
Berichtskennung: 569b9f98-4557-4687-b457-000e87aeeacc
Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge

Error: (01/24/2017 05:31:35 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: edgehtml.dll, Version: 11.0.10586.162, Zeitstempel: 0x56cd3d95
Ausnahmecode: 0xc0000602
Fehleroffset: 0x00000000004a5851
ID des fehlerhaften Prozesses: 0x15d8
Startzeit der fehlerhaften Anwendung: 0x01d275fa7ec9c3bc
Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\edgehtml.dll
Berichtskennung: 72017a3c-39b0-48d7-aa89-9c44bbad21d6
Vollständiger Name des fehlerhaften Pakets: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge

Error: (01/24/2017 01:56:28 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC)
Description: Bei der Aktivierung der App „Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (01/24/2017 01:23:56 AM) (Source: MSDTC Client 2) (EventID: 4361) (User: )
Description: Fehler des Cluster-API-Aufrufs mit dem Fehlercode: 0x800706D9. Cluster-API-Funktion: OpenCluster, Argumente: lpszClusterName: (null)

Error: (01/23/2017 11:43:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC)
Description: Bei der Aktivierung der App „Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (01/23/2017 11:25:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SystemSettings.exe, Version: 10.0.10586.11, Zeitstempel: 0x56457cb1
Name des fehlerhaften Moduls: Windows.UI.Xaml.dll, Version: 10.0.10586.71, Zeitstempel: 0x5699d8e0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000023c018
ID des fehlerhaften Prozesses: 0x1a54
Startzeit der fehlerhaften Anwendung: 0x01d275c768039362
Pfad der fehlerhaften Anwendung: C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe
Pfad des fehlerhaften Moduls: C:\Windows\System32\Windows.UI.Xaml.dll
Berichtskennung: 2b4653e2-a5e0-4b02-a640-7d38792bce4c
Vollständiger Name des fehlerhaften Pakets: windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoft.windows.immersivecontrolpanel

Error: (01/23/2017 10:39:12 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Dragonfly-PC)
Description: Bei der Aktivierung der App „Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App“ ist folgender Fehler aufgetreten: -2147024770. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.


Systemfehler:
=============
Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenspeicher _487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kontaktdaten_487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/24/2017 08:10:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_487cb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/24/2017 01:56:28 AM) (Source: DCOM) (EventID: 10001) (User: Dragonfly-PC)
Description: Ein DCOM-Server konnte nicht gestartet werden: App.AppXck5aaxyarfx8gxrgfk6pvakmmxeqvepc.mca als Nicht verfügbar/Nicht verfügbar. Fehler:
"15616"
Aufgetreten beim Start dieses Befehls:
"C:\Program Files\WindowsApps\Microsoft.Messaging_1.10.22012.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer

Error: (01/24/2017 01:30:45 AM) (Source: DCOM) (EventID: 10029) (User: NT-AUTORITÄT)
Description: Das Zeitlimit für die Aktivierung der CLSID "{752073A1-23F2-4396-85F0-8FDB879ED0ED}" wurde überschritten, während auf das Beenden von Dienst "TrustedInstaller" gewartet wurde.

Error: (01/24/2017 01:25:54 AM) (Source: DCOM) (EventID: 10010) (User: Dragonfly-PC)
Description: Der Server "{0002DF02-0000-0000-C000-000000000046}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (01/24/2017 01:25:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_3dca0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/24/2017 01:25:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenspeicher _3dca0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/24/2017 01:25:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kontaktdaten_3dca0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.


CodeIntegrity:
===================================
  Date: 2017-01-24 01:56:04.124
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Store signing level requirements.

  Date: 2017-01-24 01:56:04.116
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Store signing level requirements.

  Date: 2017-01-24 01:56:04.109
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Store signing level requirements.

  Date: 2017-01-23 22:13:12.937
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2017-01-23 21:21:04.596
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system.

  Date: 2017-01-23 21:21:04.591
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system.

  Date: 2017-01-23 21:15:36.505
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Prozentuale Nutzung des RAM: 25%
Installierter physikalischer RAM: 8053.6 MB
Verfügbarer physikalischer RAM: 6032.96 MB
Summe virtueller Speicher: 9973.6 MB
Verfügbarer virtueller Speicher: 7916.26 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:930.91 GB) (Free:862.76 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 9BCA118F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=930.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=511 MB) - (Type=27)

==================== Ende von Addition.txt ============================
         

Alt 24.01.2017, 09:54   #11
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Code:
ATTFilter
Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 22-01-2017
durchgeführt von Dragonfly (24-01-2017 09:40:19)
Gestartet von C:\Users\Dragonfly\Desktop
Start-Modus: Normal

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)





Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\Dragonfly\Documents ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\Dragonfly\Downloads ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\Dragonfly\Music ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\Dragonfly\Pictures ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\Dragonfly\Videos ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk -> Microsoft.Windows.Homegroup
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk -> Microsoft.Windows.Network
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\Dragonfly ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk -> C:\Windows\DevicesFlow\DevicesFlow.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk -> C:\Windows\MiracastView\MiracastView.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk -> C:\Windows\PrintDialog\PrintDialog.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Deinstallieren.lnk -> C:\Program Files\Emsisoft Anti-Malware\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Emsisoft Anti-Malware.lnk -> C:\Program Files\Emsisoft Anti-Malware\a2start.exe (Emsisoft Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Emsisoft Homepage.lnk -> C:\Program Files\Emsisoft Anti-Malware\Emsisoft.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware\Hilfe.lnk -> C:\Program Files\Emsisoft Anti-Malware\de-de.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\syswow64\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\Links\Desktop.lnk -> C:\Users\Dragonfly\Desktop ()
Shortcut: C:\Users\Dragonfly\Links\Downloads.lnk -> C:\Users\Dragonfly\Downloads ()
Shortcut: C:\Users\Dragonfly\Links\RecentPlaces.lnk -> L ᐁ  À  䘀                         耟穭⊇㞡䘚낑�깚馼 ć 	ꀀz 匱卐뜥䟯ယ怂麌곫1 
 ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ   
 Systemordner     匱卐檦⡣锽ᇒ횵쀀�퀘e  ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀        
Shortcut: C:\Users\Dragonfly\Documents\Projects\fl stuff\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\ASIO4ALL v2 Anleitung.lnk -> C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Anleitung.pdf (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Avira Launcher.lnk -> C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\CyberGhost 6.lnk -> C:\Program Files\CyberGhost 6\CyberGhost.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe ()
Shortcut: C:\Users\Dragonfly\Desktop\-\McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\McUICnt.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\OpenOffice 4.1.2.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Security Task Manager.lnk -> C:\Program Files (x86)\Security Task Manager\TaskMan.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Dragonfly\Desktop\-\True Key.lnk -> C:\Program Files\Intel Security\True Key\application\truekey.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Winamp.lnk -> C:\Program Files (x86)\Winamp\winamp.exe (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Windows 10-Upgrade-Assistent.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\Desktop\-\WinZip.lnk -> C:\Program Files\WinZip\WINZIP64.EXE (Keine Datei)
Shortcut: C:\Users\Dragonfly\Desktop\-\Tor Browser\Start Tor Browser.lnk -> C:\Users\Dragonfly\Desktop\-\Tor Browser\Browser\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk -> C:\Program Files\Emsisoft Anti-Malware\a2start.exe (Emsisoft Ltd)
Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Public\Desktop\League of Legends.lnk -> C:\Riot Games\League of Legends\lol.launcher.exe ()




ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> -sta {C90FB8CA-3295-4462-A721-2935E83694BA}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsDefaults
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemDevices
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Dragonfly\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}


InternetURL: C:\Users\Dragonfly\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
InternetURL: C:\Users\Dragonfly\Favorites\Teen Babysitter Sydney Cole Fucks for Job - Pornhub.com.url -> BASEURL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4 URL: hxxp://de.pornhub.com/view_video.php?viewkey=ph5702a0c68d4f4
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=70742
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Ideas.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72700
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Mail.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72681
InternetURL: C:\Users\Dragonfly\Favorites\Windows Live\Windows Live Spaces.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72682
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Auto.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72680
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Fernsehen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72659
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Money.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72640
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Nachrichten.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72636
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN Sport.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72635
InternetURL: C:\Users\Dragonfly\Favorites\MSN-Websites\MSN.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72630
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\IE-Site auf Microsoft.com.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72186
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Deutschland GmbH.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72520
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Store.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft Windows - Start.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72629
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft zu Hause.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72406
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Microsoft.com durchsuchen.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72893
InternetURL: C:\Users\Dragonfly\Favorites\Microsoft-Websites\Site für IE Add-Ons.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Users\Dragonfly\Favorites\Links\Vorgeschlagene Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice
InternetURL: C:\Users\Dragonfly\Favorites\Links\Web Slice-Katalog.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\Dragonfly\Documents\Projects\fl stuff\deep_house_drum_samples\soundpacks.com.url -> URL: hxxp://soundpacks.com/
InternetURL: C:\Users\Dragonfly\Desktop\Neuer Ordner (2)\soundpacks.com.url -> URL: hxxp://soundpacks.com/
InternetURL: C:\Users\Dragonfly\Desktop\Neuer Ordner (2)\hidden_gems_massive_presets\soundpacks.com.url -> URL: hxxp://soundpacks.com/

==================== Ende von Shortcut.txt =============================
         

Alt 24.01.2017, 10:03   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Bitte ab jetzt meine Instruktionen RICHTIG lesen und RICHTIG umsetzen. Du solltest 1. noch kein weiteres AV installieren und 2. waren neue FRST-Logs auch nicht gefordert. Aber egal.

1. Schritt: Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers




2. Schritt: Kaspersky TDSS-Killer

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.




Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 24.01.2017, 16:05   #13
izockdi
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



hab beides nach anleitung durchgeführt aber weder tdsskiller noch Malwarebytes haben was gefunden.

hier report von tdss:

Code:
ATTFilter
12:07:38.0579 0x1414  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
12:07:41.0048 0x1414  ============================================================
12:07:41.0048 0x1414  Current date / time: 2017/01/24 12:07:41.0048
12:07:41.0048 0x1414  SystemInfo:
12:07:41.0063 0x1414  
12:07:41.0063 0x1414  OS Version: 10.0.10586 ServicePack: 0.0
12:07:41.0063 0x1414  Product type: Workstation
12:07:41.0063 0x1414  ComputerName: DRAGONFLY-PC
12:07:41.0063 0x1414  UserName: Dragonfly
12:07:41.0063 0x1414  Windows directory: C:\WINDOWS
12:07:41.0063 0x1414  System windows directory: C:\WINDOWS
12:07:41.0063 0x1414  Running under WOW64
12:07:41.0063 0x1414  Processor architecture: Intel x64
12:07:41.0063 0x1414  Number of processors: 4
12:07:41.0063 0x1414  Page size: 0x1000
12:07:41.0063 0x1414  Boot type: Normal boot
12:07:41.0063 0x1414  CodeIntegrityOptions = 0x00000001
12:07:41.0063 0x1414  ============================================================
12:07:41.0407 0x1414  KLMD registered as C:\WINDOWS\system32\drivers\49387004.sys
12:07:41.0407 0x1414  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 10586.162, osProperties = 0x19
12:07:41.0657 0x1414  System UUID: {BA761053-A871-8A1A-3A0E-D0D9996800FB}
12:07:41.0985 0x1414  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:07:41.0985 0x1414  ============================================================
12:07:41.0985 0x1414  \Device\Harddisk0\DR0:
12:07:41.0985 0x1414  MBR partitions:
12:07:41.0985 0x1414  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
12:07:41.0985 0x1414  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x745D3C39
12:07:41.0985 0x1414  ============================================================
12:07:42.0017 0x1414  C: <-> \Device\Harddisk0\DR0\Partition2
12:07:42.0017 0x1414  ============================================================
12:07:42.0017 0x1414  Initialize success
12:07:42.0017 0x1414  ============================================================
12:07:47.0368 0x1830  ============================================================
12:07:47.0368 0x1830  Scan started
12:07:47.0368 0x1830  Mode: Manual; SigCheck; TDLFS; 
12:07:47.0368 0x1830  ============================================================
12:07:47.0368 0x1830  KSN ping started
12:07:49.0741 0x1830  KSN ping finished: true
12:07:50.0386 0x1830  ================ Scan system memory ========================
12:07:50.0386 0x1830  System memory - ok
12:07:50.0386 0x1830  ================ Scan services =============================
12:07:50.0667 0x1830  [ DF1C3D7E6C7929AD83BE22852B5B08CB, 9ECF6211CCD30273A23247E87C31B3A2ACDA623133CEF6E9B3243463C0609C5F ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
12:07:50.0723 0x1830  1394ohci - ok
12:07:50.0755 0x1830  [ 2C5B3035B86770ADD2FE9BFBAF5B35A4, 19E16F9144FE3E33B5FF248CF0040AB079ACAE22290B1369CC72AE4CB5FE3A90 ] 3ware           C:\WINDOWS\system32\drivers\3ware.sys
12:07:50.0755 0x1830  3ware - ok
12:07:51.0154 0x1830  [ D57CE14F8A32EECD2F0D76761ED0744E, 116F23D7CF035CE0E46A1EB294F983A59AAC051F9CD2BE415604F6C8535AB07B ] a2AntiMalware   C:\Program Files\Emsisoft Anti-Malware\a2service.exe
12:07:51.0320 0x1830  a2AntiMalware - ok
12:07:51.0414 0x1830  [ 469441BAE3FF8A16826FC62C51EF5E18, E1204677B87F47222D05F670F8DF3DB65EA0881782A8DCFBE0103478ED71187C ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
12:07:51.0447 0x1830  ACPI - ok
12:07:51.0476 0x1830  [ 7EADED8087C392876521F7EBCE846EF4, 99BF1BD948F97C1ECBC049C7F949B71D73D0B41FB505B2F75B208E655F7DC8A3 ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
12:07:51.0489 0x1830  acpiex - ok
12:07:51.0523 0x1830  [ C498887123327CDFD73A05E7A2780920, B45392C46254FCB8D79B6C3A82C8D894063199E6167D8E5F7EA7D60C75CD16EA ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
12:07:51.0535 0x1830  acpipagr - ok
12:07:51.0561 0x1830  [ C8DBE6EFFCF014CAA010B9BDDAC833EC, 96FC29340C62A6B0910DCCBF8945F32089FC300F45B451A540B8854D53734298 ] AcpiPmi         C:\WINDOWS\System32\drivers\acpipmi.sys
12:07:51.0573 0x1830  AcpiPmi - ok
12:07:51.0591 0x1830  [ 17039DBEB3B7B9ADCDB4B4533AA9771F, A4D38B144639A20B8B31E4F35FB776A028DB502FAC849FC73EECEB3CCD91830B ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
12:07:51.0603 0x1830  acpitime - ok
12:07:51.0659 0x1830  [ E13DE7CD2B62254DD4FF658B7798A37D, 9FCCC90DEF6BE83F8C41D4552D235A7BB5534954D2E7CB7B1C336A31FCCAB3AD ] ACPIVPC         C:\WINDOWS\System32\drivers\AcpiVpc.sys
12:07:51.0674 0x1830  ACPIVPC - ok
12:07:51.0740 0x1830  [ F7D0CD345D2DA42E7042ABCD73662403, 03183F90A994D69066F15C3DFC1D7D7514AEAF46A5AAC059B1FB327F8C30A35C ] ADP80XX         C:\WINDOWS\system32\drivers\ADP80XX.SYS
12:07:51.0777 0x1830  ADP80XX - ok
12:07:51.0809 0x1830  [ 70148EFA9A562E7185B75BBE7D376BF7, 8200E3349A1AFA1040B3D956A17BAF3CDC784A1A3CA396125E7872B36C03D84A ] AFD             C:\WINDOWS\system32\drivers\afd.sys
12:07:51.0824 0x1830  AFD - ok
12:07:51.0856 0x1830  [ 870F1A2C936F92B5D053DF7EC75B352F, D617524FD5886D6D3BC2EFBBB5EA310E906454CD7CA7257C3D7BDEA8C4F2DA71 ] agp440          C:\WINDOWS\system32\drivers\agp440.sys
12:07:51.0871 0x1830  agp440 - ok
12:07:51.0903 0x1830  [ 3DF7751D5DC6525E7DC6617FBB45054F, 8E6D4C809DB3B66E7558C4829E01F5C227EE614AC82F33FD99DCC629770D1BE3 ] ahcache         C:\WINDOWS\system32\DRIVERS\ahcache.sys
12:07:51.0918 0x1830  ahcache - ok
12:07:51.0949 0x1830  [ 19707ECBCEA71080A85DB2336580DB39, A09AE69C9DE2F3765417F212453B6927C317A94801AE68FBA6A8E8A7CB16CED7 ] AJRouter        C:\WINDOWS\System32\AJRouter.dll
12:07:51.0949 0x1830  AJRouter - ok
12:07:51.0981 0x1830  [ AA91A5E156D0364ABA7B01658C2EB014, F61055D581745023939C741CAB3370074D1416BB5A0BE0BD47642D5A75669E12 ] ALG             C:\WINDOWS\System32\alg.exe
12:07:51.0996 0x1830  ALG - ok
12:07:52.0030 0x1830  [ B70F0F2F54B4A4DB6E9C830454752F5A, C882DEAC30812E5FA4479A8CB688603C6AF269EF08236688F4C5E7EBED1D4572 ] AmdK8           C:\WINDOWS\System32\drivers\amdk8.sys
12:07:52.0043 0x1830  AmdK8 - ok
12:07:52.0057 0x1830  [ 35E890482C9728DD5C552B85DA8A5AB2, 1E0EB7D902AB4C38E23CAFC0BEA250E7F6E180E8814385B4F29730BFC373A191 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
12:07:52.0072 0x1830  AmdPPM - ok
12:07:52.0096 0x1830  [ 5B30BCFE6E02E45D3EE268FF001BC5E0, 9901DB728885CE36911F79998629B2DD42D56AF9633B5277834F498CC59B0346 ] amdsata         C:\WINDOWS\system32\drivers\amdsata.sys
12:07:52.0107 0x1830  amdsata - ok
12:07:52.0139 0x1830  [ F20B30F35A5C7888441B4DCA001ECF8E, 695A5BC1F18B65992EB06A202AD3CBFA17228E76DDFD1AE6977FD315724F75C2 ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
12:07:52.0170 0x1830  amdsbs - ok
12:07:52.0194 0x1830  [ AFE838D7576C581D6483529621AB10CC, 14476A04CC64E7A0F1BBFDACCBD7A87F384BE1877C27656DBB973AF3975D4AE2 ] amdxata         C:\WINDOWS\system32\drivers\amdxata.sys
12:07:52.0203 0x1830  amdxata - ok
12:07:52.0242 0x1830  [ EDDB0D726DBECDFC1DBCC6DB464E5A13, 98D128D1E6FA270ED9ADBFE50078F68A794C00D4CBB86E28EC6161FFAD0CA8FF ] AppID           C:\WINDOWS\system32\drivers\appid.sys
12:07:52.0259 0x1830  AppID - ok
12:07:52.0281 0x1830  [ 7A55F9237F726D1667073A47B0D1B90F, 7C2D9AA84F1D4CC6C1FAF6848DF9479A534E01029C4387E8C0647745F1E74603 ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
12:07:52.0299 0x1830  AppIDSvc - ok
12:07:52.0326 0x1830  [ 56E219DF92BE16F62308F884739BE022, FE189EE8A52BC5A0E6B76C632021F84F60307A182F2A67C0C0C7CAA72DEFC723 ] Appinfo         C:\WINDOWS\System32\appinfo.dll
12:07:52.0351 0x1830  Appinfo - ok
12:07:52.0381 0x1830  [ 610499A73DF3599608EBB6B3F9929052, A9CA49C4A39A825916AB3791090BCFC7044FDB6B2C3538E01F0CFBC2A9931152 ] AppReadiness    C:\WINDOWS\system32\AppReadiness.dll
12:07:52.0427 0x1830  AppReadiness - ok
12:07:52.0537 0x1830  [ 3DF25A56F18D2AB4CF58C1300C8CD323, 34A20004A93BC0F22BF99E56E6657CF0A68B64B375A66408FB1E26ADA7A72FC4 ] AppXSvc         C:\WINDOWS\system32\appxdeploymentserver.dll
12:07:52.0599 0x1830  AppXSvc - ok
12:07:52.0615 0x1830  [ E3FE8F610B1CC12BC3B2E6BC43DC97E2, 0E18542CF2095A9ADA1759AB8F986E78B0A50A3C6B2AD4EACD80A23D832A2C6D ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
12:07:52.0631 0x1830  arcsas - ok
12:07:52.0646 0x1830  [ 5E00748A1AD246CAECBBB7553BED36CC, DAD2C93F0894E7BB5E5D8D767D8286A909086B49172C504A01097C3A180998C6 ] AsyncMac        C:\WINDOWS\System32\drivers\asyncmac.sys
12:07:52.0662 0x1830  AsyncMac - ok
12:07:52.0709 0x1830  [ 492B99D2E3D5D7BFD5F0AE1BE7BD37DD, A3F6BFC4FDC1933FBF3145019B118689A414108B04F43E2563946B2673C89324 ] atapi           C:\WINDOWS\system32\drivers\atapi.sys
12:07:52.0709 0x1830  atapi - ok
12:07:52.0865 0x1830  [ 41DFF214D30294F18F64257167F1CCBA, 87BB8BC1AB5EC4F5DAD84CB0B16CDD4634F10DC687264E4C84E47EFEFF4310F6 ] athr            C:\WINDOWS\System32\drivers\athw8x.sys
12:07:52.0990 0x1830  athr - ok
12:07:53.0052 0x1830  [ 42BF7FA295F453618104B5A50BEE105B, AB44BA2AD2FC5AF3B6BE4489C444C03FD1AB02C22109BF5F39BE459294C4CB18 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
12:07:53.0084 0x1830  AudioEndpointBuilder - ok
12:07:53.0146 0x1830  [ 9610CE53A9ED0789C8B669A5F86008F7, 9EE4B3F8528B20682595DDBDB0FF9F98FD8B957EE4C335FDD4382AE30D3C2EA0 ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
12:07:53.0187 0x1830  Audiosrv - ok
12:07:53.0234 0x1830  [ 7062CE507814D5306DCA5D6A15B7B6B6, 9D60506003A66C2E516B1FCB70CC5B26FB3A9948B95D97C828DD0328E76F2C91 ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
12:07:53.0249 0x1830  AxInstSV - ok
12:07:53.0296 0x1830  [ 6447BA6FA709514B6C803D159B4C7D1E, 549DDCEAD93DF333F6BBD56A9258A867E4DA219741C00D48C68F8F230A87B11A ] b06bdrv         C:\WINDOWS\system32\drivers\bxvbda.sys
12:07:53.0327 0x1830  b06bdrv - ok
12:07:53.0359 0x1830  [ B4AC08B1D04D0CE085435E5CD0E663C5, 61E641388E5692B2EB351E44BA1DB86B5305DD105EE56865D59072CA9407C8AC ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
12:07:53.0374 0x1830  BasicDisplay - ok
12:07:53.0390 0x1830  [ 25B5BB369DEE2BAE4BF459C978FF9035, DBC2157B2AC0BC92B4011CE5E01F2DCDAAE71E37D9D21102503C6455FAAC4DCA ] BasicRender     C:\WINDOWS\System32\drivers\BasicRender.sys
12:07:53.0405 0x1830  BasicRender - ok
12:07:53.0437 0x1830  [ 3F5523DCEFE42B385659C5CB46A6B810, CA24A3DF002B19E7BDEDE9B5EB60623F299D0E78B2E4F58DCFC028D76DEFE52D ] bcmfn           C:\WINDOWS\System32\drivers\bcmfn.sys
12:07:53.0452 0x1830  bcmfn - ok
12:07:53.0452 0x1830  [ 0B750A6A6D847E73CA48ADD7A0F5A393, 6A43020F23846EFB1AFA3C070465B0059E9DF60DEB16899E09559462DF30939F ] bcmfn2          C:\WINDOWS\System32\drivers\bcmfn2.sys
12:07:53.0468 0x1830  bcmfn2 - ok
12:07:53.0515 0x1830  [ F8F398A4AF7E0917320BC2B2CD812888, 02B9A6EA0AA750CA9B62AB09E99956C35E252A12B22C2CBFDC4E941ED5870591 ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
12:07:53.0562 0x1830  BDESVC - ok
12:07:53.0593 0x1830  [ 5A88834AEE15D97695FAE0837B73B3E4, 03035FB51DE218B8EDB15129A0376DDED0C7E7B6DA58DD95B12E4E5C8D852ED8 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
12:07:53.0609 0x1830  Beep - ok
12:07:53.0671 0x1830  [ 8EA08141590CB9331FA773FB430E91E4, 0507499EF423CC9EE9AC18C2B5CBF9965E69481C69DC96E361C2184C53C3F404 ] BFE             C:\WINDOWS\System32\bfe.dll
12:07:53.0702 0x1830  BFE - ok
12:07:53.0749 0x1830  [ 64582C924C48175D52AED0D0E64AB413, 75DC6BC01D26A4BABEDB8013F0C106780F0991CA63075798C7C24B66022F58E3 ] BITS            C:\WINDOWS\System32\qmgr.dll
12:07:53.0780 0x1830  BITS - ok
12:07:53.0827 0x1830  [ DA2C6F7ACE392193C424FEA975C5BFFB, 668F91F3E5F8EA170C10823D6959E0EDB32434C51FAA68BEA782EDDF5618690E ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
12:07:53.0843 0x1830  bowser - ok
12:07:53.0890 0x1830  [ 9972A886D911234F833A265D5D641D30, E64199AB64CC60C75371D8421031DC02818C852427C4F66AD3DF7DCDF33952B1 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
12:07:53.0905 0x1830  BrokerInfrastructure - ok
12:07:53.0952 0x1830  [ DA4C9335434E71D6CC86A3CA567769CC, 9FE5EE3CC91CADBF952446E0A9A79A8834B03C8D4C47D6E9257AF64B2C17F518 ] Browser         C:\WINDOWS\System32\browser.dll
12:07:53.0968 0x1830  Browser - ok
12:07:54.0015 0x1830  [ C8BF11D79B29BB23A461B65B58BA8593, 35AFAD5ED40304976287E6C982085DF7A91FF48F0320DAC32370FA039AA03C69 ] BtFilter        C:\WINDOWS\system32\DRIVERS\btfilter.sys
12:07:54.0046 0x1830  BtFilter - ok
12:07:54.0093 0x1830  [ CAEC7BC11AF69A181AF7932E636E09E4, 503C69045F1E025CBEE2405043BB71CC58478985ECAF6587F73FCB57860F5709 ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
12:07:54.0109 0x1830  BthAvrcpTg - ok
12:07:54.0124 0x1830  [ 36417FC4F11C31C880CB428037DEDF3F, ACDB798A038E3D5CC350AC53A9EC8E14AD02E2C28AE4578EC0205E6DF537A8F9 ] BthEnum         C:\WINDOWS\system32\DRIVERS\BthEnum.sys
12:07:54.0140 0x1830  BthEnum - ok
12:07:54.0171 0x1830  [ 5F2B4B32E986C058525D3BA2A475A16C, CEC5BB0B025DD9525CFBBEDF6EB6F63336534798495A4F95763CE112DF915088 ] BthHFEnum       C:\WINDOWS\System32\drivers\bthhfenum.sys
12:07:54.0187 0x1830  BthHFEnum - ok
12:07:54.0218 0x1830  [ 5406289E8AE2CB52FC408154E0A64BA7, 0A3795F2E6E2B51198452CF69A99159D8E11650E95F41DF0B575CB72F9C6C6B5 ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
12:07:54.0234 0x1830  bthhfhid - ok
12:07:54.0249 0x1830  [ BAB101E7826BE287F79C4BA721621989, E6DD25C89267FE87253B8226292F2894F5E702075D3B23B09339D3B28744C060 ] BthHFSrv        C:\WINDOWS\System32\BthHFSrv.dll
12:07:54.0283 0x1830  BthHFSrv - ok
12:07:54.0315 0x1830  [ CC6C1393B423EBFF9F6696CB9CC4CBCB, AB1861727631EDDD5B8404C51E75A67CAA42FD640E067A6ECC07EF0FCC871840 ] BthLEEnum       C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
12:07:54.0333 0x1830  BthLEEnum - ok
12:07:54.0366 0x1830  [ A76F20CCCA31895A1DA78A875E50F946, ECD4B3670DA5984AA24F4354457B4E45983938A89FF6DB03B556A633B4B37E3C ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
12:07:54.0379 0x1830  BTHMODEM - ok
12:07:54.0428 0x1830  [ 09C3DB1B137B269A822F941D867A6BB6, CC99FBD76DA19D951864D4967EA9F3C048811E9BB7BBB67B724FC82A50B14516 ] BthPan          C:\WINDOWS\System32\drivers\bthpan.sys
12:07:54.0442 0x1830  BthPan - ok
12:07:54.0482 0x1830  [ CEFF59649E90987D263D96078724A54A, 3EB69F0BA282085682FB09F1469BF66A84229D8C7A044C6B98B78477716917EE ] BTHPORT         C:\WINDOWS\system32\DRIVERS\BTHport.sys
12:07:54.0516 0x1830  BTHPORT - ok
12:07:54.0539 0x1830  [ 7A177E18AA6A6A6365E6351C2BF8EDAE, A35224A20014B1215A6824AE5E17B8869A775EA272EF7F25EAFFA18733F8D09D ] bthserv         C:\WINDOWS\system32\bthserv.dll
12:07:54.0539 0x1830  bthserv - ok
12:07:54.0558 0x1830  [ 0D279373091AA1BBEEE958AAF02B5EDF, 79CEBC2D9345103958DC161C31AC4BE078626D6DC28F6F06C432917872A1E3B4 ] BTHUSB          C:\WINDOWS\system32\DRIVERS\BTHUSB.sys
12:07:54.0570 0x1830  BTHUSB - ok
12:07:54.0630 0x1830  [ BF89BDBA5D3A0B4256D3F6FC8D31880D, 940F3BF55B88261C9E9A951A092331559FC5B24FE3BA0F1E1AB3450D2CA364C1 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys
12:07:54.0645 0x1830  buttonconverter - ok
12:07:54.0676 0x1830  [ C24C27FDF93B85A4EFCF25F830253AA2, 35C87518BB59663B57C2361A13AD4E57E37392598F1EB9F07F86CA5A6321AF5A ] CapImg          C:\WINDOWS\System32\drivers\capimg.sys
12:07:54.0719 0x1830  CapImg - ok
12:07:54.0751 0x1830  [ 7F9C7226D743B232907ED2537B8A574F, 2211AFC30E8F8FA03020DB48EE14914CD31E50BB6A63FF20AC7C6FA481E72C18 ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
12:07:54.0766 0x1830  cdfs - ok
12:07:54.0797 0x1830  [ 0A92DC116CFC7F6BE8167DD25CB925CC, 50CAC7BE14FF69B10C029E049F7C441A5572540F027F95F940B185C76C689409 ] CDPSvc          C:\WINDOWS\System32\CDPSvc.dll
12:07:54.0813 0x1830  CDPSvc - ok
12:07:54.0844 0x1830  [ 82D97776BF982AA143BDC7DFB5054EA8, 954F56728371E6B3514586DCEAF15C4727BAED6CAFBF788654C4E03BD702942C ] cdrom           C:\WINDOWS\System32\drivers\cdrom.sys
12:07:54.0860 0x1830  cdrom - ok
12:07:54.0891 0x1830  [ 4E9158CECF77A029AB98E8FBB43FCED5, AFF8BDB8F8F8DDF4FC0D65712E031DC360856CD3CE5C8A4C8FF960388F37462F ] CertPropSvc     C:\WINDOWS\System32\certprop.dll
12:07:54.0907 0x1830  CertPropSvc - ok
12:07:54.0945 0x1830  [ 0505C1D991D0F9D47F3353BB98597C7E, 3B801CCF4980256327A4A9FBD98007DA1E3ACE9C94E5A4C23AB21303B46E8B5A ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
12:07:54.0956 0x1830  circlass - ok
12:07:54.0993 0x1830  [ 8B4B39C507ABA09AAFE8E3932D1B392C, 734700155A658BC08FC96E8F99A01DE7F7251D7DDEFA79D258B2EEB370BA7AA8 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
12:07:55.0010 0x1830  CLFS - ok
12:07:55.0075 0x1830  [ F7526C133AC265F283012E9CD751F873, 6AABDD92FD880F49F63C1CC478C3D8291AF670802CEC58B32730E7675D858D88 ] ClipSVC         C:\WINDOWS\System32\ClipSVC.dll
12:07:55.0097 0x1830  ClipSVC - ok
12:07:55.0131 0x1830  [ 95832B049E2833B9F5189823CDF946C7, 72773A42A89220B4A6AC72D1633B16F11191A44D876A44FAB5CEFB717CE3223D ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
12:07:55.0142 0x1830  CmBatt - ok
12:07:55.0168 0x1830  [ A1105260EEEE3DBD8D38FD054B22BD00, CA943B0B03527B07690CAFFD53F8ABF14FB3974DAAA1036E54815BD0DAF803D8 ] CNG             C:\WINDOWS\system32\Drivers\cng.sys
12:07:55.0189 0x1830  CNG - ok
12:07:55.0210 0x1830  [ 58D640BC2294C71BDE0953F12D4B432F, 0B3B7659FCB97791A2A1F895C8E6F9078F855C94C13EB47464492588C4B02B85 ] cnghwassist     C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
12:07:55.0210 0x1830  cnghwassist - ok
12:07:55.0391 0x1830  [ 14F9883588398A1BDE49C75098C75DE6, D9D82DE89FAFE60BC902683BC44C7555533A030150FD5E5A35A24542FACC5CAD ] CompositeBus    C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_912dfdedc3d2f520\CompositeBus.sys
12:07:55.0422 0x1830  CompositeBus - ok
12:07:55.0422 0x1830  COMSysApp - ok
12:07:55.0437 0x1830  [ 02B8E49148DE5E0A2F6FDF28CE94A6AC, EEA405823F441CA604BEAA44EB71A1D20BC80E124FF7B27380D0201AAF2E0849 ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
12:07:55.0453 0x1830  condrv - ok
12:07:55.0531 0x1830  [ DE6DF2C34718EADCFF8776E597F2104D, 35D03E95853CEAC69F674FB09C819A4698EBEDFD8AC0474F0ADF02741492401E ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll
12:07:55.0562 0x1830  CoreMessagingRegistrar - ok
12:07:55.0719 0x1830  [ A28D6FA203CE094BDE7ED8CEC6079E42, 5DCA8BA21F5FD0D9F00620E7592949ABCF3BA202CF7AF3D84F93DF7C13E2D4C9 ] cphs            C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
12:07:55.0753 0x1830  cphs - ok
12:07:55.0806 0x1830  [ 2CE0D74AED86A372997E9D77AE10B9F5, 1AFAA22C68FD0B81F73CE0EB763AD77AB97E78916752843A5056E1352F0FEA82 ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
12:07:55.0830 0x1830  CryptSvc - ok
12:07:55.0862 0x1830  [ 2619DC483579DB9FE804044C1ADFFD1A, 23A5420288735A980917091532BE7BB36EB51660AA4555C615AF736357EB02EC ] dam             C:\WINDOWS\system32\drivers\dam.sys
12:07:55.0876 0x1830  dam - ok
12:07:55.0935 0x1830  [ B339861C6A2A86FBCA67C2006B461473, 228ADC8A8603C0A4342C6CBC6F2CC919271D42391365061AF660E0D7151C66A4 ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
12:07:55.0977 0x1830  DcomLaunch - ok
12:07:56.0018 0x1830  [ 620921E77351FB651632322AD2C195C4, 5A98971995D7A2B5AE6BEA69344FCC6687B582FEF74BDA206D32FB2E6CEB0478 ] DcpSvc          C:\WINDOWS\system32\dcpsvc.dll
12:07:56.0038 0x1830  DcpSvc - ok
12:07:56.0081 0x1830  [ 6129EA4294C5C69E4665801E95B16AB2, CE419186CF0F57434426FF925A09F13BE87639679CBB5F2074B0E1A243349D27 ] defragsvc       C:\WINDOWS\System32\defragsvc.dll
12:07:56.0110 0x1830  defragsvc - ok
12:07:56.0147 0x1830  [ D12B9B6A6C4885824876422AACC89954, 5853ED5CAF84B7AAFF3EDC5C71FE23EB121DB681D81267D77118424BA9AB6F88 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
12:07:56.0166 0x1830  DeviceAssociationService - ok
12:07:56.0203 0x1830  [ 15BA68662CED4B0618010A54478E18E5, 1B913BFA7AA11F3A82D80E95FC4857B810D341F9E68545710F90EBE44DAC1DF8 ] DeviceInstall   C:\WINDOWS\system32\umpnpmgr.dll
12:07:56.0223 0x1830  DeviceInstall - ok
12:07:56.0265 0x1830  [ 5BF8BD9B19D665452494C8D56DF4B28D, E5FC649207EF42C04B6737D442FECD3383E82F8998B140319FF400773F1D0978 ] DevQueryBroker  C:\WINDOWS\system32\DevQueryBroker.dll
12:07:56.0280 0x1830  DevQueryBroker - ok
12:07:56.0312 0x1830  [ C9478D7DB7BE5D7ACE65CB1167F07320, D5082D09EE62E34A195768040B741E22ACC9421CFF315423D77A63ABF8F5E39E ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
12:07:56.0340 0x1830  Dfsc - ok
12:07:56.0365 0x1830  [ 5841A361D28069DFC82E1E98040FDC3F, 3A48DB7ADE90654242CB54DAD07F5FF0CD5CABF372C50D5B2C4D7AED068986E1 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
12:07:56.0381 0x1830  Dhcp - ok
12:07:56.0475 0x1830  [ 9F5AC03F5A0000DD96FA29CD68A6605B, 6964E077635E65DA902CA6C69E704A9DCD5856D22BA75E1CF823E63E62266AF7 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
12:07:56.0490 0x1830  diagnosticshub.standardcollector.service - ok
12:07:56.0553 0x1830  [ 15D174719872A30F2FDD6B5B1B8BA5D9, B0E6FF6FC47B731C204F110D4B768231906B144B31F602ECE8EAC24D70BA880D ] DiagTrack       C:\WINDOWS\system32\diagtrack.dll
12:07:56.0584 0x1830  DiagTrack - ok
12:07:56.0615 0x1830  [ 4904B152E4942BF700F2D73228B4D477, 0E5646DCA05A24C71F057C9F9F64AE992D338DA72DF3126175C2FA178854C30F ] disk            C:\WINDOWS\system32\drivers\disk.sys
12:07:56.0631 0x1830  disk - ok
12:07:56.0678 0x1830  [ 49F069E2D22F33955A69D44DFD1B5179, 739C52C7B961BA683E8C7CCDB0E95423C17561B2F1F506BAE923DC53DB96B067 ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll
12:07:56.0694 0x1830  DmEnrollmentSvc - ok
12:07:56.0709 0x1830  [ 0197AE4B9790A4E73751CACFAA480126, 86BBB398F1A93754B2C329271F13A88FD2F285F30225C38F068F565CCA14EB9F ] dmvsc           C:\WINDOWS\System32\drivers\dmvsc.sys
12:07:56.0725 0x1830  dmvsc - ok
12:07:56.0772 0x1830  [ 5EF8EC71A7A91F3DF7798BEFE6786B0E, A3A56B43C72926881C66B7A17C9EAA35C2D9603C8D3849438838536BCD3F4633 ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll
12:07:56.0787 0x1830  dmwappushservice - ok
12:07:56.0819 0x1830  [ 570BB222E3AFC4407636B53F6EABFA70, D0194A128370BB0A337B61402F9EEDD6F7942ADB19BF672D0F92DA2DA563D0DD ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
12:07:56.0850 0x1830  Dnscache - ok
12:07:56.0881 0x1830  [ 1B15297A3A2CAB6BD586676154F389D8, 623D5F5FC8622B7D9AEEEB1787E6846C1570F0EEF94341239440B616D09D672A ] dot3svc         C:\WINDOWS\System32\dot3svc.dll
12:07:56.0897 0x1830  dot3svc - ok
12:07:56.0928 0x1830  [ 316C2D8B8E3C0727969F1C3790EF7193, 631F8578FDB26578C8436E4B9C4DF21E1F58FCFE6DA66E5769AAC3739005D465 ] DPS             C:\WINDOWS\system32\dps.dll
12:07:56.0944 0x1830  DPS - ok
12:07:56.0990 0x1830  [ 25FA06D3B49D6ADF8E874FFCDCD76B50, 9AF09B96ED79D94EA36581ABE6CC73313A72891779774B15860D018BEA2BBA0F ] drmkaud         C:\WINDOWS\system32\DRIVERS\drmkaud.sys
12:07:57.0022 0x1830  drmkaud - ok
12:07:57.0053 0x1830  [ 16EE6701115BECF8C657D9D6E123F6A1, 16E115B5245C3C988F8B58B90D30F183021C7C7792D3D1C74BEC606E49672B2A ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
12:07:57.0069 0x1830  DsmSvc - ok
12:07:57.0115 0x1830  [ FBC8C56814642A7CA88ACBCA8DD1121F, 108690704A359991C3D6577477E232F5F2F46B36DF6B4B0738A893EF05D7D4EB ] DsSvc           C:\WINDOWS\System32\DsSvc.dll
12:07:57.0147 0x1830  DsSvc - ok
12:07:57.0225 0x1830  [ F45665E77D11F3C1552EDBEAD1559DC8, C7C4B493CB36A1A35B8CA33C044BA0ED273CDA80E36F48BFF7CE3A0356246838 ] DXGKrnl         C:\WINDOWS\System32\drivers\dxgkrnl.sys
12:07:57.0272 0x1830  DXGKrnl - ok
12:07:57.0303 0x1830  [ 0CDF6B61D7F7FFCD195AF0113B9B2C16, 828D3FA31742B54075EAED2E67BBB5166D2EF4F84B791077E96DC0BD5557F11E ] Eaphost         C:\WINDOWS\System32\eapsvc.dll
12:07:57.0319 0x1830  Eaphost - ok
12:07:57.0444 0x1830  [ 491275B864B704B54EC08168344E0F38, B4849400C3F819CF7809A2001EA2ECB527022483F7DFE31C3930F951EAFE50CE ] ebdrv           C:\WINDOWS\system32\drivers\evbda.sys
12:07:57.0537 0x1830  ebdrv - ok
12:07:57.0553 0x1830  [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] EFS             C:\WINDOWS\System32\lsass.exe
12:07:57.0569 0x1830  EFS - ok
12:07:57.0600 0x1830  [ CEF108FCE06892CFA5F1B49527D4BF49, FA337584024B6E6EE4AF519F57FFA4C0FCA19EDC148FF309336C4CCA8F9C9CE8 ] EhStorClass     C:\WINDOWS\system32\drivers\EhStorClass.sys
12:07:57.0600 0x1830  EhStorClass - ok
12:07:57.0666 0x1830  [ 5B1EAAE3001A7A320C106FC3859F4111, 700BA2C7D4DFAFFEB78D3804B310A4EE5B4295C84600442665693FF661673951 ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
12:07:57.0677 0x1830  EhStorTcgDrv - ok
12:07:57.0710 0x1830  [ E34DEFC09F2843C2C24C2248F1ABE6D8, 1FD67EB5820A1D2F4402DE9D95DE288DB69D421A8473074FF23491D7CA8B5ACE ] embeddedmode    C:\WINDOWS\System32\embeddedmodesvc.dll
12:07:57.0725 0x1830  embeddedmode - ok
12:07:57.0758 0x1830  [ 062152DD5B225518A991DFCD8536770C, 5C8EF4E0C7DE3B24387FF239A8D0CDA39C2376826F16EAFF09739A6C7EDA01E0 ] EntAppSvc       C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
12:07:57.0778 0x1830  EntAppSvc - ok
12:07:57.0896 0x1830  [ 0E840AA66CAB02CBA9730C772BBE305B, 8862583E653D13D1D10A1A4A33704E4F70576E80370943AAFD1EAED6657A0104 ] epp             C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys
12:07:57.0905 0x1830  epp - ok
12:07:57.0936 0x1830  [ 7A2705148A4BB3CA255F81624338B461, 68AC8F8D2DD8AA4E8F2224A0054DE2AF67EA199217E87CD3C7299B021048F14F ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
12:07:57.0947 0x1830  ErrDev - ok
12:07:57.0990 0x1830  [ 17BE4A35829B37C742084DC02D48E5F0, 7FDA62B56DF585C3F2C6FFB10AC7C0D8F70FA921C4DEA47B2789745CFE2618CE ] EventSystem     C:\WINDOWS\system32\es.dll
12:07:58.0006 0x1830  EventSystem - ok
12:07:58.0037 0x1830  [ DFE8A33FBCF6F38182631A4D6097B92D, F9D06780830E74FD5309E6DC5C3EEDB9334A8AE284F381FA91EF2729297F8632 ] exfat           C:\WINDOWS\system32\drivers\exfat.sys
12:07:58.0053 0x1830  exfat - ok
12:07:58.0084 0x1830  [ 03DE0EC072C5EBD5B018CAD83F1E522A, 9D0B30A2870FBA20B95017CE3A4205F2DD53FE169A0D16715E962D83DE040FB3 ] fastfat         C:\WINDOWS\system32\drivers\fastfat.sys
12:07:58.0099 0x1830  fastfat - ok
12:07:58.0146 0x1830  [ 952F10D2116B91BA433842D07879AE7A, 9E1EC0C719877EF198AA4DDBE896E9DDEAD360AAC1FC6DF305E7C5C73C7A761D ] Fax             C:\WINDOWS\system32\fxssvc.exe
12:07:58.0178 0x1830  Fax - ok
12:07:58.0209 0x1830  [ 2C003DA244EDF9BC3FD058DCB3422798, 78F2A4143E1A0273DF4F778AE9E1C3CEC1F91501114367EE91DADB2D9A7CDC0D ] fcvsc           C:\WINDOWS\System32\drivers\fcvsc.sys
12:07:58.0209 0x1830  fcvsc - ok
12:07:58.0224 0x1830  [ 9D299AE86D671488926126A84DF77BFD, C076EEDD0524B7D88BC56C97089E0A836CC1AD725E1A544CC4F8DDBB6670C366 ] fdc             C:\WINDOWS\System32\drivers\fdc.sys
12:07:58.0240 0x1830  fdc - ok
12:07:58.0256 0x1830  [ 47D09B8C312658ACE433E46DDF51C3A5, E76948DA0F51C7DC6D69B7E36D63CE6E98FDE619FA30E91637F75B5084107D22 ] fdPHost         C:\WINDOWS\system32\fdPHost.dll
12:07:58.0271 0x1830  fdPHost - ok
12:07:58.0287 0x1830  [ 177AC945B20C81400A1525ED7B49A425, FD215A2E718EA38A95D985F53AB3DD44B50C2549AA67F44BA98C4709E492051F ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
12:07:58.0303 0x1830  FDResPub - ok
12:07:58.0318 0x1830  [ 3E78BEC276DA5A062E4D55F3291B3463, 62983457F506C70D1F89F527AB61C1C0F4D1B002631256A2708F9AF092A8C95E ] fhsvc           C:\WINDOWS\system32\fhsvc.dll
12:07:58.0350 0x1830  fhsvc - ok
12:07:58.0365 0x1830  [ 8F12AB59336143B680F71B217B495AD2, A28F62F065C68CC1A7EEF0CA52F83C3284B001565D8E154BF8568DE4A525104E ] FileCrypt       C:\WINDOWS\system32\drivers\filecrypt.sys
12:07:58.0381 0x1830  FileCrypt - ok
12:07:58.0396 0x1830  [ 92ECCFA58C8195B8EA33ED942469D4E6, 8DB12E8CF80ECA22182F9A1F4CA922336A430297F1F596F204ECF4D9D19F30D9 ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
12:07:58.0412 0x1830  FileInfo - ok
12:07:58.0444 0x1830  [ 87C51FDD50C17882BA93E28BBABB9847, 8987D80FB77D1D3F9E89B491B1287B027DA26FFC4E4BA7B01E07D4D4FC69E236 ] Filetrace       C:\WINDOWS\system32\drivers\filetrace.sys
12:07:58.0464 0x1830  Filetrace - ok
12:07:58.0487 0x1830  [ E99261DD76D1C9E05AF575939CAE5AC5, A789724FD2E22AFB2F921836F5C19A21D17F4BBD604771E2908C2651BD31989C ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
12:07:58.0500 0x1830  flpydisk - ok
12:07:58.0511 0x1830  [ 25D7A58625E1453E40D36825DE74E4F1, 74119803D35E3C3CC349B44C6CD9EDF6B797F88584B847F0BF9EED542719B86B ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
12:07:58.0527 0x1830  FltMgr - ok
12:07:58.0605 0x1830  [ 4387DE200BF8DD0E2EE828E655434B9A, 9148D65E54663EEC139E754091F47ABF439A637BEA83F600D30736522DAA845D ] FontCache       C:\WINDOWS\system32\FntCache.dll
12:07:58.0652 0x1830  FontCache - ok
12:07:58.0745 0x1830  [ E79DAC43A5E191FC4DDB04197A704BFA, 2FA6C8B5B2DFE66C05828E3F55DFD6268A8210E9BD083F2D09367AD59AF1C6C1 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:07:58.0761 0x1830  FontCache3.0.0.0 - ok
12:07:58.0777 0x1830  [ B4175E8BE60B099686FF55CA7D692316, 3158FC5B4D1A2F1FC1346754392AE24AE58999B9061B1CE78A65E785BFFADD52 ] FsDepends       C:\WINDOWS\system32\drivers\FsDepends.sys
12:07:58.0792 0x1830  FsDepends - ok
12:07:58.0808 0x1830  [ CC71372CEB811A72F1DC99089C5CBF53, BB9DDE74D60E534A6F8A51B63DDBB441245F06A00A0AFD37DBBE86255690946D ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
12:07:58.0808 0x1830  Fs_Rec - ok
12:07:58.0839 0x1830  [ 421497634C86EF4B8F86D0EBC076728F, E0D1449555D8849364E00AA747DBC820EF914A9F5B796E35070072FCBC532ADE ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
12:07:58.0870 0x1830  fvevol - ok
12:07:58.0886 0x1830  [ B9981A4CB9F728B3312A3885BFAA7204, 12FB2EB2E5D2A912769823DD9C1B33DB358CD0B7FBFC788529EF83DD584334F8 ] gagp30kx        C:\WINDOWS\system32\drivers\gagp30kx.sys
12:07:58.0902 0x1830  gagp30kx - ok
12:07:58.0961 0x1830  [ 77555B11B264991DDC26872FFCF1AB97, D5F230EEF74EB869F771F8A4AB19C1E6C845BB0EF4A1234882EBDA4FDC431E44 ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
12:07:58.0976 0x1830  gencounter - ok
12:07:59.0008 0x1830  [ F3AC9652D88BF87BA6596CBEA28CE10F, 115F3C0A5B9903B17ADEA80E1825FE927B7361F5BDDF80CE3685EF2D327EDF4F ] genericusbfn    C:\WINDOWS\System32\drivers\genericusbfn.sys
12:07:59.0023 0x1830  genericusbfn - ok
12:07:59.0055 0x1830  [ F802FBABF0C4DF1BAA733187B2E476F5, E2533284CEBBB872196B013DD1FBBCA794DB1CAAA37D64849BD9264ECDD2CEE6 ] GPIOClx0101     C:\WINDOWS\system32\Drivers\msgpioclx.sys
12:07:59.0070 0x1830  GPIOClx0101 - ok
12:07:59.0117 0x1830  [ B55458A83395A2CFD4E745E9EC4AB5F2, EAB06B089D8A7DBC9AE2A1C919B489911690D341013A5F8F906819C68431CA85 ] gpsvc           C:\WINDOWS\System32\gpsvc.dll
12:07:59.0164 0x1830  gpsvc - ok
12:07:59.0211 0x1830  [ D011B0ADB15F4815310CE1BF4780B33E, 3860630917F83A89FE7A6407CC544505FA4BD754619CF273DD630ABFBAAE42EE ] GpuEnergyDrv    C:\WINDOWS\system32\drivers\gpuenergydrv.sys
12:07:59.0226 0x1830  GpuEnergyDrv - ok
12:07:59.0320 0x1830  [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:07:59.0336 0x1830  gupdate - ok
12:07:59.0336 0x1830  [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:07:59.0351 0x1830  gupdatem - ok
12:07:59.0383 0x1830  [ 0F93EBE9071A6BB1548BF0F816EEA24B, 79A99544C00F59996980D299BFACA0463D86158BFA51C8045CE4FF4951779A44 ] HdAudAddService C:\WINDOWS\system32\DRIVERS\HdAudio.sys
12:07:59.0398 0x1830  HdAudAddService - ok
12:07:59.0430 0x1830  [ 84BC034B6BB763733C1949B7B9BAF976, 18C2C0F15BAFA46197F0BB629C4F585D893C2A78324CA198F88A04527D524F23 ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
12:07:59.0445 0x1830  HDAudBus - ok
12:07:59.0475 0x1830  [ 6B8CB114B8E64C0636EB49F7B914D1FC, 1AD7A43CC5CD99DCEF60C61242B6843D4AD925CE93BA5D75CD8395C7125EF5A7 ] HidBatt         C:\WINDOWS\System32\drivers\HidBatt.sys
12:07:59.0491 0x1830  HidBatt - ok
12:07:59.0507 0x1830  [ D1AD197CCDAAC0CB4819DA1D6EB17BAE, C370F974D0A1F7B60F47EAFF57B6CCABE82913187F8BFEE169B8237AE91247B1 ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
12:07:59.0522 0x1830  HidBth - ok
12:07:59.0538 0x1830  [ 64909DECCFCC6FB5D9A5BAFDCCB31FEE, E19C91FD8D5102A8C4F6C6FF70CA058BB272FEC1B6E9CBA3A473C49948E6AC7E ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
12:07:59.0554 0x1830  hidi2c - ok
12:07:59.0598 0x1830  [ F510F7B7BF61DEAAC04E65C3B65E8D59, 11566086B06FB08B6A179E3068E022DA381C762DC8962D1E1D63DC646DD4D301 ] hidinterrupt    C:\WINDOWS\System32\drivers\hidinterrupt.sys
12:07:59.0613 0x1830  hidinterrupt - ok
12:07:59.0629 0x1830  [ 90F3ED42D423C942BA5EA54E2FFE7AC7, BF7DE0C8141CD20A6235657BA897A019ABEFF6A01AA3FB202C73C33433CDEAF8 ] HidIr           C:\WINDOWS\System32\drivers\hidir.sys
12:07:59.0645 0x1830  HidIr - ok
12:07:59.0688 0x1830  [ 46DE2EF6382DD9613CB506760648F262, 419555220794380134A64E1956B83B2FD1D1B6E403C5FC729A9107E14A12E968 ] hidserv         C:\WINDOWS\system32\hidserv.dll
12:07:59.0704 0x1830  hidserv - ok
12:07:59.0743 0x1830  [ 128DEDDD61915DBA4D451D91D21F0513, 961A0DDA02B0879989300C15E4FF9022882A4CD895D65335C263AC0DD1918314 ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
12:07:59.0759 0x1830  HidUsb - ok
12:07:59.0790 0x1830  [ 2FEF4D90C0CAED258C93CFF72A8FFD71, 56473D90E9FE52849067D080FD88B29C0BBE76E5266657E2ABD6366B7A4E9474 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
12:07:59.0806 0x1830  HomeGroupListener - ok
12:07:59.0837 0x1830  [ E2145534FB853921788F52701BED0CAB, DF71F842772FAC21DD8994C97F578A78AC43D06C5F26F752FB69B47DFE3BB112 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
12:07:59.0868 0x1830  HomeGroupProvider - ok
12:07:59.0884 0x1830  [ FF442DCDCE1F6E9FAA9C8AD0CD1D199B, A239414E97B310C9545995B0E723B5E792B08D71F651450EB006AD4D1765E4F7 ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
12:07:59.0884 0x1830  HpSAMD - ok
12:07:59.0940 0x1830  [ 318E816717431D3C23DC82779900C744, 363702CC8A5B5FBF5E8CE2DA5C48D52CBD6244C9398B164EFDF1A4B0FAF592E6 ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
12:07:59.0971 0x1830  HTTP - ok
12:07:59.0987 0x1830  [ CBA5E88A0F0475B7F49653BB72150BEF, 0F03560D9C30E069D117A555AEE729C81E6BCAE443FA25172D0E9E6903695C67 ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
12:08:00.0002 0x1830  hwpolicy - ok
12:08:00.0033 0x1830  [ D668FAB4B0397B426EE3D41683B9A1C0, 66F3E3B2ABC3C9B25A0DADBF09818547ED301230374AC5302B4794629A95DDF8 ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
12:08:00.0065 0x1830  hyperkbd - ok
12:08:00.0080 0x1830  [ 53FDD9E69189E546DE4740F8C4D8AB2F, 45ED5B229ED5FD0CEE8BF52EFF88FD8B1889BF348ED7187926F290B3AD48A76D ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
12:08:00.0096 0x1830  i8042prt - ok
12:08:00.0112 0x1830  [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c           C:\WINDOWS\System32\drivers\iai2c.sys
12:08:00.0127 0x1830  iai2c - ok
12:08:00.0174 0x1830  [ 59A20F5AD9F4AE54098154359519408E, E27B7389C9D123CDDA4EC9CBDB06C4AA5000012391F940EE1492419B593608FE ] iaLPSS2i_I2C    C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys
12:08:00.0190 0x1830  iaLPSS2i_I2C - ok
12:08:00.0205 0x1830  [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO    C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
12:08:00.0221 0x1830  iaLPSSi_GPIO - ok
12:08:00.0252 0x1830  [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C     C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
12:08:00.0268 0x1830  iaLPSSi_I2C - ok
12:08:00.0330 0x1830  [ C224331A54571C8C9162F7714400BBBD, C2CA4881ACD46071E67435BE5E3DB133D0743B026FD20D6D6E26B2FE7A03FCAA ] iaStor          C:\WINDOWS\system32\drivers\iaStor.sys
12:08:00.0346 0x1830  iaStor - ok
12:08:00.0393 0x1830  [ 6B0029A0253098CCE28EACCFDB9E7208, E33AD69644E1683A971DA1169B704FBCFD9F715E9550816058E420BB5DE4D946 ] iaStorAV        C:\WINDOWS\system32\drivers\iaStorAV.sys
12:08:00.0424 0x1830  iaStorAV - ok
12:08:00.0455 0x1830  [ 9652E1E35A92D8C75710C17A63B15796, 72F8C4A49B874226DEE9B7C9704F0E0A98DAA2DF4EAE2F2258E8324ACBD242E4 ] iaStorV         C:\WINDOWS\system32\drivers\iaStorV.sys
12:08:00.0471 0x1830  iaStorV - ok
12:08:00.0502 0x1830  [ FFADF691F7BF727AF5C863454A372723, FCF5A5595E8C9C937BE9F1C3AB5D9BD0EFE82DE1298D12085E0CCD84A186D2F2 ] ibbus           C:\WINDOWS\System32\drivers\ibbus.sys
12:08:00.0518 0x1830  ibbus - ok
12:08:00.0565 0x1830  [ 80BF2990E01E774D64F6E13F30661942, ADFEA2280D29F2C7B0A556C61709301D6327C288064FF5A4D29358403DF41DCE ] icssvc          C:\WINDOWS\System32\tetheringservice.dll
12:08:00.0580 0x1830  icssvc - ok
12:08:00.0580 0x1830  IEEtwCollectorService - ok
12:08:00.0752 0x1830  [ 9CE4D3A79D3180AC5A141E2F7E7137F4, 1D717D2156B78632895281779D2646AB066619EA1DB293A9505BF7C174F53271 ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
12:08:00.0830 0x1830  igfx - ok
12:08:00.0846 0x1830  [ 6A9C613D0F5F9676D128F39B63ACE45B, 027B9568C740E336C7CBBE952309E2719E8FFA14E7DFC2B85B49E0C0CE7D2149 ] igfxCUIService1.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
12:08:00.0862 0x1830  igfxCUIService1.0.0.0 - ok
12:08:00.0924 0x1830  [ 12F8D27ED8623DDDC09A549EDADCBAC9, D3A3F0588D9CAF1027D8BC14601E2A6AB7E5924A2C23C90D38A9E14538DB02A9 ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
12:08:00.0971 0x1830  IKEEXT - ok
12:08:01.0033 0x1830  [ 87871AB7AC797F922A6F3D4C874CED96, 2BCD89911E42827CD294DD7D1486A7845D1F98019E51958E0F488384401B2944 ] IntcDAud        C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
12:08:01.0049 0x1830  IntcDAud - ok
12:08:01.0080 0x1830  [ ECDB27420D3A98424666904525A8562A, BDA98C3C95F2AD79945EF8213D5C65064052C09C82DD36F0D6724E1D21DCC30A ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
12:08:01.0096 0x1830  intelide - ok
12:08:01.0127 0x1830  [ 8FF1978643EFD219C5BA49690191D701, 6FD78A8490107C80090D7125644B8C910855374BE1373D1D6B199307C79680BA ] intelpep        C:\WINDOWS\system32\drivers\intelpep.sys
12:08:01.0127 0x1830  intelpep - ok
12:08:01.0159 0x1830  [ B61B60F36E1C8022FA8166ABF0F66B07, 23161F1DA51D44D936329E62DF4C2DAEE3DDD4B3D62CC501A888C0E149788968 ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
12:08:01.0174 0x1830  intelppm - ok
12:08:01.0190 0x1830  [ CA0D42029AFFC4514D295E1EF823D02D, F2A05CB2B2E8C843FD02DC37E86F23CF928A4B2F9044424A60DE4E82B87DF5C3 ] IoQos           C:\WINDOWS\system32\drivers\ioqos.sys
12:08:01.0205 0x1830  IoQos - ok
12:08:01.0237 0x1830  [ 6E3F9D95235DFC9417384080A216F310, 6F13D72661038A91CFABB360621F4B169D78955C3EAD64956A7C825ABAEC5121 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:08:01.0252 0x1830  IpFilterDriver - ok
12:08:01.0299 0x1830  [ 6E75B731A8A7EFED0821327B08DAB46D, A77B746447824BD3C68B82D7329B82D62098B2409F8AEE4738FA23CB1561E629 ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
12:08:01.0346 0x1830  iphlpsvc - ok
12:08:01.0362 0x1830  [ 4F527ECB5EAB47D8EAF34A469666C469, 8FFBEEF42515B6A7758BE579ED69E3911856CBF7710D9785011332C5E3DFE495 ] IPMIDRV         C:\WINDOWS\System32\drivers\IPMIDrv.sys
12:08:01.0377 0x1830  IPMIDRV - ok
12:08:01.0393 0x1830  [ 9E5E8F2A1996F23B7E9687846AA81B01, 29E59384A4F92B3B4F2974942C91A12380113C13D3800900B5F44E2355D05455 ] IPNAT           C:\WINDOWS\system32\drivers\ipnat.sys
12:08:01.0424 0x1830  IPNAT - ok
12:08:01.0440 0x1830  [ C317EB660138BC9CBFE37CCDE56351AE, F3AF6C573419D7F65C96A4841D4F056CA281CD5AFACDC7A5F586A390DC6E615B ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
12:08:01.0455 0x1830  IRENUM - ok
12:08:01.0471 0x1830  [ 531994A6D9399D9B74BE12B5BB58A81E, 6D5CF540C777F4828E1D4C5FE58EE41E6C2F5F399C554DC85F19D1E52229B094 ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
12:08:01.0487 0x1830  isapnp - ok
12:08:01.0534 0x1830  [ 68D5354A4A9692EEC24664C60F47D4A2, 92124E98B6E286B6127DC6D0BFACC9C6D293D58EAE2B47B45532714CE6A6D0CD ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
12:08:01.0549 0x1830  iScsiPrt - ok
12:08:01.0580 0x1830  [ 48B904D31F2369D7B0122617038D3F5B, 8A43CB37667929CCCC37B6E79E82509BBCA6C8884B44059DC87BCA7C21BE7FE1 ] iwdbus          C:\WINDOWS\System32\drivers\iwdbus.sys
12:08:01.0580 0x1830  iwdbus - ok
12:08:01.0612 0x1830  [ 701D7DB13B0815E7076EF4CB4CE981F8, 02585661656C0069AC318B82DE83DAC660451A0B970FDBCA0F7A8B4CBF7D93A9 ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
12:08:01.0643 0x1830  kbdclass - ok
12:08:01.0659 0x1830  [ 884EBBDDBF5968003B40185BD96FF0E6, E3934D0FF0BEDDF5526AF529F7D15BA8BE479383894975B1AF1A1818C394A6E3 ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
12:08:01.0674 0x1830  kbdhid - ok
12:08:01.0721 0x1830  [ 6B3A0C7902811E6372643447E41F7048, 30667B56A306CFD5D15BC46F8E7D9E167612E71B6C8F554406E706A6330F5B94 ] kdnic           C:\WINDOWS\System32\drivers\kdnic.sys
12:08:01.0721 0x1830  kdnic - ok
12:08:01.0737 0x1830  [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] KeyIso          C:\WINDOWS\system32\lsass.exe
12:08:01.0752 0x1830  KeyIso - ok
12:08:01.0768 0x1830  [ 982C795DE20CED7AEDD2E7899B5D9BC1, 9F4E7536DB253CD83AA2AB89E9F3311714CD70F13AFD16F9B4D4CD86A70FC164 ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
12:08:01.0784 0x1830  KSecDD - ok
12:08:01.0815 0x1830  [ 7D8B9214692C4D0F1646215D9984E19A, DC73503A8CA67F4E167DEA69AADDEA5F2D756E1C1F4FF42B6ECEA7E637BB80AB ] KSecPkg         C:\WINDOWS\system32\Drivers\ksecpkg.sys
12:08:01.0830 0x1830  KSecPkg - ok
12:08:01.0846 0x1830  [ E9BB0023D730701BB5D9839B44F5E6B5, 19D4BAC09424D331922472CFD2D0E32BEFA9188A6AF194C8D1F93FD77CE36691 ] ksthunk         C:\WINDOWS\system32\drivers\ksthunk.sys
12:08:01.0877 0x1830  ksthunk - ok
12:08:01.0909 0x1830  [ 71DE1AD9B23661EEC4F2A6EAA5A7D33D, 3219AEF3D6AE5933AE669FD2ED9ED95A8780612E39F31DB3DB9ED6B6244C5F7B ] KtmRm           C:\WINDOWS\system32\msdtckrm.dll
12:08:01.0944 0x1830  KtmRm - ok
12:08:01.0975 0x1830  [ 8BBB2B4429AF340481520C20C17FC5B6, 9E32815349195FC4B1BE213600FD407F2EAEEC8368289EB3E6B769125A739C08 ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
12:08:02.0007 0x1830  LanmanServer - ok
12:08:02.0038 0x1830  [ 1F5D48B1DA1B812BD2411CA44D75DD32, D1BDB8142CB13E8C6DD6F42E07C9D19BBBF6410D5122A04C01B34B95B442DD95 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
12:08:02.0069 0x1830  LanmanWorkstation - ok
12:08:02.0085 0x1830  [ 02C54C5C7EBE371EC0C59795ED22213F, 712AFE0EDF40436124F3FD55ED9B5A3A33A8761A58F4D482BB65229741B1C270 ] lfsvc           C:\WINDOWS\System32\lfsvc.dll
12:08:02.0085 0x1830  lfsvc - ok
12:08:02.0132 0x1830  [ 01BF128CC327A2E53898F732AF52B3DB, D62ACDA69D9942F9CEF400874DBB6EAF9811D9657CBFEF89174F88D76BB8D8EA ] LicenseManager  C:\WINDOWS\system32\LicenseManagerSvc.dll
12:08:02.0147 0x1830  LicenseManager - ok
12:08:02.0194 0x1830  [ EC34EED89C34B27C292166B725AC7A7B, 58F1BA0CB7743314AC012A82F8CE4072CBDD05D9570C52BC18DC551882F5B1BA ] lltdio          C:\WINDOWS\system32\drivers\lltdio.sys
12:08:02.0225 0x1830  lltdio - ok
12:08:02.0257 0x1830  [ 2C23283A0815B048C06D8C0ED76AAD95, 4335546939C1A98CFE9A4403CC82D79CC713439E4DFD1F4760FDD867305151E0 ] lltdsvc         C:\WINDOWS\System32\lltdsvc.dll
12:08:02.0288 0x1830  lltdsvc - ok
12:08:02.0319 0x1830  [ CB6365E995F4DB856866500EDD8F61C1, 717ED387F245CAC68217B0F393D7B8AB3805721AB2C4D2D43430FE6E740F0856 ] lmhosts         C:\WINDOWS\System32\lmhsvc.dll
12:08:02.0350 0x1830  lmhosts - ok
12:08:02.0382 0x1830  [ 961F28D879D345BFA50AF51285C90F2E, F9931A436651F695B746BC0C07E833D9C9F64126746DF976E691E6CAE26DAC9B ] LSI_SAS         C:\WINDOWS\system32\drivers\lsi_sas.sys
12:08:02.0382 0x1830  LSI_SAS - ok
12:08:02.0429 0x1830  [ 6BFB8D1B3407518BE06B6F81F92FA0F5, DE0818DCC0D8D1D30A29AB167C65461A78100ABE2368637CEB9D0ED2B4E88D8E ] LSI_SAS2i       C:\WINDOWS\system32\drivers\lsi_sas2i.sys
12:08:02.0429 0x1830  LSI_SAS2i - ok
12:08:02.0460 0x1830  [ BE0E47988D78F731DEC2C0CB03E765CB, CA0015E87A3962611DBF714253FA618A6568346BAE640884432C1D44DE4C8684 ] LSI_SAS3i       C:\WINDOWS\system32\drivers\lsi_sas3i.sys
12:08:02.0460 0x1830  LSI_SAS3i - ok
12:08:02.0491 0x1830  [ F99BF02BE9219986817BF094981EEB18, 4303C772366065885C5D937B2E9AC0BF80C84BFB2737716055AD57BF6AADD673 ] LSI_SSS         C:\WINDOWS\system32\drivers\lsi_sss.sys
12:08:02.0491 0x1830  LSI_SSS - ok
12:08:02.0522 0x1830  [ FFAA37FBBDD161E8C200C83B40F7872E, 0637B3119FC220CB8E23EE6694A9F1F25CF8D61008B14F6E30FDC17DCF9E077E ] LSM             C:\WINDOWS\System32\lsm.dll
12:08:02.0554 0x1830  LSM - ok
12:08:02.0554 0x1830  [ 2FCF837196082864F66CFD9CAB256275, 8BE01C3BCBC1E6E5D1FD7F49E936482E61ACB805F397AB81B8D39C2F0F1083BD ] luafv           C:\WINDOWS\system32\drivers\luafv.sys
12:08:02.0585 0x1830  luafv - ok
12:08:02.0616 0x1830  [ 88B38A7435DFA9B7E8F94F5D5FE999D2, FF4EBB6CE013D0EA62FEDA5FBBD1205D9A6F684E701F40039A95A4EF4145DC16 ] MapsBroker      C:\WINDOWS\System32\moshost.dll
12:08:02.0616 0x1830  MapsBroker - ok
12:08:02.0647 0x1830  [ 2ED29B635F35E31A1C0D3DDB7DD2AD03, F70CC20B98C2DBCD13B0D509D92B3BC3828D1B88F3ACD60C860E163064844181 ] megasas         C:\WINDOWS\system32\drivers\megasas.sys
12:08:02.0663 0x1830  megasas - ok
12:08:02.0694 0x1830  [ 22E3CB85870879CBAE13C5095A8B12E3, 5FA5A8EFBA117089CFDBE09743A16BC3A7CC2042C96ABA1F57901747493106BF ] megasr          C:\WINDOWS\system32\drivers\megasr.sys
12:08:02.0710 0x1830  megasr - ok
12:08:02.0741 0x1830  [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64          C:\WINDOWS\System32\drivers\HECIx64.sys
12:08:02.0757 0x1830  MEIx64 - ok
12:08:02.0788 0x1830  [ F2C23E25636BCA3543E6AD7858E861B7, 0CAB0A037471B4858CE9477E49BF50A5E3E6685E05F8A4BD2D9238551D5073A6 ] MessagingService C:\WINDOWS\System32\MessagingService.dll
12:08:02.0804 0x1830  MessagingService - ok
12:08:02.0929 0x1830  [ D41920FBFFF2BBCBBC69A5B383AD022E, E66218A8303422EA10C19BA12343740B9A1A70B11B39E185E805B4F74CD2B75E ] mlx4_bus        C:\WINDOWS\System32\drivers\mlx4_bus.sys
12:08:02.0944 0x1830  mlx4_bus - ok
12:08:02.0960 0x1830  [ 64BD0C87064EA20C2D3DC4199F9C239C, ED69706277A58ED2C5F2B1B4E9A4A9C7C20173D46EB57FB31D8B63340BA23193 ] MMCSS           C:\WINDOWS\system32\drivers\mmcss.sys
12:08:02.0975 0x1830  MMCSS - ok
12:08:03.0007 0x1830  [ 8D4B46FA84A3A3702EDADD37FAC6EDBA, E3B9E12BD324FE637C365FDC5E490C41889047004D4FC8F7D78339484F2F717B ] Modem           C:\WINDOWS\system32\drivers\modem.sys
12:08:03.0022 0x1830  Modem - ok
12:08:03.0038 0x1830  [ 78FEC1BDB168370F131BFBFEA0A04E9D, E07B1BC429C2CFBD6162F89A6502C67A4BAD904ADC05D3505D87A0B2BCE1061B ] monitor         C:\WINDOWS\System32\drivers\monitor.sys
12:08:03.0063 0x1830  monitor - ok
12:08:03.0073 0x1830  [ D1CC0833CFBC4222A95CAA5D0C8C78FF, 54F04374C6D3EFF5C1B794C069870458F10757E5773AEE911957089EAF51EC8D ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
12:08:03.0084 0x1830  mouclass - ok
12:08:03.0093 0x1830  [ C2E05EC6B80BCF5AE362DA873E1BCE64, 4ABE5CA2005A54E92259EDB52205A5C59BDB83026FC0CD7CBB1E3A003C2B535B ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
12:08:03.0106 0x1830  mouhid - ok
12:08:03.0126 0x1830  [ D5B7668A8F6C67C51FA5C6C513396D6C, 35985AD89344A8464BD78B8DA6A772E4E60A2EB93072AC23673A86EFD0B2270A ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
12:08:03.0138 0x1830  mountmgr - ok
12:08:03.0157 0x1830  [ 5FBCB85D127BE21E3A9DAF11A13C00EA, D00AB99CC813E26B0BD2D39161D4138AB89A06B3E3A28712F2D5BCA60905BEC4 ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
12:08:03.0171 0x1830  mpsdrv - ok
12:08:03.0248 0x1830  [ 553F19DC6F3F73545CB17FCD7A8AE37B, 49ABB625EB9C2981254EEA1FE7858DF630BA2D65653CC91CD4FEEACF69C5392F ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
12:08:03.0301 0x1830  MpsSvc - ok
12:08:03.0332 0x1830  [ BF6CA7EA5ECD6CF72D3D76652A9B8280, 8EC031D0D8E75CB583B129CBA518701097697498621307108388FA05FBF604BB ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
12:08:03.0364 0x1830  MRxDAV - ok
12:08:03.0379 0x1830  [ 0B3B0C1D86050355676640488FA897D3, DBED9D6F7AAFB11F4C00C1F69DB7A887A3058E5FA66615A1640242439822B60C ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:08:03.0395 0x1830  mrxsmb - ok
12:08:03.0442 0x1830  [ 1A490555FD330CA2764D89191177C867, 1004AE2F80BEA9A6DBA3E6B5D2DDFA44FBA253F7137D60B000B094699DE1CB12 ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
12:08:03.0457 0x1830  mrxsmb10 - ok
12:08:03.0489 0x1830  [ 0F47A6C09F0A7FB5513D322A2B9BE4EC, 00A17CB55D232E11F3D24D0B43FE4FA9E55F7EF5E5607B26ED84C13108AAC4FA ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
12:08:03.0520 0x1830  mrxsmb20 - ok
12:08:03.0535 0x1830  [ A4411C522D41707D5BCA817A5BB9E30B, EF7505BE475ECAB2B5E66A7419EDAF42A7E7A65BAD3BBE346A8CEE5DD69782CC ] MsBridge        C:\WINDOWS\system32\drivers\bridge.sys
12:08:03.0535 0x1830  MsBridge - ok
12:08:03.0567 0x1830  [ 807A6636828E5F43C10A01474B8907EE, F275645F4F0D0A796C33C03EA7FA563A0B890AB3A93E5F99C5EA166F91D249B1 ] MSDTC           C:\WINDOWS\System32\msdtc.exe
12:08:03.0582 0x1830  MSDTC - ok
12:08:03.0598 0x1830  [ D123343DDB02E372B02BF2C4293F835F, 8E02D9F7E5DA717B64538444B3FE1C55AA4B0F26F51DA20947E971D27EA09D12 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
12:08:03.0614 0x1830  Msfs - ok
12:08:03.0645 0x1830  [ B3358F380BA3F29F56BE0F7734C24D5F, 229D9E72C429AC51BF6E7C8306218620CB1AA50FE39BA6C11ED0F643E7AF90E5 ] msgpiowin32     C:\WINDOWS\System32\drivers\msgpiowin32.sys
12:08:03.0675 0x1830  msgpiowin32 - ok
12:08:03.0693 0x1830  [ B2044D5D125F249680508EC0B2AAEFAC, 9631FF42DA5A7CEE1F2607AA8972EF0A67616F0EEEBC95F97B1C8F5A577ED5C4 ] mshidkmdf       C:\WINDOWS\System32\drivers\mshidkmdf.sys
12:08:03.0709 0x1830  mshidkmdf - ok
12:08:03.0721 0x1830  [ 36ABE7FC80BED4FE44754AE5CFB51432, FB89DF3A50C52B69D4E831A370157D1901810093A0D7D7120A120FC5C6E14BF5 ] mshidumdf       C:\WINDOWS\System32\drivers\mshidumdf.sys
12:08:03.0736 0x1830  mshidumdf - ok
12:08:03.0749 0x1830  [ 59307FEAFC9E72EEEC56B7FD7D294F4C, 56576635870FC68980977FFA0E7F8E8D69A7981DECF5B52D0B2A82E3BA6685EA ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
12:08:03.0760 0x1830  msisadrv - ok
12:08:03.0805 0x1830  [ 236A38F5CB0A23BF0ACCD70ED0BD7F70, 8106B528458E6C8E4437D9064D58F10FF195E67CD308AEBBD5F860AD2D59DCC4 ] MSiSCSI         C:\WINDOWS\system32\iscsiexe.dll
12:08:03.0821 0x1830  MSiSCSI - ok
12:08:03.0825 0x1830  msiserver - ok
12:08:03.0835 0x1830  [ E9457EDFEBC774199F907395C6D09CA2, C3655CE83F4AD1258382722E9A99C33FDD3AA40B62CFEB8DFDD141E254E6DCE2 ] MSKSSRV         C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys
12:08:03.0846 0x1830  MSKSSRV - ok
12:08:03.0860 0x1830  [ C85D79735641D27C5821C35ECDDC2334, C1BAFD98122B04665870171C143EC119181351D10777A83680A63BF305703FF3 ] MsLldp          C:\WINDOWS\system32\drivers\mslldp.sys
12:08:03.0875 0x1830  MsLldp - ok
12:08:03.0891 0x1830  [ EF75184B64356850D0F04D049C253526, 325476F53372BD70201347F044C8EFEC0DB939E1926454B6DCC0CF7864969650 ] MSPCLOCK        C:\WINDOWS\system32\DRIVERS\MSPCLOCK.sys
12:08:03.0902 0x1830  MSPCLOCK - ok
12:08:03.0920 0x1830  [ 543933D166C618E7588EA77707EC1683, 84A65D277E28FDD7CE2345188891093AC88B577E4C528AD39AB629E341199688 ] MSPQM           C:\WINDOWS\system32\DRIVERS\MSPQM.sys
12:08:03.0920 0x1830  MSPQM - ok
12:08:03.0959 0x1830  [ 182711E9DDF70121A20EBB61B2DFB9E8, 70606503F6280EA3175B9AEC8370A8F461575755DA86EF6E9C9D04EAD61481FA ] MsRPC           C:\WINDOWS\system32\drivers\MsRPC.sys
12:08:03.0971 0x1830  MsRPC - ok
12:08:04.0002 0x1830  [ E887FFDD6734C496407E9219225CB6FF, 0EC9A79224BCE5D0A782E62CC38E3494E8FB65DFC07C66D25C5A1A351121C27D ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
12:08:04.0017 0x1830  mssmbios - ok
12:08:04.0033 0x1830  [ 83A2AB75951000D681FABDB80C07AEFC, 3B2F582F097E3F934C4587B27CB05525350F36924B74CA6BCD364878FA8EC273 ] MSTEE           C:\WINDOWS\system32\DRIVERS\MSTEE.sys
12:08:04.0049 0x1830  MSTEE - ok
12:08:04.0071 0x1830  [ 4FA0483896FC16583851EFB733FCB083, BB59243ABE32FBE92EC1B04D24239BE2DF7C2354A407C2EFF97623F07DCBDA35 ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
12:08:04.0086 0x1830  MTConfig - ok
12:08:04.0118 0x1830  [ 60F88248608315E13391C2F1C3B4473F, 99E8B74118A01FC281A1C6B323EFD1A8EA1997B81A013442205066F55327D555 ] Mup             C:\WINDOWS\system32\Drivers\mup.sys
12:08:04.0149 0x1830  Mup - ok
12:08:04.0180 0x1830  [ 218705233D02776AE4D19CC37D985C1B, 3D92925867B6B8FFAF78E4080139DCB3D45E1E6E1D0AFB6A4FE248B002BD8471 ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
12:08:04.0180 0x1830  mvumis - ok
12:08:04.0227 0x1830  [ 536A0806CE2061A2157E65D4D8ABF30C, F9893F66505E3F748365CD4625B34357531804BDFE33E57285C0106C03F7916C ] NativeWifiP     C:\WINDOWS\system32\DRIVERS\nwifi.sys
12:08:04.0258 0x1830  NativeWifiP - ok
12:08:04.0274 0x1830  [ A340A4B27CC7DEDDF953B7E2C9699747, 4C5AB23BD0C69B17E9BD29CAFEDC100A6EFC78BAB645B007FCAE4318C459D345 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
12:08:04.0290 0x1830  NcaSvc - ok
12:08:04.0321 0x1830  [ 7467BD76D6ED5981E6C3DBFEB50F0F4D, 237E1C2E15D5F3BAC49B09E1CD0EAE56A6998AE1FF560A4F7A7EFFEB46884798 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
12:08:04.0368 0x1830  NcbService - ok
12:08:04.0399 0x1830  [ 476466DC3AB2327E2DBFAEC11798E2EE, 9ACD74720664CF3F239601DF0BE80AC443AF0FBF666CBB8509169364FB22B95D ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
12:08:04.0415 0x1830  NcdAutoSetup - ok
12:08:04.0430 0x1830  [ B57CE307DA101C739885B7CC0678077F, F7F45DB6D306060F0FE0E59F39C3B95F6A9B6173930F22C5C41B2003895D6642 ] ndfltr          C:\WINDOWS\System32\drivers\ndfltr.sys
12:08:04.0446 0x1830  ndfltr - ok
12:08:04.0493 0x1830  [ AFAECF904F1C343EBD50F91BC8D0DBE8, FABAE70F62895708415B8E176A880D2D20D46D9A14C3D41D371B905CE4D64BA0 ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
12:08:04.0524 0x1830  NDIS - ok
12:08:04.0555 0x1830  [ 202260E7CDD731A32AF62ABD1ABEE008, 0E019FAE09B2659CC3267756DB962CCD69172BA67E3288B491F7B455287A5392 ] NdisCap         C:\WINDOWS\system32\drivers\ndiscap.sys
12:08:04.0571 0x1830  NdisCap - ok
12:08:04.0586 0x1830  [ A1D473D0CF10561F29B58EA7C5412A92, 3DBFC1D769E03E30C87FF4F30A9B523A69A7E0CD4EB87F8A9ECE190FEB84C569 ] NdisImPlatform  C:\WINDOWS\system32\drivers\NdisImPlatform.sys
12:08:04.0602 0x1830  NdisImPlatform - ok
12:08:04.0633 0x1830  [ 1A0AE283B8DE6BB76412A0F8213D45AC, 91AFFDC7A9277EB59CD54021049BEA715078F90470B8A12F3E9F1386DF068D2D ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:08:04.0649 0x1830  NdisTapi - ok
12:08:04.0665 0x1830  [ A74EE2D2C0BFF5EC3A6185791868C4CA, A346320DEBEAE890575B4C6594FB3A3A9890A0E86881ADD8376E442282C88D38 ] Ndisuio         C:\WINDOWS\system32\drivers\ndisuio.sys
12:08:04.0680 0x1830  Ndisuio - ok
12:08:04.0696 0x1830  [ 32A9BD1342640D48AD85C8B3E812B984, B702B05A0180472139B35B105DD3B6B6F75AEDC9DD1EE342FB576259076455AE ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
12:08:04.0711 0x1830  NdisVirtualBus - ok
12:08:04.0774 0x1830  [ 6A6A8CF5EE61801375A38EBB871D4057, AE8EFF18D82BBE83101B380189A6889822891A993EB865E2E81C1D2F60B77C4C ] NdisWan         C:\WINDOWS\System32\drivers\ndiswan.sys
12:08:04.0805 0x1830  NdisWan - ok
12:08:04.0805 0x1830  [ 6A6A8CF5EE61801375A38EBB871D4057, AE8EFF18D82BBE83101B380189A6889822891A993EB865E2E81C1D2F60B77C4C ] ndiswanlegacy   C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:08:04.0821 0x1830  ndiswanlegacy - ok
12:08:04.0852 0x1830  [ 50AEF8EF0064A91ABB08D858D039C9DE, 16F1CBE1EC3778D157CC054261068C8D7F8A72D85853CB70178F8DF81D238C8F ] ndproxy         C:\WINDOWS\system32\DRIVERS\NDProxy.sys
12:08:04.0868 0x1830  ndproxy - ok
12:08:04.0915 0x1830  [ D358DF634F52247CB43F0781218F4D6E, D375E9E681551467FC5F7AB2AC053C9F22AAC541C0BCBA57090211F45009342C ] Ndu             C:\WINDOWS\system32\drivers\Ndu.sys
12:08:04.0930 0x1830  Ndu - ok
12:08:04.0946 0x1830  [ 026618ECF6C4BEBDCB7885D42EC0DBE4, 8E7E13361DCF8748FA3AD518B3DE0A3DCE932316EE32E5529E75785BC5395AD1 ] NetBIOS         C:\WINDOWS\system32\drivers\netbios.sys
12:08:04.0961 0x1830  NetBIOS - ok
12:08:05.0008 0x1830  [ F51C02D992A8D6BC5EC4D990F227D4C7, DBBDA422BFA82219403689637BE8D6B0D0A893895143E807FA5A007C166454CB ] NetBT           C:\WINDOWS\system32\DRIVERS\netbt.sys
12:08:05.0040 0x1830  NetBT - ok
12:08:05.0055 0x1830  [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] Netlogon        C:\WINDOWS\system32\lsass.exe
12:08:05.0071 0x1830  Netlogon - ok
12:08:05.0087 0x1830  [ 7FD4C3D32DAE890608F44074A3437CD8, 5B7D9E9AEE26896B818F3C5DBE4C96A33D43CE2CF7716B95AAB7203611C03BFE ] Netman          C:\WINDOWS\System32\netman.dll
12:08:05.0121 0x1830  Netman - ok
12:08:05.0168 0x1830  [ A059F75402710535A90A8D043674A514, E98536DF74A2B75FDBA6B866DC1909544292DFE5E14F984941470FBA6E8D810C ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
12:08:05.0199 0x1830  netprofm - ok
12:08:05.0235 0x1830  [ 3D58D04A9269CE21B61960544A05573D, 250DB1266EE37BAAA9F9E51434879DB4564A8550FCAB28BAB3308772882850CF ] NetSetupSvc     C:\WINDOWS\System32\NetSetupSvc.dll
12:08:05.0252 0x1830  NetSetupSvc - ok
12:08:05.0354 0x1830  [ 9E9BEB22644CE1DA521A1D7821BF891F, 5480D52AE1942205B513F916DBCBF5B5F2FFF92D927F4E598FBA618E75BBC2E9 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:08:05.0380 0x1830  NetTcpPortSharing - ok
12:08:05.0428 0x1830  [ 91B32D7036700BEED5343E1F6A7122CC, 8123CA398A79F0E69126F962AA29C2464FAB50182E961CB6A6ADB6CEA09A6732 ] NgcCtnrSvc      C:\WINDOWS\System32\NgcCtnrSvc.dll
12:08:05.0444 0x1830  NgcCtnrSvc - ok
12:08:05.0475 0x1830  [ C64B693DF26EB7BFF25F9BAD8B54D571, 12363E81B329D048E0148739AA542958F7CAF6FF3404BB001AF51850EF84338D ] NgcSvc          C:\WINDOWS\system32\ngcsvc.dll
12:08:05.0506 0x1830  NgcSvc - ok
12:08:05.0537 0x1830  [ 1B8F07B59F7DAE02264FB8A16088C467, 1795DA9F72C34A9F47D9AAF5E95D40C3296948EB89D9600679AB4660671A5C65 ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
12:08:05.0569 0x1830  NlaSvc - ok
12:08:05.0600 0x1830  [ 465DC580170CD844206D7E3EF1DBF2A1, 5A14001029BE154C708CCA34449B280905DB79978FC7F0BE0CF20B20E47752CF ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
12:08:05.0600 0x1830  Npfs - ok
12:08:05.0647 0x1830  [ 29395C214D2CD4C81F73166AB988A797, 3631EB2EA17E455ECD151C0BC9A3DF6EC87C75B15DC9B607CFB68D7C463E04B7 ] npsvctrig       C:\WINDOWS\System32\drivers\npsvctrig.sys
12:08:05.0662 0x1830  npsvctrig - ok
12:08:05.0678 0x1830  [ AF8B7848E102A83AAECCD24B181CEBE5, B2AAE3567EE3A7975CDFCB3FE41D33C74D4486BFF35FF56E0516A01C744BA52B ] nsi             C:\WINDOWS\system32\nsisvc.dll
12:08:05.0694 0x1830  nsi - ok
12:08:05.0709 0x1830  [ 2871225495F832A8C8A7DD1A17EDB3DC, 2F6664C7F5FB2341B2AAF3C5A258FA0D7AEEE447562D7F39FD5A4EE905C18C6D ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
12:08:05.0725 0x1830  nsiproxy - ok
12:08:05.0803 0x1830  [ 58BFFEF692A47FCE3FAAEDBC8F3DCBBB, 4F55CDF153306B17EDEA6F621939990667735676CBA460CC3078789C2766EF68 ] NTFS            C:\WINDOWS\system32\drivers\NTFS.sys
12:08:05.0850 0x1830  NTFS - ok
12:08:05.0865 0x1830  [ 6DBD703320484C37CEA9E4E2D266A8CE, 85D6F73C0E3FDE16829C9BC0D13DD89E64183EAE02F84607F6B8440CB7F366E6 ] Null            C:\WINDOWS\system32\drivers\Null.sys
12:08:05.0865 0x1830  Null - ok
12:08:06.0225 0x1830  [ 60328FA27CB565D708CACAC8206037FB, 6D3A4B1B593428CA9F6EB2607C3F5A60DFEB92F4F437956FD916DF6B3B8E27FD ] nvlddmkm        C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys
12:08:06.0459 0x1830  nvlddmkm - ok
12:08:06.0522 0x1830  [ 019557823197E07EE33C8E363AE648BB, B9D9E9A013FDEF0F37CD37D5C92F4B1CFE0ADC08FD4ED86966E9A02FF9D80183 ] nvpciflt        C:\WINDOWS\system32\DRIVERS\nvpciflt.sys
12:08:06.0553 0x1830  nvpciflt - ok
12:08:06.0569 0x1830  [ 604D27CC38CC23493F218D0BB834B3FF, EF5E5759CCF16DD97271C82DAF47FB2086EBCA5DE7D05177B70CA1197B95F41E ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
12:08:06.0584 0x1830  nvraid - ok
12:08:06.0600 0x1830  [ 8B50D897657AB4A15FD9E251BBF7D107, 36036130DD46D9BF105AC7176E219F3BE7D1168A660A0F8DFF76F61FBFA4B417 ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
12:08:06.0615 0x1830  nvstor - ok
12:08:06.0647 0x1830  [ 4398DCC9BA21E1BE911A13BD18C63481, 251DF1EF6101AC071100665686811915C3B306055C3901BDA96F99612FD001B2 ] NvStUSB         C:\WINDOWS\System32\drivers\nvstusb.sys
12:08:06.0662 0x1830  NvStUSB - ok
12:08:06.0772 0x1830  [ 85397430F424516BF8300FAAEF929366, 2EDF41407C7483AC8E4703BC0A13F764563E4B00D6923FD4678E6E361AC14D6B ] nvsvc           C:\WINDOWS\system32\nvvsvc.exe
12:08:06.0803 0x1830  nvsvc - ok
12:08:06.0834 0x1830  [ 31F990B2B6B91E9D7A667405CE12FCB1, 907E095D1E83CDAFF34BE789FC41CDD7BB4DEE23261E1D03C1CF0D4D030534AC ] nv_agp          C:\WINDOWS\system32\drivers\nv_agp.sys
12:08:06.0834 0x1830  nv_agp - ok
12:08:06.0881 0x1830  [ 7F3A0D052B8E00E730316210B1DD092F, 14BD026EA759F6C81ED6B4DBB04E0584B7F6456725503FC73CD4347B7743005F ] OneSyncSvc      C:\WINDOWS\System32\APHostService.dll
12:08:06.0912 0x1830  OneSyncSvc - ok
12:08:06.0991 0x1830  [ 334131C162B118EF49930D41B0E17825, 10EF08870B6E118AED2E0E3F45E06BA8A485439823BE98F44E34E7D2B65AA2EF ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
12:08:07.0006 0x1830  p2pimsvc - ok
12:08:07.0053 0x1830  [ 4A5634915AF62C983E08425905D0C04C, 09BC3F7AD9F79C5FF59520933D06FE155AC21CD0ABAFE66B81C9F87D83A2339F ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
12:08:07.0084 0x1830  p2psvc - ok
12:08:07.0116 0x1830  [ 7D0FC96264C0F8F2C1321E33E8EB646C, 82A06437B9B096BCCF5CE31BDF3539696E2E41DFA9870C358566EEE2F7D3B447 ] Parport         C:\WINDOWS\System32\drivers\parport.sys
12:08:07.0131 0x1830  Parport - ok
12:08:07.0169 0x1830  [ 24AC0FD10325FBC2303B29A5F237AEB0, D94B26A36EBE4EFE8EA270FA6600811206830480BE953809F74FAB80628DF879 ] partmgr         C:\WINDOWS\system32\drivers\partmgr.sys
12:08:07.0171 0x1830  partmgr - ok
12:08:07.0218 0x1830  [ 0ECA2ADD5FBCE73183A68935C71B40B7, 08CC5F2F10D1DD1A1396CC29196314003491D3AF3DE59CADB281F252577F1860 ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
12:08:07.0233 0x1830  PcaSvc - ok
12:08:07.0265 0x1830  [ 1D4E995955BDAE781C46CB97AE1CFB58, FF7475F19782CA253AA839DDB86E5AC20C5785D5CC1DD57D9FECBE4F5A5C0BFB ] pci             C:\WINDOWS\system32\drivers\pci.sys
12:08:07.0280 0x1830  pci - ok
12:08:07.0327 0x1830  [ 2B4D98DF0CA57FB9536DBC80D2449D1F, AB34FA8585A20854369C0FAEB18BF5C7734D7E3C791F644B0576E40D609FCD09 ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
12:08:07.0343 0x1830  pciide - ok
12:08:07.0358 0x1830  [ F4D5793BF2E58AF15C6CF2FEEF9E73EB, 9B5A40AF8838063F8F0A2B1480B39A2711AAE78BD972CDA60CCA0EB2BA211A87 ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
12:08:07.0374 0x1830  pcmcia - ok
12:08:07.0390 0x1830  [ 22A53744CEEADFFFD33BA010FAD95229, 30B775EC9795105B8BF785BD63115C160955E7EFF74B995D3EC288138D1825A3 ] pcw             C:\WINDOWS\system32\drivers\pcw.sys
12:08:07.0405 0x1830  pcw - ok
12:08:07.0436 0x1830  [ 48F3A3222CF340FE31535CB6D49C6D6F, 5F8904871219FA6C1BD74747583855B0FBCE42F340A3BE10270D8D3F02766E9D ] pdc             C:\WINDOWS\system32\drivers\pdc.sys
12:08:07.0452 0x1830  pdc - ok
12:08:07.0483 0x1830  [ E2F8376F9731D12A009C522036C6073A, 5B8B68D3C013AAA8ED368C97042984C35E8D023542DBA404E7A03E89F2357E66 ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
12:08:07.0515 0x1830  PEAUTH - ok
12:08:07.0530 0x1830  [ 1398A85E59698067CBBE1D66A9C13ADF, E3609F183068BFAED756B2F9237181D60A6F6D78691248B8BF5B0AEB6A367E3D ] percsas2i       C:\WINDOWS\system32\drivers\percsas2i.sys
12:08:07.0546 0x1830  percsas2i - ok
12:08:07.0577 0x1830  [ 35F7C7AD709D909D618D9EDF987FC3ED, EE713E33688E74C5A2546CC58EBD8EA8F8116F25E42DCF8DA21DCBC7C7590E0E ] percsas3i       C:\WINDOWS\system32\drivers\percsas3i.sys
12:08:07.0593 0x1830  percsas3i - ok
12:08:07.0768 0x1830  [ 0DAF7B7D85F7AF38E29161460899C63F, F2609F2BD02C714857F5D5E6EF580643429C54E175AA72D38467F8F3A4E7F59F ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
12:08:07.0799 0x1830  PerfHost - ok
12:08:07.0893 0x1830  [ 57606281E23B0F53347527691E947B2B, 7030182E706CEBE6BD52BDC71CA8F2230AD445AE6554188E76F09A5E2612BD2E ] PhoneSvc        C:\WINDOWS\System32\PhoneService.dll
12:08:07.0924 0x1830  PhoneSvc - ok
12:08:07.0971 0x1830  [ 04F7878E7017105AB782353231561749, FB2811D98216720D4FDF0AC0EDF16C6CD33D7224B4CAFA752B4D2A839E6DD88A ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll
12:08:07.0987 0x1830  PimIndexMaintenanceSvc - ok
12:08:08.0049 0x1830  [ A546F72EFFE5CBBC98003A0CA19DA0F8, 89AE396676A37D851F46427E421E8E8ED5B4BADC33023F1E215CC352A4110F44 ] pla             C:\WINDOWS\system32\pla.dll
12:08:08.0112 0x1830  pla - ok
12:08:08.0158 0x1830  [ 15BA68662CED4B0618010A54478E18E5, 1B913BFA7AA11F3A82D80E95FC4857B810D341F9E68545710F90EBE44DAC1DF8 ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
12:08:08.0174 0x1830  PlugPlay - ok
12:08:08.0205 0x1830  [ 6BF7093B27EA90FD9222845D19C1BE5F, CF8A6764BB6B369258F21FD303E4CAE08632195620A0BD66B62F62F5D7B762B8 ] PNRPAutoReg     C:\WINDOWS\system32\pnrpauto.dll
12:08:08.0221 0x1830  PNRPAutoReg - ok
12:08:08.0252 0x1830  [ 334131C162B118EF49930D41B0E17825, 10EF08870B6E118AED2E0E3F45E06BA8A485439823BE98F44E34E7D2B65AA2EF ] PNRPsvc         C:\WINDOWS\system32\pnrpsvc.dll
12:08:08.0268 0x1830  PNRPsvc - ok
12:08:08.0315 0x1830  [ 5A91C28F99043215121499257468C4BD, 816D2AEBA29B8A050747E01CE11EB12A05C1CDDF91835C44BBB6A7B9D348B15A ] PolicyAgent     C:\WINDOWS\System32\ipsecsvc.dll
12:08:08.0346 0x1830  PolicyAgent - ok
12:08:08.0377 0x1830  [ AE3B1056FC1795F18D990C4908A6ECBF, 1C41F7714EBF54DF358D9B19D6AFE7281D3EABE20038B568A12031B76E1D50D9 ] Power           C:\WINDOWS\system32\umpo.dll
12:08:08.0393 0x1830  Power - ok
12:08:08.0440 0x1830  [ 5BA6B9AD03B81546BA64E488C4EF9D17, C43442577685FA1A7C32094B2F14FC92BA6B511FD9FDBA6FD82473A1B165FC61 ] PptpMiniport    C:\WINDOWS\System32\drivers\raspptp.sys
12:08:08.0455 0x1830  PptpMiniport - ok
12:08:08.0643 0x1830  [ 959F94AD1255BC749884EDDD14EC29C4, 2CD6DA9778EA36FA0B4080F6DB1C634712238E014E47546403CD3CDB35A1DCA8 ] PrintNotify     C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
12:08:08.0737 0x1830  PrintNotify - ok
12:08:08.0783 0x1830  [ 21AECFF3EB5748CBE12538A2500EFDE5, A1679F21363E99E3698B9C6F7E7E3BB2877D47089BC381AF0C51B1DD8B24325B ] Processor       C:\WINDOWS\System32\drivers\processr.sys
12:08:08.0815 0x1830  Processor - ok
12:08:08.0846 0x1830  [ A08AAC62EF7A1E291B3E895B5864BB86, 340E6648F9A5F4B7543FDEC5BDAFBDA3DE319B8F998FF2EF60D02EE5EF3D56CB ] ProfSvc         C:\WINDOWS\system32\profsvc.dll
12:08:08.0862 0x1830  ProfSvc - ok
12:08:08.0893 0x1830  [ 596FB6C5A72F34B7566930985E543806, 870B43783DB4CF845FA72BC5E40CE76BE6DFC66FE9E9B4B0A52D6B7FE7EA65FC ] Psched          C:\WINDOWS\system32\drivers\pacer.sys
12:08:08.0908 0x1830  Psched - ok
12:08:08.0940 0x1830  [ E84F66BA185934C166F8DF0FA8F88455, 2E0380E98DA29B3F43FB3FE0E1ECA52B3C9AEF54CE982D5514F70FAE81758449 ] QWAVE           C:\WINDOWS\system32\qwave.dll
12:08:08.0955 0x1830  QWAVE - ok
12:08:08.0971 0x1830  [ CFBA9C976CBF6796E5DC39EF59984021, A1C956AD828FC70ED92D702516E0F88A4BDAF8C93C571D7CA20F1695FD8E70C2 ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
12:08:08.0987 0x1830  QWAVEdrv - ok
12:08:09.0018 0x1830  [ 7B2AD8C55217B514C14281AB97B4E21D, A1E295897B864B9C0177FF1C502EB060084A1783C0E7E53636291F901C2E2AA8 ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
12:08:09.0018 0x1830  RasAcd - ok
12:08:09.0065 0x1830  [ E15A9CE1E2E7D1C8DF97A4FC1FFE6289, 44B53418D6BC51ACC567CF6917A0981889B44AE420489C9C03F5A30418B37267 ] RasAgileVpn     C:\WINDOWS\System32\drivers\AgileVpn.sys
12:08:09.0096 0x1830  RasAgileVpn - ok
12:08:09.0127 0x1830  [ D60BA4C76D194472D6602FF3D2D51ADE, 01272663897685C75FFBC3F1C0CFDB8D0E1A58182049E0B607D634536A8F6400 ] RasAuto         C:\WINDOWS\System32\rasauto.dll
12:08:09.0143 0x1830  RasAuto - ok
12:08:09.0174 0x1830  [ E3C82823B22463BC38AA4F8ADA852624, FF601B117F4003E2CC65B6143C2A270331EB257EE82B3BC020247D1AB1CD625F ] Rasl2tp         C:\WINDOWS\System32\drivers\rasl2tp.sys
12:08:09.0174 0x1830  Rasl2tp - ok
12:08:09.0205 0x1830  [ 3655D86C5E2982B131FC0935DE24F98F, 0386B31FECDDED77450609A807097B2307361CB59B236DEC41037BDC95897463 ] RasMan          C:\WINDOWS\System32\rasmans.dll
12:08:09.0237 0x1830  RasMan - ok
12:08:09.0281 0x1830  [ 3369023EB5790A75BA7DABA14B75D922, 36B63D5B74FDC932AAF1A876514024602D2F3EAF2CA33D1247CBA1E52FDB0418 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:08:09.0299 0x1830  RasPppoe - ok
12:08:09.0321 0x1830  [ 1E32A8CD65C4AD0A827CFEB13034DA29, 5D9A92E13020D994CCD39F701BACAFE2177A40A9CC89649441B91E3F3DECD911 ] RasSstp         C:\WINDOWS\System32\drivers\rassstp.sys
12:08:09.0337 0x1830  RasSstp - ok
12:08:09.0366 0x1830  [ 2B648363E4C5E34B469C58596F377DD9, 30F82770468BBA562CEA0E9E39B24ACEFBE022343D0180C82E2ACE8957B73E44 ] rdbss           C:\WINDOWS\system32\DRIVERS\rdbss.sys
12:08:09.0385 0x1830  rdbss - ok
12:08:09.0408 0x1830  [ D0221C13960E274CC539D72D5A842ED0, A5A961506B9D7429D97D0635FD69E74736C0E8405487E1D22BB5CD978A60044C ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
12:08:09.0420 0x1830  rdpbus - ok
12:08:09.0441 0x1830  [ 1DC2CC74B51E4DC4CD5A20C1021E4010, 46B7D17EE27439F2191504D1C6F6C70B2540BD4F2261DBB1F4BE783BEA99B04C ] RDPDR           C:\WINDOWS\system32\drivers\rdpdr.sys
12:08:09.0456 0x1830  RDPDR - ok
12:08:09.0506 0x1830  [ 177DF954D0DEC0465A380C75F6E7F65F, 6B30C78223029BD5DBA586BF961968F85762209BA55CD031460A215B20F93AB2 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
12:08:09.0515 0x1830  RdpVideoMiniport - ok
12:08:09.0531 0x1830  [ 5D1680871054D2B0B8A971BC8AB3B837, 9CAB0B2E3857829D34A82A78B120D07E292D4D5060168D964295EB23339B7DE7 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
12:08:09.0562 0x1830  rdyboost - ok
12:08:09.0609 0x1830  [ 341E6830DA70F65730300DAB4CB0B490, 341EC8DB5E39963EF89E726F08730AFB2356C3BAD71CCE9EECCAB4D9B31C4863 ] ReFSv1          C:\WINDOWS\system32\drivers\ReFSv1.sys
12:08:09.0640 0x1830  ReFSv1 - ok
12:08:09.0703 0x1830  [ 8355BCA85B0928382DFCDD02FCD1681A, F306F038DA09C8D2095C311818E2F991B55BCD96B40B95D2A53A60EA6AC37014 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
12:08:09.0734 0x1830  RemoteAccess - ok
12:08:09.0781 0x1830  [ 2C82F4DCABAB389CEBB1C9E86C715C9C, 70354621D3D467616A419A818C54D2C89EA013C5050BA9944E3A7A4F25CAD6BA ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
12:08:09.0796 0x1830  RemoteRegistry - ok
12:08:09.0859 0x1830  [ AD43141CE6D5074DA1D28B5BCD4E4507, C1A9AA856DD4FEE00BBA329C150E0CBCD1CE13ED0BB7B4AC9B152321CD854212 ] RetailDemo      C:\WINDOWS\system32\RDXService.dll
12:08:09.0906 0x1830  RetailDemo - ok
12:08:09.0937 0x1830  [ 74727B8BF0227820660A79450F2D94EF, 86BC249322A3C63CBC3B532AD86BFDCB5A46A24A767137D02C944B94A899C521 ] RFCOMM          C:\WINDOWS\System32\drivers\rfcomm.sys
12:08:09.0953 0x1830  RFCOMM - ok
12:08:09.0984 0x1830  [ 176D8470B15CD9080861594F9A33FA01, CFB66D7FEB9465985C2866D64EA03B7E7BE830DCF6C02B3FE2244D7F7E5343E2 ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
12:08:10.0000 0x1830  RpcEptMapper - ok
12:08:10.0031 0x1830  [ 1A563653DAEDFE4CA81936E0D2FD8B56, 308B0DFEBA63333D407093C449A08ABFECE118C9274100809356BDAF7FA32EB6 ] RpcLocator      C:\WINDOWS\system32\locator.exe
12:08:10.0031 0x1830  RpcLocator - ok
12:08:10.0078 0x1830  [ B339861C6A2A86FBCA67C2006B461473, 228ADC8A8603C0A4342C6CBC6F2CC919271D42391365061AF660E0D7151C66A4 ] RpcSs           C:\WINDOWS\system32\rpcss.dll
12:08:10.0109 0x1830  RpcSs - ok
12:08:10.0140 0x1830  [ 0AC5FCDC29ED97ECDEF1276425EE2059, 8A12D1732D4AA18A9ED8416F4D4A49B81CE7C4C86ABCEE8FF28A16EA61993CFE ] rspndr          C:\WINDOWS\system32\drivers\rspndr.sys
12:08:10.0156 0x1830  rspndr - ok
12:08:10.0218 0x1830  [ FBEFF38DE03450E03E6CD9E8E37A8C74, C1C0876785DB4366D67792A3AFA219FC933FC1894AF93D07B0016BBCC81A5886 ] rt640x64        C:\WINDOWS\System32\drivers\rt640x64.sys
12:08:10.0234 0x1830  rt640x64 - ok
12:08:10.0312 0x1830  [ 4DBBD2B451A2C45536F14FA972DD3E83, 22B47D79452593E57640B70F3A2EAA9D448046BD1BACBFD2851366DD6FC6DCAE ] RTSUER          C:\WINDOWS\system32\Drivers\RtsUer.sys
12:08:10.0328 0x1830  RTSUER - ok
12:08:10.0375 0x1830  [ 044890BB0D6CF1E23C1087234D320509, FA6C79D24BE4ACCFAC617D2850B922BFAA7C2766AE625C725F3ACF43C934EFAF ] s3cap           C:\WINDOWS\System32\drivers\vms3cap.sys
12:08:10.0375 0x1830  s3cap - ok
12:08:10.0409 0x1830  [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] SamSs           C:\WINDOWS\system32\lsass.exe
12:08:10.0414 0x1830  SamSs - ok
12:08:10.0461 0x1830  [ 530F797129776AA7E81994783A97E2AD, F131EF036702C6E741E5A6851AE07E81043CE8BAEED0768838C0F31CE14FEC1A ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
12:08:10.0477 0x1830  sbp2port - ok
12:08:10.0515 0x1830  [ 0C12493B333B96797AFC5F3C7831C051, BEE786D7ED14221B1A9450060597393AC44116D776B913E045B5F6066D720F74 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
12:08:10.0541 0x1830  SCardSvr - ok
12:08:10.0585 0x1830  [ 40110802D217FE1CB581D9A70B1FD16F, CCB920593CCC6663676039F3F731536DFEF535C3F715F6DB6F34D0D733BEF89B ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
12:08:10.0605 0x1830  ScDeviceEnum - ok
12:08:10.0618 0x1830  [ 9B6B1D4DB35A3D9BEAF023BC95E1F49D, CA44124CA3E9958FB77A891CD234A993B63E8AC6632AE801CDEC6666267E7C7E ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
12:08:10.0634 0x1830  scfilter - ok
12:08:10.0676 0x1830  [ EA195B8BC11C1CDB313CFD456EFFA0E9, EEDF349C59ED0645B04040707906BB4496527243858C2A6BE46BE7029B4A7F37 ] Schedule        C:\WINDOWS\system32\schedsvc.dll
12:08:10.0713 0x1830  Schedule - ok
12:08:10.0733 0x1830  [ 4E9158CECF77A029AB98E8FBB43FCED5, AFF8BDB8F8F8DDF4FC0D65712E031DC360856CD3CE5C8A4C8FF960388F37462F ] SCPolicySvc     C:\WINDOWS\System32\certprop.dll
12:08:10.0737 0x1830  SCPolicySvc - ok
12:08:10.0769 0x1830  [ 70165A0A2653FB8AFDE3D85000727F29, BAC35D7B0296CAC78EAC4266FC96E292174827E0B24ECAF085228B26A5052911 ] sdbus           C:\WINDOWS\System32\drivers\sdbus.sys
12:08:10.0784 0x1830  sdbus - ok
12:08:10.0815 0x1830  [ 811EC0B1221402FCED0BA37E112BF627, 366EB8AF04C603BED6CF53652CC937099B247D5DD8C58D699D0D8DA22F8FDD51 ] SDRSVC          C:\WINDOWS\System32\SDRSVC.dll
12:08:10.0831 0x1830  SDRSVC - ok
12:08:10.0862 0x1830  [ DE6D7DC78D956928F59F7415A0F41E13, C0F8EEED29BF63A0D8FB5A0286C1C768BFEF598EC52715D910B5BB1A76231805 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
12:08:10.0878 0x1830  sdstor - ok
12:08:10.0894 0x1830  [ EBD07BD20B5E0E92A398566EF8720F79, 8A88C861D4113B9938C32CBD28FD3D7F1C3133E700E23E17F5DFD7B26CCDA04A ] seclogon        C:\WINDOWS\system32\seclogon.dll
12:08:10.0909 0x1830  seclogon - ok
12:08:10.0925 0x1830  [ B7B9EEBCB7466338403A75D15AC120D7, B8F79DA71F8CD0F30983F7D92B625A431C212DD543DE2B3DC03EC5A68C41B00D ] SENS            C:\WINDOWS\System32\sens.dll
12:08:10.0940 0x1830  SENS - ok
12:08:11.0019 0x1830  [ D14DD7D766664F880FECF44CE6017966, ECF966E3ACF4EBD5A3259468A076619A539E35F1B97AB6A98FBD7882F1FBBBAB ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
12:08:11.0081 0x1830  SensorDataService - ok
12:08:11.0128 0x1830  [ A74C62AE99A015CD6275F0D8D8843886, DF08E0BB1160E054C6B000BC5F62DEF77C6D9E4B5679AD013C313BA14207B589 ] SensorService   C:\WINDOWS\system32\SensorService.dll
12:08:11.0159 0x1830  SensorService - ok
12:08:11.0190 0x1830  [ 7363A65C738F5A5292D7BDBE55D8C3C2, C53C10A0AE58613DFCC91E62E004D9B188E4793C2A19B4BE871A705EEE77048E ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
12:08:11.0237 0x1830  SensrSvc - ok
12:08:11.0253 0x1830  [ 67585C295FF2D221679E376B68893B35, 4B5E9A8DA8C6F7B1F7129F80A0603503D467E5650306FB4C309977D74037E46B ] SerCx           C:\WINDOWS\system32\drivers\SerCx.sys
12:08:11.0269 0x1830  SerCx - ok
12:08:11.0284 0x1830  [ B8C4852CBCAAC1374C08EC7445443824, DDE577A81B3E11B5B56096317BC47AA6E286573042407B96A9D29BE981F3FA4D ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
12:08:11.0300 0x1830  SerCx2 - ok
12:08:11.0347 0x1830  [ D3A103944A8FCD78FD48B2B19092790C, 252DB8395DA8639E748658D3BE7863C1700E27AA5C41BB700CFCE193FE3F04E9 ] Serenum         C:\WINDOWS\System32\drivers\serenum.sys
12:08:11.0362 0x1830  Serenum - ok
12:08:11.0378 0x1830  [ 88D58E1DAA6C5062DD3A26273106961F, D1E2FF37C888245BD0BABCD7C6B76AD5A87415B68FEFE37B5FA29AE3342AE50B ] Serial          C:\WINDOWS\System32\drivers\serial.sys
12:08:11.0404 0x1830  Serial - ok
12:08:11.0433 0x1830  [ 0F5B43074AE731D2C6F061241C9D84A6, 05CFEB30A4FC11441552D37687608C8C2FD6DC2F2266AE9D6526753E26283DE6 ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
12:08:11.0433 0x1830  sermouse - ok
12:08:11.0464 0x1830  [ CD90E445F6458512A5BA884D561EFCF1, E792FAB8AFF4126C1977024060842D788A06475139782896AFD7B39C85FCDF3F ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
12:08:11.0479 0x1830  SessionEnv - ok
12:08:11.0511 0x1830  [ D9FE59276BD56A9643C32D5FACE2F251, 591862D868A545F468496DE97DEE42C9DB3AFBFC0881CBA79EB6641A254AF033 ] sfloppy         C:\WINDOWS\System32\drivers\sfloppy.sys
12:08:11.0511 0x1830  sfloppy - ok
12:08:11.0558 0x1830  [ F8083C536BEDE61AFB4069D8A8C16DA7, 13AADAD7B5582911B8ABBE0CF7132CC517F7413A361CCF8ED502F803D061FFA3 ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
12:08:11.0573 0x1830  SharedAccess - ok
12:08:11.0620 0x1830  [ AE6E4D3172FBF45B944668CB3998B8A8, E7D7F98CB464C236A17069987F7B678D7688D9D577334151EF09DF5C6F22AFFC ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
12:08:11.0651 0x1830  ShellHWDetection - ok
12:08:11.0683 0x1830  [ ABBE803FE0BDAE0E5BE74DDEFBE62F23, 5009F489F7A6D66628C23A0FA3D7632399D0AD72BD11A1B70D7E768ED507377D ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
12:08:11.0698 0x1830  SiSRaid2 - ok
12:08:11.0714 0x1830  [ 6043DF55CFE3C7ACF477645FA64DEA98, 0E18EF8EC589841BC319C17FBABA7383FD247C9441ABF64A0D830976F3E611AE ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
12:08:11.0729 0x1830  SiSRaid4 - ok
12:08:11.0761 0x1830  [ C584D941C2F915B27FAEE9B407744641, 539CF92D713F502FB4C60E0ED4239ED993D94985B03067A9007343AFA5D8E497 ] SmbDrv          C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys
12:08:11.0761 0x1830  SmbDrv - ok
12:08:11.0808 0x1830  [ 8A6571231D93C08434A56E19E33A35CB, 78A12B58D129D5B2017C9A94734656B9F1ED41345DF1D01F82702D4D95C1BE3F ] SmbDrvI         C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys
12:08:11.0823 0x1830  SmbDrvI - ok
12:08:11.0854 0x1830  [ B922D32039A3B5991E64429EC4EE52A9, 5EB7EB1F6D2C25F06044D8CA9F3BA0471FB40C8C96432BDC2C80CC36DC49BA0B ] smphost         C:\WINDOWS\System32\smphost.dll
12:08:11.0886 0x1830  smphost - ok
12:08:11.0933 0x1830  [ F07301C282AA222C33F8C28B4F545275, 2938943A3A62B33C8296DF3B57897D32293F5395A5E2A01C76B0160A98C12520 ] SmsRouter       C:\WINDOWS\system32\SmsRouterSvc.dll
12:08:11.0964 0x1830  SmsRouter - ok
12:08:11.0995 0x1830  [ 0B6BECB2651EF947249CDC3715E8B9CC, EB7281AF3529DE16FE8CD0C0C0C8877641865A5864D58628DBAB865B510B0D0B ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
12:08:12.0011 0x1830  SNMPTRAP - ok
12:08:12.0058 0x1830  [ 1A6CB30F0EFC1632E6F1B852CA892583, 0E6BDCEE837AEC3D02C437478143C75550C94A50E36895DDB095F54A2FA18E2A ] spaceport       C:\WINDOWS\system32\drivers\spaceport.sys
12:08:12.0073 0x1830  spaceport - ok
12:08:12.0089 0x1830  [ E1C158F6C00359278727A2CEE5D2ED71, 1591F942C6DD99D3BA7FD4D72D957864117B2263F205468A15F1D1417C6F799D ] SpbCx           C:\WINDOWS\system32\drivers\SpbCx.sys
12:08:12.0104 0x1830  SpbCx - ok
12:08:12.0136 0x1830  [ D1241DFC397FA8CCFB4BB4B63AAD31AC, F8C57C2F7CA8B6D8FEE1505A143A3FECF502C8DCFFC375F9C8848A87D9714C9E ] Spooler         C:\WINDOWS\System32\spoolsv.exe
12:08:12.0167 0x1830  Spooler - ok
12:08:12.0323 0x1830  [ 7C58AFEC26E9F7730A8AA7FD40225937, 546EAD8889F2A1BB6DCCB7781976B975F34DA1C9047F95FEAA52CF38EC60C6DD ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
12:08:12.0480 0x1830  sppsvc - ok
12:08:12.0512 0x1830  [ ACC1709EC7FE6EB8999DBC91C50C2B34, 83ABF51751A264291C53A32B86239A607361E56CB045CD2CBE6E41DBB8A01F54 ] srv             C:\WINDOWS\system32\DRIVERS\srv.sys
12:08:12.0543 0x1830  srv - ok
12:08:12.0590 0x1830  [ AFBCFC946FAE7483E27BD316D03F94A5, CC9478EA717E85C38304957E923997821DFE2A995D7C8DF98C15267D952BEFBE ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
12:08:12.0621 0x1830  srv2 - ok
12:08:12.0668 0x1830  [ 107C1EBE79710E4A759449BD6604245A, 963D693F4E61EDC7B3AA9006CC274D56E577CE0035A61DDB2A6DE72116D5C52B ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
12:08:12.0699 0x1830  srvnet - ok
12:08:12.0715 0x1830  [ 8C1786C073A496B8C0C8A5450A4FFD5B, 13BF3B42A63CE6C461259D4CE767FB0DE1F10433512A11D2B2C033E36E652542 ] SSDPSRV         C:\WINDOWS\System32\ssdpsrv.dll
12:08:12.0746 0x1830  SSDPSRV - ok
12:08:12.0777 0x1830  [ 217A982201052EFC8C3C0C88D229791C, 11509E3446ED7B75C9A05CDC4A7AF18926CB463E0D98BAE1CD5DB43E88F94F90 ] SstpSvc         C:\WINDOWS\system32\sstpsvc.dll
12:08:12.0793 0x1830  SstpSvc - ok
12:08:12.0902 0x1830  [ 58863C57E4598C4F9DA967C5C36CFA5D, BB34FBC324E84E05128258CE3755241ECB63F7F2AE7F96716AC373931FAF92A8 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
12:08:12.0980 0x1830  StateRepository - ok
12:08:13.0012 0x1830  [ CCDA497C880AD16D87EDFAEFCFB2EDF5, 622599AA35ACFF0375DA252210BE42E7E90F30EDFEFF2F62FDB14AE6E45B5F88 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
12:08:13.0027 0x1830  stexstor - ok
12:08:13.0059 0x1830  [ 75476CAA8FA0A4E573948CDE8C7F0304, 68C4405CACA77AEED71761875A9AF60BCFBDD39E356BEA1BA8226E099BAA5FA4 ] stisvc          C:\WINDOWS\System32\wiaservc.dll
12:08:13.0090 0x1830  stisvc - ok
12:08:13.0137 0x1830  [ BF8EA6FC3358C2F69678E3E94F764F84, D274DAD7B5756DD49CA44277C73497F1EC465C8E365CC730CD194932C3825920 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
12:08:13.0152 0x1830  storahci - ok
12:08:13.0199 0x1830  [ 32FF460DA8C1F370F5C08B7654899B73, 0C9D5D38D033109BA672ABAFEF0F0CD295E9FFA108ACFCA9044429D9B2CA9057 ] storflt         C:\WINDOWS\system32\drivers\vmstorfl.sys
12:08:13.0215 0x1830  storflt - ok
12:08:13.0230 0x1830  [ CC21DB3EF619B9480FE31A4EFE92CBEB, 256EFCA2F231F41D34250E1460BF88894D943EAE83A0B153FCADE700AB4DE11E ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
12:08:13.0246 0x1830  stornvme - ok
12:08:13.0262 0x1830  [ 390B8A75768E2689586539C224520895, D72F52E6D7AC5DC318FF9C1DF1F4E8A435D65B6BB59D7F1642222EC026BC54DB ] storqosflt      C:\WINDOWS\system32\drivers\storqosflt.sys
12:08:13.0287 0x1830  storqosflt - ok
12:08:13.0321 0x1830  [ 9953FA89A4E3BC33296DAFB1ACFDC62F, D2F2698834691FF7915BDFFB82DB549354311A5DD7D37BF767F95D407AC4019F ] StorSvc         C:\WINDOWS\system32\storsvc.dll
12:08:13.0352 0x1830  StorSvc - ok
12:08:13.0367 0x1830  [ 770A92D9D3A0BF61C97C3AFCB36847D9, 21A8CC3F8E63B971C4FF8DDED5C7032E093A7B0F16E2128A9BD2E890BA76A1D9 ] storufs         C:\WINDOWS\system32\drivers\storufs.sys
12:08:13.0383 0x1830  storufs - ok
12:08:13.0399 0x1830  [ 736A2418E3E7F3DB3CF6EB0A55D1D581, 2D3BBC4E0C7B51EDE7479A978E4BCD5F47A7257745179F01D2D9ECFD83CCCC82 ] storvsc         C:\WINDOWS\system32\drivers\storvsc.sys
12:08:13.0414 0x1830  storvsc - ok
12:08:13.0446 0x1830  [ FA8F6E3AD3F92B35D2673CC9FD20429C, 62F81CBACF7E16FEF9DE3BE95FA5C9BDB51BAE4667AE5AE71399864A390FF6D5 ] svsvc           C:\WINDOWS\system32\svsvc.dll
12:08:13.0461 0x1830  svsvc - ok
12:08:13.0477 0x1830  [ BD98B0225BCD49E8A62F4F8EE1D1F613, CDAD11969B2DA417079547724BECC3DB4FC4711B3C01590EB0D02774B69B6D90 ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
12:08:13.0477 0x1830  swenum - ok
12:08:13.0524 0x1830  [ 22E539A9B96C66A713583EC017562616, 210DA61DFC7AA9AD23277D9CC0239B781F4EABD322D0803AEC9434D68B81FABD ] swprv           C:\WINDOWS\System32\swprv.dll
12:08:13.0555 0x1830  swprv - ok
12:08:13.0586 0x1830  [ CAE4B27B469C583131EA5AAE622F5D76, 3979006EB22489D1AAD2EC2E9F32C286EEDCDB83B37B97E58BA831263EC33B84 ] Synth3dVsc      C:\WINDOWS\System32\drivers\Synth3dVsc.sys
12:08:13.0602 0x1830  Synth3dVsc - ok
12:08:13.0633 0x1830  [ 7DC2B34FB6F1798F2D13453E0321D025, 60EF12A8824384DD88D9C5D188E8FB137F0F85A63C06AAF720CB2D616EB847F4 ] SynTP           C:\WINDOWS\System32\drivers\SynTP.sys
12:08:13.0649 0x1830  SynTP - ok
12:08:13.0789 0x1830  [ 6FBDBC24B1642868E041463795CBFA44, E9FA0DB094E7B2129ABD325BC91A48D6646380D6AA97BE6233C220E0C98637AF ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
12:08:13.0805 0x1830  SynTPEnhService - ok
12:08:13.0883 0x1830  [ 34A3EB84B2A830E6F450B8F885AE4E6E, E61AC6D17B815CB71F26D71CA3CCAFD9E66A170E3ED2E64A4F20D097A0C683B5 ] SysMain         C:\WINDOWS\system32\sysmain.dll
12:08:13.0930 0x1830  SysMain - ok
12:08:13.0961 0x1830  [ AF2C8D7C1D4DCFD5C31501F009DF42B7, 3DDF9353F014EE99B031BBC969620CA07647FBB8D78EB4697C8D633021B46B11 ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
12:08:13.0977 0x1830  SystemEventsBroker - ok
12:08:14.0008 0x1830  [ 6979A147C0D5C5CAB621ADC394D32B80, C30B8E3D271A1591D965559EA4A11A1BE63A34D832ED53B26CE91799C888DF77 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
12:08:14.0024 0x1830  TabletInputService - ok
12:08:14.0055 0x1830  [ 86B62FC8CB89946446F9B24FE49A66FD, 7B095310D1C78B82E5ACAC4713E101DD1323A3CF6FB39218C2E78ABE2B0385B5 ] TapiSrv         C:\WINDOWS\System32\tapisrv.dll
12:08:14.0071 0x1830  TapiSrv - ok
12:08:14.0164 0x1830  [ 892F30506DCCF230C5A57019C1D8D31B, 52C83A963E2D05770B6A281E8E559C8203E102D6B4C9C37801B1F58CB4B92D2F ] Tcpip           C:\WINDOWS\system32\drivers\tcpip.sys
12:08:14.0227 0x1830  Tcpip - ok
12:08:14.0274 0x1830  [ 892F30506DCCF230C5A57019C1D8D31B, 52C83A963E2D05770B6A281E8E559C8203E102D6B4C9C37801B1F58CB4B92D2F ] Tcpip6          C:\WINDOWS\system32\drivers\tcpip.sys
12:08:14.0321 0x1830  Tcpip6 - ok
12:08:14.0367 0x1830  [ 17F37EC9042D84561C550620643D9A85, B01620BA319A1383D403E6E50C7724879520F3267654556D975CAFFF91A82C78 ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
12:08:14.0383 0x1830  tcpipreg - ok
12:08:14.0414 0x1830  [ 91D3F2A6253EF83EFBD7903028F58C4D, C15768CCCF734093B0F8A5E76882B35927B716E4F14D91ACEE897E1C078D43D1 ] tdx             C:\WINDOWS\system32\DRIVERS\tdx.sys
12:08:14.0430 0x1830  tdx - ok
12:08:14.0461 0x1830  [ E730D0EB1B84EBC98423FC8D285EDBC0, 442DD433F9D22304E64EC7ACFC4E04892D4D92D8AC545A3530FC932A2EEC4767 ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
12:08:14.0461 0x1830  terminpt - ok
12:08:14.0518 0x1830  [ 14307D4801C8CEF0A615907C09E886B3, C7F34C294D70DE689F673E0B5E9253B27EFEBBE6FA38B68B3B0B0374A896407E ] TermService     C:\WINDOWS\System32\termsrv.dll
12:08:14.0580 0x1830  TermService - ok
12:08:14.0627 0x1830  [ D009D1BC14FD5F2AC93D1878735F6C39, D8BCE505B66E05BC00075E46B38359CA4D0FA484EB7981A74221885E8A1FFB87 ] Themes          C:\WINDOWS\system32\themeservice.dll
12:08:14.0659 0x1830  Themes - ok
12:08:14.0690 0x1830  [ 5F27DE2082E16D4C1D6C627C8ECBD341, 08DA3EB3EF2B2006B6F9F2C8C149DF55DE6738975D556206A814096CAB5C1411 ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
12:08:14.0705 0x1830  TieringEngineService - ok
12:08:14.0752 0x1830  [ FC971E1D1B5900C231591A7720FCD8B8, DF58C350977019E4A8F381FB35702E9BEA89F6A8C6BF36C56376D36BC8FE630F ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll
12:08:14.0768 0x1830  tiledatamodelsvc - ok
12:08:14.0799 0x1830  [ 7E81E3E0D7F83BFE3C3975020B6C7F12, 316F9415646CC7A4E9A5F1E07310D433457E623B3E589543E4A6C73C4F77712C ] TimeBroker      C:\WINDOWS\System32\TimeBrokerServer.dll
12:08:14.0815 0x1830  TimeBroker - ok
12:08:14.0846 0x1830  [ 169B0A246067457FEF8A18EED7EED9D5, BF5AC0CB29E1E456253B881CD0608B578D7343E9DFE1738A14598D1DFFE1AB66 ] TPM             C:\WINDOWS\System32\drivers\tpm.sys
12:08:14.0846 0x1830  TPM - ok
12:08:14.0877 0x1830  [ AA84AF93CE5AF1F05838B51D20295419, 85B3EE773C691EEDFA080CD9C59D31CB58A5BC577AEE91A929F5DFBE1368AB6D ] TrkWks          C:\WINDOWS\System32\trkwks.dll
12:08:14.0893 0x1830  TrkWks - ok
12:08:14.0940 0x1830  [ E50DD57F496CED8873FA3E7D38BCCD42, 36B95F6F2CF48078C6B19FB452C87BB07E95C8804A5C6B526D349AC6227CAB26 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
12:08:14.0955 0x1830  TrustedInstaller - ok
12:08:14.0987 0x1830  [ 48E828C66AB016E48F2CB4DD585315FD, 063809B610F6B177B65D62D12605FB94F108DB26A9FD3067E6D6C51F0D92E774 ] TsUsbFlt        C:\WINDOWS\system32\drivers\tsusbflt.sys
12:08:15.0002 0x1830  TsUsbFlt - ok
12:08:15.0034 0x1830  [ 267C76EE60736EA5A1811A53FA02AABE, 28D4C4CB972534204B8336D0403B70E4EFE4F8369ABDE7401FFCCF7D4E3EA165 ] TsUsbGD         C:\WINDOWS\System32\drivers\TsUsbGD.sys
12:08:15.0049 0x1830  TsUsbGD - ok
12:08:15.0080 0x1830  [ 8CE72F094B822AD5EE9C3A3AFC0C16B6, 827CCD849544E1DA364B03DBC82A848D2F93AD32BA14ED52709C609BC70CE5CA ] tunnel          C:\WINDOWS\System32\drivers\tunnel.sys
12:08:15.0096 0x1830  tunnel - ok
12:08:15.0112 0x1830  [ 1A9A77ACDAC29C39F50D2A492FD0DB16, E21F2E2BA6EABE0F6B5A1930DDB2CE5A921389A58C08A2D3F66D245E8698E6B4 ] tzautoupdate    C:\WINDOWS\system32\tzautoupdate.dll
12:08:15.0127 0x1830  tzautoupdate - ok
12:08:15.0159 0x1830  [ 42C546414F80BD6C0137FC3A106F8A69, 067FFCAF0059935851888BD984E848E4E1A6CC1941A8F4534067CCF0B2A3B2E6 ] uagp35          C:\WINDOWS\system32\drivers\uagp35.sys
12:08:15.0174 0x1830  uagp35 - ok
12:08:15.0190 0x1830  [ 1686DBC81748B096232B15F16C302985, 63D72D1838C42A95599AF3C0B19A069E310ADB091208011D7D6FBAC968D1A59A ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
12:08:15.0205 0x1830  UASPStor - ok
12:08:15.0237 0x1830  [ 3995CC3DEDED258768B8EBC2F4C0DC73, 130E99EF13EB494B8BB6A8E037DD8D59C195190EA3C27CA9E3A695AF4349DC7C ] UcmCx0101       C:\WINDOWS\system32\Drivers\UcmCx.sys
12:08:15.0252 0x1830  UcmCx0101 - ok
12:08:15.0268 0x1830  [ 1C95F7CE37D9EFB90EBE987A9712356C, B9EE7743ADA50276F05D735C5C29E44039D630A7DC93766A0EAF400DA037E4AF ] UcmUcsi         C:\WINDOWS\System32\drivers\UcmUcsi.sys
12:08:15.0284 0x1830  UcmUcsi - ok
12:08:15.0299 0x1830  [ AED081772091C98173905E2DF28C223B, 08541CF3354EBB634BD590E0019128F70A6FCA9075B7E785A9E9BD82EC234DD3 ] Ucx01000        C:\WINDOWS\system32\drivers\ucx01000.sys
12:08:15.0315 0x1830  Ucx01000 - ok
12:08:15.0330 0x1830  [ DCA34A111C29E4578DF2B8CEA3C7CDBD, 86BCE4C8EC228724D5896067A85A4768B6069D10A482ECC51A8F828DBD3880C9 ] UdeCx           C:\WINDOWS\system32\drivers\udecx.sys
12:08:15.0346 0x1830  UdeCx - ok
12:08:15.0362 0x1830  [ 718A956AE00CE086F381044AB66CC29C, E4EED1600C72CECE1D4507827C329A93D356BBA027470FCF6C4B5C1651DED643 ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
12:08:15.0393 0x1830  udfs - ok
12:08:15.0409 0x1830  [ BA760F8E66428BA9FF1E8BFBC6248136, BE7DCBB293B12672CB3653E640C46F669BD738D320F34F4FA4A26F6B248561F0 ] UEFI            C:\WINDOWS\System32\drivers\UEFI.sys
12:08:15.0409 0x1830  UEFI - ok
12:08:15.0440 0x1830  [ 5F0D997E6FC5A418D7673148CEF72887, 6C142CB8F06E5958045451253C9188CE876A84D08266FFD7F64AAE09964D8431 ] Ufx01000        C:\WINDOWS\system32\drivers\ufx01000.sys
12:08:15.0455 0x1830  Ufx01000 - ok
12:08:15.0487 0x1830  [ 2B1DABA97DDF5365FC66EE7DEDD86A13, 2FF3355862938B37EE63FCA149415CE5032BF54747B07517BB21460733B65AD8 ] UfxChipidea     C:\WINDOWS\System32\drivers\UfxChipidea.sys
12:08:15.0502 0x1830  UfxChipidea - ok
12:08:15.0541 0x1830  [ DB630FC660443D63EBAB2C830C298EFE, 7698772FF9C988DF752DF3FAF1B154E923EBA425B92F288ABB6EF0805ABD3296 ] ufxsynopsys     C:\WINDOWS\System32\drivers\ufxsynopsys.sys
12:08:15.0568 0x1830  ufxsynopsys - ok
12:08:15.0605 0x1830  [ 63451BD694651307254B8DD37A3D79C7, C781E2D876AF42D5972CCDCF86B7A59F6AF8AF0C6350647F3FA1B209119B5EF9 ] UI0Detect       C:\WINDOWS\system32\UI0Detect.exe
12:08:15.0627 0x1830  UI0Detect - ok
12:08:15.0641 0x1830  [ 6DE78C04BF32ECA7AF3064F53687C9A5, 164D3BB24EBA3EAF613799928063FE75220A4E583D985F53A895017782C18600 ] uliagpkx        C:\WINDOWS\system32\drivers\uliagpkx.sys
12:08:15.0652 0x1830  uliagpkx - ok
12:08:15.0672 0x1830  [ 67D1E0E6E4D5D33AF0AEF0E33B4DA0F4, BA2E6F16B6B3B54C943F1E7B9F79A6D1332A7ED228D754CC5AE70E3CD78B1F37 ] umbus           C:\WINDOWS\System32\drivers\umbus.sys
12:08:15.0685 0x1830  umbus - ok
12:08:15.0707 0x1830  [ 11680607944A719EF20E0E740785712A, 1567C2B3AAD702DCC2DC9C6B7B92EE5B681C06701A39DAC3AA7E2BE9E1E04F47 ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
12:08:15.0718 0x1830  UmPass - ok
12:08:15.0742 0x1830  [ FD949725D9EB52C0B87435CDE1134668, 96E2B3D3379E9AE225E5A4C5251207F1E7DA573901F4F026758EDE9FAEF4F2C5 ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
12:08:15.0774 0x1830  UmRdpService - ok
12:08:15.0813 0x1830  [ CB902A15DD21B363FECA5DCCF34F5C57, 6A0836A12A410EBD5C667982852B58CA9E9EDB11EA666C413CC0F811E01A549D ] UnistoreSvc     C:\WINDOWS\System32\unistore.dll
12:08:15.0859 0x1830  UnistoreSvc - ok
12:08:15.0911 0x1830  [ B85A8CF2BE74DFF1E80097AC94584112, B1DBACC33A4143FEE2CF54E567590A69580312AD7A053BCC85B487C4D451FBDA ] upnphost        C:\WINDOWS\System32\upnphost.dll
12:08:15.0942 0x1830  upnphost - ok
12:08:15.0958 0x1830  [ 2410A0C20D21A25E6C01979FA886BE90, DD3F92D8CF110D47B9E36BA0EB10EB34C0FDD28FE0D57E4B60F9326703388F75 ] UrsChipidea     C:\WINDOWS\System32\drivers\urschipidea.sys
12:08:15.0973 0x1830  UrsChipidea - ok
12:08:16.0005 0x1830  [ 6E59CE43B6BA5AA1ADCF36A4DBBB92BB, 647D66775A90F67D803043DE8C8AE8BC2F7A042A8DCF9C95BF5458C79609481B ] UrsCx01000      C:\WINDOWS\system32\drivers\urscx01000.sys
12:08:16.0020 0x1830  UrsCx01000 - ok
12:08:16.0036 0x1830  [ E8A59FA109A22FC07E44BDFCC9727DBD, 0DC5928C0FF7E5B38917660D6EFECCC22172DB0BB9B23216F33E750790529C16 ] UrsSynopsys     C:\WINDOWS\System32\drivers\urssynopsys.sys
12:08:16.0051 0x1830  UrsSynopsys - ok
12:08:16.0083 0x1830  [ D8A44550ECE102B6443F5D54DCE7DAB3, 97F5AE7B17DAC4A4F3186C77116BC8E49874FB0018C99D8E2CDA29D89E8B0912 ] usbccgp         C:\WINDOWS\System32\drivers\usbccgp.sys
12:08:16.0083 0x1830  usbccgp - ok
12:08:16.0098 0x1830  [ 66B3D22DAB5312FF238ABF5C6D9F8FAB, 4A644AFC1C27D692D352BEB8801398A00EA5B4055476063AF905A0A46DDBF8BB ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
12:08:16.0114 0x1830  usbcir - ok
12:08:16.0161 0x1830  [ 3E4F20DB902D2E2914F3FF3DB9772200, F3D32BE06A26164B5F6E8DB67160D1DBBDC6D14666EEF84EA43C78CB7706E31C ] usbehci         C:\WINDOWS\System32\drivers\usbehci.sys
12:08:16.0161 0x1830  usbehci - ok
12:08:16.0176 0x1830  [ 41F7F00D76904416EF1F9EFA1A4C37A2, 7A4250EB2E2E0037B3AE1480C13B229ECFF5C575E68E4F934EE011DB1833B46A ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
12:08:16.0208 0x1830  usbhub - ok
12:08:16.0255 0x1830  [ B7E1CAA9429E4C3E7E01CB35B97E1536, 11A6431C27821F247202AC9F18441FEA26544630461522C129F1671257C527BA ] USBHUB3         C:\WINDOWS\System32\drivers\UsbHub3.sys
12:08:16.0270 0x1830  USBHUB3 - ok
12:08:16.0301 0x1830  [ DAB35CCA86F5FBE77D870A40089BC4A1, 4A47D59D882D0F2B93F2EE7F10995E7D68B58009434E2CBD04C659E0D1F059D8 ] usbohci         C:\WINDOWS\System32\drivers\usbohci.sys
12:08:16.0317 0x1830  usbohci - ok
12:08:16.0333 0x1830  [ 21162F65C7756AAECAEBED9E67D0A5FE, DE3B43964171DB5B0464DA5E7A674A5D200A8695E6EF1AE2030681066ABA2688 ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
12:08:16.0348 0x1830  usbprint - ok
12:08:16.0395 0x1830  [ F259A45D6B555B14CC8365AA6BC8DC20, 28A588656449307F6E9C999BE5D73E34A2542A5771F4B504D9D36B9F93F32303 ] usbser          C:\WINDOWS\System32\drivers\usbser.sys
12:08:16.0411 0x1830  usbser - ok
12:08:16.0442 0x1830  [ 8949F77132A4F8F3BA17C6727099F002, 86AD4A2263B34983335180FDAE775D1744E042D2A11300D27DF546F15F285A25 ] USBSTOR         C:\WINDOWS\System32\drivers\USBSTOR.SYS
12:08:16.0442 0x1830  USBSTOR - ok
12:08:16.0458 0x1830  [ 8B3E458A8851F9A3B2109B1680EE1159, 753AC8F82F65564F00EA2F60B43E4B815FEAABE0DA35B6356210A5F4B1CA3EFC ] usbuhci         C:\WINDOWS\System32\drivers\usbuhci.sys
12:08:16.0489 0x1830  usbuhci - ok
12:08:16.0520 0x1830  [ 4B13B61CBB9CC3CB373C60B930D648F5, C79D10A1BF2B6BF141DD37A90BCCA0E1F2AF31B5028BB21537A8EE6EED630F5B ] usbvideo        C:\WINDOWS\System32\Drivers\usbvideo.sys
12:08:16.0551 0x1830  usbvideo - ok
12:08:16.0598 0x1830  [ 325727F01F03C504CF788618A13DC266, 9F685113F714ADBC6DCD423CCD205F71E00D1AA9B5DD045B95E61E53B0F8E9AF ] USBXHCI         C:\WINDOWS\System32\drivers\USBXHCI.SYS
12:08:16.0614 0x1830  USBXHCI - ok
12:08:16.0694 0x1830  [ 2771EBB565F5C121E66060B173991D4D, 1EB34A6262A18E47ADCA392FDB2D58E8428A1CA43EB4196D76A897F74A03CA7F ] UserDataSvc     C:\WINDOWS\System32\userdataservice.dll
12:08:16.0732 0x1830  UserDataSvc - ok
12:08:16.0795 0x1830  [ 36EC82F0E399F36BD25F593D63DC144A, 2A9E916A098ACD5A5074A5FD053ECAB027A0932A348C728F20CD63EF16289533 ] UserManager     C:\WINDOWS\System32\usermgr.dll
12:08:16.0857 0x1830  UserManager - ok
12:08:16.0888 0x1830  [ 05F4CB5991D897E4253BF61FA5E828F8, 25B5B6751B4455491E9A050DF5C12F788B5677F70FB4844E0BF851090AC1F74C ] UsoSvc          C:\WINDOWS\system32\usocore.dll
12:08:16.0904 0x1830  UsoSvc - ok
12:08:16.0920 0x1830  [ 889459F1FDDC5EC58B437AA6C436F33F, 8ACC32C88D81943A8A90FDAF4772C3EDE06CAB5F489F59525BEA7AAB99DAAE73 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
12:08:16.0935 0x1830  VaultSvc - ok
12:08:16.0966 0x1830  [ E1BE37312785A71862516F66B3FD24CE, D248C513DBEACB192653C6E46809209F341771B146544BBF43B86369280B4F8B ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
12:08:16.0982 0x1830  vdrvroot - ok
12:08:17.0013 0x1830  [ 67A6E949395A09914AD8B38FE14B8D15, 593F2FAA880B2E0468F98BD58B5214A170E5890907B25294D7A47C66505A3D45 ] vds             C:\WINDOWS\System32\vds.exe
12:08:17.0060 0x1830  vds - ok
12:08:17.0076 0x1830  [ E42C0F2850735FF9D908B9DB581E6314, E2204A56BF37FC57CD2ED96E3F908882D72B4BFF1BFB97C5172C851F1E4F9650 ] VerifierExt     C:\WINDOWS\system32\drivers\VerifierExt.sys
12:08:17.0091 0x1830  VerifierExt - ok
12:08:17.0138 0x1830  [ EC15FD6A28757793E2DA394CD94ABD52, DC758BBEE9C6952D7B3F7171EF67B037B4068E88189A2C4A894122D1D1209468 ] vhdmp           C:\WINDOWS\System32\drivers\vhdmp.sys
12:08:17.0154 0x1830  vhdmp - ok
12:08:17.0185 0x1830  [ D0C9632C350F46786643A069251BC249, CF65BA0D3F3D2B821C10E2D4F53F5B6BF6236CA9767419392A561CFA79254C3B ] vhf             C:\WINDOWS\System32\drivers\vhf.sys
12:08:17.0185 0x1830  vhf - ok
12:08:17.0263 0x1830  [ FF9E47752DE943B35D00E5BC96BDC714, 953A14637E310E27BDBD46B3A711875DBE0963AF185A523BC7E002427EA0E710 ] vm331avs        C:\WINDOWS\System32\Drivers\vm331avs.sys
12:08:17.0295 0x1830  vm331avs - ok
12:08:17.0326 0x1830  [ E886CB75DA2B6EB35469EF10135624C7, 3AFC59A0709B984F517A918D5BBEBEB1C80001BEC87C133447DCEAEDE00E516D ] vmbus           C:\WINDOWS\system32\drivers\vmbus.sys
12:08:17.0326 0x1830  vmbus - ok
12:08:17.0341 0x1830  [ 46D2EC27820EC0F798F85821E53C2942, D298A7D6AC16F76A069F843C8DD323ECB340D361733CB9B076BCDE8FC5F1FEFC ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
12:08:17.0357 0x1830  VMBusHID - ok
12:08:17.0404 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll
12:08:17.0420 0x1830  vmicguestinterface - ok
12:08:17.0435 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicheartbeat   C:\WINDOWS\System32\ICSvc.dll
12:08:17.0451 0x1830  vmicheartbeat - ok
12:08:17.0466 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
12:08:17.0482 0x1830  vmickvpexchange - ok
12:08:17.0498 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicrdv         C:\WINDOWS\System32\ICSvc.dll
12:08:17.0529 0x1830  vmicrdv - ok
12:08:17.0529 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicshutdown    C:\WINDOWS\System32\ICSvc.dll
12:08:17.0560 0x1830  vmicshutdown - ok
12:08:17.0576 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmictimesync    C:\WINDOWS\System32\ICSvc.dll
12:08:17.0591 0x1830  vmictimesync - ok
12:08:17.0607 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicvmsession   C:\WINDOWS\System32\ICSvc.dll
12:08:17.0623 0x1830  vmicvmsession - ok
12:08:17.0638 0x1830  [ 9AFCCEBFC4D311B62EF0C5457FBB405C, 965736DD97D7BF23AA62D4DFB4563534B252E26C66A3FDD1461024FD2315C53A ] vmicvss         C:\WINDOWS\System32\ICSvc.dll
12:08:17.0670 0x1830  vmicvss - ok
12:08:17.0701 0x1830  [ B9265F47E7A354BAAA0AF5CBA3F8F7CE, F836E7BEDC7CAB1C01225164D171A0210D8F909F52992E4C0BF3C92B365BCD52 ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
12:08:17.0711 0x1830  volmgr - ok
12:08:17.0722 0x1830  [ BEE9C8B72AB752B794F69C2B9B3678AA, 49A5093C26F3CDCD60577F7F2D7F936C7B2BD010B27F2C49A7B6AA41E42DF98D ] volmgrx         C:\WINDOWS\system32\drivers\volmgrx.sys
12:08:17.0738 0x1830  volmgrx - ok
12:08:17.0785 0x1830  [ E1F91A727A04C9F8199D04FF3BBBF63C, 076CAEE621DBF7DE24ED92BA239C440879FDB674CF3213DF3E35AEC03D0D2031 ] volsnap         C:\WINDOWS\system32\drivers\volsnap.sys
12:08:17.0800 0x1830  volsnap - ok
12:08:17.0816 0x1830  [ F7B1B1101271E31F43CC76E890704F51, 2282D82B220C3D13FF980ED8E40443C83816D3DA9557EACEA137873F92BB9CF4 ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
12:08:17.0832 0x1830  vpci - ok
12:08:17.0847 0x1830  [ D48ED0A08BD2FD25A833E6AC99623091, 6CA7580878D3893E14B4938023A00CDFC9BE215A0CE4ED59A94F95DFD9FDF4D8 ] vsmraid         C:\WINDOWS\system32\drivers\vsmraid.sys
12:08:17.0863 0x1830  vsmraid - ok
12:08:17.0925 0x1830  [ 4CF5A1E0C4FCA956ACD6C654E2A8610E, 57F3C7200C25E8717AF92AF2ED7615C6605179D3514B432220FA6EA94CAB4F2E ] VSS             C:\WINDOWS\system32\vssvc.exe
12:08:17.0972 0x1830  VSS - ok
12:08:18.0035 0x1830  [ 6990D4AFDF545669D4E6C232F26DE1FB, 9B8F99A035188FD96BA79E935E8EF387BEA2223ECA0B74CF64AB993DABAA5722 ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
12:08:18.0066 0x1830  VSTXRAID - ok
12:08:18.0082 0x1830  [ 1EE11F0508C58EF081F4176E66D6970B, 9069B3FC8850C7CF617909C6DBFC3753FEB59A9E708379CC57190F4097FB374E ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
12:08:18.0097 0x1830  vwifibus - ok
12:08:18.0113 0x1830  [ 938E4EF58E42D252B742B0E243011B90, AC0C21FBAF15924CB271CA43ACB7A86287936C78B4852BCFC59EC7EC703E036C ] vwififlt        C:\WINDOWS\system32\drivers\vwififlt.sys
12:08:18.0128 0x1830  vwififlt - ok
12:08:18.0144 0x1830  [ 3BE5AAC930447FD18D4A8255A2FEC95C, A517357188FE4A5BD98A3CDB2165ACCE96CCE4BE2B90DDBEAF70B6DDF393F506 ] vwifimp         C:\WINDOWS\System32\drivers\vwifimp.sys
12:08:18.0160 0x1830  vwifimp - ok
12:08:18.0207 0x1830  [ 48C1A256591297C43ECFC4E30D144EAA, 8E66833ED2CEB6D7E499EB2E4282B4F9DFA28B6D21757BB88EC52FD069D7FACE ] W32Time         C:\WINDOWS\system32\w32time.dll
12:08:18.0238 0x1830  W32Time - ok
12:08:18.0253 0x1830  [ 00C27B64C758C111E5D78A70DE6CA2B6, C99761B9B671B3A1FF1C52796CCA3F4F825BF50D9657D13B551E849CDD82055D ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
12:08:18.0253 0x1830  WacomPen - ok
12:08:18.0316 0x1830  [ D76D1AC4F2C642D09A68227D129A4726, D14D6C4D94E9660848C74B220359683D91A4A3D70750E781A20B6D86D46794CE ] WalletService   C:\WINDOWS\system32\WalletService.dll
12:08:18.0347 0x1830  WalletService - ok
12:08:18.0394 0x1830  [ 8CB53620B2C2F0641DD7563EA0FDF491, D62FE75C908409A54949F0E3C39558DC7A8F11AF7496ED7B0872D80D08CB67A7 ] wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:08:18.0425 0x1830  wanarp - ok
12:08:18.0425 0x1830  [ 8CB53620B2C2F0641DD7563EA0FDF491, D62FE75C908409A54949F0E3C39558DC7A8F11AF7496ED7B0872D80D08CB67A7 ] wanarpv6        C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:08:18.0441 0x1830  wanarpv6 - ok
12:08:18.0535 0x1830  [ 2598BBF11C9E7D0885DCA52E7FD5BCBD, 46B1FB080A2CD88C89A0EB8BA2594A1FA2C341ED77A6C6835CBFFE42907FAC55 ] wbengine        C:\WINDOWS\system32\wbengine.exe
12:08:18.0582 0x1830  wbengine - ok
12:08:18.0628 0x1830  [ 642EFABF900374FA85639D83B5533AFD, 292692D6AAC2A785D237ADFBC7CA3D379E8FC79FA366A8CE7D06F5CA5CE6866B ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
12:08:18.0675 0x1830  WbioSrvc - ok
12:08:18.0724 0x1830  [ E9A0D466F6D8EC349DB526146618BCB6, CFD6F3F979E4366A68FBEC3BE90A42BF3D65403A987E80741A720C0622871F32 ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
12:08:18.0767 0x1830  Wcmsvc - ok
12:08:18.0813 0x1830  [ 53A036CED1270F2459E708A05922FD49, 2F281A72E4B0408DE6C8153F5988C9AA38591FB1E72558767D389637D0666A85 ] wcncsvc         C:\WINDOWS\System32\wcncsvc.dll
12:08:18.0860 0x1830  wcncsvc - ok
12:08:18.0907 0x1830  [ 965B6197A659782B6A0F68411A180AAD, 5541AB78B71E4FA655BCBF2D80D574B2A3B4AA8871F65D26620BDE549FA5459A ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
12:08:18.0923 0x1830  WcsPlugInService - ok
12:08:18.0923 0x1830  [ 069D3D6E20AD753B34FCE856F0436869, CF8C12295DDAA56E7350019AADBA533D7857CFB3F20DEE14E557963645A9331B ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
12:08:18.0938 0x1830  WdBoot - ok
12:08:18.0970 0x1830  [ 6CC727E94CD84E9720FDCDA8089CABCC, BCF66056B06DED6BC2D329E910FCD3E685D627BAD3B5D7F4B0E970B45CD9CEF4 ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
12:08:18.0985 0x1830  Wdf01000 - ok
12:08:19.0032 0x1830  [ E3E97151A1D1E87BB2D5371F66C5F169, 0ED0B9852FE0533816F5EE2F06045B3964A00FD749A7011DB3C663AB6FA369E2 ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
12:08:19.0048 0x1830  WdFilter - ok
12:08:19.0048 0x1830  [ 75DC67553051103547B693898CB32D08, 4FCF2C3DBBE85461364B1F3A3F3629B52C8664487D30142D15937A4C96EF6A8F ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
12:08:19.0079 0x1830  WdiServiceHost - ok
12:08:19.0079 0x1830  [ 75DC67553051103547B693898CB32D08, 4FCF2C3DBBE85461364B1F3A3F3629B52C8664487D30142D15937A4C96EF6A8F ] WdiSystemHost   C:\WINDOWS\system32\wdi.dll
12:08:19.0095 0x1830  WdiSystemHost - ok
12:08:19.0142 0x1830  [ E70DDD8E2245CC67547B0861983912D8, 64C73B1496FFF1F6BB3D877CB5BE54DE35C303AE234B11FC90038DC4F73241D9 ] wdiwifi         C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
12:08:19.0173 0x1830  wdiwifi - ok
12:08:19.0204 0x1830  [ 07B043160399AF4009054E2EA3464BF4, 8D652D7CD75F8FB2B5414155355F0C970015914E1AC6522DBB8387BB8662F542 ] WdNisDrv        C:\WINDOWS\system32\Drivers\WdNisDrv.sys
12:08:19.0204 0x1830  WdNisDrv - ok
12:08:19.0267 0x1830  WdNisSvc - ok
12:08:19.0282 0x1830  [ 9972D395DBD05D91DA5EDADEB9325680, 9382D846793F285721A1A0FED42F914035A53D856B902FADB0B7144C471BDA91 ] WebClient       C:\WINDOWS\System32\webclnt.dll
12:08:19.0298 0x1830  WebClient - ok
12:08:19.0329 0x1830  [ B6BF579761489720BCE787F723F596E5, 879B17F6A4F23F5E85A09126B7B407955DDCEB1BA4A8FFC0A418B7F47311C056 ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
12:08:19.0360 0x1830  Wecsvc - ok
12:08:19.0360 0x1830  [ 10C9CF8771A2A87F575F9FB56821474E, 15E3DFFE9CF6777F67E426ECF797D2DF743EA152DEE336DCC9C2F92A0E6EB9A3 ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
12:08:19.0376 0x1830  WEPHOSTSVC - ok
12:08:19.0423 0x1830  [ 357C083FE35D030D991D163AAF622A06, F301852D49DBDEF0D28F56CD74CBDC71CA003EBD07D3F46EA5C870DC1BD07896 ] wercplsupport   C:\WINDOWS\System32\wercplsupport.dll
12:08:19.0438 0x1830  wercplsupport - ok
12:08:19.0454 0x1830  [ 2235AF716D15D9DFE4C59DC2AC0C440C, 2DCFCEBEA77E7E40CEF9A785BE1A794B390B36E40FBCF49B494F9CEA3F6A28C4 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
12:08:19.0470 0x1830  WerSvc - ok
12:08:19.0485 0x1830  [ C11272713719922DE5711094333BD166, 61D4F07E02AECF04964FF51EEA31069A2B0EAA549AD2B29B5FD3E1E6BB543593 ] WFPLWFS         C:\WINDOWS\system32\drivers\wfplwfs.sys
12:08:19.0501 0x1830  WFPLWFS - ok
12:08:19.0517 0x1830  [ 205A1FAE910F5C493D236245850BB62A, DBA4D1D734BAA3CDEB8A7F9C81A8DAA88CEA55AF5C4C5908E76FB8E522C5EC8A ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
12:08:19.0532 0x1830  WiaRpc - ok
12:08:19.0563 0x1830  [ EF536C54AB9281FDC4E83B07279FCFC4, 22E4F133170682EE14413CA8FDC2DBE73AB31960D6ACB728A6B398229FDDFD3B ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
12:08:19.0591 0x1830  WIMMount - ok
12:08:19.0594 0x1830  WinDefend - ok
12:08:19.0621 0x1830  [ D8966A76408107224C6013993135DD78, 6159F69BC26FF817078E68C70E6DFC9075FEBF9EF9F4F046C7A65BC377544AE6 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
12:08:19.0638 0x1830  WindowsTrustedRT - ok
12:08:19.0657 0x1830  [ 8B102A7B6CE326FD4208CC7C2D183343, E47C1D76CBFD2A382C3A7BB048D752FB6DD4616FADDEB1C3ADD5DDAE149742AF ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
12:08:19.0671 0x1830  WindowsTrustedRTProxy - ok
12:08:19.0707 0x1830  [ FFD04E8263FC9CDB89BAD8C27C337223, 7021161D354F1536DA261D001524B92301466631DCFA161A7C6355AAC86BBE40 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
12:08:19.0741 0x1830  WinHttpAutoProxySvc - ok
12:08:19.0765 0x1830  [ 4A53441C1C4D2878BEF27E381138BB2D, C221E74491E6FD2AF472B53876B46788D5CF62F4E645457F3B3816FD0ED2BAA1 ] WinMad          C:\WINDOWS\System32\drivers\winmad.sys
12:08:19.0775 0x1830  WinMad - ok
12:08:19.0898 0x1830  [ 1033C37122C7404C3B926ADF84874832, 163B3A7112F13AE7BB2655A28C6B19AF9B263F2AD2FF1B75314BE3E2B9118903 ] Winmgmt         C:\WINDOWS\system32\wbem\WMIsvc.dll
12:08:19.0929 0x1830  Winmgmt - ok
12:08:20.0023 0x1830  [ 703D0F62C5AA4D08EE8756516C0D125D, 02015A5E62490C11EC968160C528C2AFD1D7194AACA27F407B06EB462657511F ] WinRM           C:\WINDOWS\system32\WsmSvc.dll
12:08:20.0101 0x1830  WinRM - ok
12:08:20.0132 0x1830  [ 260907CE034FE327AC99BDA4153AB22F, B96501F43248713C2E153B9D22B78D51412A3C6989A2FB5F53A406C6CDC98D30 ] WINUSB          C:\WINDOWS\System32\drivers\WinUSB.SYS
12:08:20.0132 0x1830  WINUSB - ok
12:08:20.0163 0x1830  [ 40A3E8D729F458B2C9A8BD9380FF83D5, CD42FFC138969EF8C9588FD113F0B9A98FBA282D46A5B6BCFA765F55ED6E97A1 ] WinVerbs        C:\WINDOWS\System32\drivers\winverbs.sys
12:08:20.0195 0x1830  WinVerbs - ok
12:08:20.0257 0x1830  [ 453740989239803FE363FF8B40EA2E08, 25499705627C38D3431B3C336E0CF3BF55ABB0C461B88DA6D3767CAAE1E2B893 ] WlanSvc         C:\WINDOWS\System32\wlansvc.dll
12:08:20.0335 0x1830  WlanSvc - ok
12:08:20.0413 0x1830  [ E48BBF1363F843E030757EC190DD33E6, B37199495115ED423BA99B7317377CE865BB482D4E847861E871480AC49D4A84 ] wlidsvc         C:\WINDOWS\system32\wlidsvc.dll
12:08:20.0476 0x1830  wlidsvc - ok
12:08:20.0523 0x1830  [ 8F010BF65238F3F822D22BA12831796E, 2CA830F259B742D2F5CDD0437960BF512D40FB4A4C2342E3BABB38D468F79694 ] WmiAcpi         C:\WINDOWS\System32\drivers\wmiacpi.sys
12:08:20.0555 0x1830  WmiAcpi - ok
12:08:20.0594 0x1830  [ 74ACA5A7880C1F0BB9D60E32E1705A70, A89817BCCBFF94D7394614DA81D1C6C4F53AF47A539E674EEF6DC3FC496BF702 ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
12:08:20.0621 0x1830  wmiApSrv - ok
12:08:20.0634 0x1830  WMPNetworkSvc - ok
12:08:20.0654 0x1830  [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof             C:\WINDOWS\system32\drivers\Wof.sys
12:08:20.0667 0x1830  Wof - ok
12:08:20.0737 0x1830  [ 4090C6738AA92B428220857B4D44F638, 4A3EE47494051E5BA8393F2AC8226EF434DA3AA1895CF4BADC9BC1BC378647C6 ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
12:08:20.0799 0x1830  workfolderssvc - ok
12:08:20.0832 0x1830  [ 22C52D7EE7C7D0E02C8EFD8CAE8E3A71, 126605A12CEC9CC07DE3050F12E43CECABEAF0D00DF12300AF70F34700F7FE8E ] wpcfltr         C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
12:08:20.0843 0x1830  wpcfltr - ok
12:08:20.0859 0x1830  [ D282ECA35ADAC7A93D6B4943E775010B, A76A9698A95646FA63AC18DFFA02B744D7C6043934CBF6C37832ED2E6B21F570 ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
12:08:20.0874 0x1830  WPDBusEnum - ok
12:08:20.0890 0x1830  [ 1C08E424CBDD5065BB7266F8C048C1B1, 0452C85EDA6CBAB75C2617886C5D8117ED25D91F1BE0F8377B08D55B6629B028 ] WpdUpFltr       C:\WINDOWS\system32\drivers\WpdUpFltr.sys
12:08:20.0906 0x1830  WpdUpFltr - ok
12:08:20.0921 0x1830  [ 2C6EEFFBB7FB1C51CCD3737C77AB9109, 8C2ED309FAF4312512E7BCCBBC51B1353603A3499077A1DE21991F0692AF1620 ] WpnService      C:\WINDOWS\system32\WpnService.dll
12:08:20.0937 0x1830  WpnService - ok
12:08:20.0953 0x1830  [ 638B43D39A3D0B47024555CF1095E6F1, C7EA0A6ED227A5256EB02CA76FEC538DF196B8DC38DA2A567757D2B221C9473E ] ws2ifsl         C:\WINDOWS\system32\drivers\ws2ifsl.sys
12:08:20.0968 0x1830  ws2ifsl - ok
12:08:21.0015 0x1830  [ 9C17CF2D05F8DA5AC66880B6BEE64E7D, 8930079A1AFA97657BE567038EE57C988D3DE9A6C24EA46160E2974837082535 ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
12:08:21.0031 0x1830  wscsvc - ok
12:08:21.0031 0x1830  WSearch - ok
12:08:21.0140 0x1830  [ 6E04BBE242E2889B37300C4DF5CE1126, FBDAEAC62C48A4FC5EF412AE47FF10590AE83E8871412F76F6F9BAE910542DFA ] WSService       C:\WINDOWS\System32\WSService.dll
12:08:21.0234 0x1830  WSService - ok
12:08:21.0296 0x1830  [ 722FA682ED9EA8B85FA843A5C8F39E61, 47B09984582E55C22450A851FAF00EBEC76CD46149B19B199916255D553C6BF8 ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
12:08:21.0375 0x1830  wuauserv - ok
12:08:21.0421 0x1830  [ A928F25CB62232F413EE655352856E10, 1D2B278A24DDDE8792ADE7649FF90A98E186B79F13AA296C30E4180293BE906A ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
12:08:21.0437 0x1830  WudfPf - ok
12:08:21.0468 0x1830  [ A932391623D5CEC4EF4A2A17D3CEBFCD, 54AA17F385347DED262BDA84F2D99106DC5D9BF8765D647BD76265356193BDFA ] WUDFRd          C:\WINDOWS\system32\drivers\WudfRd.sys
12:08:21.0484 0x1830  WUDFRd - ok
12:08:21.0562 0x1830  [ 1336DA39FE006EAB2733CA4DE5B3560C, F0D6C71ADCB66D4D14EC6D09FD43F5521A3A8CA53F248DFD01696FB4F033BE77 ] wudfsvc         C:\WINDOWS\System32\WUDFSvc.dll
12:08:21.0578 0x1830  wudfsvc - ok
12:08:21.0656 0x1830  [ 417D1526811D9646A7E8779209F11361, 220FE28801474AB26579F2A37D792975D9AAD2384B420BCE52215B1389E08F91 ] WwanSvc         C:\WINDOWS\System32\wwansvc.dll
12:08:21.0703 0x1830  WwanSvc - ok
12:08:21.0750 0x1830  [ 405A419F4CDAC3C18F91FEDBD146C0A8, 92A6539AE6FC1B140366A0F733FDB784CAFB2359C4E0E2DF80629FEEA2CBFC98 ] XblAuthManager  C:\WINDOWS\System32\XblAuthManager.dll
12:08:21.0781 0x1830  XblAuthManager - ok
12:08:21.0875 0x1830  [ 7118498F6E48758A2EF5A7D1982E2B62, 1FF75AE64CB6DB263E8B35515E092B325AA71A6B2210F8F2B0AD087B3BA33345 ] XblGameSave     C:\WINDOWS\System32\XblGameSave.dll
12:08:21.0906 0x1830  XblGameSave - ok
12:08:21.0937 0x1830  [ F279536122B83FD0D8E158AA753E1B7C, 6A542F28E24B30DBDC2EEE24DA33C2F4ADB3596AEDDD71DC1495DD40577CE4BB ] xboxgip         C:\WINDOWS\System32\drivers\xboxgip.sys
12:08:21.0953 0x1830  xboxgip - ok
12:08:22.0000 0x1830  [ 69E727F94BEA64E66C284F3C482F33E6, B3E0F287E7A251E0FC17C41089C45737027E54F0213BDE847356AC882B4D3700 ] XboxNetApiSvc   C:\WINDOWS\system32\XboxNetApiSvc.dll
12:08:22.0047 0x1830  XboxNetApiSvc - ok
12:08:22.0070 0x1830  [ DBACD4E4FE191D0CE7C624ACA389535E, A706DA0A284398E80AEB6FBE1B5F6C3192C3F4D1C1B7533528D689D163374DDF ] xinputhid       C:\WINDOWS\System32\drivers\xinputhid.sys
12:08:22.0082 0x1830  xinputhid - ok
12:08:22.0083 0x1830  ================ Scan global ===============================
12:08:22.0118 0x1830  [ D923EC03E24F7633DED3F2D46AD59A28, C635DB4483E24BE0188583E63B06D0F37BDE7AD944E4D0246A7D19CBC3EA3A6B ] C:\WINDOWS\system32\basesrv.dll
12:08:22.0143 0x1830  [ E2899695BD30B5F93EC626EBBEF2CB69, B190D2903A109D2C146D881F90769060A0E971942F4AA61AEAD81861032D89C3 ] C:\WINDOWS\system32\winsrv.dll
12:08:22.0174 0x1830  [ 09E92888FFF86F3334E59778724DCA6F, 2344763B52395EF565A9DE5F55BEDCA026AD2E8072FFD06F826BF366B3BA2AB4 ] C:\WINDOWS\system32\sxssrv.dll
12:08:22.0215 0x1830  [ 6FF8248F3A9D69A095C7F3F42BC29CB2, 9077B1AA0AFB8DB329FDED0E51085DE1C51B22A986162F29037FCA404A80D512 ] C:\WINDOWS\system32\services.exe
12:08:22.0223 0x1830  [ Global ] - ok
12:08:22.0223 0x1830  ================ Scan MBR ==================================
12:08:22.0236 0x1830  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:08:22.0513 0x1830  \Device\Harddisk0\DR0 - ok
12:08:22.0528 0x1830  ================ Scan VBR ==================================
12:08:22.0528 0x1830  [ 42125037B6005A1EC6B8538B6EA7EBE5 ] \Device\Harddisk0\DR0\Partition1
12:08:22.0528 0x1830  \Device\Harddisk0\DR0\Partition1 - ok
12:08:22.0528 0x1830  [ CF84383B7833112A93E1F4F09734CA55 ] \Device\Harddisk0\DR0\Partition2
12:08:22.0528 0x1830  \Device\Harddisk0\DR0\Partition2 - ok
12:08:22.0528 0x1830  ================ Scan generic autorun ======================
12:08:22.0528 0x1830  SynTPEnh - ok
12:08:22.0638 0x1830  [ 6FDE88ED6A92F34EFAFA6C20E849D694, 9FA9ACD9B67F75E9E6FF6D682C1C957E6845756D059792814F4EA938DF03FDBA ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
12:08:22.0685 0x1830  NvBackend - ok
12:08:22.0981 0x1830  [ 7FCDC7D1591DCB3036ECE8DFC0342E50, 44C2D67425D35784F3A857FF4238A344FAA15EBBB56C58AF83D942353A698C60 ] c:\program files\emsisoft anti-malware\a2guard.exe
12:08:23.0122 0x1830  emsisoft anti-malware - ok
12:08:23.0205 0x1830  [ 279175F66914D5BE0D3A3DD9F85FD5B3, 24FC4EF12209BBACD523570E66182D9470A3499BB74FD50E890298281F422097 ] C:\Program Files (x86)\USB Camera\VM331STI.EXE
12:08:23.0229 0x1830  331BigDog - ok
12:08:23.0626 0x1830  [ 88F8A731DEA7F49D92F84A0A77C5CC67, 030458922DA43AAF6C95EC430860A73032616851E03E58170F71E918720717CB ] C:\Windows\SysWOW64\OneDriveSetup.exe
12:08:23.0774 0x1830  OneDriveSetup - ok
12:08:23.0918 0x1830  [ 88F8A731DEA7F49D92F84A0A77C5CC67, 030458922DA43AAF6C95EC430860A73032616851E03E58170F71E918720717CB ] C:\Windows\SysWOW64\OneDriveSetup.exe
12:08:24.0043 0x1830  OneDriveSetup - ok
12:08:24.0214 0x1830  [ 91DD4AD85BB341CC8CF5187EA06FD171, 68330A5EBDA7E4A51926EC2085D71C11BD2857A6EB1D4749DEE7A6D1D5679B98 ] C:\Users\Dragonfly\AppData\Local\Microsoft\OneDrive\OneDrive.exe
12:08:24.0214 0x1830  OneDrive - ok
12:08:24.0386 0x1830  [ 88F8A731DEA7F49D92F84A0A77C5CC67, 030458922DA43AAF6C95EC430860A73032616851E03E58170F71E918720717CB ] C:\Windows\SysWOW64\OneDriveSetup.exe
12:08:24.0523 0x1830  OneDriveSetup - ok
12:08:24.0523 0x1830  Waiting for KSN requests completion. In queue: 162
12:08:25.0540 0x1830  Waiting for KSN requests completion. In queue: 162
12:08:26.0541 0x1830  Waiting for KSN requests completion. In queue: 162
12:08:27.0562 0x1830  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.0 ), 0x60100 ( disabled : updated )
12:08:27.0562 0x1830  AV detected via SS2: Emsisoft Anti-Malware, C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2start.exe ( 12.2.0.7060 ), 0x41000 ( enabled : updated )
12:08:27.0578 0x1830  Win FW state via NFP2: enabled ( trusted )
12:08:29.0926 0x1830  ============================================================
12:08:29.0926 0x1830  Scan finished
12:08:29.0926 0x1830  ============================================================
12:08:29.0946 0x1db8  Detected object count: 0
12:08:29.0946 0x1db8  Actual detected object count: 0
         
und hier die mbar logfile

Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2017.01.24.02
  rootkit: v2016.11.20.01

Windows 10 x64 NTFS
Internet Explorer 11.162.10586.0
Dragonfly :: DRAGONFLY-PC [administrator]

24.01.2017 11:36:43
mbar-log-2017-01-24 (11-36-43).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 315303
Time elapsed: 17 minute(s), 32 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         

Alt 24.01.2017, 16:12   #14
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 24.01.2017, 16:12   #15
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - Standard

rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......



Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

__________________
Logfiles bitte immer in CODE-Tags posten

Thema geschlossen

Themen zu rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......
100%, anleitung, antivirenprogramm, anwendungen, arbeitet, ausgelastet, festplatte, frst scan habe ich angehängt., funktionieren, komplett, kostenlose, laptop, lüfter, lösung, mal-ware, maus, nicht mehr, nichts, platte, programme, rootkit, system, update, verfügbar, viren befall ???, virus, virus?, win, win 10 update




Ähnliche Themen: rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,......


  1. Win 10: BlueScreen Ereignis 41, Kernel-Power
    Alles rund um Windows - 14.02.2017 (38)
  2. FRST Logfile, eventuell Virus...
    Plagegeister aller Art und deren Bekämpfung - 04.09.2016 (1)
  3. Festplatte zu 100% ausgelastet, Datenübertragungsrate aber bei 0 MB/s
    Netzwerk und Hardware - 21.04.2016 (11)
  4. ich habe einen Virus eingefangen der aus FRST.txt ein FRST.txt!___prosschiff@gmail.com_ macht
    Log-Analyse und Auswertung - 27.09.2015 (3)
  5. Festplatte manchmal 10 minutenlang auf 100% ausgelastet
    Netzwerk und Hardware - 03.02.2015 (19)
  6. Ereignis div. Fehlermeldungen
    Plagegeister aller Art und deren Bekämpfung - 11.07.2014 (1)
  7. Interpol Virus - FRST.exe
    Plagegeister aller Art und deren Bekämpfung - 25.03.2014 (21)
  8. FRST Scan bei Bka Virus
    Plagegeister aller Art und deren Bekämpfung - 09.12.2013 (14)
  9. GMER, FRST, ADWCleaner Auswertung. Festplatte defekt. Neustart
    Log-Analyse und Auswertung - 19.11.2013 (7)
  10. Weißer Bildschirm nach Neustart, scan via FRST.exe --> FRST.txt
    Log-Analyse und Auswertung - 06.08.2013 (5)
  11. rootkit virus auf externen Festplatte? o.O
    Plagegeister aller Art und deren Bekämpfung - 20.03.2012 (1)
  12. HILFE bitte ich drehe durch !!!!!!! .... Virus Rootkit Win32.TDSS.d
    Plagegeister aller Art und deren Bekämpfung - 12.05.2010 (10)
  13. Dringende Hilfe!!!Virus trotzt Festplatte Formatieung nicht gelöscht!
    Mülltonne - 08.10.2008 (0)
  14. seltsames Ereignis bei MSN Hotmail
    Plagegeister aller Art und deren Bekämpfung - 07.11.2007 (3)
  15. MSN Virus eingefangen!!! Zugriff auf Festplatte versagt! BITTE HILFE!!!
    Plagegeister aller Art und deren Bekämpfung - 31.07.2007 (12)
  16. Hilfe PC ist andaurnd ausgelastet
    Log-Analyse und Auswertung - 03.11.2004 (15)
  17. Suche hilfe, hab XP und nur 1000 MB im Monat
    Alles rund um Windows - 20.09.2004 (2)

Zum Thema rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... - hi, hab das gefühl, dass mal wieder irgendwas mit meinem laptop nicht stimmt. heißt meine maus bewegt sich teilweise nicht wie sie soll, vor allem wenn ich zocke, meine festplatte - rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,.........
Archiv
Du betrachtest: rootkit? virus? festplatte zu 100% ausgelastet. hilfe mit frst. ereignis id: 1014, 7031, 10010, 5973, 69, 1000, 10016, 7006,...... auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.