Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 30.03.2016, 13:16   #1
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Ich habe heute eine Mail von GiroPay24 bekommen, welche sich für mich erst im nachhinein als Spam/Phishing Mail rausstellte.

Nun habe ich aber schon den Anhang in Form einer .zip Datei geladen und mit Winrar geöffnet gehabt.
Die Datei die sich dort drinnen befand, habe ich nicht angerührt (weder entpackt noch Ausgeführt), und habe die zip Datei auch sofort wieder gelöscht.

Nun bin ich mir aber unsicher ob ich nicht trotzdem einen Trojaner/Virus auf meinem Notebook habe und wollte hier einmal fragen ob Sie mir da helfen können dies her raus zu finden.

Den FRST Scan habe ich schon gemacht:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
durchgeführt von Zajii (Administrator) auf ZAJI (30-03-2016 14:07:41)
Gestartet von C:\Users\Zajii\Desktop
Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\EslWire\service\WireHelperSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\Zajii\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LU.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.XboxApp_15.15.22005.0_x64__8wekyb3d8bbwe\XboxApp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Steam\Steam.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Steam\bin\steamwebhelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor)
HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] ()
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated)
HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH)
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.)
HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] ()
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-28] (Valve Corporation)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30]
ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1
ManualProxies: 

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation)
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab

FireFox:
========
FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] ()
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc)
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare)
FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26]
FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25]
FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden

Chrome: 
=======
CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25]
CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09]
CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20]
CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14]
CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23]
CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-12]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] ()
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd)
R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo)
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo)
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated)
S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd)
R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>)
S3 gkernel; C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [31512 2016-01-14] ()
S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm))
R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation)
S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek                                            )
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated)
S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS)
S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] ()
S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] ()
S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] ()
S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.)
R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation)
S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-03-30 14:07 - 2016-03-30 14:08 - 00031900 _____ C:\Users\Zajii\Desktop\FRST.txt
2016-03-30 14:07 - 2016-03-30 14:07 - 00000000 ____D C:\FRST
2016-03-30 13:58 - 2016-03-30 13:58 - 00002879 _____ C:\Users\Zajii\Desktop\mbam2.txt
2016-03-30 13:58 - 2016-03-30 13:58 - 00002878 _____ C:\Users\Zajii\Desktop\mbam.txt
2016-03-30 13:52 - 2016-03-30 13:52 - 01610352 _____ (Malwarebytes) C:\Users\Zajii\Desktop\JRT.exe
2016-03-30 13:21 - 2016-03-30 13:21 - 00000000 ____D C:\AdwCleaner
2016-03-30 13:20 - 2016-03-30 14:07 - 02374144 _____ (Farbar) C:\Users\Zajii\Desktop\FRST64.exe
2016-03-30 13:20 - 2016-03-30 13:21 - 03102208 _____ C:\Users\Zajii\Desktop\AdwCleaner_5.107.exe
2016-03-30 13:06 - 2016-03-30 13:08 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-30 13:05 - 2016-03-30 13:59 - 00001180 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2016-03-30 13:05 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-03-30 13:05 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-03-30 13:05 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-03-30 12:59 - 2016-03-30 13:05 - 22851472 _____ (Malwarebytes ) C:\Users\Zajii\Desktop\mbam-setup-2.2.1.1043.exe
2016-03-30 12:34 - 2016-03-30 12:34 - 00000000 ____D C:\Program Files\Common Files\AV
2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions
2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions
2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc
2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer
2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer
2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer
2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple
2016-03-20 13:55 - 2016-03-26 00:28 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben
2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive
2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4
2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4
2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4
2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4
2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4
2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4
2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4
2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4
2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4
2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4
2016-03-18 03:28 - 2016-03-18 03:28 - 00003040 _____ C:\WINDOWS\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062
2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe
2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5
2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload
2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games
2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2016-03-07 23:56 - 2016-03-08 00:03 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers
2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-06 22:50 - 2016-03-06 22:50 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062_2016.03.06.20.52.54
2016-03-05 13:47 - 2016-03-30 13:03 - 00000000 ____D C:\Program Files\Defraggler
2016-03-05 01:50 - 2016-03-30 13:59 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk
2016-03-05 01:50 - 2016-03-30 13:58 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk
2016-03-05 01:49 - 2016-03-05 01:50 - 00000000 ____D C:\ProgramData\BlueStacksGameManager
2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\ProgramData\BlueStacks
2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2016-03-05 01:46 - 2016-03-05 01:46 - 00000000 ____D C:\Users\Zajii\AppData\Local\Bluestacks
2016-03-02 11:52 - 2016-02-23 12:32 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-02 11:52 - 2016-02-23 11:38 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 13:25 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-03-02 11:51 - 2016-02-23 12:34 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 12:32 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-02 11:51 - 2016-02-23 12:32 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-03-02 11:51 - 2016-02-23 12:31 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-03-02 11:51 - 2016-02-23 12:31 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-02 11:51 - 2016-02-23 12:21 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-02 11:51 - 2016-02-23 11:45 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-03-02 11:51 - 2016-02-23 11:38 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2016-03-02 11:51 - 2016-02-23 11:38 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-03-02 11:51 - 2016-02-23 11:27 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-02 11:51 - 2016-02-23 10:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-03-02 11:51 - 2016-02-23 10:29 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-02 11:51 - 2016-02-23 10:28 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-02 11:51 - 2016-02-23 10:09 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-03-02 11:51 - 2016-02-23 10:00 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-03-02 11:51 - 2016-02-23 09:30 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-03-02 11:51 - 2016-02-23 09:24 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-03-02 11:51 - 2016-02-23 09:22 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-03-02 11:51 - 2016-02-23 09:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-02 11:51 - 2016-02-23 08:59 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-03-02 11:51 - 2016-02-23 08:55 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-03-02 11:51 - 2016-02-23 08:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-03-02 11:51 - 2016-02-23 08:50 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-03-02 11:51 - 2016-02-23 08:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-02 11:51 - 2016-02-23 08:39 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-02 11:51 - 2016-02-23 08:36 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-02 11:51 - 2016-02-23 08:30 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-03-02 11:51 - 2016-02-09 05:04 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-03-02 11:50 - 2016-02-23 13:29 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-03-02 11:50 - 2016-02-23 13:29 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-02 11:50 - 2016-02-23 13:27 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-02 11:50 - 2016-02-23 13:27 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-02 11:50 - 2016-02-23 13:25 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-03-02 11:50 - 2016-02-23 13:25 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-03-02 11:50 - 2016-02-23 13:15 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2016-03-02 11:50 - 2016-02-23 13:08 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-03-02 11:50 - 2016-02-23 12:34 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-03-02 11:50 - 2016-02-23 12:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-02 11:50 - 2016-02-23 12:32 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-03-02 11:50 - 2016-02-23 12:32 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 12:32 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-02 11:50 - 2016-02-23 12:31 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 12:31 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-02 11:50 - 2016-02-23 12:31 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-03-02 11:50 - 2016-02-23 12:25 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-02 11:50 - 2016-02-23 12:22 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2016-03-02 11:50 - 2016-02-23 12:17 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2016-03-02 11:50 - 2016-02-23 11:40 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-03-02 11:50 - 2016-02-23 11:39 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2016-03-02 11:50 - 2016-02-23 11:37 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2016-03-02 11:50 - 2016-02-23 11:32 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-03-02 11:50 - 2016-02-23 11:30 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-02 11:50 - 2016-02-23 11:27 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-02 11:50 - 2016-02-23 11:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
2016-03-02 11:50 - 2016-02-23 11:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-03-02 11:50 - 2016-02-23 11:19 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-03-02 11:50 - 2016-02-23 11:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-03-02 11:50 - 2016-02-23 11:06 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
2016-03-02 11:50 - 2016-02-23 10:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-03-02 11:50 - 2016-02-23 10:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2016-03-02 11:50 - 2016-02-23 10:50 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-03-02 11:50 - 2016-02-23 10:40 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-03-02 11:50 - 2016-02-23 10:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-02 11:50 - 2016-02-23 10:38 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2016-03-02 11:50 - 2016-02-23 10:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-03-02 11:50 - 2016-02-23 10:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-03-02 11:50 - 2016-02-23 10:37 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-02 11:50 - 2016-02-23 10:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-02 11:50 - 2016-02-23 10:34 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-02 11:50 - 2016-02-23 10:34 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-02 11:50 - 2016-02-23 10:27 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-03-02 11:50 - 2016-02-23 10:26 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2016-03-02 11:50 - 2016-02-23 10:22 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-02 11:50 - 2016-02-23 10:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2016-03-02 11:50 - 2016-02-23 10:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-03-02 11:50 - 2016-02-23 10:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 10:19 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-03-02 11:50 - 2016-02-23 10:19 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2016-03-02 11:50 - 2016-02-23 10:18 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-02 11:50 - 2016-02-23 10:14 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-02 11:50 - 2016-02-23 10:12 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-02 11:50 - 2016-02-23 10:11 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-03-02 11:50 - 2016-02-23 10:10 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2016-03-02 11:50 - 2016-02-23 10:10 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-02 11:50 - 2016-02-23 10:09 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-03-02 11:50 - 2016-02-23 10:09 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-03-02 11:50 - 2016-02-23 10:06 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-03-02 11:50 - 2016-02-23 10:05 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-03-02 11:50 - 2016-02-23 10:04 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-02 11:50 - 2016-02-23 10:04 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-03-02 11:50 - 2016-02-23 10:04 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-03-02 11:50 - 2016-02-23 10:02 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-02 11:50 - 2016-02-23 10:02 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-03-02 11:50 - 2016-02-23 09:58 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-02 11:50 - 2016-02-23 09:52 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-03-02 11:50 - 2016-02-23 09:50 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2016-03-02 11:50 - 2016-02-23 09:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2016-03-02 11:50 - 2016-02-23 09:47 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2016-03-02 11:50 - 2016-02-23 09:38 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-03-02 11:50 - 2016-02-23 09:37 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-03-02 11:50 - 2016-02-23 09:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-03-02 11:50 - 2016-02-23 09:36 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2016-03-02 11:50 - 2016-02-23 09:36 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 09:35 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2016-03-02 11:50 - 2016-02-23 09:31 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-03-02 11:50 - 2016-02-23 09:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-02 11:50 - 2016-02-23 09:29 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-02 11:50 - 2016-02-23 09:28 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-03-02 11:50 - 2016-02-23 09:24 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-02 11:50 - 2016-02-23 09:24 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-03-02 11:50 - 2016-02-23 09:24 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-03-02 11:50 - 2016-02-23 09:21 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-03-02 11:50 - 2016-02-23 09:14 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-02 11:50 - 2016-02-23 09:11 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-02 11:50 - 2016-02-23 09:05 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-03-02 11:50 - 2016-02-23 09:01 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-03-02 11:50 - 2016-02-23 08:58 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-03-02 11:50 - 2016-02-23 08:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-03-02 11:50 - 2016-02-23 08:55 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-03-02 11:50 - 2016-02-23 08:53 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-02 11:50 - 2016-02-23 08:51 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-03-02 11:50 - 2016-02-23 08:42 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-03-02 11:50 - 2016-02-23 08:41 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-03-02 11:50 - 2016-02-23 08:36 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-03-02 11:50 - 2016-02-23 08:35 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-03-02 11:50 - 2016-02-23 08:33 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-03-02 11:50 - 2016-02-23 08:32 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-03-02 11:50 - 2016-02-23 08:28 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-03-02 11:50 - 2016-02-09 06:28 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-03-02 11:50 - 2016-02-09 06:13 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-03-02 11:50 - 2016-02-09 05:24 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-03-02 11:50 - 2016-02-09 05:18 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2016-03-02 11:50 - 2016-02-09 05:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2016-03-02 11:50 - 2016-02-09 05:07 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-03-02 11:50 - 2016-02-09 05:07 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-02 11:49 - 2016-02-23 12:33 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-03-02 11:49 - 2016-02-23 11:25 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2016-03-02 11:49 - 2016-02-23 11:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-02 11:49 - 2016-02-23 10:53 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-03-02 11:49 - 2016-02-23 10:52 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-02 11:49 - 2016-02-23 10:39 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2016-03-02 11:49 - 2016-02-23 10:31 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-03-02 11:49 - 2016-02-23 09:58 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-03-02 11:49 - 2016-02-23 09:49 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-03-02 11:49 - 2016-02-23 09:28 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-03-02 11:48 - 2016-02-23 11:12 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2016-03-02 11:48 - 2016-02-23 11:10 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-02 11:48 - 2016-02-23 11:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-02 11:48 - 2016-02-23 11:07 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-03-02 11:48 - 2016-02-23 11:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-02 11:48 - 2016-02-23 11:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-03-02 11:48 - 2016-02-23 10:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-03-02 11:48 - 2016-02-23 10:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-03-02 11:48 - 2016-02-23 10:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
2016-03-02 11:48 - 2016-02-23 10:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2016-03-02 11:48 - 2016-02-23 10:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-03-02 11:48 - 2016-02-23 10:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-02 11:48 - 2016-02-23 10:33 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2016-03-02 11:48 - 2016-02-23 10:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-03-02 11:48 - 2016-02-23 10:23 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-03-02 11:48 - 2016-02-23 10:20 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 11:48 - 2016-02-23 10:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-03-02 11:48 - 2016-02-23 10:06 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-03-02 11:48 - 2016-02-23 10:06 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-03-02 11:48 - 2016-02-23 10:02 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-03-02 11:48 - 2016-02-23 09:58 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-02 11:48 - 2016-02-23 09:58 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-02 11:48 - 2016-02-23 09:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
2016-03-02 11:48 - 2016-02-23 09:36 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 11:48 - 2016-02-23 09:21 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-02 11:48 - 2016-02-23 09:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-03-30 14:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk
2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk
2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk
2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk
2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk
2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk
2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk
2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk
2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk
2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk
2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk
2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk
2016-03-30 13:58 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk
2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk
2016-03-30 13:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games
2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs
2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-30 13:07 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini
2016-03-30 13:07 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-03-30 13:07 - 2015-05-08 23:28 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media
2016-03-30 12:24 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-30 12:20 - 2014-12-12 23:08 - 00000000 ____D C:\Steam
2016-03-30 11:22 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0
2016-03-30 11:09 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-30 11:06 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat
2016-03-30 11:06 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat
2016-03-30 11:06 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-03-30 11:06 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-30 11:04 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-03-30 11:01 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-03-30 11:01 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-30 11:01 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager
2016-03-30 11:00 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-03-30 11:00 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles
2016-03-30 10:59 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-03-30 10:58 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-30 07:28 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-03-30 05:20 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc
2016-03-30 05:03 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype
2016-03-30 01:28 - 2015-12-16 22:25 - 00345848 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2016-03-30 01:27 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client
2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java
2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage
2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java
2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie
2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml
2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml
2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta
2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple
2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii
2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net
2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like
2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net
2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt
2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS
2016-03-12 19:25 - 2016-02-26 22:51 - 00011914 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods
2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood
2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt
2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames
2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games
2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-07 19:41 - 2015-11-14 16:27 - 00000000 ____D C:\Users\Zajii\AppData\Local\Skype
2016-03-07 19:41 - 2015-11-14 16:26 - 00000000 ____D C:\ProgramData\Skype
2016-03-05 05:22 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-03-05 01:49 - 2015-10-30 09:24 - 00000000 __RHD C:\Users\Public\Libraries
2016-03-05 01:44 - 2015-02-13 12:27 - 00000000 ____D C:\Users\Zajii\.VirtualBox
2016-03-03 13:44 - 2014-12-13 02:46 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-03 05:00 - 2015-10-30 20:44 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 __RSD C:\WINDOWS\Media
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-03-02 02:38 - 2015-02-19 19:12 - 00000000 ____D C:\Users\Zajii\AppData\Local\Steam
2016-03-01 01:44 - 2016-02-22 13:40 - 00000000 ____D C:\Users\Zajii\Desktop\Musik
2016-02-29 00:05 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log
2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg
2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip
2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Einige Dateien in TEMP:
====================
C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll
C:\Users\Zajii\AppData\Local\Temp\7230fefd864f35e6569012bef46d88ae.dll
C:\Users\Zajii\AppData\Local\Temp\7b71d939ac8f4f430ba02b964dfb5794.dll
C:\Users\Zajii\AppData\Local\Temp\EslWireSetup-1.19.0.8185-x64.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u71-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\LSCSetup64.exe
C:\Users\Zajii\AppData\Local\Temp\proxy_vole4465310535655270772.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole4974038499892493031.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole732673072298846164.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole8651342122685071258.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole9215304146252064412.dll
C:\Users\Zajii\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-03-28 13:58

==================== Ende von FRST.txt ============================
         

Alt 30.03.2016, 13:17   #2
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Additional.txt

Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
durchgeführt von Zajii (2016-03-30 14:09:11)
Gestartet von C:\Users\Zajii\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled)
Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled)
Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji
Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC)
7 Days to Die (HKLM-x32\...\Steam App 251570) (Version:  - The Fun Pimps)
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.)
Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version:  - Ensemble Studios)
Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation)
Anno 2070 (HKLM-x32\...\Steam App 48240) (Version:  - BlueByte)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
Arms Dealer (HKLM-x32\...\Steam App 325630) (Version:  - Case in Point Studios, LLC)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version:  - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version:  - DICE)
Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC)
Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden
Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation)
BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version:  - )
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com)
Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version:  - Eidos Montreal)
Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version:  - Splash Damage®)
DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - )
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Down To One (HKLM-x32\...\Steam App 334040) (Version:  - Gadget Games)
Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version:  - )
Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version:  - Eyedentity Games)
Endless Space (HKLM-x32\...\Steam App 208140) (Version:  - AMPLITUDE Studios)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo)
Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden
Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version:  - momoStorm Entertainment)
ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version:  - Turtle Entertainment GmbH)
Europa Universalis IV (HKLM\...\Steam App 236850) (Version:  - Paradox Development Studio)
Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version:  - )
Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups)
Garena - Android Emulator (HKLM-x32\...\nox) (Version:  - Garena Online Pte Ltd.)
Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.)
Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q)
Garena+ (HKLM-x32\...\im) (Version: 2011 - Garena Online Pte Ltd.)
Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grim Dawn (HKLM-x32\...\Steam App 219990) (Version:  - Crate Entertainment)
Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version:  - Trek Industries, Inc)
GUILD WARS (HKLM-x32\...\Guild Wars) (Version:  - )
H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version:  - Daybreak Game Company)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version:  - IO Interactive)
Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.)
Insurgency (HKLM\...\Steam App 222880) (Version:  - New World Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kenshi (HKLM-x32\...\Steam App 233860) (Version:  - Lo-Fi Games)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
KuaiZip (HKLM-x32\...\KuaiZip) (Version:  - )
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.)
Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab)
Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo)
Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version:  - Arkavi Studios)
Magic Duels (HKLM-x32\...\Steam App 316010) (Version:  - Stainless Games Ltd.)
Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - )
Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo)
Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden
MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG)
MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version:  - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version:  - BlueByte)
Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version:  - TaleWorlds Entertainment)
Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version:  - TRUE Software)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version:  - NCSOFT)
Nightbanes (HKLM-x32\...\Steam App 338340) (Version:  - Diviad)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team)
NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version:  - Haemimont Games)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software)
Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version:  - Ndemic Creations)
Planet Explorers (HKLM-x32\...\Steam App 237870) (Version:  - Pathea Games)
Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version:  - Uber Entertainment)
Portal Knights (HKLM\...\Steam App 374040) (Version:  - Keen Games)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version:  - Millenway Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.)
Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version:  - EasyGameStation)
Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version:  - Ascaron)
SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden
Saints Row IV (HKLM-x32\...\Steam App 206420) (Version:  - Deep Silver Volition)
Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version:  - Winged Cloud)
Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH)
Sengoku (HKLM-x32\...\Steam App 73210) (Version:  - Paradox Development Studio)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version:  - Ironclad Games)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version:  - United Front Games)
Spellweaver (HKLM-x32\...\Steam App 429680) (Version:  - Dream Reactor)
Star Realms (HKLM\...\Steam App 438140) (Version:  - White Wizard Games)
Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version:  - Little Green Men Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Survivalist (HKLM-x32\...\Steam App 340050) (Version:  - Bob the Game Development Bot)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version:  - Berserk Games)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Tempest (HKLM-x32\...\Steam App 418180) (Version:  - Lion's Shade)
The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version:  - KTX Software)
The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version:  - Virtual Basement LLC)
Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH)
Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - BigNox Corporation XQHDrv System  (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll ()

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe
Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated)
Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software)
Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo)
Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)
Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\"
Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\"
Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires"
Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software)
Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {F8887BAF-4E6A-45F7-B7D9-2140E874EBFB} - System32\Tasks\avast! Windows 10 Start Menu helper => c:\program files\avast software\avast\asww10mon.exe [2016-03-18] (AVAST Software)
Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)
Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe
2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll
2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll
2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-03-29 11:43 - 2016-03-29 11:47 - 00016896 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-03-29 11:43 - 2016-03-29 11:47 - 17535488 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2016-03-04 12:15 - 2016-03-04 12:15 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2016-03-24 09:17 - 2016-03-24 09:19 - 00016384 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.15.22005.0_x64__8wekyb3d8bbwe\XboxApp.exe
2016-03-24 09:17 - 2016-03-24 09:19 - 35425280 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.15.22005.0_x64__8wekyb3d8bbwe\XboxApp.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-03-29 19:12 - 2016-03-29 19:12 - 02846208 _____ () C:\Program Files\AVAST Software\Avast\defs\16032901\algo.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-12-23 10:25 - 2016-03-30 11:01 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll
2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2014-01-07 15:03 - 2014-01-07 15:03 - 02440512 _____ () C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterFilter.ax
2014-12-12 23:20 - 2016-03-11 02:56 - 00783360 _____ () C:\Steam\SDL2.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 04962816 _____ () C:\Steam\v8.dll
2014-12-12 23:20 - 2016-03-28 23:34 - 02549840 _____ () C:\Steam\video.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00332800 _____ () C:\Steam\libavresample-2.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00491008 _____ () C:\Steam\libavformat-56.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 02549760 _____ () C:\Steam\libavcodec-56.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00442880 _____ () C:\Steam\libavutil-54.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00485888 _____ () C:\Steam\libswscale-3.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 01556992 _____ () C:\Steam\icui18n.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 01187840 _____ () C:\Steam\icuuc.dll
2014-12-12 23:20 - 2016-03-28 23:34 - 00829008 _____ () C:\Steam\bin\chromehtml.DLL
2016-03-09 12:09 - 2016-02-18 00:25 - 00281088 _____ () C:\Steam\openvr_api.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll
2015-12-05 12:29 - 2016-02-09 03:33 - 48400672 _____ () C:\Steam\bin\libcef.dll
2015-12-05 12:29 - 2015-09-25 01:56 - 00119208 _____ () C:\Steam\winh264.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com

Da befinden sich 7866 mehr Seiten.


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk"
HKLM\...\StartupApproved\Run: => "PhoneCompanion"
HKLM\...\StartupApproved\Run: => "LogMeIn GUI"
HKLM\...\StartupApproved\Run: => "Connectify Hotspot"
HKLM\...\StartupApproved\Run: => "Start WingMan Profiler"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "Raptr"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [{381CD377-1188-4C89-A1C9-D083F12FE010}] => (Allow) C:\Users\Zajii\AppData\Roaming\Tencent\穿越火线\4D3FC433DB9BBD3BB0CC9DEB630740EA\TenioDL\TenioDL.exe
FirewallRules: [{7E92482E-8282-49EC-8643-A8AE86E0612E}] => (Allow) C:\Users\Zajii\AppData\Roaming\Tencent\穿越火线\4D3FC433DB9BBD3BB0CC9DEB630740EA\TenioDL\TenioDL.exe
FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [{61F44546-AF90-4052-BDC8-8C2BA3998852}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\PCMng\PCMLoader\QQPCDetector.exe
FirewallRules: [{67430F27-84E3-4BCB-B13E-9FE5DB5F0422}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\PCMng\PCMLoader\QQPCDetector.exe
FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe
FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe
FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe
FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [{38E9D37A-19CD-4C3D-9DA3-0DD35DBD4610}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{B23BAC6E-B86A-4175-AEA4-62C0A239B4DF}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Wiederherstellungspunkte =========================

23-03-2016 17:25:55 Installed Windows 7 USB/DVD Download Tool
30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (03/30/2016 11:23:32 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (03/29/2016 09:00:08 PM) (Source: MsiInstaller) (EventID: 11722) (User: ZAJI)
Description: Produkt: Java 8 Update 77 (64-bit) -- Fehler 1722. Es liegt ein Problem mit diesem Windows Installer-Paket vor. Ein Programm, das im Rahmen der Installation ausgeführt wurde, wurde nicht erfolgreich abgeschlossen. Wenden Sie sich an den Support oder den Hersteller des Pakets. Aktion: installexe, Pfad: C:\Program Files\Java\jre1.8.0_77\installer.exe, Befehl: /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_77\\" REPAIRMODE=0 ProductCode={26A24AE4-039D-4CA4-87B4-2F86418077F0}

Error: (03/29/2016 08:59:55 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm jre-8u77-windows-au.exe, Version 8.0.770.3 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: c1c

Startzeit: 01d189ecd9e77df6

Beendigungszeit: 4294967295

Anwendungspfad: C:\Users\Zajii\AppData\Local\Temp\jds35309750.tmp\jre-8u77-windows-au.exe

Berichts-ID: 6c29d6ce-f5e0-11e5-8326-54ee7517f830

Vollständiger Name des fehlerhaften Pakets: 

Auf das fehlerhafte Paket bezogene Anwendungs-ID:

Error: (03/29/2016 08:06:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: igd10iumd64.dll, Version: 10.18.15.4279, Zeitstempel: 0x55db7ece
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000151c3a
ID des fehlerhaften Prozesses: 0x2d90
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (03/29/2016 04:20:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 44.0.2.5884, Zeitstempel: 0x56bbf417
Name des fehlerhaften Moduls: mozglue.dll, Version: 44.0.2.5884, Zeitstempel: 0x56bbe58e
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000ed3b
ID des fehlerhaften Prozesses: 0x2890
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5

Error: (03/29/2016 04:20:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 44.0.2.5884 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1e44

Startzeit: 01d189bb993dce2a

Beendigungszeit: 149

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: 6c791c20-f5b9-11e5-8326-54ee7517f830

Vollständiger Name des fehlerhaften Pakets: 

Auf das fehlerhafte Paket bezogene Anwendungs-ID:

Error: (03/29/2016 03:54:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZAJI)
Description: Bei der Aktivierung der App „Microsoft.XboxApp_8wekyb3d8bbwe!Microsoft.XboxApp“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (03/28/2016 08:59:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   12 1.0.0.127.in-addr.arpa. PTR Zaji.local.

Error: (03/28/2016 08:59:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 127.0.0.1:5353   14 1.0.0.127.in-addr.arpa. PTR Zaji-2.local.

Error: (03/28/2016 08:58:07 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1171


Systemfehler:
=============
Error: (03/30/2016 12:51:23 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 12:51:15 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 12:51:15 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 12:51:15 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 12:21:05 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 12:21:05 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 12:21:04 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 12:21:04 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (03/30/2016 11:24:56 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar

Error: (03/30/2016 11:04:09 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Übermittlungsoptimierung" wurde nicht richtig gestartet.


CodeIntegrity:
===================================
  Date: 2016-03-24 02:26:58.699
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-23 04:00:10.692
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-22 14:17:50.313
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 18:18:45.659
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 14:34:08.548
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-10 10:17:26.727
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-03 12:41:33.511
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-02 15:35:16.954
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 17:56:24.126
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 07:03:27.892
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 33%
Installierter physikalischer RAM: 12196.01 MB
Verfügbarer physikalischer RAM: 8127.68 MB
Summe virtueller Speicher: 12964.01 MB
Verfügbarer virtueller Speicher: 8339.14 MB

==================== Laufwerke ================================

Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:402.4 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3)

Partition: GPT.

==================== Ende von Addition.txt ============================
         
__________________


Alt 01.04.2016, 13:55   #3
burningice
/// Malwareteam
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall




Mein Name ist Rafael und ich werde dir bei der Bereinigung helfen.

Damit ich dir optimal helfen kann, halte dich bitte an folgende Regeln:
  • Bitte lies meine Posts komplett durch bevor du sie abarbeitest
  • Wenn ein Problem auftauchen sollte oder dir etwas unklar ist, unterbreche deine Arbeit und beschreibe es so genau wie möglich.
  • Bitte kein Crossposting
  • Installiere oder Deinstalliere keine Software ohne Aufforderung
  • Bitte verwende nur die Tools, welche hier im Thread erwähnt werden und führe sie nur gemäß Anweisung aus
  • Bitte antworte innerhalb von 24h um eine sinnvolle Bereinigung zu ermöglichen
  • Poste die Logs immer in CODE-Tags (#-Button), zur Not die Logs einfach aufteilen
  • Wichtig: Nur weil dein Problem mit einem Schritt plötzlich behoben ist, bedeutet das nicht, dass dein PC auch sauber ist. Mache solange weiter, bis ich dir sage, dass dein PC "clean" ist
  • Wenn ich dir nicht binnen 36h antworte, sende mir bitte eine persönliche Nachricht!
Los geht's

Also normal kann dabei nichts passieren. Machen wir einfach mal einen allgemeinen Scan, um ganz sicher zu gehen dass dein PC passt.

Schritt 1
Lade dir folgendes Programm herunter und installiere es: Malwarebytes Anti-Malware Hier findest du dazu eine bebilderte Anleitung
  • Klicke auf die Einstellungen / Erkennung und Schutz und setze dabei den Haken bei "Nach Rootkits suchen"
  • Klicke im Anschluss auf Durchsuchen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Suchlaufprotokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Schritt 2
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).


Schritt 3
Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen.

Bitte poste in deiner nächsten Antwort also:
  • Logfile von AdwCleaner
  • Logfile von Malwarebytes
  • Frst.txt
  • Addition.txt
__________________
__________________

Alt 01.04.2016, 18:52   #4
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Guten Tag,

die mbam.txt haben wir hier:

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 30.03.2016
Suchlaufzeit: 13:09
Protokolldatei: 123.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2016.03.30.02
Rootkit-Datenbank: v2016.03.12.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Zajii

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 495639
Abgelaufene Zeit: 48 Min., 23 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 5
PUP.Optional.APNToolBar.Gen, HKLM\SOFTWARE\WOW6432NODE\AskPartnerNetwork, , [ebff64297722e94d65ead2620ef5669a], 
PUP.Optional.HomeTab, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\HomeTab, , [df0b5637acedec4a76b51c04c53f6f91], 
PUP.Optional.SearchProtect.AppFlsh, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\SearchProtectWS, , [af3bb3da6930e452eb9abac91aea9868], 
PUP.Optional.Wajam, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\WajIEnhance, , [8961c5c8811824120e9b162dbd47ce32], 
PUP.Optional.Wajam, HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\SOFTWARE\WajIntEnhance, , [d1192a63089182b46c3e4102c73d27d9], 

Registrierungswerte: 1
PUP.Optional.FFToolbar, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fftoolbar2014@etech.com, C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\066h65fl.default\extensions\fftoolbar2014@etech.com, , [76740984fd9c63d3ffeac753cc3827d9]

Registrierungsdaten: 2
PUP.Optional.MyStartSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}),,[d713e2ab207957df326159cb3acbd927]
PUP.Optional.MyStartSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423754718&from=smt&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX21A93N0074N0074&q={searchTerms}),,[9d4d3b52d9c069cd286bed37ae5758a8]

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
AdwCleaner Log:

Code:
ATTFilter
# AdwCleaner v5.108 - Bericht erstellt am 01/04/2016 um 19:31:25
# Aktualisiert am 30/03/2016 von Xplode
# Datenbank : 2016-03-30.1 [Server]
# Betriebssystem : Windows 10 Home  (x64)
# Benutzername : Zajii - ZAJI
# Gestartet von : C:\Users\Zajii\Downloads\adwcleaner_5.108.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum

***** [ Dienste ] *****


***** [ Ordner ] *****

[-] Ordner gelöscht : C:\Program Files (x86)\tencent
[-] Ordner gelöscht : C:\ProgramData\tencent
[-] Ordner gelöscht : C:\Users\Zajii\AppData\Roaming\tencent
[-] Ordner gelöscht : C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\tencent

***** [ Dateien ] *****

[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d2ixp54vc4byye.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d2ixp54vc4byye.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d1733r3id7jrw5.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d1733r3id7jrw5.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_dabfg7woo1qnr.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_dabfg7woo1qnr.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_film.qq.com_0.localstorage
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_film.qq.com_0.localstorage-journal
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_v.qq.com_0.localstorage
[-] Datei gelöscht : C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_v.qq.com_0.localstorage-journal

***** [ DLLs ] *****


***** [ Verknüpfungen ] *****


***** [ Aufgabenplanung ] *****


***** [ Registrierungsdatenbank ] *****

[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\AndyAPK
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\metnsd
[-] Schlüssel gelöscht : HKCU\Software\Conduit
[-] Schlüssel gelöscht : HKCU\Software\Kromtech
[-] Schlüssel gelöscht : HKCU\Software\simplytech
[-] Schlüssel gelöscht : HKLM\SOFTWARE\AIM Toolbar
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Conduit
[-] Schlüssel gelöscht : HKLM\SOFTWARE\SearchProtect
[-] Schlüssel gelöscht : HKLM\SOFTWARE\SpeedBit
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IM
[-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{381CD377-1188-4C89-A1C9-D083F12FE010}]
[-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{7E92482E-8282-49EC-8643-A8AE86E0612E}]
[-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{61F44546-AF90-4052-BDC8-8C2BA3998852}]
[-] Wert gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{67430F27-84E3-4BCB-B13E-9FE5DB5F0422}]
[-] Schlüssel gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\image.tgp.qq.com
[-] Schlüssel gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\qq.com
[-] Schlüssel gelöscht : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d2ixp54vc4byye.cloudfront.net
[-] Schlüssel gelöscht : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d2ixp54vc4byye.cloudfront.net

***** [ Internetbrowser ] *****


*************************

:: "Tracing" schlüssel löschen
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [4707 Bytes] - [01/04/2016 19:31:25]
C:\AdwCleaner\AdwCleaner[S1].txt - [4743 Bytes] - [01/04/2016 19:26:07]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4853 Bytes] ##########
         
Hier der FRST Log:

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
durchgeführt von Zajii (Administrator) auf ZAJI (01-04-2016 19:41:38)
Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS
Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\EslWire\service\WireHelperSvc.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Users\Zajii\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\Zajii\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.168_none_76587b40265ca57e\TiWorker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor)
HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] ()
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated)
HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH)
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.)
HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] ()
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30]
ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1
ManualProxies: 

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation)
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab

FireFox:
========
FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] ()
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc)
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare)
FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26]
FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25]
FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden

Chrome: 
=======
CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25]
CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09]
CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20]
CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14]
CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23]
CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-12]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] ()
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd)
R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo)
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo)
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated)
S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd)
R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>)
S3 gkernel; C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [31512 2016-01-14] ()
S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm))
R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation)
S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek                                            )
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated)
S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS)
S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] ()
S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] ()
S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] ()
S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.)
R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation)
S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-01 19:24 - 2016-04-01 19:24 - 03102720 _____ C:\Users\Zajii\Downloads\adwcleaner_5.108.exe
2016-04-01 14:48 - 2016-04-01 14:48 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Abrakam
2016-03-31 10:53 - 2016-03-31 12:54 - 00018188 _____ C:\Users\Zajii\Downloads\Wilhelma.odt
2016-03-31 10:53 - 2016-03-31 12:54 - 00018057 _____ C:\Users\Zajii\Downloads\Zoo Leipzig.odt
2016-03-31 10:52 - 2016-03-31 12:53 - 00018002 _____ C:\Users\Zajii\Downloads\Wildpark.odt
2016-03-31 10:52 - 2016-03-31 12:53 - 00017959 _____ C:\Users\Zajii\Downloads\Allwetterzoo.odt
2016-03-30 14:17 - 2016-04-01 19:40 - 00000000 ____D C:\Users\Zajii\Desktop\ANTI VIRUS
2016-03-30 14:07 - 2016-04-01 19:41 - 00000000 ____D C:\FRST
2016-03-30 13:52 - 2016-03-30 13:52 - 01610352 _____ (Malwarebytes) C:\Users\Zajii\Desktop\JRT.exe
2016-03-30 13:21 - 2016-04-01 19:31 - 00000000 ____D C:\AdwCleaner
2016-03-30 13:06 - 2016-04-01 19:16 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-30 13:05 - 2016-03-30 13:59 - 00001180 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2016-03-30 13:05 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-03-30 13:05 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-03-30 13:05 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-03-30 12:34 - 2016-03-30 12:34 - 00000000 ____D C:\Program Files\Common Files\AV
2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions
2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions
2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc
2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer
2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer
2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer
2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple
2016-03-20 13:55 - 2016-04-01 12:23 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben
2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive
2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4
2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4
2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4
2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4
2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4
2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4
2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4
2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4
2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4
2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4
2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062
2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe
2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5
2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload
2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games
2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2016-03-07 23:56 - 2016-03-08 00:03 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers
2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-06 22:50 - 2016-03-06 22:50 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062_2016.03.06.20.52.54
2016-03-05 01:50 - 2016-03-30 13:59 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk
2016-03-05 01:50 - 2016-03-30 13:58 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk
2016-03-05 01:49 - 2016-03-05 01:50 - 00000000 ____D C:\ProgramData\BlueStacksGameManager
2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\ProgramData\BlueStacks
2016-03-05 01:49 - 2016-03-05 01:49 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2016-03-05 01:46 - 2016-03-05 01:46 - 00000000 ____D C:\Users\Zajii\AppData\Local\Bluestacks
2016-03-02 11:52 - 2016-02-23 12:32 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-02 11:52 - 2016-02-23 11:38 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 13:25 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-03-02 11:51 - 2016-02-23 12:34 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 12:32 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-02 11:51 - 2016-02-23 12:32 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-03-02 11:51 - 2016-02-23 12:31 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-03-02 11:51 - 2016-02-23 12:31 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-02 11:51 - 2016-02-23 12:21 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-02 11:51 - 2016-02-23 11:45 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-03-02 11:51 - 2016-02-23 11:38 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2016-03-02 11:51 - 2016-02-23 11:38 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-03-02 11:51 - 2016-02-23 11:27 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-02 11:51 - 2016-02-23 10:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-03-02 11:51 - 2016-02-23 10:29 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-02 11:51 - 2016-02-23 10:28 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-02 11:51 - 2016-02-23 10:09 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-03-02 11:51 - 2016-02-23 10:00 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-03-02 11:51 - 2016-02-23 09:30 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-03-02 11:51 - 2016-02-23 09:24 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-03-02 11:51 - 2016-02-23 09:22 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-03-02 11:51 - 2016-02-23 09:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-02 11:51 - 2016-02-23 08:59 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-03-02 11:51 - 2016-02-23 08:55 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-03-02 11:51 - 2016-02-23 08:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-03-02 11:51 - 2016-02-23 08:50 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-03-02 11:51 - 2016-02-23 08:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-02 11:51 - 2016-02-23 08:39 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-02 11:51 - 2016-02-23 08:36 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-02 11:51 - 2016-02-23 08:30 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-03-02 11:51 - 2016-02-09 05:04 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-03-02 11:50 - 2016-02-23 13:29 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-03-02 11:50 - 2016-02-23 13:29 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-02 11:50 - 2016-02-23 13:27 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-02 11:50 - 2016-02-23 13:27 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-02 11:50 - 2016-02-23 13:25 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-03-02 11:50 - 2016-02-23 13:25 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-03-02 11:50 - 2016-02-23 13:15 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2016-03-02 11:50 - 2016-02-23 13:08 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-03-02 11:50 - 2016-02-23 12:34 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-03-02 11:50 - 2016-02-23 12:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-02 11:50 - 2016-02-23 12:32 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-03-02 11:50 - 2016-02-23 12:32 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 12:32 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-02 11:50 - 2016-02-23 12:31 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 12:31 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-02 11:50 - 2016-02-23 12:31 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-03-02 11:50 - 2016-02-23 12:25 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-02 11:50 - 2016-02-23 12:22 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2016-03-02 11:50 - 2016-02-23 12:17 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2016-03-02 11:50 - 2016-02-23 11:40 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-03-02 11:50 - 2016-02-23 11:39 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2016-03-02 11:50 - 2016-02-23 11:38 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2016-03-02 11:50 - 2016-02-23 11:37 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2016-03-02 11:50 - 2016-02-23 11:32 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-03-02 11:50 - 2016-02-23 11:30 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-02 11:50 - 2016-02-23 11:27 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-02 11:50 - 2016-02-23 11:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
2016-03-02 11:50 - 2016-02-23 11:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-03-02 11:50 - 2016-02-23 11:19 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-03-02 11:50 - 2016-02-23 11:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-03-02 11:50 - 2016-02-23 11:06 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
2016-03-02 11:50 - 2016-02-23 10:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-03-02 11:50 - 2016-02-23 10:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2016-03-02 11:50 - 2016-02-23 10:50 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-03-02 11:50 - 2016-02-23 10:40 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-03-02 11:50 - 2016-02-23 10:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-02 11:50 - 2016-02-23 10:38 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2016-03-02 11:50 - 2016-02-23 10:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-03-02 11:50 - 2016-02-23 10:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-03-02 11:50 - 2016-02-23 10:37 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-02 11:50 - 2016-02-23 10:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-02 11:50 - 2016-02-23 10:34 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-02 11:50 - 2016-02-23 10:34 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-02 11:50 - 2016-02-23 10:27 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-03-02 11:50 - 2016-02-23 10:26 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2016-03-02 11:50 - 2016-02-23 10:22 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-02 11:50 - 2016-02-23 10:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2016-03-02 11:50 - 2016-02-23 10:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-03-02 11:50 - 2016-02-23 10:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 10:19 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-03-02 11:50 - 2016-02-23 10:19 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2016-03-02 11:50 - 2016-02-23 10:18 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-02 11:50 - 2016-02-23 10:14 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-02 11:50 - 2016-02-23 10:12 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-02 11:50 - 2016-02-23 10:11 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-03-02 11:50 - 2016-02-23 10:10 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2016-03-02 11:50 - 2016-02-23 10:10 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-02 11:50 - 2016-02-23 10:09 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-03-02 11:50 - 2016-02-23 10:09 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-03-02 11:50 - 2016-02-23 10:06 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-03-02 11:50 - 2016-02-23 10:05 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-03-02 11:50 - 2016-02-23 10:04 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-02 11:50 - 2016-02-23 10:04 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-03-02 11:50 - 2016-02-23 10:04 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-03-02 11:50 - 2016-02-23 10:02 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-02 11:50 - 2016-02-23 10:02 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-03-02 11:50 - 2016-02-23 09:58 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-02 11:50 - 2016-02-23 09:52 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-03-02 11:50 - 2016-02-23 09:50 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2016-03-02 11:50 - 2016-02-23 09:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2016-03-02 11:50 - 2016-02-23 09:47 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2016-03-02 11:50 - 2016-02-23 09:38 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-03-02 11:50 - 2016-02-23 09:37 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-03-02 11:50 - 2016-02-23 09:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-03-02 11:50 - 2016-02-23 09:36 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2016-03-02 11:50 - 2016-02-23 09:36 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2016-03-02 11:50 - 2016-02-23 09:35 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2016-03-02 11:50 - 2016-02-23 09:31 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-03-02 11:50 - 2016-02-23 09:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-02 11:50 - 2016-02-23 09:29 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-02 11:50 - 2016-02-23 09:28 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-03-02 11:50 - 2016-02-23 09:24 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-02 11:50 - 2016-02-23 09:24 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-03-02 11:50 - 2016-02-23 09:24 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-03-02 11:50 - 2016-02-23 09:21 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-03-02 11:50 - 2016-02-23 09:14 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-02 11:50 - 2016-02-23 09:11 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-02 11:50 - 2016-02-23 09:05 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-03-02 11:50 - 2016-02-23 09:01 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-03-02 11:50 - 2016-02-23 08:58 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-03-02 11:50 - 2016-02-23 08:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-03-02 11:50 - 2016-02-23 08:55 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-03-02 11:50 - 2016-02-23 08:53 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-02 11:50 - 2016-02-23 08:51 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-03-02 11:50 - 2016-02-23 08:42 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-03-02 11:50 - 2016-02-23 08:41 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-03-02 11:50 - 2016-02-23 08:36 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-03-02 11:50 - 2016-02-23 08:35 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-03-02 11:50 - 2016-02-23 08:33 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-03-02 11:50 - 2016-02-23 08:32 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-03-02 11:50 - 2016-02-23 08:28 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-03-02 11:50 - 2016-02-09 06:28 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-03-02 11:50 - 2016-02-09 06:13 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-03-02 11:50 - 2016-02-09 05:24 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-03-02 11:50 - 2016-02-09 05:18 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2016-03-02 11:50 - 2016-02-09 05:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2016-03-02 11:50 - 2016-02-09 05:07 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-03-02 11:50 - 2016-02-09 05:07 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-02 11:49 - 2016-02-23 12:33 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-03-02 11:49 - 2016-02-23 11:25 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2016-03-02 11:49 - 2016-02-23 11:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-02 11:49 - 2016-02-23 10:53 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-03-02 11:49 - 2016-02-23 10:52 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-02 11:49 - 2016-02-23 10:39 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2016-03-02 11:49 - 2016-02-23 10:31 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-03-02 11:49 - 2016-02-23 09:58 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-03-02 11:49 - 2016-02-23 09:49 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-03-02 11:49 - 2016-02-23 09:28 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-03-02 11:48 - 2016-02-23 11:12 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2016-03-02 11:48 - 2016-02-23 11:10 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-02 11:48 - 2016-02-23 11:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-02 11:48 - 2016-02-23 11:07 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-03-02 11:48 - 2016-02-23 11:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-02 11:48 - 2016-02-23 11:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-03-02 11:48 - 2016-02-23 10:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-03-02 11:48 - 2016-02-23 10:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-03-02 11:48 - 2016-02-23 10:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
2016-03-02 11:48 - 2016-02-23 10:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2016-03-02 11:48 - 2016-02-23 10:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-03-02 11:48 - 2016-02-23 10:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-02 11:48 - 2016-02-23 10:33 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2016-03-02 11:48 - 2016-02-23 10:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-03-02 11:48 - 2016-02-23 10:23 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-03-02 11:48 - 2016-02-23 10:20 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 11:48 - 2016-02-23 10:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-03-02 11:48 - 2016-02-23 10:06 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-03-02 11:48 - 2016-02-23 10:06 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-03-02 11:48 - 2016-02-23 10:02 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-03-02 11:48 - 2016-02-23 09:58 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-02 11:48 - 2016-02-23 09:58 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-02 11:48 - 2016-02-23 09:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
2016-03-02 11:48 - 2016-02-23 09:36 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 11:48 - 2016-02-23 09:21 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-02 11:48 - 2016-02-23 09:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-01 19:41 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-01 19:41 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-01 19:41 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-01 19:41 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-01 19:38 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-01 19:36 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-01 19:36 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles
2016-04-01 19:36 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-04-01 19:35 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-01 19:34 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-04-01 19:23 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client
2016-04-01 19:14 - 2014-12-12 23:08 - 00000000 ____D C:\Steam
2016-04-01 19:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-01 18:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-01 13:38 - 2016-02-26 22:51 - 00011993 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods
2016-04-01 12:22 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-01 07:42 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-01 07:35 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-04-01 07:32 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager
2016-04-01 02:47 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype
2016-04-01 00:13 - 2015-12-16 22:25 - 00345848 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2016-03-31 13:00 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-31 13:00 - 2015-01-25 22:54 - 00000000 __RDO C:\Users\Zajii\OneDrive
2016-03-31 10:44 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-03-31 10:42 - 2015-05-08 23:28 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk
2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk
2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk
2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk
2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk
2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk
2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk
2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk
2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk
2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk
2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk
2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk
2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk
2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk
2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games
2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs
2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-30 13:07 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini
2016-03-30 13:07 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media
2016-03-30 11:22 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0
2016-03-30 05:20 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc
2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java
2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage
2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java
2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie
2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml
2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml
2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta
2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple
2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii
2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net
2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like
2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net
2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt
2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS
2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood
2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt
2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames
2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games
2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-07 19:41 - 2015-11-14 16:27 - 00000000 ____D C:\Users\Zajii\AppData\Local\Skype
2016-03-07 19:41 - 2015-11-14 16:26 - 00000000 ____D C:\ProgramData\Skype
2016-03-05 05:22 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-03-05 01:49 - 2015-10-30 09:24 - 00000000 __RHD C:\Users\Public\Libraries
2016-03-05 01:44 - 2015-02-13 12:27 - 00000000 ____D C:\Users\Zajii\.VirtualBox
2016-03-03 13:44 - 2014-12-13 02:46 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-03 05:00 - 2015-10-30 20:44 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 __RSD C:\WINDOWS\Media
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-03-03 05:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-03-03 05:00 - 2015-10-30 08:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-03-02 02:38 - 2015-02-19 19:12 - 00000000 ____D C:\Users\Zajii\AppData\Local\Steam

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log
2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg
2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip
2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Einige Dateien in TEMP:
====================
C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll
C:\Users\Zajii\AppData\Local\Temp\7230fefd864f35e6569012bef46d88ae.dll
C:\Users\Zajii\AppData\Local\Temp\7b71d939ac8f4f430ba02b964dfb5794.dll
C:\Users\Zajii\AppData\Local\Temp\EslWireSetup-1.19.0.8185-x64.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u71-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\libeay32.dll
C:\Users\Zajii\AppData\Local\Temp\LSCSetup64.exe
C:\Users\Zajii\AppData\Local\Temp\msvcr120.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole4465310535655270772.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole4974038499892493031.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole732673072298846164.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole8651342122685071258.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole9215304146252064412.dll
C:\Users\Zajii\AppData\Local\Temp\sqlite3.dll
C:\Users\Zajii\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-03-28 13:58

==================== Ende von FRST.txt ============================
         

Geändert von Zaji (01.04.2016 um 18:43 Uhr)

Alt 01.04.2016, 18:56   #5
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Icon26

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



FRST Addition Log:

Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
durchgeführt von Zajii (2016-04-01 19:45:09)
Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS
Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled)
Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled)
Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji
Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC)
7 Days to Die (HKLM-x32\...\Steam App 251570) (Version:  - The Fun Pimps)
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.)
Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version:  - Ensemble Studios)
Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation)
Anno 2070 (HKLM-x32\...\Steam App 48240) (Version:  - BlueByte)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
Arms Dealer (HKLM-x32\...\Steam App 325630) (Version:  - Case in Point Studios, LLC)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version:  - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version:  - DICE)
Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC)
Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden
Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation)
BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version:  - )
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com)
Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version:  - Eidos Montreal)
Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version:  - Splash Damage®)
DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - )
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Down To One (HKLM-x32\...\Steam App 334040) (Version:  - Gadget Games)
Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version:  - )
Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version:  - Eyedentity Games)
Endless Space (HKLM-x32\...\Steam App 208140) (Version:  - AMPLITUDE Studios)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo)
Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden
Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version:  - momoStorm Entertainment)
ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version:  - Turtle Entertainment GmbH)
Europa Universalis IV (HKLM\...\Steam App 236850) (Version:  - Paradox Development Studio)
Faeria (HKLM\...\Steam App 397060) (Version:  - Abrakam SA)
Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version:  - )
Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups)
Garena - Android Emulator (HKLM-x32\...\nox) (Version:  - Garena Online Pte Ltd.)
Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.)
Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q)
Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grim Dawn (HKLM-x32\...\Steam App 219990) (Version:  - Crate Entertainment)
Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version:  - Trek Industries, Inc)
GUILD WARS (HKLM-x32\...\Guild Wars) (Version:  - )
H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version:  - Daybreak Game Company)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version:  - IO Interactive)
Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.)
Insurgency (HKLM\...\Steam App 222880) (Version:  - New World Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kenshi (HKLM-x32\...\Steam App 233860) (Version:  - Lo-Fi Games)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
KuaiZip (HKLM-x32\...\KuaiZip) (Version:  - )
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.)
Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab)
Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo)
Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version:  - Arkavi Studios)
Magic Duels (HKLM-x32\...\Steam App 316010) (Version:  - Stainless Games Ltd.)
Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - )
Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo)
Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden
MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG)
MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version:  - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version:  - BlueByte)
Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version:  - TaleWorlds Entertainment)
Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version:  - TRUE Software)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version:  - NCSOFT)
Nightbanes (HKLM-x32\...\Steam App 338340) (Version:  - Diviad)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team)
NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version:  - Haemimont Games)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software)
Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version:  - Ndemic Creations)
Planet Explorers (HKLM-x32\...\Steam App 237870) (Version:  - Pathea Games)
Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version:  - Uber Entertainment)
Portal Knights (HKLM\...\Steam App 374040) (Version:  - Keen Games)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version:  - Millenway Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.)
Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version:  - EasyGameStation)
Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version:  - Ascaron)
SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden
Saints Row IV (HKLM-x32\...\Steam App 206420) (Version:  - Deep Silver Volition)
Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version:  - Winged Cloud)
Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH)
Sengoku (HKLM-x32\...\Steam App 73210) (Version:  - Paradox Development Studio)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version:  - Ironclad Games)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version:  - United Front Games)
Spellweaver (HKLM-x32\...\Steam App 429680) (Version:  - Dream Reactor)
Star Realms (HKLM\...\Steam App 438140) (Version:  - White Wizard Games)
Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version:  - Little Green Men Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Survivalist (HKLM-x32\...\Steam App 340050) (Version:  - Bob the Game Development Bot)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version:  - Berserk Games)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Tempest (HKLM-x32\...\Steam App 418180) (Version:  - Lion's Shade)
The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version:  - KTX Software)
The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version:  - Virtual Basement LLC)
Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH)
Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - BigNox Corporation XQHDrv System  (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll ()

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe
Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated)
Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software)
Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo)
Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)
Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\"
Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\"
Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires"
Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software)
Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)
Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe
2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll
2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-12-23 21:59 - 2015-12-07 06:59 - 03081568 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll
2015-12-23 21:59 - 2015-12-07 06:57 - 02394976 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-03-31 22:48 - 2016-03-31 22:48 - 02846208 _____ () C:\Program Files\AVAST Software\Avast\defs\16033102\algo.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-12-23 10:25 - 2016-04-01 19:37 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll
2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll
2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-09-25 23:48 - 2015-09-25 23:48 - 00043656 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32api.pyd
2015-09-25 23:47 - 2015-09-25 23:47 - 00061576 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pywintypes27.dll
2015-09-25 23:47 - 2015-09-25 23:47 - 00127624 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pythoncom27.dll
2015-09-25 23:48 - 2015-09-25 23:48 - 00024200 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_multiprocessing.pyd

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com

Da befinden sich 7866 mehr Seiten.


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk"
HKLM\...\StartupApproved\Run: => "PhoneCompanion"
HKLM\...\StartupApproved\Run: => "LogMeIn GUI"
HKLM\...\StartupApproved\Run: => "Connectify Hotspot"
HKLM\...\StartupApproved\Run: => "Start WingMan Profiler"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "Raptr"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe
FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe
FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe
FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [{38E9D37A-19CD-4C3D-9DA3-0DD35DBD4610}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{B23BAC6E-B86A-4175-AEA4-62C0A239B4DF}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{124EAD6D-953A-40D4-B784-7094D523B660}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe
FirewallRules: [{0213AE30-CEA2-43FB-A4CE-E09573D2B084}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe

==================== Wiederherstellungspunkte =========================

30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/01/2016 01:34:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1063

Error: (04/01/2016 01:34:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1063

Error: (04/01/2016 01:34:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/01/2016 01:34:45 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]

Error: (04/01/2016 12:30:31 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]

Error: (04/01/2016 09:05:58 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (03/31/2016 01:48:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203
Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb
Ausnahmecode: 0xc0000094
Fehleroffset: 0x00016a0c
ID des fehlerhaften Prozesses: 0xc78
Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0
Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1
Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2
Berichtskennung: RazerIngameEngine.exe3
Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5

Error: (03/31/2016 07:59:03 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]

Error: (03/30/2016 02:49:44 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (03/30/2016 11:23:32 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.


Systemfehler:
=============
Error: (04/01/2016 07:39:24 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}

Error: (04/01/2016 07:36:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MBAMScheduler" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (04/01/2016 07:36:13 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MBAMScheduler erreicht.

Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Razer Game Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Razer Game Scanner Service erreicht.

Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MBAMService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (04/01/2016 07:36:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MBAMService erreicht.

Error: (04/01/2016 07:36:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "BstHdUpdaterSvc" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (04/01/2016 07:36:10 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst BstHdUpdaterSvc erreicht.

Error: (04/01/2016 07:34:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_4e6d0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.


CodeIntegrity:
===================================
  Date: 2016-03-24 02:26:58.699
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-23 04:00:10.692
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-22 14:17:50.313
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 18:18:45.659
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 14:34:08.548
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-10 10:17:26.727
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-03 12:41:33.511
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-02 15:35:16.954
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 17:56:24.126
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 07:03:27.892
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 25%
Installierter physikalischer RAM: 12196.01 MB
Verfügbarer physikalischer RAM: 9033.21 MB
Summe virtueller Speicher: 24484.01 MB
Verfügbarer virtueller Speicher: 20997.27 MB

==================== Laufwerke ================================

Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:394.86 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3)

Partition: GPT.

==================== Ende von Addition.txt ============================
         

Ich will mich schon jetzt dafür bedanken dass Sie sich Zeit für mich genommen haben.


Alt 02.04.2016, 19:48   #6
burningice
/// Malwareteam
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Leider hast du die Anleitung nicht genau befolgt:

Starte bitte wieder Malwarebytes Anti-Malware
  • Klicke auf die Einstellungen / Erkennung und Schutz und setze dabei den Haken bei "Nach Rootkits suchen"
  • Klicke im Anschluss auf Dashboard und klicke unter dem Punkt Datenbankversion auf "Jetzt aktualisieren"
  • Wechsle zum Reiter Scannen und wähle den Bedrohungssuchlauf aus und klicke im Anschluss auf Suchlauf starten
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Suchlaufprotokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.
__________________
--> GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall

Alt 03.04.2016, 01:32   #7
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



So hier mein neuer scan:

mbam

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 03.04.2016
Suchlaufzeit: 01:20
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2016.04.02.06
Rootkit-Datenbank: v2016.03.30.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Zajii

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 487225
Abgelaufene Zeit: 1 Std., 9 Min., 45 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 1
HackTool.Agent, C:\Users\Zajii\Desktop\Folder\alle möglichen dateien\1\wl.2.2.2.zip, In Quarantäne, [41cdc5e5e2b745f18ab139038a77857b], 

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         

Alt 04.04.2016, 01:50   #8
burningice
/// Malwareteam
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Schritt: 1

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Hinweis: Dieser Scan kann schon einmal mehrere Stunden dauern...

Schritt: 2
Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen.


Hast du noch irgendwelche Probleme mit deinem Rechner?
__________________
Mfg,
Rafael

~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~

Unterstütze uns mit einer Spende
......... Lob, Kritik oder Wünsche .........
.......... Folge uns auf Facebook ..........

Alt 05.04.2016, 09:51   #9
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



ESET-Log:

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=3aaf1d9009c61e488a7e0333c22ae738
# end=init
# utc_time=2016-04-04 06:33:28
# local_time=2016-04-04 08:33:28 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT 
Update Init
Update Download
Update Finalize
Updated modules version: 28905
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=3aaf1d9009c61e488a7e0333c22ae738
# end=updated
# utc_time=2016-04-04 06:35:17
# local_time=2016-04-04 08:35:17 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT 
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=3aaf1d9009c61e488a7e0333c22ae738
# engine=28905
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-04-05 01:28:43
# local_time=2016-04-05 03:28:43 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT 
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=788 16777213 100 98 204887 20361712 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 2642231 13633866 0 0
# scanned=623155
# found=0
# cleaned=0
# scan_time=24806
         
FRST

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
durchgeführt von Zajii (Administrator) auf ZAJI (05-04-2016 10:42:53)
Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS
Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
() C:\Program Files\EslWire\service\WireHelperSvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Users\Zajii\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Steam\Steam.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
(Valve Corporation) C:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\Zajii\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe
(Valve Corporation) C:\Steam\bin\steamwebhelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avBugReport.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor)
HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] ()
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated)
HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH)
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.)
HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] ()
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30]
ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1
ManualProxies: 

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation)
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab

FireFox:
========
FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] ()
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc)
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare)
FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26]
FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25]
FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden

Chrome: 
=======
CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25]
CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09]
CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20]
CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14]
CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23]
CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-12]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] ()
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd)
R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo)
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated)
S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd)
R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>)
S3 gkernel; C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [31512 2016-01-14] ()
S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm))
R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation)
S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek                                            )
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated)
S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS)
S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] ()
S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] ()
S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] ()
S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.)
R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation)
S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-04 20:33 - 2016-04-04 20:33 - 02870984 _____ (ESET) C:\Users\Zajii\Downloads\esetsmartinstaller_deu.exe
2016-04-04 20:33 - 2016-04-04 20:33 - 00000000 ____D C:\Program Files (x86)\ESET
2016-04-03 02:31 - 2016-04-03 02:31 - 00001291 _____ C:\Users\Zajii\Desktop\mbam.txt
2016-04-01 19:24 - 2016-04-01 19:24 - 03102720 _____ C:\Users\Zajii\Downloads\adwcleaner_5.108.exe
2016-04-01 14:48 - 2016-04-01 14:48 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Abrakam
2016-03-31 10:53 - 2016-03-31 12:54 - 00018188 _____ C:\Users\Zajii\Downloads\Wilhelma.odt
2016-03-31 10:53 - 2016-03-31 12:54 - 00018057 _____ C:\Users\Zajii\Downloads\Zoo Leipzig.odt
2016-03-31 10:52 - 2016-03-31 12:53 - 00018002 _____ C:\Users\Zajii\Downloads\Wildpark.odt
2016-03-31 10:52 - 2016-03-31 12:53 - 00017959 _____ C:\Users\Zajii\Downloads\Allwetterzoo.odt
2016-03-30 14:17 - 2016-04-01 19:46 - 00000000 ____D C:\Users\Zajii\Desktop\ANTI VIRUS
2016-03-30 14:07 - 2016-04-05 10:42 - 00000000 ____D C:\FRST
2016-03-30 13:21 - 2016-04-01 19:31 - 00000000 ____D C:\AdwCleaner
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-30 12:34 - 2016-03-30 12:34 - 00000000 ____D C:\Program Files\Common Files\AV
2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions
2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions
2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc
2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer
2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer
2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer
2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple
2016-03-20 13:55 - 2016-04-01 12:23 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben
2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive
2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4
2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4
2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4
2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4
2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4
2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4
2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4
2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4
2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4
2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4
2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062
2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe
2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5
2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload
2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games
2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2016-03-07 23:56 - 2016-03-08 00:03 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers
2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-07 19:41 - 2016-03-07 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-06 22:50 - 2016-03-06 22:50 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062_2016.03.06.20.52.54

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-05 10:41 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-04-05 10:40 - 2014-12-12 23:08 - 00000000 ____D C:\Steam
2016-04-05 10:38 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-05 10:38 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager
2016-04-05 10:37 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-05 10:37 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles
2016-04-05 10:36 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-05 10:36 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-04-05 04:40 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-04-05 04:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-05 03:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-05 02:01 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client
2016-04-04 14:45 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc
2016-04-04 02:37 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype
2016-04-04 01:52 - 2015-12-16 22:25 - 00307448 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2016-04-03 12:13 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini
2016-04-03 12:13 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-04-02 12:45 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-02 12:45 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-02 12:45 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-02 12:45 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-02 12:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-02 11:58 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-04-01 13:38 - 2016-02-26 22:51 - 00011993 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods
2016-04-01 07:42 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-31 13:00 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-31 13:00 - 2015-01-25 22:54 - 00000000 __RDO C:\Users\Zajii\OneDrive
2016-03-30 13:59 - 2016-03-05 01:50 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk
2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk
2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk
2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk
2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk
2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk
2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk
2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk
2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk
2016-03-30 13:58 - 2016-03-05 01:50 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk
2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk
2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk
2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk
2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk
2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk
2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk
2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games
2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs
2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media
2016-03-30 11:22 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0
2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java
2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage
2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java
2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie
2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml
2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml
2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta
2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple
2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii
2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net
2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like
2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net
2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt
2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS
2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood
2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt
2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames
2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games
2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-07 19:41 - 2015-11-14 16:27 - 00000000 ____D C:\Users\Zajii\AppData\Local\Skype
2016-03-07 19:41 - 2015-11-14 16:26 - 00000000 ____D C:\ProgramData\Skype

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log
2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg
2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip
2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Einige Dateien in TEMP:
====================
C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll
C:\Users\Zajii\AppData\Local\Temp\7230fefd864f35e6569012bef46d88ae.dll
C:\Users\Zajii\AppData\Local\Temp\7b71d939ac8f4f430ba02b964dfb5794.dll
C:\Users\Zajii\AppData\Local\Temp\EslWireSetup-1.19.0.8185-x64.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u71-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Zajii\AppData\Local\Temp\libeay32.dll
C:\Users\Zajii\AppData\Local\Temp\LSCSetup64.exe
C:\Users\Zajii\AppData\Local\Temp\msvcr120.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole4465310535655270772.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole4974038499892493031.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole732673072298846164.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole8651342122685071258.dll
C:\Users\Zajii\AppData\Local\Temp\proxy_vole9215304146252064412.dll
C:\Users\Zajii\AppData\Local\Temp\sqlite3.dll
C:\Users\Zajii\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-03-28 13:58

==================== Ende von FRST.txt ============================
         

Alt 05.04.2016, 09:54   #10
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Additional:

Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
durchgeführt von Zajii (2016-04-05 10:45:19)
Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS
Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled)
Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled)
Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji
Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC)
7 Days to Die (HKLM-x32\...\Steam App 251570) (Version:  - The Fun Pimps)
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.)
Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version:  - Ensemble Studios)
Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation)
Anno 2070 (HKLM-x32\...\Steam App 48240) (Version:  - BlueByte)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
Arms Dealer (HKLM-x32\...\Steam App 325630) (Version:  - Case in Point Studios, LLC)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version:  - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version:  - DICE)
Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC)
Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden
Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation)
BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version:  - )
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com)
Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version:  - Eidos Montreal)
Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version:  - Splash Damage®)
DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - )
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Down To One (HKLM-x32\...\Steam App 334040) (Version:  - Gadget Games)
Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version:  - )
Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version:  - Eyedentity Games)
Endless Space (HKLM-x32\...\Steam App 208140) (Version:  - AMPLITUDE Studios)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo)
Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden
Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version:  - momoStorm Entertainment)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version:  - Turtle Entertainment GmbH)
Europa Universalis IV (HKLM\...\Steam App 236850) (Version:  - Paradox Development Studio)
Faeria (HKLM\...\Steam App 397060) (Version:  - Abrakam SA)
Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version:  - )
Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups)
Garena - Android Emulator (HKLM-x32\...\nox) (Version:  - Garena Online Pte Ltd.)
Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.)
Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q)
Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grim Dawn (HKLM-x32\...\Steam App 219990) (Version:  - Crate Entertainment)
Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version:  - Trek Industries, Inc)
GUILD WARS (HKLM-x32\...\Guild Wars) (Version:  - )
H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version:  - Daybreak Game Company)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version:  - IO Interactive)
Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.)
Insurgency (HKLM\...\Steam App 222880) (Version:  - New World Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kenshi (HKLM-x32\...\Steam App 233860) (Version:  - Lo-Fi Games)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
KuaiZip (HKLM-x32\...\KuaiZip) (Version:  - )
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.)
Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab)
Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo)
Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version:  - Arkavi Studios)
Magic Duels (HKLM-x32\...\Steam App 316010) (Version:  - Stainless Games Ltd.)
Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - )
Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo)
Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden
MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG)
MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version:  - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version:  - BlueByte)
Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version:  - TaleWorlds Entertainment)
Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version:  - TRUE Software)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version:  - NCSOFT)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team)
NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version:  - Haemimont Games)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software)
Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version:  - Ndemic Creations)
Planet Explorers (HKLM-x32\...\Steam App 237870) (Version:  - Pathea Games)
Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version:  - Uber Entertainment)
Portal Knights (HKLM\...\Steam App 374040) (Version:  - Keen Games)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version:  - Millenway Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.)
Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version:  - EasyGameStation)
Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version:  - Ascaron)
SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden
Saints Row IV (HKLM-x32\...\Steam App 206420) (Version:  - Deep Silver Volition)
Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version:  - Winged Cloud)
Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH)
Sengoku (HKLM-x32\...\Steam App 73210) (Version:  - Paradox Development Studio)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version:  - Ironclad Games)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version:  - United Front Games)
Spellweaver (HKLM-x32\...\Steam App 429680) (Version:  - Dream Reactor)
Star Realms (HKLM\...\Steam App 438140) (Version:  - White Wizard Games)
Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version:  - Little Green Men Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Survivalist (HKLM-x32\...\Steam App 340050) (Version:  - Bob the Game Development Bot)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version:  - Berserk Games)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Tempest (HKLM-x32\...\Steam App 418180) (Version:  - Lion's Shade)
The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version:  - KTX Software)
The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version:  - Virtual Basement LLC)
Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH)
Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - BigNox Corporation XQHDrv System  (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll ()

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe
Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated)
Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software)
Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo)
Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)
Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\"
Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\"
Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires"
Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software)
Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)
Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-11-05 02:11 - 2015-11-05 02:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe
2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll
2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-04-04 11:28 - 2016-04-04 11:28 - 02850816 _____ () C:\Program Files\AVAST Software\Avast\defs\16040400\algo.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-12-23 10:25 - 2016-04-05 10:38 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll
2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll
2014-12-12 23:20 - 2016-03-11 02:56 - 00783360 _____ () C:\Steam\SDL2.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 04962816 _____ () C:\Steam\v8.dll
2014-12-12 23:20 - 2016-03-31 22:55 - 02549840 _____ () C:\Steam\video.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 02549760 _____ () C:\Steam\libavcodec-56.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00491008 _____ () C:\Steam\libavformat-56.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00332800 _____ () C:\Steam\libavresample-2.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00442880 _____ () C:\Steam\libavutil-54.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00485888 _____ () C:\Steam\libswscale-3.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 01556992 _____ () C:\Steam\icui18n.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 01187840 _____ () C:\Steam\icuuc.dll
2014-12-12 23:20 - 2016-03-31 22:55 - 00829008 _____ () C:\Steam\bin\chromehtml.DLL
2016-03-09 12:09 - 2016-02-18 00:25 - 00281088 _____ () C:\Steam\openvr_api.dll
2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll
2015-12-05 12:29 - 2016-02-09 03:33 - 48400672 _____ () C:\Steam\bin\libcef.dll
2015-09-25 23:48 - 2015-09-25 23:48 - 00043656 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32api.pyd
2015-09-25 23:47 - 2015-09-25 23:47 - 00061576 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pywintypes27.dll
2015-09-25 23:47 - 2015-09-25 23:47 - 00127624 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pythoncom27.dll
2015-09-25 23:48 - 2015-09-25 23:48 - 00024200 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_multiprocessing.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00046728 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ctypes.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00027784 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32service.pyd
2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll
2015-12-05 12:29 - 2015-09-25 01:56 - 00119208 _____ () C:\Steam\winh264.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com

Da befinden sich 7866 mehr Seiten.


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk"
HKLM\...\StartupApproved\Run: => "PhoneCompanion"
HKLM\...\StartupApproved\Run: => "LogMeIn GUI"
HKLM\...\StartupApproved\Run: => "Connectify Hotspot"
HKLM\...\StartupApproved\Run: => "Start WingMan Profiler"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "Raptr"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe
FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe
FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe
FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [{38E9D37A-19CD-4C3D-9DA3-0DD35DBD4610}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{B23BAC6E-B86A-4175-AEA4-62C0A239B4DF}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{124EAD6D-953A-40D4-B784-7094D523B660}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe
FirewallRules: [{0213AE30-CEA2-43FB-A4CE-E09573D2B084}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe

==================== Wiederherstellungspunkte =========================

30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/05/2016 04:39:18 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/05/2016 01:16:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203
Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb
Ausnahmecode: 0xc0000094
Fehleroffset: 0x00016a0c
ID des fehlerhaften Prozesses: 0x2354
Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0
Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1
Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2
Berichtskennung: RazerIngameEngine.exe3
Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5

Error: (04/04/2016 08:34:06 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/04/2016 08:33:23 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/04/2016 08:33:17 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/04/2016 08:33:16 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/04/2016 02:53:01 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]

Error: (04/04/2016 12:29:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZAJI)
Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (04/04/2016 12:29:30 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]

Error: (04/04/2016 04:53:25 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]


Systemfehler:
=============
Error: (04/05/2016 10:41:48 AM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/05/2016 10:41:48 AM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/05/2016 10:40:41 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Übermittlungsoptimierung" wurde nicht richtig gestartet.

Error: (04/05/2016 10:39:58 AM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}

Error: (04/05/2016 04:40:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Synchronisierungshost_573a3 erreicht.

Error: (04/05/2016 04:40:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Benutzerdatenspeicher _573a3 erreicht.

Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenspeicher _573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kontaktdaten_573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2016 04:40:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_573a3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.


CodeIntegrity:
===================================
  Date: 2016-03-24 02:26:58.699
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-23 04:00:10.692
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-22 14:17:50.313
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 18:18:45.659
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 14:34:08.548
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-10 10:17:26.727
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-03 12:41:33.511
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-02 15:35:16.954
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 17:56:24.126
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 07:03:27.892
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 31%
Installierter physikalischer RAM: 12196.01 MB
Verfügbarer physikalischer RAM: 8330.16 MB
Summe virtueller Speicher: 24484.01 MB
Verfügbarer virtueller Speicher: 20213.86 MB

==================== Laufwerke ================================

Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:383.31 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3)

Partition: GPT.

==================== Ende von Addition.txt ============================
         
Also soweit habe ich keine Probleme mit dem Pc, alles läuft wie gewohnt.

Alt 07.04.2016, 01:13   #11
burningice
/// Malwareteam
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Schritt: 1
Deinstalliere bitte Spybot Search & Destroy - das Produkt ist nicht mehr, was es mal war.

Schritt: 2
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKLM-x32\...\Run: [] => [X] 
Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG 

Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG 

Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG 

Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG 

Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG 

Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG 

Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG 

Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG 

Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG 

Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG 

Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG

emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Schritt: 2
Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen.
__________________
Mfg,
Rafael

~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~

Unterstütze uns mit einer Spende
......... Lob, Kritik oder Wünsche .........
.......... Folge uns auf Facebook ..........

Alt 07.04.2016, 12:51   #12
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Hier habe ich die gewünschten Logs

Fixlog

Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
durchgeführt von Zajii (2016-04-07 13:29:22) Run:1
Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS\FRST 2
Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKLM-x32\...\Run: [] => [X] 
Task: {0022D505-89DC-4004-B6CF-3E97576D1FD5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG 

Task: {03D2038E-5F0B-4095-A307-BD3BE6727F06} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG 

Task: {385D07FE-CFED-4E3A-AB32-5BB218EE7ABF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG 

Task: {408FCF42-4944-455C-8A72-DE33EB8B2D85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG 

Task: {50469B9C-E247-4829-9E2D-2E4855321279} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG 

Task: {6C88E871-DE39-4E8F-AD06-9431B840223A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG 

Task: {71A56DF0-B4F7-451D-A5D5-48DA2552F458} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG 

Task: {C5A62FD1-C481-44EC-AAEC-48A50DD050DC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG 

Task: {D21116EB-D486-463F-90C7-430EAAFAFE3F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG 

Task: {ED0F84BF-9B51-4532-86E2-84DE21936120} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG 

Task: {FC7427EE-B27B-49A8-A899-0418E15003C9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG

emptytemp:
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0022D505-89DC-4004-B6CF-3E97576D1FD5}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0022D505-89DC-4004-B6CF-3E97576D1FD5}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03D2038E-5F0B-4095-A307-BD3BE6727F06}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03D2038E-5F0B-4095-A307-BD3BE6727F06}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{385D07FE-CFED-4E3A-AB32-5BB218EE7ABF}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{385D07FE-CFED-4E3A-AB32-5BB218EE7ABF}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{408FCF42-4944-455C-8A72-DE33EB8B2D85}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{408FCF42-4944-455C-8A72-DE33EB8B2D85}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{50469B9C-E247-4829-9E2D-2E4855321279}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50469B9C-E247-4829-9E2D-2E4855321279}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C88E871-DE39-4E8F-AD06-9431B840223A}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C88E871-DE39-4E8F-AD06-9431B840223A}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{71A56DF0-B4F7-451D-A5D5-48DA2552F458}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71A56DF0-B4F7-451D-A5D5-48DA2552F458}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5A62FD1-C481-44EC-AAEC-48A50DD050DC}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5A62FD1-C481-44EC-AAEC-48A50DD050DC}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D21116EB-D486-463F-90C7-430EAAFAFE3F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D21116EB-D486-463F-90C7-430EAAFAFE3F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED0F84BF-9B51-4532-86E2-84DE21936120}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED0F84BF-9B51-4532-86E2-84DE21936120}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC7427EE-B27B-49A8-A899-0418E15003C9}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC7427EE-B27B-49A8-A899-0418E15003C9}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => Schlüssel erfolgreich entfernt
EmptyTemp: => 3.3 GB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 13:34:05 ====
         

FRST

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
durchgeführt von Zajii (Administrator) auf ZAJI (07-04-2016 13:39:52)
Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS\FRST 2
Geladene Profile: Zajii (Verfügbare Profile: Zajii & Zaji)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
() C:\Program Files\EslWire\service\WireHelperSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\setup\instup.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(NVIDIA Corporation) C:\Users\Zajii\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2016-02-19] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5052120 2016-02-19] (Realtek semiconductor)
HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [405416 2015-09-09] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-06-04] ()
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-06-04] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-06-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-02-19] (Synaptics Incorporated)
HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH)
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-05-15] (Raptr, Inc)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [594240 2016-01-13] (Razer Inc.)
HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502Helper.exe [1599808 2015-08-14] (Razer Inc)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Zajii\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [10008512 2015-11-24] ()
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Steam] => C:\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [912920 2016-03-03] (BlueStack Systems, Inc.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\MountPoints2: {6d572d39-a47a-11e4-826e-54ee7517f830} - "E:\setup.exe" 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-19] (AVAST Software)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\KuaiZip\KZipShell.dll [2011-09-08] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk [2016-03-30]
ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{62de1182-7272-49fb-8e9d-38edb667c219}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{e98e577f-fe4c-4c84-b945-d5605a31f7ce}: [DhcpNameServer] 192.168.178.1
ManualProxies: 

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE01&ocid=UE01DHP
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {7D50DB01-13EA-472E-8BA7-12A6CC2FD7EF} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {8515961F-DC97-4797-BC64-B80FE999E9A4} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {DAC246D1-0986-4CA0-931D-4231C44BD759} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001 -> {E9E88D9A-4C7C-45E9-A1C6-6CE3F01CBF8A} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-19] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-19] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-19] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-29] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-07-31] (Perfect World Entertainment Inc)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-19] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation)
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab

FireFox:
========
FF ProfilePath: C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] ()
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-07-31] (Perfect World Entertainment Inc)
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Zajii\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-11-06] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zajii\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3509251487-2946272100-3589144056-1001: Fshare.vn/FshareToolPlugin -> C:\Program Files (x86)\Fshare Tool\npFshareToolPlugin.dll [2015-01-08] (Fshare)
FF user.js: detected! => C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\user.js [2015-06-26]
FF Extension: MEGA - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\firefox@mega.co.nz.xpi [2015-08-04] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Zajii\AppData\Roaming\Mozilla\Firefox\Profiles\0zozvt93.default-1423755319522\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-25]
FF HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Firefox\Extensions: [hotro@fshare.vn] - C:\Program Files (x86)\Fshare Tool\Addon => nicht gefunden

Chrome: 
=======
CHR Profile: C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-09-25]
CHR Extension: (Google Drive) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Adblock Plus) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09]
CHR Extension: (Steam inventory helper) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2016-03-20]
CHR Extension: (Google-Suche) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Crunchyroll Unblocker) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\dldddkdajilplfikaadakojgjocbnjim [2016-03-14]
CHR Extension: (LoungeDestroyer) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2016-03-23]
CHR Extension: (Avast Online Security) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-07]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\Zajii\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-06]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-02-19]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-19]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-07-31] (Perfect World Entertainment Inc)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-19] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1314848 2016-01-19] ()
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437784 2016-03-03] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417304 2016-03-03] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [880152 2016-03-03] (BlueStack Systems, Inc.)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-12-16] (EasyAntiCheat Ltd)
R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2013-12-05] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-06-04] (Lenovo)
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3667696 2015-11-30] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-30] (Electronic Arts)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-07] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-06-04] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-06-04] (Lenovo)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-11-13] (Razer Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-02-19] (Synaptics Incorporated)
S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-06-04] (Lenovo)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-06-04] (Lenovo)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-12-24] (Atheros) [Datei ist nicht signiert]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-19] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-19] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-19] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-19] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-19] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4322440 2016-02-19] (Qualcomm Atheros Communications, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-03-03] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-27] (Disc Soft Ltd)
R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [102176 2016-01-11] (<Turtle Entertainment>)
S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-19] (REALiX(tm))
R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [93992 2011-04-15] (KuaiZip International Inc)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-19] (Intel Corporation)
S1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2016-02-19] (Realtek                                            )
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-02-19] (Realtek Semiconductor Corp.)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-23] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-02-19] (Synaptics Incorporated)
S3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [25088 2015-04-14] (SteelSeries ApS)
S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2015-12-18] (TENCENT)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [Datei ist nicht signiert]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 X6va031; \??\C:\WINDOWS\SysWOW64\Drivers\X6va031 [25816 2015-08-02] ()
S3 X6va034; \??\C:\WINDOWS\SysWOW64\Drivers\X6va034 [26840 2015-09-25] ()
S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [21184 2016-03-17] ()
S3 xhunter1; C:\WINDOWS\xhunter1.sys [37416 2016-02-28] (Wellbia.com Co., Ltd.)
R1 XQHDrv; C:\Windows\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (BigNox Corporation)
S3 gkernel; \??\C:\Users\Zajii\AppData\Local\Temp\gkernel.sys [X]
S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-06 17:21 - 2016-04-06 17:21 - 02103566 _____ C:\Users\Zajii\Downloads\matchmaking_server_picker_423.zip
2016-04-04 20:33 - 2016-04-04 20:33 - 00000000 ____D C:\Program Files (x86)\ESET
2016-04-03 02:31 - 2016-04-03 02:31 - 00001291 _____ C:\Users\Zajii\Desktop\mbam.txt
2016-04-01 14:48 - 2016-04-01 14:48 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Abrakam
2016-03-31 10:53 - 2016-03-31 12:54 - 00018188 _____ C:\Users\Zajii\Downloads\Wilhelma.odt
2016-03-31 10:53 - 2016-03-31 12:54 - 00018057 _____ C:\Users\Zajii\Downloads\Zoo Leipzig.odt
2016-03-31 10:52 - 2016-03-31 12:53 - 00018002 _____ C:\Users\Zajii\Downloads\Wildpark.odt
2016-03-31 10:52 - 2016-03-31 12:53 - 00017959 _____ C:\Users\Zajii\Downloads\Allwetterzoo.odt
2016-03-30 14:17 - 2016-04-07 13:28 - 00000000 ____D C:\Users\Zajii\Desktop\ANTI VIRUS
2016-03-30 14:07 - 2016-04-07 13:39 - 00000000 ____D C:\FRST
2016-03-30 13:21 - 2016-04-01 19:31 - 00000000 ____D C:\AdwCleaner
2016-03-30 13:05 - 2016-03-30 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-24 18:11 - 2016-03-25 12:15 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\WindSolutions
2016-03-24 18:11 - 2016-03-24 18:17 - 00000000 ____D C:\ProgramData\WindSolutions
2016-03-24 03:29 - 2016-03-30 13:59 - 00001233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-30 13:59 - 00001215 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-24 03:29 - 2016-03-24 03:29 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-03-24 03:29 - 2016-03-24 03:29 - 00003178 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458782977
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Software4u
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\IsolatedStorage
2016-03-22 16:00 - 2016-03-22 16:00 - 00000000 ____D C:\ProgramData\Software4u
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files\Bonjour
2016-03-22 15:59 - 2016-03-22 15:59 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-03-22 15:16 - 2016-03-22 15:38 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Inc
2016-03-22 15:15 - 2016-03-22 16:29 - 00000000 ____D C:\ProgramData\Apple Computer
2016-03-22 15:04 - 2016-03-22 17:16 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Apple Computer
2016-03-22 15:04 - 2016-03-22 16:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple Computer
2016-03-22 15:03 - 2016-03-22 15:03 - 00000000 ____D C:\Users\Zajii\AppData\Local\Apple
2016-03-20 13:55 - 2016-04-01 12:23 - 00000000 ____D C:\Users\Zajii\Desktop\Anscheiben
2016-03-18 14:08 - 2016-03-18 14:08 - 00000000 ____D C:\Users\Zajii\Documents\Paradox Interactive
2016-03-18 12:58 - 2016-03-18 13:02 - 485036365 _____ C:\Users\Zajii\Downloads\Part9.mp4
2016-03-18 12:58 - 2016-03-18 12:59 - 345343373 _____ C:\Users\Zajii\Downloads\Part10.mp4
2016-03-18 12:57 - 2016-03-18 13:00 - 369992431 _____ C:\Users\Zajii\Downloads\Part8.mp4
2016-03-18 12:48 - 2016-03-18 12:55 - 479490079 _____ C:\Users\Zajii\Downloads\Part7.mp4
2016-03-18 12:47 - 2016-03-18 12:56 - 554941905 _____ C:\Users\Zajii\Downloads\Part5.mp4
2016-03-18 12:47 - 2016-03-18 12:55 - 457891103 _____ C:\Users\Zajii\Downloads\Part4.mp4
2016-03-18 12:47 - 2016-03-18 12:48 - 473615544 _____ C:\Users\Zajii\Downloads\Part6.mp4
2016-03-18 04:23 - 2016-03-18 04:29 - 613969239 _____ C:\Users\Zajii\Downloads\Part3.mp4
2016-03-18 04:23 - 2016-03-18 04:27 - 397529844 _____ C:\Users\Zajii\Downloads\Part2.mp4
2016-03-18 04:22 - 2016-03-18 04:30 - 561565217 _____ C:\Users\Zajii\Downloads\Part1.mp4
2016-03-17 16:57 - 2016-03-17 16:57 - 00021184 _____ C:\WINDOWS\SysWOW64\Drivers\X6va062
2016-03-15 01:46 - 2016-03-15 01:46 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\Adobe
2016-03-14 21:28 - 2016-03-16 17:16 - 00000000 ____D C:\Users\Zajii\Desktop\5
2016-03-13 21:22 - 2016-03-30 13:58 - 00001348 _____ C:\Users\Zajii\Desktop\4K Video Downloader.lnk
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Users\Zajii\AppData\Local\4kdownload.com
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2016-03-13 21:22 - 2016-03-13 21:22 - 00000000 ____D C:\Program Files (x86)\4KDownload
2016-03-11 01:43 - 2016-03-11 01:43 - 00000000 ____D C:\Users\Zajii\AppData\LocalLow\White Wizard Games
2016-03-09 00:13 - 2016-02-24 11:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 11:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 00:13 - 2016-02-24 11:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-03-09 00:13 - 2016-02-24 11:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-09 00:13 - 2016-02-24 11:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-03-09 00:13 - 2016-02-24 11:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-03-09 00:13 - 2016-02-24 10:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-09 00:13 - 2016-02-24 10:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 10:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-09 00:13 - 2016-02-24 10:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-03-09 00:13 - 2016-02-24 10:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-03-09 00:13 - 2016-02-24 10:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-03-09 00:13 - 2016-02-24 10:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-03-09 00:13 - 2016-02-24 10:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-03-09 00:13 - 2016-02-24 09:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-03-09 00:13 - 2016-02-24 08:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-09 00:13 - 2016-02-24 08:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-03-09 00:13 - 2016-02-24 08:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-03-09 00:13 - 2016-02-24 08:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2016-03-09 00:13 - 2016-02-24 08:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-09 00:13 - 2016-02-24 08:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-03-09 00:13 - 2016-02-24 08:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-09 00:13 - 2016-02-24 08:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-03-09 00:13 - 2016-02-24 07:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-03-09 00:13 - 2016-02-24 07:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-09 00:13 - 2016-02-24 07:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 00:13 - 2016-02-24 07:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-09 00:13 - 2016-02-24 07:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-09 00:13 - 2016-02-24 06:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-09 00:13 - 2016-02-24 06:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-09 00:12 - 2016-03-01 07:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-03-09 00:12 - 2016-03-01 07:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-03-09 00:12 - 2016-02-24 11:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-09 00:12 - 2016-02-24 11:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-03-09 00:12 - 2016-02-24 10:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-09 00:12 - 2016-02-24 10:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2016-03-09 00:12 - 2016-02-24 10:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 10:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2016-03-09 00:12 - 2016-02-24 10:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-09 00:12 - 2016-02-24 10:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-03-09 00:12 - 2016-02-24 10:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 10:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 10:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-09 00:12 - 2016-02-24 10:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-03-09 00:12 - 2016-02-24 09:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 09:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 09:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-09 00:12 - 2016-02-24 09:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-09 00:12 - 2016-02-24 09:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-09 00:12 - 2016-02-24 09:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-09 00:12 - 2016-02-24 09:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-03-09 00:12 - 2016-02-24 09:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 09:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 09:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 09:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-03-09 00:12 - 2016-02-24 09:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2016-03-09 00:12 - 2016-02-24 09:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-09 00:12 - 2016-02-24 09:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-09 00:12 - 2016-02-24 09:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 09:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2016-03-09 00:12 - 2016-02-24 09:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 09:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 09:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 09:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-09 00:12 - 2016-02-24 09:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-03-09 00:12 - 2016-02-24 09:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-09 00:12 - 2016-02-24 09:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-03-09 00:12 - 2016-02-24 09:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2016-03-09 00:12 - 2016-02-24 09:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2016-03-09 00:12 - 2016-02-24 08:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-03-09 00:12 - 2016-02-24 08:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2016-03-09 00:12 - 2016-02-24 08:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 00:12 - 2016-02-24 08:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-03-09 00:12 - 2016-02-24 08:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-09 00:12 - 2016-02-24 08:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-09 00:12 - 2016-02-24 08:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-09 00:12 - 2016-02-24 08:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-03-09 00:12 - 2016-02-24 08:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-09 00:12 - 2016-02-24 08:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-03-09 00:12 - 2016-02-24 08:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:42 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-03-09 00:12 - 2016-02-24 08:42 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-03-09 00:12 - 2016-02-24 08:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-09 00:12 - 2016-02-24 08:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 00:12 - 2016-02-24 08:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2016-03-09 00:12 - 2016-02-24 08:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-03-09 00:12 - 2016-02-24 08:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 00:12 - 2016-02-24 08:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-03-09 00:12 - 2016-02-24 08:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2016-03-09 00:12 - 2016-02-24 08:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-03-09 00:12 - 2016-02-24 08:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2016-03-09 00:12 - 2016-02-24 08:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 00:12 - 2016-02-24 08:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2016-03-09 00:12 - 2016-02-24 08:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 00:12 - 2016-02-24 08:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-03-09 00:12 - 2016-02-24 08:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2016-03-09 00:12 - 2016-02-24 08:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2016-03-09 00:12 - 2016-02-24 08:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-09 00:12 - 2016-02-24 08:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-03-09 00:12 - 2016-02-24 08:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-03-09 00:12 - 2016-02-24 08:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-03-09 00:12 - 2016-02-24 07:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-09 00:12 - 2016-02-24 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2016-03-09 00:12 - 2016-02-24 07:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-07 13:40 - 2014-12-13 14:51 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-04-07 13:40 - 2014-12-12 23:08 - 00000000 ____D C:\Steam
2016-04-07 13:39 - 2015-02-13 09:27 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-07 13:38 - 2015-08-13 11:27 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-04-07 13:37 - 2015-12-23 09:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-07 13:37 - 2015-06-25 06:06 - 00000000 __SHD C:\Users\Zajii\IntelGraphicsProfiles
2016-04-07 13:35 - 2015-12-23 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-07 13:35 - 2015-01-06 21:01 - 00000661 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-04-07 13:34 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-04-07 13:04 - 2015-02-13 09:27 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-07 12:55 - 2014-12-12 21:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-07 10:59 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-07 10:59 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-07 10:50 - 2014-06-04 11:57 - 00000000 ____D C:\ProgramData\Energy Manager
2016-04-07 01:32 - 2014-12-12 23:09 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\TS3Client
2016-04-06 17:22 - 2016-02-19 12:40 - 00000000 ____D C:\Program Files\mmpicker
2016-04-06 14:21 - 2014-12-12 22:43 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\vlc
2016-04-06 13:44 - 2015-03-05 13:41 - 00000000 ____D C:\Users\Zajii\AppData\Local\JDownloader 2.0
2016-04-06 05:24 - 2015-11-14 16:26 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Skype
2016-04-06 04:52 - 2015-01-04 21:37 - 00000000 ____D C:\Users\Zajii\Desktop\Folder
2016-04-06 03:40 - 2015-12-16 22:25 - 00325880 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2016-04-05 23:27 - 2015-10-30 20:35 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-05 23:27 - 2015-10-30 20:35 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-05 23:27 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-05 23:27 - 2015-07-30 08:41 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-05 15:55 - 2015-09-25 22:44 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2016-04-03 12:13 - 2015-05-11 18:14 - 00000085 _____ C:\WINDOWS\wininit.ini
2016-04-03 12:13 - 2015-05-08 23:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-04-01 13:38 - 2016-02-26 22:51 - 00011993 _____ C:\Users\Zajii\Desktop\Weightwatcher.ods
2016-03-31 13:00 - 2015-07-30 13:12 - 00002433 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-31 13:00 - 2015-01-25 22:54 - 00000000 __RDO C:\Users\Zajii\OneDrive
2016-03-30 13:59 - 2016-03-05 01:50 - 00001693 _____ C:\Users\Public\Desktop\BlueStacks.lnk
2016-03-30 13:59 - 2016-02-25 00:46 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-25 00:46 - 00001225 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-03-30 13:59 - 2016-02-21 19:32 - 00001334 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
2016-03-30 13:59 - 2016-01-27 13:19 - 00002034 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-30 13:59 - 2016-01-21 00:43 - 00001367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk
2016-03-30 13:59 - 2016-01-13 00:49 - 00002312 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
2016-03-30 13:59 - 2016-01-11 00:23 - 00000869 _____ C:\Users\Public\Desktop\ESL Wire.lnk
2016-03-30 13:59 - 2015-12-23 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-03-30 13:59 - 2015-12-05 12:23 - 00000604 _____ C:\Users\Public\Desktop\Steam.lnk
2016-03-30 13:59 - 2015-11-29 14:33 - 00001131 _____ C:\Users\Public\Desktop\Mstar.lnk
2016-03-30 13:59 - 2015-11-16 11:56 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2016-03-30 13:59 - 2015-11-14 16:26 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-30 13:59 - 2015-10-27 09:34 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk
2016-03-30 13:59 - 2015-06-24 22:30 - 00000728 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2016-03-30 13:59 - 2015-03-10 08:11 - 00001004 _____ C:\Users\Public\Desktop\MyPublicWiFi.lnk
2016-03-30 13:59 - 2015-02-20 20:50 - 00001619 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-30 13:59 - 2015-02-13 09:27 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-30 13:59 - 2015-01-24 21:44 - 00001323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2016-03-30 13:59 - 2014-06-04 11:56 - 00001981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Transfer.lnk
2016-03-30 13:59 - 2014-06-04 11:51 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartVoiceToast.lnk
2016-03-30 13:58 - 2016-03-05 01:50 - 00001753 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk
2016-03-30 13:58 - 2016-01-15 21:48 - 00001019 _____ C:\Users\Zajii\Desktop\Open Broadcaster Software.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001138 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk
2016-03-30 13:58 - 2015-12-18 00:02 - 00001114 _____ C:\Users\Zajii\Desktop\RaidCall.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001069 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2016-03-30 13:58 - 2015-12-16 00:27 - 00001061 _____ C:\Users\Zajii\Desktop\osu!.lnk
2016-03-30 13:58 - 2015-11-18 17:32 - 00001257 _____ C:\Users\Zajii\Desktop\Gw2.lnk
2016-03-30 13:58 - 2015-09-17 18:03 - 00001062 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2016-03-30 13:58 - 2015-08-20 22:27 - 00001748 _____ C:\Users\Zajii\Desktop\shutdown STOP.lnk
2016-03-30 13:58 - 2015-08-20 22:24 - 00001764 _____ C:\Users\Zajii\Desktop\shutdown.lnk
2016-03-30 13:58 - 2015-07-18 11:57 - 00001283 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-03-30 13:58 - 2015-05-17 08:07 - 00000837 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\KuaiZip.lnk
2016-03-30 13:58 - 2014-12-23 13:24 - 00000295 _____ C:\Users\Zajii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk
2016-03-30 13:39 - 2015-12-26 14:34 - 00000000 ____D C:\Games
2016-03-30 13:35 - 2015-01-10 23:23 - 00000000 ____D C:\ProgramData\media center programs
2016-03-30 13:35 - 2014-06-04 11:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-30 12:34 - 2014-12-14 16:30 - 00000000 ____D C:\Media
2016-03-29 21:00 - 2015-06-26 07:15 - 00000000 ____D C:\Program Files\Java
2016-03-29 21:00 - 2015-02-01 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-29 20:59 - 2016-02-05 00:10 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-03-29 20:59 - 2015-08-30 14:50 - 00000000 ____D C:\Users\Zajii\.oracle_jre_usage
2016-03-29 20:58 - 2015-02-01 23:50 - 00000000 ____D C:\Program Files (x86)\Java
2016-03-29 00:39 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-03-28 03:18 - 2015-01-19 19:34 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\7DaysToDie
2016-03-24 14:55 - 2014-12-12 21:38 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-03-24 03:29 - 2015-08-13 11:24 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-24 03:29 - 2015-08-13 11:22 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-23 18:07 - 2015-07-30 07:22 - 00002562 _____ C:\WINDOWS\diagwrn.xml
2016-03-23 18:07 - 2015-07-30 07:22 - 00001908 _____ C:\WINDOWS\diagerr.xml
2016-03-23 12:58 - 2016-02-22 00:52 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\omerta
2016-03-23 11:41 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-22 17:19 - 2014-12-14 20:26 - 00000000 ____D C:\ProgramData\Apple
2016-03-22 15:38 - 2015-12-23 09:29 - 00000000 ____D C:\Users\Zajii
2016-03-21 02:12 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Local\Battle.net
2016-03-21 00:12 - 2014-12-22 17:00 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-03-19 13:03 - 2015-11-20 15:09 - 00000000 ____D C:\Users\Zajii\Desktop\applocale like
2016-03-18 23:36 - 2015-01-09 22:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2016-03-18 23:16 - 2014-12-22 16:51 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-18 23:15 - 2014-12-22 17:00 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\Battle.net
2016-03-16 12:28 - 2016-02-12 16:05 - 00000156 _____ C:\Users\Zajii\Desktop\Neues Textdokument.txt
2016-03-14 02:23 - 2016-01-15 21:48 - 00000000 ____D C:\Users\Zajii\AppData\Roaming\OBS
2016-03-11 13:50 - 2015-09-22 17:47 - 00000000 ____D C:\Users\Zajii\Downloads\Strike The Blood
2016-03-11 12:20 - 2015-01-24 03:21 - 00000000 ____D C:\Users\Zajii\Downloads\alt
2016-03-11 00:55 - 2015-02-06 18:43 - 00000000 ____D C:\Users\Zajii\Documents\Mount&Blade Warband Savegames
2016-03-10 11:14 - 2015-12-23 09:18 - 00287536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 03:34 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 03:28 - 2015-08-13 11:27 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-03-10 03:28 - 2015-08-13 11:27 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-03-10 00:44 - 2014-12-13 00:45 - 00000000 ____D C:\Users\Zajii\Documents\my games
2016-03-09 14:36 - 2014-12-14 19:43 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 14:36 - 2014-12-14 19:43 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-08 09:12 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 09:12 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-08 00:03 - 2016-03-07 23:56 - 00000000 ____D C:\Users\Zajii\Documents\PlanetExplorers

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-02-13 12:17 - 2015-07-12 10:04 - 0002517 _____ () C:\Users\Zajii\AppData\Roaming\droid4xinstaller.log
2015-12-14 12:55 - 2016-01-13 08:20 - 0007646 _____ () C:\Users\Zajii\AppData\Local\Resmon.ResmonCfg
2015-02-24 14:48 - 2015-02-24 14:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip
2015-12-23 09:25 - 2015-12-23 09:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Einige Dateien in TEMP:
====================
C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-07 11:13

==================== Ende von FRST.txt ============================
         

Alt 07.04.2016, 12:52   #13
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Addition

Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
durchgeführt von Zajii (2016-04-07 13:45:37)
Gestartet von C:\Users\Zajii\Desktop\ANTI VIRUS\FRST 2
Windows 10 Home Version 1511 (X64) (2015-12-23 08:15:26)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3509251487-2946272100-3589144056-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3509251487-2946272100-3589144056-503 - Limited - Disabled)
Gast (S-1-5-21-3509251487-2946272100-3589144056-501 - Limited - Disabled)
Zaji (S-1-5-21-3509251487-2946272100-3589144056-1004 - Administrator - Enabled) => C:\Users\Zaji
Zajii (S-1-5-21-3509251487-2946272100-3589144056-1001 - Administrator - Enabled) => C:\Users\Zajii

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4K Video Downloader 4.0 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.0.0.2016 - Open Media LLC)
7 Days to Die (HKLM-x32\...\Steam App 251570) (Version:  - The Fun Pimps)
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\{7E33E883-0D17-4397-A461-B576605E34B1}) (Version: 12.1.6.156 - Adobe Systems, Inc)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.)
Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version:  - Ensemble Studios)
Akamai NetSession Interface (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.8 - Sereby Corporation)
Anno 2070 (HKLM-x32\...\Steam App 48240) (Version:  - BlueByte)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
Arms Dealer (HKLM-x32\...\Steam App 325630) (Version:  - Case in Point Studios, LLC)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version:  - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 2 (HKLM-x32\...\Steam App 24860) (Version:  - DICE)
Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC)
Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden
Blender (HKLM\...\Blender) (Version: 2.72b - Blender Foundation)
BlueStacks App Player (HKLM-x32\...\{6B261D83-D9FD-4CC0-B8F7-63B8EABA6649}) (Version: 2.1.1.5648 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version:  - )
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CrossFire (HKLM-x32\...\CrossFire_is1) (Version: 1208 - Z8Games.com)
Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version:  - Eidos Montreal)
Dirty Bomb (HKLM-x32\...\Steam App 333930) (Version:  - Splash Damage®)
DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - )
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Down To One (HKLM-x32\...\Steam App 334040) (Version:  - Gadget Games)
Dragon Nest Europe (HKLM-x32\...\Dragon Nest Europe) (Version:  - )
Dragon Nest Europe (HKLM-x32\...\Steam App 258700) (Version:  - Eyedentity Games)
Endless Space (HKLM-x32\...\Steam App 208140) (Version:  - AMPLITUDE Studios)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo)
Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden
Epic Cards Battle(TCG) (HKLM-x32\...\Steam App 381560) (Version:  - momoStorm Entertainment)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
ESL Wire 1.19.0 (HKLM\...\ESL Wire_is1) (Version:  - Turtle Entertainment GmbH)
Europa Universalis IV (HKLM\...\Steam App 236850) (Version:  - Paradox Development Studio)
Faeria (HKLM\...\Steam App 397060) (Version:  - Abrakam SA)
Forgoten Hope 2 (2 of 2) (dummy) (HKLM-x32\...\Forgotten Hope 2) (Version:  - )
Fshare Tool version 5.1.7 (HKLM-x32\...\{0AA81912-18DE-4E3A-9CDB-BA60AB36AF50}_is1) (Version: 5.1.7 - www.Fshare.vn Groups)
Garena - Android Emulator (HKLM-x32\...\nox) (Version:  - Garena Online Pte Ltd.)
Garena - MSTAR (HKLM-x32\...\MSTAR) (Version: 2015102101 - Garena Online Pte Ltd.)
Garena - Mstar (HKLM-x32\...\MstarTW) (Version: 2015120901 - ¥xÆWÄv»R®T¼Ö¦³**¤½¥q)
Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.1.0 - Genesys Logic)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grim Dawn (HKLM-x32\...\Steam App 219990) (Version:  - Crate Entertainment)
Guardians of Orion (HKLM-x32\...\Steam App 407840) (Version:  - Trek Industries, Inc)
GUILD WARS (HKLM-x32\...\Guild Wars) (Version:  - )
H1Z1: King of the Kill (HKLM-x32\...\Steam App 433850) (Version:  - Daybreak Game Company)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version:  - IO Interactive)
Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{E5C1C342-5E78-4D91-85BE-40C716B09391}) (Version: 3.55.7671.0901 - Sony Computer Entertainment Inc.)
Insurgency (HKLM\...\Steam App 222880) (Version:  - New World Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kenshi (HKLM-x32\...\Steam App 233860) (Version:  - Lo-Fi Games)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
KuaiZip (HKLM-x32\...\KuaiZip) (Version:  - )
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.)
Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab)
Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo)
Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.1.14.1221 - Lenovo)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
LibreOffice 4.4.5.2 (HKLM-x32\...\{406EECCC-AF98-4F2C-A99F-FED788F7580C}) (Version: 4.4.5.2 - The Document Foundation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Lords of the Black Sun (HKLM-x32\...\Steam App 246940) (Version:  - Arkavi Studios)
Magic Duels (HKLM-x32\...\Steam App 316010) (Version:  - Stainless Games Ltd.)
Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - )
Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo)
Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden
MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG)
MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version:  - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version:  - BlueByte)
Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version:  - TaleWorlds Entertainment)
Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version:  - TRUE Software)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version:  - NCSOFT)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team)
NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 354.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 354.35 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Omerta - City of Gangsters (HKLM-x32\...\Steam App 208520) (Version:  - Haemimont Games)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{2053acc7-85e7-42c2-85d5-2fc4256ff69b}) (Version: latest - ppy Pty Ltd)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.0.2 - onOne Software)
Plague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version:  - Ndemic Creations)
Planet Explorers (HKLM-x32\...\Steam App 237870) (Version:  - Pathea Games)
Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version:  - Uber Entertainment)
Portal Knights (HKLM\...\Steam App 374040) (Version:  - Keen Games)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
Pro Gamer Manager (HKLM-x32\...\Steam App 408740) (Version:  - Millenway Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.4.6.10930 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.28549 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7673 - Realtek Semiconductor Corp.)
Recettear: An Item Shop's Tale (HKLM-x32\...\Steam App 70400) (Version:  - EasyGameStation)
Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version:  - Ascaron)
SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden
Saints Row IV (HKLM-x32\...\Steam App 206420) (Version:  - Deep Silver Volition)
Sakura Clicker (HKLM-x32\...\Steam App 383080) (Version:  - Winged Cloud)
Savu Mouse (HKLM-x32\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH)
Sengoku (HKLM-x32\...\Steam App 73210) (Version:  - Paradox Development Studio)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Sins of a Solar Empire: Rebellion (HKLM\...\Steam App 204880) (Version:  - Ironclad Games)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version:  - United Front Games)
Spellweaver (HKLM-x32\...\Steam App 429680) (Version:  - Dream Reactor)
Star Realms (HKLM\...\Steam App 438140) (Version:  - White Wizard Games)
Starpoint Gemini 2 (HKLM-x32\...\Steam App 236150) (Version:  - Little Green Men Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Survivalist (HKLM-x32\...\Steam App 340050) (Version:  - Bob the Game Development Bot)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version:  - Berserk Games)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Tempest (HKLM-x32\...\Steam App 418180) (Version:  - Lion's Shade)
The Haunted: Hells Reach (HKLM-x32\...\Steam App 43190) (Version:  - KTX Software)
The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version:  - Virtual Basement LLC)
Total Commander 64-bit (Remove or Repair) (HKLM-x32\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH)
Unity Web Player (HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - BigNox Corporation XQHDrv System  (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Zajii\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll ()

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {09E02415-CDCF-4972-80AC-90A7B916831B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {3D73E82F-49A1-4C6D-A377-250C51829C99} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {3E2A9EBB-EC4C-49B5-B915-4FAA31BEF2A1} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe
Task: {45E82E06-E381-42CA-9098-7F2E992A1769} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated)
Task: {7119FDB6-09DD-4B48-AEE5-30AD93153B86} - System32\Tasks\SafeZone scheduled Autoupdate 1458782977 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software)
Task: {8378CCD0-977C-4ACF-97DF-069054A386F3} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-06-04] (Lenovo)
Task: {984F07AB-6E7A-4D83-9C6A-2A2868FCEBB0} - System32\Tasks\Driver Booster SkipUAC (Zajii) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {A4A1EA07-FAA1-4D58-ABBB-F4837DAA20B3} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {BA12288C-2B3A-4326-822C-43D99C19740D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)
Task: {CA65B611-6A0C-48A0-A664-A7FDF8E5BB6D} - System32\Tasks\{62CF23B5-05FA-40C4-8C1F-6C8CFB120926} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\"
Task: {DF883339-5F78-4558-8370-0BC0F63B7D42} - System32\Tasks\{998D315E-3727-4088-92E6-AF1897EC703D} => pcalua.exe -a "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\SimJP.exe" -d "C:\Program Files (x86)\Universal Interactive\Blue Tongue Software\Jurassic Park Operation Genesis\JPOG\"
Task: {E3727C56-35E9-4256-AA5F-9A10C773D6F3} - System32\Tasks\{5359B77D-7325-483F-8F30-7C9B462D7106} => pcalua.exe -a "C:\Dynasty Warriors 8 Empires\Launch.exe" -d "C:\Dynasty Warriors 8 Empires"
Task: {EB436C35-1D95-4626-8105-093679E3D50B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-19] (AVAST Software)
Task: {F3DACE12-C7BA-44BF-9EE5-E21129CF0236} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {FC56B8E1-7F27-4817-9130-4179D1CFC095} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-23 09:25 - 2015-10-15 05:46 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-01-11 00:24 - 2013-12-05 22:06 - 00663056 _____ () C:\Program Files\EslWire\service\WireHelperSvc.exe
2016-01-11 00:24 - 2014-10-14 20:33 - 00214016 _____ () C:\Program Files\EslWire\service\NocIPC64.dll
2014-06-04 11:49 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-11-05 02:11 - 2015-11-05 02:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2014-06-04 11:43 - 2014-06-04 11:43 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 11:51 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-05-17 08:07 - 2011-09-08 05:44 - 00278056 _____ () C:\Program Files\KuaiZip\KZipShell.dll
2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-23 21:59 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-02 11:50 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 18:21 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 18:21 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 18:06 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 18:06 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
2014-03-26 12:50 - 2014-06-04 11:56 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00109328 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
2016-02-19 15:27 - 2016-02-19 15:27 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-04-07 02:53 - 2016-04-07 02:53 - 02853376 _____ () C:\Program Files\AVAST Software\Avast\defs\16040603\algo.dll
2016-02-19 15:27 - 2016-02-19 15:27 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-04-07 13:38 - 2016-04-07 13:38 - 02853376 _____ () C:\Program Files\AVAST Software\Avast\defs\16040700\algo.dll
2016-04-07 13:38 - 2016-04-07 13:38 - 00619840 _____ () C:\Users\Zajii\AppData\Local\Temp\0Kraken0502DevProps.dll
2014-06-04 11:51 - 2014-06-04 11:51 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
2015-04-16 20:07 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00105744 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
2014-06-04 11:43 - 2014-06-04 11:43 - 00102160 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
2016-01-27 13:19 - 2016-01-27 13:19 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-01-06 03:11 - 2016-01-06 03:11 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll
2016-03-28 21:11 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll
2014-12-12 23:20 - 2016-03-11 02:56 - 00783360 _____ () C:\Steam\SDL2.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 04962816 _____ () C:\Steam\v8.dll
2014-12-12 23:20 - 2016-03-31 22:55 - 02549840 _____ () C:\Steam\video.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 02549760 _____ () C:\Steam\libavcodec-56.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00491008 _____ () C:\Steam\libavformat-56.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00332800 _____ () C:\Steam\libavresample-2.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00442880 _____ () C:\Steam\libavutil-54.dll
2014-12-12 23:20 - 2016-02-09 01:14 - 00485888 _____ () C:\Steam\libswscale-3.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 01556992 _____ () C:\Steam\icui18n.dll
2015-01-20 15:51 - 2015-07-03 18:12 - 01187840 _____ () C:\Steam\icuuc.dll
2014-12-12 23:20 - 2016-03-31 22:55 - 00829008 _____ () C:\Steam\bin\chromehtml.DLL
2016-03-09 12:09 - 2016-02-18 00:25 - 00281088 _____ () C:\Steam\openvr_api.dll
2015-12-05 12:29 - 2016-02-09 03:33 - 48400672 _____ () C:\Steam\bin\libcef.dll
2015-12-05 12:29 - 2015-09-25 01:56 - 00119208 _____ () C:\Steam\winh264.dll
2015-12-21 09:55 - 2015-12-21 09:55 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
2016-02-19 15:25 - 2015-10-06 21:26 - 50656768 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll
2014-06-04 11:03 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-09-25 23:48 - 2015-09-25 23:48 - 00043656 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32api.pyd
2015-09-25 23:47 - 2015-09-25 23:47 - 00061576 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pywintypes27.dll
2015-09-25 23:47 - 2015-09-25 23:47 - 00127624 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pythoncom27.dll
2015-09-25 23:48 - 2015-09-25 23:48 - 00024200 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_multiprocessing.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00046728 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ctypes.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00027784 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32service.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00024712 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\servicemanager.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00031368 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_socket.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00445064 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ssl.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00288904 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_hashlib.pyd
2015-09-25 23:48 - 2015-09-25 23:48 - 00019080 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\select.pyd
2016-02-19 15:25 - 2015-10-06 21:26 - 01874944 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll
2016-02-19 15:25 - 2015-10-06 21:26 - 00075264 _____ () C:\Users\Zajii\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-22 08:05 - 2016-01-22 08:05 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\sony.com -> sony.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\123simsen.com -> www.123simsen.com

Da befinden sich 7866 mehr Seiten.


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Zajii\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{ac9f5b57-3e14-47e3-a8d4-5ea26c5ff75f}.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\StartupFolder: => "Inhaltsmanager-Assistent für PlayStation(R).lnk"
HKLM\...\StartupApproved\Run: => "PhoneCompanion"
HKLM\...\StartupApproved\Run: => "LogMeIn GUI"
HKLM\...\StartupApproved\Run: => "Connectify Hotspot"
HKLM\...\StartupApproved\Run: => "Start WingMan Profiler"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "Raptr"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "GarenaPlus"
HKU\S-1-5-21-3509251487-2946272100-3589144056-1001\...\StartupApproved\Run: => "BlueStacks Agent"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{30DEFFD4-DE91-4D9D-B8D7-B9CD0C4127A3}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [TCP Query User{4A11F7B4-950F-4C58-921B-3807F6BAED49}C:\program files (x86)\arxgaming\crossfire\updater.exe] => (Allow) C:\program files (x86)\arxgaming\crossfire\updater.exe
FirewallRules: [UDP Query User{B5D3EF40-7C0A-4348-937C-7AF9A12A06E7}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [TCP Query User{5712D6F8-44D4-4B0F-8884-817691407F12}C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe] => (Allow) C:\program files\ìúñ¶óîï·\´©ô½»ðïß\tcls\tenprotect\tensafe_1.exe
FirewallRules: [{2BD807AC-61A1-4E50-9D41-ECC9E3F1DB6F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{2218E877-F1F5-4C30-A009-D400B9B7400F}] => (Allow) C:\TGP\tgp_daemon.exe
FirewallRules: [{0BD08A28-CC08-45F5-9EB7-006E4AE9B67A}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{F97D9211-BA4E-4B0B-9755-F00834E75192}] => (Allow) C:\TGP\tcls\Tenio\TenioDL\TenioDL.exe
FirewallRules: [{B2196D47-9C07-4978-899D-45DACA814365}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [{7BE892A4-A86B-4EB1-AD11-12A56C65065E}] => (Allow) C:\TGP\tcls\tcls_core.exe
FirewallRules: [UDP Query User{2DDF5112-4515-456F-982B-990158D7962A}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [TCP Query User{2C577F25-9CAE-476E-B64D-2DE88BB362BC}C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe] => (Allow) C:\users\zajii\appdata\local\temp\qqgamedownloader\cf_1450185573_39835\teniodl.exe
FirewallRules: [{B245BAF5-7CA1-46F8-9479-642A849E88E1}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{BB1C1C28-F704-4222-9652-98E9A508D09F}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\QQGameDownloader\cf_1450185573_39835\MiniQQDL.exe
FirewallRules: [{FD464DCE-447B-44F4-91A2-AE81833F4425}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{FDD2E4D5-5A85-4464-948D-4E6704E72B82}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe
FirewallRules: [{F3F2037E-ECFA-4E0F-A0E1-85D3674419AF}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{DE24193E-6577-40F3-B27F-4CB205610933}] => (Allow) C:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [UDP Query User{32980F34-D1F1-4462-9461-336CC0746BAA}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [TCP Query User{FB27E516-C5F1-48D8-A1D8-FD7E52A6689C}C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe] => (Allow) C:\program files (x86)\garenamstartw\apps\mstartw\binaries\nurien.exe
FirewallRules: [UDP Query User{FB6742FD-A2D7-454B-A861-737E582C16E0}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [TCP Query User{2EB9ADEC-3907-499C-82CC-E22A6875EB5C}C:\program files (x86)\garena plus\updatemanager.exe] => (Allow) C:\program files (x86)\garena plus\updatemanager.exe
FirewallRules: [{BDAF2237-221F-476A-B493-4684E680C9C0}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{C3900ED8-7FF2-4982-8293-5CA0E499B6C7}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [UDP Query User{3A9DF6FF-7CF7-4484-ACED-984264A995A8}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [TCP Query User{F9C3A8BB-EC68-4CE9-8A92-2087F02D9B05}C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe] => (Allow) C:\steam\steamapps\common\battlefield 2\forgottenhope2.exe
FirewallRules: [UDP Query User{41DC094A-949C-481C-84E3-2989AC94A043}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [TCP Query User{B5A72C4A-D53D-4E27-A31B-33A0EC6B572A}C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe] => (Allow) C:\users\zajii\appdata\local\forgotten_hope\updater\fh2updater.exe
FirewallRules: [{542CA125-165D-4204-9DFF-F4C019039841}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{F6072883-B37B-4169-8F02-08212D80F90F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{17C99EFB-88D8-4C03-AB3C-A29E4119C400}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E81B3A94-6D42-4DF0-930A-338D0B08FCC6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B1906909-B1E7-4FB1-857D-E0E28AAA45DD}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{6D80DC10-D85D-4BAF-AB76-FC2129713534}] => (Allow) C:\GarenaDownload\Games\mstartw\MstarTWInstaller.exe
FirewallRules: [{A169D80B-5EF8-4631-9B0C-5CB2702D359C}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{956BAECA-6E5B-44B5-845F-6FFBE0900CB6}] => (Allow) C:\GarenaDownload\Games\mstar\MstarInstaller.exe
FirewallRules: [{D50F347B-2E4B-4F04-AF40-9522A5BE3442}] => (Allow) F:\Garena Plus\ggdllhost.exe
FirewallRules: [{22FC374D-4513-461D-8FCE-246BCD2E5D82}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EA64E4AA-2053-4450-9A70-E3CB971BF8F8}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe
FirewallRules: [{FDF59907-64CD-4D72-9A3D-902266B0D7AB}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [UDP Query User{92BEC967-EAF6-488A-BD74-B9F12B97BB4C}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{2A890CD3-CD4C-4D04-A435-0B883FB9CC92}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [{FE5E9C14-21FE-476C-8179-E1027B6481E0}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{235B915E-8395-4358-BFE3-2E5061C87E15}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{493E2AE4-75F8-4263-862B-5FB3C20B229F}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{A48F0780-5FDE-4070-B607-FFB2D99A7DDC}] => (Allow) C:\Steam\steamapps\common\mercenary_kings\MercenaryKings.exe
FirewallRules: [{827CCDEB-F70E-4BD4-ACC9-D9007E07CC51}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{7F09FF69-CAB0-4B27-BBFA-BDC193C18FDC}] => (Allow) C:\Steam\steamapps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{6CC3EF01-D900-495F-9763-C05144BDDFFE}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [{F8BECA90-83F1-47A0-9862-3954F8FC097E}] => (Allow) C:\Steam\steamapps\common\Pro Gamer Manager\PGM.exe
FirewallRules: [UDP Query User{3433385F-998B-43D1-92D8-8522FE3D8463}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [TCP Query User{6953C6AA-C545-48A3-AF5B-DC2FD2B85A5D}C:\sierra\empire earth\empire earth.exe] => (Allow) C:\sierra\empire earth\empire earth.exe
FirewallRules: [{FCBDA19C-B883-4FF8-84C2-ACA24FA072D8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{D0706688-74B6-4237-8F35-84F729D65322}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\server.exe
FirewallRules: [{3D01E816-2CC5-416A-8AFC-DD4CC1604F8C}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{379B5781-668C-4E8F-B329-E84CB1D23175}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{14A8700C-63AE-4F63-BA14-81A070274E88}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{974349E3-F0EA-4BC3-A306-46C9E15F4D1E}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\crashupload.exe
FirewallRules: [{9208EE21-EC0F-4C75-B084-96282752BAD3}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{D9A6B187-19DD-4270-94C6-22E97294C9EA}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{B9856D6B-53EA-43A3-8064-41CB4CB145B9}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{7C4BE1E2-669A-47B0-BC45-7C5553B74EF8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\crashupload.exe
FirewallRules: [{714F0F26-FF4F-4D66-AAE5-6BEA31AEDCE8}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{B08F7454-E8BC-49AE-A1BD-C170C624BD59}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x86\PA.exe
FirewallRules: [{7977A3E4-0EFB-4192-A069-FE795ADE9645}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{2CA0562E-CD08-4760-8500-A7563DAC84B7}] => (Allow) C:\Steam\steamapps\common\Planetary Annihilation\bin_x64\PA.exe
FirewallRules: [{455020EA-5BFB-4C1A-A7AF-4E9E6ABEA076}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{A813E2CD-340F-47E8-B37F-D11C9A62C01F}] => (Allow) C:\Steam\steamapps\common\Battlefield 2\BF2.exe
FirewallRules: [{B2390BF6-FDEA-4900-B629-39A6D78BDFD6}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{26CBC18F-7537-4622-B887-6BB7A0150C2B}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [UDP Query User{EBA5A158-C27D-4C67-B69B-C443763EE5B7}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{3B1ED3D4-3AEE-4B20-8720-A01E919BFFAC}C:\users\zajii\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\zajii\appdata\local\akamai\netsession_win.exe
FirewallRules: [{EBECDC52-5B6D-495B-A97E-47F98FC48615}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{78E53AE0-2E9F-4CB6-899E-A363F68BF5E6}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{29E48C3A-809B-4CFC-9BC1-793A0B42F608}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{C527E80B-4D0F-4BE0-AB51-946350D4F49F}] => (Allow) C:\Steam\steamapps\common\Sakura Clicker\Sakura Clicker.exe
FirewallRules: [{3ED3CAD3-9298-4265-B60D-A021ED8D99F3}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{1233BBCE-E7BB-4C2F-AD16-750F0E23E52D}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{6EF0B44D-E36F-484C-86CF-4A0F1C364896}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{597EA663-B9CE-4240-A51D-CF10EE2414BD}] => (Allow) C:\Program Files (x86)\SDGi Europe\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{EA82EEC9-7951-4036-AF8B-0255B3D6AF59}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{57EBBCCE-7BEC-4BFA-9D57-FBCA42B8665C}] => (Allow) C:\Steam\steamapps\common\Dragon Nest Europe\DragonNest\DragonNest.exe
FirewallRules: [{8D76408C-F28C-4F2F-BD43-6E1D84A83B88}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{F478326E-6D9C-42B0-9CAE-D8FA68806612}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{1839DEBB-EE03-4A06-ADB2-214E1FBB1DBB}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{F4FDF7DA-7837-42BD-8786-9BA6BFFE6ECF}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{97A04AA2-6F14-4BA5-B0A6-5D1DFEB2209A}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{8906D0CD-CBB0-4D12-B694-10BDB497C9BC}] => (Allow) C:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [UDP Query User{A514C6D2-A6CD-4F45-8F27-1970E9E0A9C2}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [TCP Query User{9C46FCB7-36BB-4B09-89BB-9E592F14AEBD}C:\program files (x86)\xenus 2\xenus.exe] => (Allow) C:\program files (x86)\xenus 2\xenus.exe
FirewallRules: [UDP Query User{EE01C6C7-092F-484D-960F-4C37BBB4FE9C}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [TCP Query User{D48472C9-D8CB-4E7A-97CE-B09C8D6CEB3F}C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe] => (Block) C:\program files (x86)\chasing carrots\cosmonautica\bin\cosmonautica.exe
FirewallRules: [{78B95254-C649-4B83-8E32-BEA9EF3623D8}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{97E48FF5-3134-4CBF-8EE2-BC8F5FE6F04E}] => (Allow) C:\Program Files (x86)\Chasing Carrots\Cosmonautica\bin\CosmoNautica.exe
FirewallRules: [{E0CED6BE-BCD5-4792-B478-AD7C2F2230E9}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{17F744A5-F086-4F3D-9892-C59B5E9164F7}] => (Allow) C:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{7A030D62-3E90-4A24-968A-08C8FE8674FE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{BF7F3009-07F4-4B93-B482-37A19BE57CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{38501A3C-7132-4B75-B69C-1FF89307C442}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{0982E365-1759-45EF-B6C5-025F5E7ECFA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{832C9998-25C8-4160-ABCD-1B8AE49D5E5B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6A27778E-7868-41B1-82F4-19895F00C829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{23311CA2-65F1-4C9F-A0F8-165BB34DCA0D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{A75D7163-D938-4C1E-8C1F-70133EB399F1}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{AA7B32DC-0CB1-488D-82D5-5DE80261370B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D6D6B32C-4532-48E1-9769-4BBE40ABC5D4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{9089980D-98A8-45BF-A38E-05E7E0863AB0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{6BBAAB49-7BD4-4B6D-A4AD-197392BCE60A}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{BEF756AD-818D-4D32-87E2-5A46CA514ADE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{CA66C22E-792D-4A35-AE2F-481130A42A72}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{0A77546B-4C5F-4AE5-95C2-185D51B5C192}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C5DDDC4F-04A8-4B54-BD78-74A57CBCF7D5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{33634B69-62A2-4D59-A06F-931839E174A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{ACA569CC-E477-4024-9BD1-C602F688F75F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{8162DA78-B1D6-4A40-9898-8E3A24D1AADB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{9F8E0927-2151-4B54-A8FF-CEE416C9225E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2E258D32-1F36-417E-954A-882B56D7F0EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{68253A36-6F85-4356-BEB7-060E0992ACEB}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{52A95E4F-AE58-4D3A-894E-95DD50089604}] => (Allow) E:\Users\AKB\Desktop\Steam\Steam.exe
FirewallRules: [{925936B6-689B-400C-BF9F-FF2E64161B72}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{31915966-137A-40FF-84CA-E452DA8E1B30}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{ED710C3D-5E1B-4F73-88D0-F68AE5B69D47}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{CF4F64D5-5DF6-4F15-8061-46FAD0D8CB87}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{5A47E627-2584-42BF-BEF0-9EAF369E560D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{04952BDF-066C-4F26-A130-D9B5907390B7}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{F4D5EECD-5E7E-474A-B13E-FE77647C5EDD}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [UDP Query User{9D26B6E2-2EF4-44BF-A1EC-E1789306C3BB}E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [{F6DA2570-377D-4F40-A7E6-F6F6DC91A423}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{A80E92D1-63C3-4F15-84D0-0DD06626DCD9}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{58A1F160-8BF3-4692-B0B1-DD42604C72D2}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [{08C49189-7B94-4959-82D6-EA1BB733794B}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\The Memory of Eldurim\EldurimLauncher.exe
FirewallRules: [TCP Query User{5854F5B4-70C8-4891-B33D-F2C5A968DE3F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{ED3F2885-91A8-4D11-B2E1-5F055E8E4D8F}E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) E:\users\akb\desktop\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{1F683D1B-177A-48E5-952E-A77F19741C48}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0198306B-2F9E-4D08-8D0C-C5F86F4D099A}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{0F20AA2D-F0C9-464C-B17D-860B2BD44DBA}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{1C104F92-EF1A-45C9-AC50-E35CCE72110E}] => (Allow) E:\Users\AKB\Desktop\Steam\SteamApps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{E7C2CD90-AB1C-4487-A376-579B359E5E6E}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{4BF2E089-8850-4E45-AFB1-B336DC4C9CAF}] => (Allow) C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{23C32BBA-1086-49BB-9B32-A58A7D0DD7E2}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{AFA20790-30A2-4776-9A06-1D99CD5BD2E3}] => (Allow) C:\Steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{A45BFEC0-9AF9-4B19-BA4C-9827F451DC86}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{241116BD-4BC8-456D-84AE-7A381A547F76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{38F453DC-BA63-4F97-B528-76BE2F35EE88}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{EF5B5934-BA0F-4C1F-B6B2-1AC8C37C801A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{055C710F-15F2-4547-B2EB-AA2A5192CF44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{1356908C-B1AD-4037-951A-39356F11C55D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{738897B7-BBDB-4105-888F-9667597C57A4}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{988A1F31-5E84-4B27-A536-2D88721AB108}] => (Allow) C:\Steam\steamapps\common\PlagueInc\PlagueIncEvolved.exe
FirewallRules: [{A5BF5871-70CA-4707-AA08-3EC606E42085}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{B0E5D8F2-814F-49F7-8F0C-63F63F072146}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_STEAM.exe
FirewallRules: [{00C79383-858B-4167-B69A-F0F176AEA612}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{2AEA3CFB-9548-4724-8A71-30D2926C06B5}] => (Allow) C:\Users\Zajii\AppData\Local\Temp\nsr3D43.tmp\CnetInstaller-75452123.exe
FirewallRules: [{F6DEB769-7389-4288-B477-DD4DE422D1BD}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{7E45C011-CBE9-423F-9FC6-455F4681E580}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [TCP Query User{332F2D2B-BD8C-487D-8FED-F196D64829CC}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [UDP Query User{41F9069D-B7F4-4A7E-96B0-FCB7E85F70F2}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [{6103FCDB-A8F2-4E4D-9EC3-F6B62721834C}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{58FA24B3-5F24-4F93-A7D8-02AF3676B87A}] => (Allow) C:\Steam\steamapps\common\the-haunted-hells-reach\Binaries\Win32\HauntedGame.exe
FirewallRules: [{EAF01A90-6DBC-47C4-BC64-282B6B1EE9A6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{18472ED1-1340-4794-B965-F409AC269BC6}] => (Allow) C:\Steam\steamapps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{958EC40D-7623-467E-A9E2-E24A62A2A84E}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{CDC3B77F-D7DC-47DF-BF00-B477F5E8BF96}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{B3C58D52-1E77-463C-9003-3D3EAA0B0870}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{4047ED26-96D1-48C0-9F90-A87ABEF5DC96}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [UDP Query User{31AB8790-7767-404A-AEF9-7A63F8385FA8}C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [TCP Query User{9ECCF799-8F34-4AB6-8C2E-F7ECB179D931}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [UDP Query User{A0D88D27-F971-4673-8CC2-E1FA01FB388B}C:\users\zajii\desktop\folder\load!\load.exe] => (Allow) C:\users\zajii\desktop\folder\load!\load.exe
FirewallRules: [TCP Query User{19B1780D-3D3F-4F34-956C-722801221C48}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{F22F36CC-4749-46AA-83A4-5B80D902390C}C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\eldurim\bin64\eldurim.exe
FirewallRules: [{6EB457BF-9E5A-43B6-8829-52029EF78612}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{56AC0D94-1717-42ED-BA7F-7EA81E26C271}] => (Allow) C:\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [TCP Query User{BFEAB654-09B9-4B79-BC5F-B6CAD5BEDFED}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [UDP Query User{FD356569-9339-4DC0-9388-F836816A28F9}C:\sierra\ee-zde\ee-aoc.exe] => (Allow) C:\sierra\ee-zde\ee-aoc.exe
FirewallRules: [{237E604C-464D-43CF-B274-1D131122CB19}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{D6885B0B-E93D-4AEE-A806-1F81BF2C23B2}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{35636838-6BA0-4393-858E-172436E06169}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{99884683-E0B5-4C1D-BB28-9132B224C4EB}] => (Allow) C:\Users\Zajii\Desktop\Folder\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F0C3402D-B2D0-4652-BBCE-A816B26D1075}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{D89FFF31-F0E2-4DA9-9D93-CC71E1470598}] => (Allow) C:\Steam\steamapps\common\Sengoku\Sengoku.exe
FirewallRules: [{3D8DA5A1-DB0A-4DB3-A789-941D17B3406A}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{CF50CC53-ABFB-44B6-A255-CE47F01DEE10}] => (Allow) C:\Steam\steamapps\common\SleepingDogs\HKShip.exe
FirewallRules: [{5799D77C-8DE7-409E-8A75-6E13441AF5B6}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{7AC69A3C-E370-40F4-9596-D7081032F312}] => (Allow) C:\Steam\steamapps\common\Starpoint Gemini 2\StarpointGemini2.exe
FirewallRules: [{CAA98664-150C-4430-AD38-E90C850ED0EF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{24840AE5-ABAD-46BA-954E-99492387A1B4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [TCP Query User{7542DC23-4B48-46AB-A30D-0EBA441ED68B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{68FEE79F-32BD-4384-8CD6-7A1E9C09E59A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{1723A352-5811-43A4-B27E-886EBEC6AC31}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{91BB7238-754A-4D03-8D2D-88829A49A76F}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{61CD7B64-66B1-4A21-8E3C-8A65053B9918}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{DD187142-2BC2-40B5-97F7-3C568BDC2F47}] => (Allow) C:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [TCP Query User{EFCC2F76-7105-4F8D-95DE-0E42656E6554}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{A122EF9D-0B8E-4009-90F4-07D2740B5B9E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{34FCB7B2-6BC8-480B-885F-82FCE2B734FC}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{6855A661-8C68-4FB4-AC11-F6A9970E789E}] => (Allow) C:\Steam\steamapps\common\Minimum\Binaries\Win32\MinGame-Win32-F.exe
FirewallRules: [{C6034756-89AB-420D-A2CB-856189DA06E7}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{794418FB-F943-4D84-9020-37A43C9B5349}] => (Allow) C:\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{9D3CA53D-DD67-40B6-8FE2-1FD247B960ED}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{173E1908-0728-4043-8A1E-54DBE9F061A1}] => (Allow) C:\Program Files (x86)\DanuSoft\WiFi HotSpot Creator\WiFi HotSpot Creator.exe
FirewallRules: [{067DCD95-2DC2-4B87-B54B-092751525963}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [{2C4716AA-8256-4FEE-A620-941699850659}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe
FirewallRules: [TCP Query User{2AA1D0DF-E1E7-4B12-8000-4D97C6DB488B}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [UDP Query User{C73D0B89-3680-4552-809B-794538E3D3EA}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [{09307100-ACB0-4723-B536-CEB27F44A180}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{31D70A1D-E189-4303-A301-C5B652D49B51}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{20C8830A-DE61-428B-8214-2E5716153101}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{F9F96A77-57B4-4AA8-B975-3B87F9FC2633}] => (Allow) C:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [TCP Query User{83CA9FA4-5630-4E3A-BBF9-2DE9C8AB1D14}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [UDP Query User{3CFDF23F-5B5E-4A65-B42A-7FA76DB77D01}C:\users\zajii\desktop\starcraft\starcraft.exe] => (Allow) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{4EFB4AC4-014B-4A14-99B7-1D5775504C57}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{526759C4-847C-4D82-A340-AF7899987A8C}] => (Block) C:\users\zajii\desktop\starcraft\starcraft.exe
FirewallRules: [{CACB995C-7D60-4D4F-8842-C6DA982C9E0F}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{759F004D-D716-4B72-B13D-D5987B5DE151}] => (Allow) C:\Steam\steamapps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{9AA9A533-EEBC-4CF0-862A-C3757050CB11}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{67223693-F287-4732-9103-79B431D1B62A}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{948D2A54-6B27-4E1A-99C4-22B75DE8F377}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\PortRoyale3.exe
FirewallRules: [{9A1A964D-23B4-422E-8970-F33471CF9087}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [{BF88DF40-D537-441D-8025-8DFBC77BE354}] => (Allow) C:\Program Files (x86)\Kalypso Media\Port Royale 3\AppData.exe
FirewallRules: [TCP Query User{72D378FC-7561-4961-BB84-9B6B2177E544}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [UDP Query User{9BFF971D-9E69-4182-B293-B948648BB740}C:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{172452BA-C5C1-4312-AB43-1D7B1988DEDA}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{BC49D58D-38D1-4F1C-B262-8EE9FD689AF7}] => (Block) C:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [TCP Query User{55A7B1FF-B609-4889-8732-EC08E5A513A9}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [UDP Query User{FF4B80B8-CED0-4D75-A48F-25E3E7AA4B23}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{79CD9685-CC69-403B-BCD7-DF6FEAC1757D}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{0AE7AADE-9994-4F0A-987D-37ED73A17B2C}] => (Block) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{E38D05B7-2F46-489A-8683-F811359A4E06}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [{74F31389-37BE-4381-B235-CEDC3470388F}] => (Allow) C:\Steam\steamapps\common\Might & Magic - Duel of Champions\Game.exe
FirewallRules: [TCP Query User{41703D9D-661D-47A0-A3F8-F503B23ED9EC}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{C6FDDC91-1CD9-4428-B60B-C2D62FA9219F}C:\users\zajii\desktop\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{1ADFB71E-7B76-4947-B41A-7BA52D26FE04}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [{6424B77F-8EA5-40E7-82C4-BA6590B90CEE}] => (Block) C:\users\zajii\desktop\grim dawn\grim dawn.exe
FirewallRules: [TCP Query User{32B27FEE-C3BC-4CCF-A607-04AF472BBEAF}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{BDC0822B-FBFC-449D-978B-6F43762E81DD}C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe] => (Allow) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B73588C8-2837-40E6-B04A-FFD299D06168}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{B0E45B03-0555-479D-A7DC-B6EFB23BF545}] => (Block) C:\users\zajii\desktop\grim.dawn\grim dawn\grim dawn.exe
FirewallRules: [{AA49D381-A29E-482D-953A-D3A3EA254B69}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{5DE14359-41CD-4128-ACCA-9E4D78E4AAB9}] => (Allow) C:\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe
FirewallRules: [{B2211614-4525-493F-BDDF-678477260A1F}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{FAA77B61-5DFA-472E-AF32-16A491103363}] => (Allow) C:\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [TCP Query User{D63EE533-14AB-4403-9484-B9C39F3849CB}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [UDP Query User{CBE3B3F9-AF98-490A-8635-1D9DD6015066}C:\users\zajii\desktop\windward\windward.exe] => (Allow) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{1A057970-C841-48AD-8409-D28585AC428D}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [{EC3CC678-1FB9-4AD4-91E4-FA1EAF67B6D0}] => (Block) C:\users\zajii\desktop\windward\windward.exe
FirewallRules: [TCP Query User{3EF79DB1-2E04-43EA-8206-590ED259170F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [UDP Query User{E708367C-C1C8-42BD-9179-0B4078C8913F}C:\users\zajii\desktop\windward\wwserver.exe] => (Allow) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{074F08E8-06E8-43BF-9D41-1E142803DD99}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [{E7E95DD4-8C6E-4EDB-BD1B-512538AF1731}] => (Block) C:\users\zajii\desktop\windward\wwserver.exe
FirewallRules: [TCP Query User{293E354C-5804-48AE-B0AA-EFBDD12ABB38}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [UDP Query User{896497D6-3297-4A17-9DE5-D9FE9573B411}C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe] => (Allow) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{71528445-E2F0-4C00-B7B7-21D83ABF0776}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [{C48D9CF9-B590-4EED-81B9-CCA3D7121A1F}] => (Block) C:\users\zajii\desktop\lol\[www.gigapurbalingga.com]_counter-strike 1.6 pb\hl.exe
FirewallRules: [TCP Query User{01DC08CD-5C8E-4E5E-942F-70D7390D7707}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{58AA1266-4D02-456D-BDEE-E28F4FA1304C}C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{0D30D21D-A7AF-4160-8A02-3925F6D13CCF}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [{27A5EB48-610A-4FBE-9C82-A3B1183EBE2F}] => (Block) C:\users\zajii\desktop\1\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{E27C8B0B-A722-4F88-B1A0-F8CF06A822B3}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [UDP Query User{FE6F006D-658D-4998-942D-C768C184A34B}C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe] => (Allow) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{F97BE72F-4E36-46D9-89B0-471FA3DB2B6B}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [{1325E053-AE6E-48F4-A839-E7AA7E4BD763}] => (Block) C:\users\zajii\desktop\2\compete-king viet nam\cstrike.exe
FirewallRules: [TCP Query User{0ED789FA-C6AA-479C-9843-B6216C1B42E2}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [UDP Query User{BE0B3CF2-5367-4AA4-94C3-F1200FEFB3A5}C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{EAC26110-CCB3-4226-86C3-A7B861259787}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{E47EA53B-6516-4DFE-86C7-DF30590A2B6C}] => (Block) C:\users\zajii\desktop\csscf\counter-strike soucre\hl2.exe
FirewallRules: [{05311AF7-DC4B-4224-9998-E896498929D6}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{0A787DAA-155A-4285-8749-434EF2D186E8}] => (Allow) C:\Steam\steamapps\common\Nightbanes\Nightbanes.exe
FirewallRules: [{6FF25DAF-F94A-4A3F-BCE0-EDF3395108D4}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{0991702B-9E61-4C34-A1DB-1CEC76E3EAB7}] => (Allow) C:\Steam\steamapps\common\Hitman Absolution\HMA.exe
FirewallRules: [{D0CA0907-6494-4B38-8F79-429D55D05602}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E9D8FBE8-BCB3-4233-8BF7-DB86D5C93FEE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{4B0426E9-F5F0-4414-91A7-56ADFC7CE012}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4A12C2E6-E237-4987-9DA7-805AECA644ED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A70DF44D-BE0D-4F81-84FA-71351F2D3FE7}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{BBB3C2A2-1A91-4772-A666-B3546F16338E}] => (Allow) C:\Steam\steamapps\common\Arms Dealer\Arms Dealer.exe
FirewallRules: [{614F0CC8-B127-4549-ADD8-80C03E1C9EF8}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{3B2A436D-FA3E-480C-9853-BD5D06ED2675}] => (Allow) C:\Steam\steamapps\common\Kenshi\kenshi_x64.exe
FirewallRules: [{2362E8FE-3394-4995-84A4-15221104EF8E}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{27842C51-5BD9-4398-9220-1E08C1B92E86}] => (Allow) C:\Steam\steamapps\common\Recettear\recettear.exe
FirewallRules: [{D2359EAB-31EC-4C14-9E7A-1F630A23755F}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{27761867-D387-45C1-AB8B-991E6192DBA5}] => (Allow) C:\Steam\steamapps\common\Recettear\custom.exe
FirewallRules: [{7A4A16EA-A2F6-4411-8D5B-79FCA5FA77F9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{B0F14B3E-BD11-429C-9F65-324D99C96DF1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{4C24124B-B739-40C5-A761-07F6A4439A59}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{60127749-9D51-4545-87FF-4ABB89789221}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{69DE4671-62FF-493A-BFFD-820E182CE47E}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{2C029895-F2DB-4B28-B376-9C4D510008B0}C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{3C72A5C5-3AFD-444F-9191-22575E2E9784}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{E04010BB-921B-4D51-8447-2D8D0C9D4805}] => (Block) C:\users\zajii\desktop\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{2CA03720-94A3-4AC4-BC02-40E385F8588F}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{FAB48BE7-661A-4E79-BBEA-DF6CDA856DD3}] => (Allow) C:\Steam\steamapps\common\Lords of the Black Sun\Lords of the Black Sun.exe
FirewallRules: [{5DF3072E-5BF1-4616-B7DE-E068258AED1C}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{31F1D687-0053-419C-BA5F-15EC20B34606}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{CA17DA8E-D015-494D-89C7-DDC14D4D31AC}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{5798E9CD-6FD2-43B1-A4CE-BDF9310F4CE4}] => (Allow) C:\Steam\steamapps\common\Anno 2070\Anno5.exe
FirewallRules: [{318E2267-C73B-4BB5-B1D6-99B37AA5AC69}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [{5BB41834-E289-4D77-9EC6-FDC433F17B68}] => (Allow) C:\Steam\steamapps\common\Epic Cards Battle\game.exe
FirewallRules: [UDP Query User{795BFA73-AD8B-4BF3-9443-9D1F78C2D659}C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{850DA4D9-5FE1-4526-8966-F24E3E45ED0D}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{A04B7ED5-40E5-44F5-B98F-F500E0D2A195}] => (Block) C:\users\zajii\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [TCP Query User{DABC388E-BDFE-46A6-B7F7-EEB566927796}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{CA3A5CF1-488A-473F-A5A9-6C54D42878D7}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [TCP Query User{FCF5DFBA-DCFB-4D37-84C2-0C6E3F79949B}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [UDP Query User{ECCD9FAC-0D13-4E19-B96C-B9FCDFE66928}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{0E57631F-20D7-47B3-81A5-0108F99534DB}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{16AB64BE-4BD0-47ED-AB8B-26873A1BB885}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [TCP Query User{F19DAD89-5696-4476-9054-D9890A54D702}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{41B4451D-2681-4933-A44D-727A3C41917A}C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe] => (Allow) C:\users\zajii\desktop\folder\csscf\csscfe 3.0\counter-strike source\hl2.exe
FirewallRules: [{025D539C-793E-4563-A404-CED0229F1765}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{27246065-AFB1-4067-927E-BD0C647EA733}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{EBD13D25-1AC6-4B0F-908D-DAA1B980D6A2}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{A8073EA4-C457-4B50-86C8-8C9800CC3815}] => (Allow) C:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{00DAD404-E45D-4D6A-B06B-B63D368F8C43}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [{F70B8050-2C54-45B1-88AB-9A638C9B7A5D}] => (Allow) C:\Steam\steamapps\common\Down To One\DownToOne.exe
FirewallRules: [TCP Query User{0420A509-0102-4B15-8D47-DD32DCB94DE4}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [UDP Query User{CC8B5AB4-19D0-41A3-A004-C8A003A83AC3}C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe] => (Allow) C:\steam\steamapps\common\the memory of eldurim\bin64\eldurim.exe
FirewallRules: [{C2EFE247-C8DA-4DC7-B3F3-43E76F7B8DB3}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{67242512-47BE-4EE6-86BE-ED5BE96DD867}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe
FirewallRules: [{FFA2C96F-E725-4621-A38B-B8FABB958053}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{7C4DE9F1-3EE7-4C6F-8ACD-584144F0D69A}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe
FirewallRules: [{0FC00518-E904-4193-81DC-61A997CC1C1F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{75811BB4-CC3E-4936-8C26-AF0D9D5CE25F}] => (Allow) C:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe
FirewallRules: [{EE89DB99-21EF-44B1-8EB9-2ABB2AC1AF6A}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{BA85DBC9-5BB8-40FE-A8C1-5A8086F5FB6C}] => (Allow) C:\Steam\steamapps\common\Magic 2015\DotP_D15.exe
FirewallRules: [{182BEA0B-6955-4C2E-AAA1-14E17D4C9381}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{B3EB731A-11B0-4506-8C0E-CA67804CF6DB}] => (Allow) C:\Steam\steamapps\common\Survivalist\Survivalist.exe
FirewallRules: [{4E6926C9-B988-4F1D-BEE2-12CB63AD5F50}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{2E6B4FFA-3B05-40F9-AAB1-C2F9E45A2533}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{66CD1E5C-468A-4C7C-8D9E-95C4B170E612}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{834D81D4-522F-47A6-B102-DBDC283FB29C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{20FFBC4A-28A4-4059-89BA-79F670B1269C}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{D9A57113-2991-4288-97D0-4744CCDABD0D}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{7047C0FD-1FFC-49AE-B264-4050B3E4BD30}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{5181F86F-9A3D-4AC4-A251-FCC6858B2B84}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{93AF4F24-A2EA-4940-9535-80F31CFD7164}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{4DC07C9F-93AF-4AB8-8B20-1187962FEA5C}] => (Allow) C:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{B4561176-2009-43DD-B17E-AEF573DC039F}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{8BCACF5D-7F18-4F67-994E-318E735AE61A}] => (Allow) C:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [TCP Query User{D2200830-3408-4D28-8A9E-ECF35E6BB9D0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{ED6933DE-3CA2-43A6-8C7D-6CD7FA3CB9DA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{B9509ADC-9BED-45D1-9607-156C724E7ED4}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{C1AF6F72-F529-4F3E-9F87-A97E346FA7C9}] => (Allow) C:\Program Files\EslWire\wire.exe
FirewallRules: [{F047781B-85C2-425B-8DB1-75218CF4EA74}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{13FF6063-D805-4D2C-AC09-FE958322C599}] => (Allow) C:\Steam\steamapps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{F41378B0-0003-4B03-AED6-1A8F45AFBA9A}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{F4A0185F-2DA5-466F-A3DA-F6F0763B3DCD}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe
FirewallRules: [{3E16EA7A-A426-4B4B-9AF4-1B8DD131A487}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{CD7E9FA0-1B58-4CE6-833A-3D514DF0A3EA}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe
FirewallRules: [{8BED7967-FDB8-4335-A733-9AC80CFE6D27}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{BC173635-2461-4073-ADE1-4E094CC33D68}] => (Allow) C:\Steam\steamapps\common\Tempest\Tempest.exe
FirewallRules: [{4D6CADAA-C9ED-42A4-9328-2D6381DC1D1A}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{53FED05C-D779-4EDD-A6B5-107E366070B9}] => (Allow) C:\Steam\steamapps\common\Planet Explorers\PE_Launcher.exe
FirewallRules: [{2386C911-D306-4B77-A138-DD84675CB4FF}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [{8170C9E0-102E-4277-90BF-E310DA4E8095}] => (Allow) C:\Steam\steamapps\common\Guardians of Orion\Orion.exe
FirewallRules: [TCP Query User{54D32260-49DC-4C41-AAAA-4F3278E0D515}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [UDP Query User{CD4B5BE7-AA3D-4D8B-BEEE-A6434C5A35AC}C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) C:\steam\steamapps\common\guardians of orion\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [{1DD17D34-6043-4A5F-9103-8ADE86A696BE}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{48221BF8-1E21-43BC-8EBB-E49643B66255}] => (Allow) C:\Steam\steamapps\common\Spellweaver\Spellweaver.exe
FirewallRules: [{3E44E2C9-2FB8-465A-8D9E-6CCD1D9FACBF}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{09CC9F19-A706-46EB-AAF3-2E497D634C4D}] => (Allow) C:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [TCP Query User{24D43A00-F22E-47B2-8E73-B96F3ABCEB88}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [UDP Query User{D3B8A57F-69D6-4E36-9154-880CBB97CDE0}C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [{3E72F93A-16BC-4358-AA43-01BE4317E52A}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{E2DD930C-6848-4A78-9D3F-21FDFA627221}] => (Allow) C:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [TCP Query User{98631710-DB66-457F-A484-370D6C0BF3CE}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [UDP Query User{03C65720-F504-4CE8-83E8-1B33F052311B}C:\program files (x86)\cockatrice\servatrice.exe] => (Allow) C:\program files (x86)\cockatrice\servatrice.exe
FirewallRules: [TCP Query User{0FFCBE29-C5C6-4BE4-8332-36D799F71C75}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [UDP Query User{9B09C988-D0EF-4EEE-B749-1BA5A3682C9B}C:\steam\steamapps\common\steamcabal\launcher\launcher.exe] => (Allow) C:\steam\steamapps\common\steamcabal\launcher\launcher.exe
FirewallRules: [{A6171E46-6F74-453D-878E-4C911DC74BC1}] => (Allow) C:\Program Files (x86)\Droid4X\MultiMgr.exe
FirewallRules: [{552E4A00-D64F-4BB8-8699-6A5BA6534145}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{2D12DA52-237D-4D0F-9B7E-582B82C22946}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{F35FFA25-BF15-4174-B2AF-3D211EF36D96}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [{74E4D161-3E1B-42A8-B837-AEAAACAE3EBC}] => (Allow) C:\Steam\steamapps\common\Omerta\OmertaSteam.exe
FirewallRules: [TCP Query User{7DABBA1B-4A2A-41A7-9725-48884E9DF7CC}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [UDP Query User{2A02C7F3-2375-45DF-AC12-E26D134B0D92}C:\steam\steamapps\common\planet explorers\pe_client.exe] => (Allow) C:\steam\steamapps\common\planet explorers\pe_client.exe
FirewallRules: [{C51034D5-8151-441D-A9D7-6F6DBB9BF6EC}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{F01285DF-7301-4B1B-8170-EAEA19AFD022}] => (Allow) C:\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{E92ED011-1526-447A-9CBF-58867AEB02F7}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [{548F583E-CA26-4D1B-841D-0B3319E19068}] => (Allow) C:\Steam\steamapps\common\Star Realms\StarRealms.exe
FirewallRules: [TCP Query User{964A15E2-BAE9-4277-B29C-CF755D6E905C}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [UDP Query User{84BF4C74-FFC8-4E18-9EF3-E7A6148A6368}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Allow) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [{62E586FA-BFA1-408D-8F31-7A9D01AB1B89}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{64D80FAF-A7BF-49CE-9BE0-E8544F835579}] => (Allow) C:\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe
FirewallRules: [{A6B5673C-718E-47D4-95B9-C202C570DA34}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{C16A8F91-19E2-402C-BE7B-D0581C68D625}] => (Allow) C:\Steam\steamapps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe
FirewallRules: [{0DB8B42F-59BE-48B8-B44B-FCB9A0DA5BE8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{A84C8CE8-4469-4C06-9AC7-87EE038BFDA8}] => (Allow) C:\Steam\steamapps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{756B27DC-E69B-43ED-9A4D-91F29CC41267}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{C6A2A01C-FFAE-477B-9DDA-C6E85E102000}] => (Allow) C:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{36C7DE15-9919-4DB1-AB37-784AC147A7C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7F98D5C7-523F-4665-AEBF-DF3C7E9609B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E9D2A775-E528-44DB-904E-F55D327ABA32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AEA8DB0D-4A1E-458B-928C-E97FF9980A36}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6BC7BD75-9E81-4C0F-B2B9-B3608D4E3C86}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{124EAD6D-953A-40D4-B784-7094D523B660}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe
FirewallRules: [{0213AE30-CEA2-43FB-A4CE-E09573D2B084}] => (Allow) C:\Steam\steamapps\common\Faeria\Faeria.exe
FirewallRules: [{8D462A59-4F7C-4668-A033-ACF56ECA0851}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{206966F0-FDBC-41DD-84C0-A12DAFAD471D}] => (Allow) C:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe

==================== Wiederherstellungspunkte =========================

30-03-2016 11:23:12 Removed Windows 7 USB/DVD Download Tool
05-04-2016 22:07:03 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/07/2016 01:53:51 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (04/06/2016 12:02:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203
Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb
Ausnahmecode: 0xc0000094
Fehleroffset: 0x00016a0c
ID des fehlerhaften Prozesses: 0x1c58
Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0
Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1
Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2
Berichtskennung: RazerIngameEngine.exe3
Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5

Error: (04/05/2016 11:28:06 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/05/2016 10:07:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/05/2016 08:09:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZAJI)
Description: Bei der Aktivierung der App „Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (04/05/2016 05:27:46 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (04/05/2016 04:39:18 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/05/2016 01:16:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RazerIngameEngine.exe, Version: 1.0.12.8578, Zeitstempel: 0x566f4203
Name des fehlerhaften Moduls: RazerOvlInput.dll, Version: 1.0.12.8578, Zeitstempel: 0x566f41cb
Ausnahmecode: 0xc0000094
Fehleroffset: 0x00016a0c
ID des fehlerhaften Prozesses: 0x2354
Startzeit der fehlerhaften Anwendung: 0xRazerIngameEngine.exe0
Pfad der fehlerhaften Anwendung: RazerIngameEngine.exe1
Pfad des fehlerhaften Moduls: RazerIngameEngine.exe2
Berichtskennung: RazerIngameEngine.exe3
Vollständiger Name des fehlerhaften Pakets: RazerIngameEngine.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: RazerIngameEngine.exe5

Error: (04/04/2016 08:34:06 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

Error: (04/04/2016 08:33:23 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.


Systemfehler:
=============
Error: (04/07/2016 01:43:45 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Manager für heruntergeladene Karten" wurde nicht richtig gestartet.

Error: (04/07/2016 01:42:22 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:22 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:22 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/07/2016 01:42:21 PM) (Source: DCOM) (EventID: 10016) (User: ZAJI)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}ZajiZajiiS-1-5-21-3509251487-2946272100-3589144056-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742


CodeIntegrity:
===================================
  Date: 2016-03-24 02:26:58.699
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-23 04:00:10.692
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-22 14:17:50.313
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 18:18:45.659
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 14:34:08.548
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-10 10:17:26.727
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-03 12:41:33.511
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-02 15:35:16.954
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 17:56:24.126
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 07:03:27.892
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 25%
Installierter physikalischer RAM: 12196.01 MB
Verfügbarer physikalischer RAM: 9083.18 MB
Summe virtueller Speicher: 24484.01 MB
Verfügbarer virtueller Speicher: 20972.6 MB

==================== Laufwerke ================================

Drive c: (Windows8_OS) (Fixed) (Total:889.19 GB) (Free:445.34 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.07 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B577EEF3)

Partition: GPT.

==================== Ende von Addition.txt ============================
         

Alt 08.04.2016, 20:26   #14
burningice
/// Malwareteam
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Java
Du hast eine veraltete Version von Java installiert.
Bitte aktualisiere sie oder entferne Java gleich komplett von deinem PC. In nur sehr seltenen Fällen benötigt man das Programm wirklich auf dem Rechner - deshalb meine Empfehlung: Behalte Java nur auf deinem Computer wenn du es wirklich benötigst, dann halte es jedoch stets aktuell.


Die Logs von deinem Rechner sehen jetzt für mich sauber aus: Herzlichen Glückwunsch - du bist Clean



Zum Schluss müssen wir noch etwas aufräumen und ich gebe dir ein paar Hinweise mit auf den Weg:

Wichtig: Entfernen der verwendeten Tools
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.

Malwarebytes Anti-Malware und ESET kannst du als Ergänzung zu deiner bestehenden Antivirus-Lösung auf dem Computer belassen und deinen Computer damit regelmäßig scannen.


Persönliche Empfehlungen
Das wichtigste zu erst:
  • Aktiviere unbedingt die automatischen Updates von Windows und stelle auch sicher, dass diese regelmäßig installiert werden.
  • Aktiviere immer eine Firewall - die in Windows integrierte reicht dazu vollkommen aus.
  • Verwende immer ein Antivirenprogramm und stelle sicher, dass es sich regelmäßig aktualisiert.

    Wenn du kein Geld ausgeben möchtest, empfehle ich dir auf Windows 8.1 bzw. Windows 10 einfach den Defender zu benutzen. Solltest du noch Windows 7 verwenden, verwende als kostenlose Lösung die Microsoft Security Essentials.

    Wenn dir etwas besserer Schutz mit Verhaltenserkennung etwas wert ist, um so auch optimalerweise ganz neue Schadsoftware zu erkennen, empfehle ich dir eine der beiden folgenden Lösungen:


Schutz vor unerwünschter Software
Adware ist zu einer Art permanenten Bedrohung geworden, weil immer mehr Programme versuchen, einem beim Installieren noch was anderes unterzujubeln - und wie schnell hat man da ein Häkchen übersehen?

Darum: pass auf, wenn du dir Software aus dem Internet herunterlädst! Viele Portale im Internet wie Chip, Softonic und Sourceforge versuchen häufig, dir Adware oder sonstige Downloader mit unerwünschten Programmen unterzujubeln. Downloade nach Möglichkeit immer direkt von der Herstellerseite oder alternativ von einem sauberen Download-Portal, wie von FilePony.de.
Lese dir dazu auch folgenden Artikel durch: CHIP-Installer - was ist das? - Anleitungen

Selbst wenn du ein Programm von einer seriösen Quelle heruntergeladen hast, ist das keine Garantie, dass dein Programm nicht doch versucht, unerwünschte Änderungen an deinem Computer vorzunehmen. So versuchen immer mehr Programme, durch modifizierte Installationsroutinen unerwünschte Programme mit auf deinen PC zu schleusen. Das klappt leider auch häufig, weil viele Anwender nicht lesen, was auf dem Bildschirm steht und stattdessen schnell durchklicken.
Deshalb: Wenn du ein Programm installierst, wähle immer die benutzerdefinierte Installation und schaue, was du da gerade eigentlich alles mit einem Klick auf "Ok" oder "Weiter" abnickst - entferne entsprechend die Haken bei Dingen, die du nicht möchtest. Wer lesen kann, ist klar im Vorteil!

Benutze keine Optimizer, Cleaner oder sonstige SpeedUp Wunder, da diese Tools fast nie einen auch nur messbaren Performancegewinn bringen.
Du kannst jedoch regelmäßig auf deinem PC die Datenträgerbereinigung ausführen, so gewinnst du belegten Speicherplatz zurück.

Aktiviere in deiner Virenschutzlösungen den "Schutz vor potentiell unerwünschter Software", um dich bestmöglich zu schützen.

Guter Trick: Wenn du den kostenlosen Windows Defender benutzt (ab Windows 8), kannst du einen vergleichbaren Schutz durch einen kleinen Trick auch nutzen! Lese dazu folgenden Artikel um dich mehr zu informieren: Windows mit verstecktem Adware-Killer
Zum aktivieren dieses "Tricks" lade einfach nur diese Datei und führe sie aus: MpEnablePlus.reg

Tipps, um dein System sicherer zu machen
Halte immer deine Plug-ins und Software, insbesondere deinen Browser aktuell. Deinstalliere wenn möglich Java und den Adobe Flashplayer von deinem Computer. Neuerdings benötigt man sie fast nie mehr und stellen darum nur mehr eine unnötige Sicherheitslücke auf deinem Computer dar. Wenn du sie doch unbedingt benötigst, halte sie aber unbedingt aktuell.

Weiters kannst du dir Malwarebytes Anti-Exploit installieren. Es schützt gegen viele aktuelle Sicherheitslücken und erhöht so deine Sicherheit.

Passwörter
Ändere regelmäßig deine Passwörter! Zudem musst du sichere Passwörter benutzen, das bedeutet: mindestens 8 Zeichen, Groß- und Kleinbuchstaben und Sonderzeichen.
Ganz wichtig: benutze pro Account ein anderes Passwort!
Tipp: Benutze einen Spruch, den du dir leicht merken kannst, als Hilfe für ein Passwort! Zum Beispiel: Der Himmel ist blau und wenn es regnet?-grau ==> DHibuwer?-grau


Unterstütze uns und empfiehl uns weiter

Du kennst Freunde und Bekannte, die Probleme mit ihrem Computer haben? Schick sie doch zu uns auf das Trojaner Board, wir helfen gerne

Wenn du uns mit einer Spende unterstützen möchtest, freuen wir uns sehr und dies kannst du hier tun: http://www.trojaner-board.de/79994-s...ndenkonto.html Herzlichen Dank dafür

Wir machen diese Tätigkeit hier freiwillig, darum freue ich mich besonders über ein kurzes Danke, wenn du mit mir zufrieden warest oder sonst über Verbesserungsvorschläge - das kannst du gerne hier machen

Besuche und like unsere Facebook-Seite!


Danke für deine Mitarbeit und alles Gute!

Bitte gib mir Bescheid, wenn du das alles gelesen hast und du keine weiteren Fragen mehr hast.
__________________
Mfg,
Rafael

~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~

Unterstütze uns mit einer Spende
......... Lob, Kritik oder Wünsche .........
.......... Folge uns auf Facebook ..........

Alt 09.04.2016, 00:46   #15
Zaji
 
GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Standard

GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall



Dass hört sich ja super an!

Da lasse ich doch ein großes Danke da, vielen Dank dass ihr euch Zeit für mich genommen habt, TOP Arbeit!

Ich werde definitiv ne kleine Spende da lassen


MfG

Zaji

Antwort

Themen zu GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall
akamai, antivirus, avast, bluestacks, bonjour, computer, defender, dnsapi.dll, email, flash player, frage, giropay24, google, home, installation, kuaizip, mozilla, prozesse, realtek, registry, rundll, scan, security, software, svchost.exe, system, trojaner/virus, updates, windows, windowsapps, wlan




Ähnliche Themen: GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall


  1. Email-Anhang mit Virus geöffnet
    Log-Analyse und Auswertung - 29.12.2015 (3)
  2. DHL-Trojaner-EMail mit PDF-Anhang geöffnet
    Log-Analyse und Auswertung - 17.05.2015 (7)
  3. Anhang (zip) von gefälschter Email geöffnet - Trojaner eingefangen?
    Plagegeister aller Art und deren Bekämpfung - 13.05.2015 (1)
  4. Windows 7: vodafone-Rechung Anhang geöffnet Trojaner/Viren
    Log-Analyse und Auswertung - 14.12.2014 (13)
  5. Anhang von falscher Zalando-Email geöffnet, Virus oder Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 18.11.2014 (11)
  6. Fake E-Mail mit anhang erhalten. Dummerweise (.zip) datei heruntergeladen aber nicht geöffnet.
    Plagegeister aller Art und deren Bekämpfung - 08.08.2014 (16)
  7. Anhang in einer Email geöffnet, Zip-Datei ausversehen ausgeführt, jetzt deutliche Leistungseinbußen, Trojaner
    Plagegeister aller Art und deren Bekämpfung - 24.07.2014 (13)
  8. Windows 8.1 32bit Email der Anwalt Ebay GmbH Anhang geöffnet -> Trojaner?
    Log-Analyse und Auswertung - 09.07.2014 (13)
  9. Komischer Mail Anhang geöffnet und unsicher
    Smartphone, Tablet & Handy Security - 21.03.2014 (1)
  10. MAC OSX 10.7.5 Trojaner.GenericKD. Email-ZIP-Anhang geöffnet.
    Plagegeister aller Art und deren Bekämpfung - 03.10.2013 (3)
  11. verseuchte email mit zip anhang geöffnet
    Plagegeister aller Art und deren Bekämpfung - 01.09.2013 (29)
  12. Ominöser Email-Anhang geöffnet
    Log-Analyse und Auswertung - 26.08.2013 (9)
  13. Verdächtigen e-mail Anhang heruntergeladen, aber nicht geöffnet: Ist das gefährlich?
    Alles rund um Mac OSX & Linux - 17.05.2013 (31)
  14. Email-Anhang (ZIP) geöffnet
    Log-Analyse und Auswertung - 18.04.2013 (1)
  15. Anhang von Fake-Groupon-Email geöffnet - Trojaner
    Log-Analyse und Auswertung - 11.03.2013 (11)
  16. Email Anhang geöffnet!
    Log-Analyse und Auswertung - 11.03.2013 (44)
  17. Email-Anhang (.zip Datei) geöffnet; Gefälschte Email über Mahngebühren
    Log-Analyse und Auswertung - 25.02.2013 (19)

Zum Thema GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall - Ich habe heute eine Mail von GiroPay24 bekommen, welche sich für mich erst im nachhinein als Spam/Phishing Mail rausstellte. Nun habe ich aber schon den Anhang in Form einer .zip - GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall...
Archiv
Du betrachtest: GiroPay24 Email Anhang (ZIP) geöffnet, Inhalt aber nicht angerührt. Unsicher ob Viren/Trojaner Befall auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.