![]() |
| |||||||
Netzwerk und Hardware: eset sysinspektor und gmer finden rootkits, diverse prozesseWindows 7 Hilfe zu Motherboards, CPUs, Lüfter, Raid-Controller, Digitalkameras, Treiber usw. Bitte alle relevanten Angaben zur Hardware machen. Welche Hardware habe ich? Themen zum Trojaner Entfernen oder Viren Beseitigung bitte in den Bereinigungsforen des Trojaner-Boards posten. |
![]() |
| | #1 |
![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse hallo, mein laptop wird von tag zu tag unbrauchbarer und ich weiß einfach nicht weiter. er ist ständig am überhitzen trotz externem lüfer und niedrigen grafikdetails, mein startmenü lässt sich nicht mehr öffnen und immer mehr programme funktionieren nicht mehr richtig. ich hab vor einiger zeit schon einmal ein thema erstellt, allerdings hat auch unter anleitung kein programm wirklich etwas gefunden. mein helfer meinte irgendwann es müsse wohl an der hardware liegen. da ich meinen pc aber gut kenne und einige der probleme wohl eher nicht hardware bedingt sind, bin ich immer noch davon überzeugt dass ich mir irgendetwas eingegfangen habe. der eset sysinspektor hat nun auch "endlich" etwas gefunden. neben 100ten registry eintägen und einigen prozessen die ich schon lange im verdacht habe, stuft er die explorer.exe als gefährlich ein. im anschluss hab ich einen rootkitscan mit GMER durchgeführt (hab mich an die anleitung gehalten) und auch der hat alarm geschlagen. wenn jemand zeit hat wäre es cool wenn er sich die logfiles mal anschaun könnte. beim sysinspektotor weiß ich allerdings nicht ob ihr die log für den privaten gebrauch, oder die zum versenden benötigt. die GMER log kann ich aber schon mal posten. gruß, dragonfly Code:
ATTFilter GMER 2.2.19882 - hxxp://www.gmer.net
Rootkit scan 2017-03-01 00:29:12
Windows 6.2.9200 x64
Running: 1onkxdyx.exe
---- Services - GMER 2.2 ----
Service system32\DRIVERS\eamonm.sys (*** hidden *** ) [DISABLED] eamonm <-- ROOTKIT !!!
Service system32\DRIVERS\edevmon.sys (*** hidden *** ) [DISABLED] edevmon <-- ROOTKIT !!!
Service system32\DRIVERS\ehdrv.sys (*** hidden *** ) [DISABLED] ehdrv <-- ROOTKIT !!!
Service system32\DRIVERS\epfwwfpr.sys (*** hidden *** ) [DISABLED] epfwwfpr <-- ROOTKIT !!!
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemStartTime 0x82 0x22 0xCB 0x07 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemLastStartTime 0xE2 0x24 0x0D 0x62 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@CMFStartTime 0x14 0x85 0xCD 0x07 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@CMFLastStartTime 0xDE 0x76 0x1B 0x62 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData\BootLanguages@de-DE 35
Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\SDC45520_00_07DC_7F^A2145B18A703222465C83CE231C04DC1@Timestamp 0xD1 0x61 0xBD 0x40 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 756
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{B3B3F2B0-F658-4E62-9374-7D528A9BEFDE}\Connection@Name isatap.home
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\Users\DRAGON~1\AppData\Local\Temp\~nsuA.tmp\Au_.exe??\??\C:\Users\DRAGON~1\AppData\Local\Temp\~nsuA.tmp??\??\C:\Users\DRAGON~1\AppData\Local\Temp\INS_c9dea586.TMP??\??\C:\Users\DRAGON~1\AppData\Local\Temp\INS_f0614208.TMP??\??\C:\Users\DRAGON~1\AppData\Local\Temp\INS_cc6eb89f.TMP??\??\C:\Users\DRAGON~1\AppData\Local\Temp\NvidiaLogging??\??\C:\Users\Dragonfly\AppData\Local\Temp\1541172\svchost.exe??\??\C:\Program Files\AVAST Software\Avast\setup\settings-8f0.ori??\??\C:\Program Files\AVAST Software\Avast\setup??\??\C:\Program Files\AVAST Software\Avast\337548cc-f784-49e8-a0a1-14cb42bf5755.cab??\??\C:\Program Files\AVAST Software\Avast\337548cc-f784-49e8-a0a1-14cb42bf5755??\??\C:\Program Files\AVAST Software\Avast\337548cc-f784-49e8-a0a1-14cb42bf5755\backup.exe??\??\C:\Program Files\AVAST Software\Avast\337548cc-f784-49e8-a0a1-14cb42bf5755\upgrade.exe??\??\C:\Program Files (x86)\Google\Chrome??\??\C:\Users\DRAGON~1\AppData\Local\Temp\epf2605.tmp??\??\C:\Users\DRAGON~1\AppData\Local\Temp\eam27FB.tmp??\??
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Executive@UuidSequenceNumber 1340060
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed -2079710322
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 35
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 498045587
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 2501
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 2063
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID d17850df-3387-499c-806e-28b2a92
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\AutoLogger\WdiContextLog@FileCounter 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh\Parameters@Reboot 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\48d2244c6a15
Reg HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\Probe\{9c629fb9-4ccc-42ff-af76-3ecdec00b121}@LastProbeTime 1488309518
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@Start 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@Tag 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@ImagePath system32\DRIVERS\eamonm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@DisplayName eamonm
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@Group FSFilter Anti-Virus
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@DependOnService FltMgr?
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@Description Eset file on-access scanner
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@SupportedFeatures 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm@DeleteFlag 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm\Instances
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm\Instances@DefaultInstance AmonMinifilter Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm\Instances\AmonMinifilter Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm\Instances\AmonMinifilter Instance@Altitude 328700
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm\Instances\AmonMinifilter Instance@Flags 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\eamonm
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@Start 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@Tag 13
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@ImagePath system32\DRIVERS\edevmon.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@DisplayName edevmon
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@Group PNP Filter
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@Description Eset device blocker
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon@DeleteFlag 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon\Instances
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon\Instances@DefaultInstance DevmonMinifilter Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon\Instances\DevmonMinifilter Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon\Instances\DevmonMinifilter Instance@Altitude 400800
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon\Instances\DevmonMinifilter Instance@Flags 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\edevmon
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@Start 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@Tag 20
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@ImagePath \SystemRoot\system32\DRIVERS\ehdrv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@DisplayName ehdrv
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@Group Base
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@Description Eset Helper driver
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv@DeleteFlag 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ehdrv
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@Start 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@Tag 9
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@ImagePath \SystemRoot\system32\DRIVERS\epfwwfpr.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@DisplayName epfwwfpr
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@Group PNP_TDI
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@DependOnService Tcpip?
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@Description EPFW Filter Driver
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr@DeleteFlag 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\epfwwfpr
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{B3B3F2B0-F658-4E62-9374-7D528A9BEFDE}@DefunctTimestamp 0x20 0x05 0xB6 0x58 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\rdyboost\Parameters@LastBootPlanUserTime ?Di?, ?Feb ?28 ?17, 07:20:28???????????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 9304
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 1978
Reg HKLM\SYSTEM\CurrentControlSet\Services\srvnet\Parameters@MajorSequence 34
Reg HKLM\SYSTEM\CurrentControlSet\Services\SynTP\Parameters@DetectTimeMS 149
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}@LeaseObtainedTime 1488322372
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}@T1 1488324022
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}@T2 1488325372
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}@LeaseTerminatesTime 1488325972
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}@Dhcpv6InformationObtainedTime 1488305917
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeEstimated 0x94 0x0A 0x02 0x67 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeHigh 0x94 0x72 0xC6 0xC8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeLow 0x94 0xA2 0x3D 0x05 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters@ServiceDllUnloadOnStop 0
Reg HKLM\SYSTEM\Maps@LastMapUpdateCheck 0x52 0xA4 0xE0 0x35 ...
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shutdown@CleanShutdown 1
Reg HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting@LastRateLimitedDumpGenerationTime 0x7B 0xAC 0x90 0x39 ...
Reg HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug@StoreLocation C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_1onkxdyx.exe_338a7d8b6f255e6a69648b03af9e2462b2f4ee_f6e57321_09317293
---- EOF - GMER 2.2 ----
Code:
ATTFilter GMER 2.2.19882 - hxxp://www.gmer.net
Rootkit scan 2017-03-01 04:49:19
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST1000LM rev.2AR2 931,51GB
Running: 1onkxdyx.exe; Driver: C:\Users\DRAGON~1\AppData\Local\Temp\uxlyquog.sys
---- User code sections - GMER 2.2 ----
? C:\WINDOWS\system32\apphelp.dll [196] entry point in ".rdata" section 0000000070940380
? C:\WINDOWS\system32\apphelp.dll [2332] entry point in ".rdata" section 0000000070940380
---- Kernel IAT/EAT - GMER 2.2 ----
IAT C:\WINDOWS\System32\drivers\CLASSPNP.SYS[ntoskrnl.exe!IofCallDriver] [fffff8007106db3c] \SystemRoot\system32\drivers\aswSP.sys [unknown section]
---- Threads - GMER 2.2 ----
Thread C:\WINDOWS\system32\csrss.exe [644:696] fffff96188b84030
Thread C:\WINDOWS\explorer.exe [3796:3952] 00007ffee8610880
Thread C:\WINDOWS\explorer.exe [3796:4052] 00007ffee7667fe0
Thread C:\WINDOWS\explorer.exe [3796:3104] 0000000055807ff0
Thread C:\WINDOWS\explorer.exe [3796:3156] 00007ffee7961c40
Thread C:\WINDOWS\explorer.exe [3796:3780] 00007ffeefc330f0
Thread C:\WINDOWS\explorer.exe [3796:4964] 00007ffeda16ed40
Thread C:\WINDOWS\explorer.exe [3796:2176] 00007ffeda17f970
---- Services - GMER 2.2 ----
Service system32\drivers\aswbidsdrivera.sys (*** hidden *** ) [SYSTEM] aswbidsdriver <-- ROOTKIT !!!
Service system32\drivers\aswbidsha.sys (*** hidden *** ) [BOOT] aswbidsh <-- ROOTKIT !!!
Service system32\drivers\aswbloga.sys (*** hidden *** ) [BOOT] aswblog <-- ROOTKIT !!!
Service system32\drivers\aswbuniva.sys (*** hidden *** ) [BOOT] aswbuniv <-- ROOTKIT !!!
Service system32\drivers\aswHwid.sys (*** hidden *** ) [MANUAL] aswHwid <-- ROOTKIT !!!
Service system32\drivers\aswKbd.sys (*** hidden *** ) [SYSTEM] aswKbd <-- ROOTKIT !!!
Service system32\drivers\aswMonFlt.sys (*** hidden *** ) [AUTO] aswMonFlt <-- ROOTKIT !!!
Service system32\drivers\aswRdr2.sys (*** hidden *** ) [SYSTEM] aswRdr <-- ROOTKIT !!!
Service system32\drivers\aswRvrt.sys (*** hidden *** ) [BOOT] aswRvrt <-- ROOTKIT !!!
Service system32\drivers\aswSnx.sys (*** hidden *** ) [SYSTEM] aswSnx <-- ROOTKIT !!!
Service system32\drivers\aswSP.sys (*** hidden *** ) [SYSTEM] aswSP <-- ROOTKIT !!!
Service system32\drivers\aswStm.sys (*** hidden *** ) [AUTO] aswStm <-- ROOTKIT !!!
Service system32\drivers\aswVmm.sys (*** hidden *** ) [BOOT] aswVmm <-- ROOTKIT !!!
Service C:\Program Files\AVAST Software\Avast\AvastSvc.exe (*** hidden *** ) [AUTO] avast! Antivirus <-- ROOTKIT !!!
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\Program Files\AVAST Software\Avast\setup\Sfx\Instup.dll??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\instup.exe??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\aswOfferTool.exe??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\avBugReport.exe??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\AvDump32.exe??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\AvDump64.exe??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\HTMLayout.dll??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\Instup.dll??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\instup.exe??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\Instup.dll??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\instup.exe??\??\C:\Program Files\AVAST Software\Avast\setup\Sfx\New_110208f0\aswOfferTool.exe??\??\C:
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Configuration Manager@BackupCount 1
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed 680140415
Reg HKLM\SYSTEM\CurrentControlSet\Control\usb\ceip@UsbCeipTaskLastRunTimestamp 0xF3 0xF8 0x73 0x7D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@Type 16
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@ImagePath "C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@DisplayName aswbIDSAgent
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent@Description Provides Identity Protection Against Cyber Crime.
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbIDSAgent
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver@ImagePath \SystemRoot\system32\drivers\aswbidsdrivera.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver@DisplayName aswbidsdriver
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsdriver
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh@ImagePath \SystemRoot\system32\drivers\aswbidsha.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh@DisplayName aswbidsh
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh\Parameters@Reboot 5
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbidsh
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog@ImagePath \SystemRoot\system32\drivers\aswbloga.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog@DisplayName aswblog
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog\Parameters@LogDir \??\C:\ProgramData\AVAST Software\Avast\log
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog\Parameters@ConfigDir \??\C:\ProgramData\AVAST Software\Avast\cfg
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog\Parameters@NotifyDrivers \Device\AvaswIDSErHr?\Device\aswIDS_Ioc2?\Device\AvaswUniv?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswblog
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv@ImagePath \SystemRoot\system32\drivers\aswbuniva.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv@DisplayName aswbuniv
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswbuniv
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswHwid
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswHwid@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswHwid@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswHwid@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswHwid@ImagePath \SystemRoot\system32\drivers\aswHwid.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswHwid@DisplayName aswHwid
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswHwid
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd@Tag 5
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd@ImagePath \SystemRoot\system32\drivers\aswKbd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd@DisplayName aswKbd
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd@Group Keyboard Port
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswKbd
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt@ImagePath \SystemRoot\system32\drivers\aswMonFlt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt@DisplayName aswMonFlt
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt@Group FSFilter Anti-Virus
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt@DependOnService FltMgr?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt\Instances
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt\Instances@DefaultInstance aswMonFlt Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt\Instances\aswMonFlt Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt\Instances\aswMonFlt Instance@Altitude 320700
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt\Instances\aswMonFlt Instance@Flags 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr@ImagePath \SystemRoot\system32\drivers\aswRdr2.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr@DisplayName aswRdr
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr@Group PNP_TDI
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr@DependOnService tcpip?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr\Parameters@MSIgnoreLSPDefault
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRdr
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt@ImagePath \SystemRoot\system32\drivers\aswRvrt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt@DisplayName aswRvrt
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt@Group Extended Base
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@SystemRoot \Device\HarddiskVolume2\WINDOWS
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@BootCounter 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@TickCounter 2369
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@ImproperShutdown 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883231355312288
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883231355312288@ Commited
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883231355312288@BootTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883231355312288@TickTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883231355312288@CreationTime 0xC6 0x82 0x76 0x2B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883231355312288@StartBootCounter 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883231355312288@StartTickCounter 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288@ Commited
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288@BootTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288@TickTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288@CreationTime 0x8D 0x0A 0x53 0xD2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288@SetupOperations MoveFile("\??\C:\Program Files\AVAST Software\Avast\afwDC75.tmp","\??\C:\Program Files\AVAST Software\Avast\afwServ.exe",TRUE)?MoveFile("\??\C:\Program Files\AVAST Software\Avast\afwDC85.tmp","\??\C:\Program Files\AVAST Software\Avast\afwCore.dll",TRUE)?MoveFile("\??\C:\Program Files\AVAST Software\Avast\afwDC86.tmp","\??\C:\Program Files\AVAST Software\Avast\afwCoreClient.dll",TRUE)?MoveFile("\??\C:\Program Files\AVAST Software\Avast\afwDC97.tmp","\??\C:\Program Files\AVAST Software\Avast\afwCoreServ.dll",TRUE)?MoveFile("\??\C:\Program Files\AVAST Software\Avast\afwDC98.tmp","\??\C:\Program Files\AVAST Software\Avast\afwGeoIP.dll",TRUE)?MoveFile("\??\C:\Program Files\AVAST Software\Avast\afwDCA8.tmp","\??\C:\Program Files\AVAST Software\Avast\afwRpc.dll",TRUE)?MoveFile("\??\C:\ProgramData\AVAST Software\Avast\fw\macDCAB.tmp","\??\C:\ProgramData\AVAST Software\Avast\fw\macaddr.db",TRUE)?MoveFile("\??\C:\Program Files\AVAST Software\Avast\ahRF6A4.tmp","\??\C:\Program Files\AVAST Software\Avast\ahResSecDns.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288@StartBootCounter 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883238441252288@StartTickCounter 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288@BootTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288@TickTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288@CreationTime 0xDE 0x43 0x65 0x64 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288@SetupOperations MoveFile("\??\C:\Program Files\AVAST Software\Avast\AavE430.tmp","\??\C:\Program Files\AVAST Software\Avast\Aavm4h.dll",TRUE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\setup\settings-8f0.ori")?RemoveDir("\??\C:\Program Files\AVAST Software\Avast\setup",FALSE,FALSE)?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288@StartBootCounter 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262370462288@StartTickCounter 2369
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@BootTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@TickTimeout 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@CreationTime 0x5B 0x6B 0x99 0x72 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@SetupOperations MoveFile("\??\C:\Program Files\AVAST Software\Avast\AavE430.tmp","\??\C:\Program Files\AVAST Software\Avast\Aavm4h.dll",TRUE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\setup\settings-8f0.ori")?RemoveDir("\??\C:\Program Files\AVAST Software\Avast\setup",FALSE,FALSE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\afwServ.exe")?RemoveDir("\??\C:\Program Files\AVAST Software\Avast",FALSE,FALSE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\afwCore.dll")?RemoveDir("\??\C:\Program Files\AVAST Software\Avast",FALSE,FALSE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\afwCoreClient.dll")?RemoveDir("\??\C:\Program Files\AVAST Software\Avast",FALSE,FALSE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\afwCoreServ.dll")?RemoveDir("\??\C:\Program Files\AVAST Software\Avast",FALSE,FALSE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\afwGeoIP.dll")?RemoveDir("\??\C:\Program Files\AVAST Software\Avast",FALSE,FALSE)?DeleteFile("\??\C:\Program Files\AVAST Software\Avast\afwRp
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@FailedOperations C0000034 MoveFile("\??\C:\Program Files\AVAST Software\Avast\AavE430.tmp","\??\C:\Program Files\AVAST Software\Avast\Aavm4h.dll",TRUE)?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@StartBootCounter 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14883262613432288@StartTickCounter 2369
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx@ImagePath \SystemRoot\system32\drivers\aswSnx.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx@DisplayName aswSnx
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx@Group FSFilter Virtualization
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx@DependOnService FltMgr?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Instances
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Instances@DefaultInstance aswSnx Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Instances\aswSnx Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Instances\aswSnx Instance@Altitude 137600
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Instances\aswSnx Instance@Flags 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSnx
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP@Type 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP@ImagePath \SystemRoot\system32\drivers\aswSP.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP@DisplayName aswSP
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP@Group FSFilter Security Enhancer
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP@DependOnService FltMgr?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Instances
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Instances@DefaultInstance aswSP Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Instances\aswSP Instance
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Instances\aswSP Instance@Altitude 388401
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Instances\aswSP Instance@Flags 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters@ProgramFilesFolder \??\C:\Program Files
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters@UsersFolder \??\C:\Users
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters@PassiveMode 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters@SZBProgramFolder \??\C:\Program Files\AVAST Software\SZBrowser
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP\Parameters@SZBDataFolder \??\C:\ProgramData\AVAST Software\SZBrowser
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswSP
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm@ImagePath \SystemRoot\system32\drivers\aswStm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm@DisplayName aswStm
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm@Group NDIS
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm@DependOnService tcpip?
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm\Parameters\Wdf
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm\Parameters\Wdf@WdfMajorVersion 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm\Parameters\Wdf@WdfMinorVersion 9
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswStm
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm@ImagePath \SystemRoot\system32\drivers\aswVmm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm@DisplayName aswVmm
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm@Group Extended Base
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswVmm
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@ImagePath "C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@DisplayName Avast Antivirus
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@Group ShellSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@DependOnService aswMonFlt?RpcSS?
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@WOW64 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus@Description Verwaltet und implementiert die Avast Antivirus Dienste auf diesem Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus Container sowie die Zeitplan.
Reg HKLM\SYSTEM\CurrentControlSet\Services\avast! Antivirus
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\48d2244c6a15
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 9524
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules@{8CFB637A-09AB-4EE3-B0B1-378BBABB1488} v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files\AVAST Software\SZBrowser\3.55.2393.561_0\SZBrowser.exe|Name=Opera Internet Browser (mDNS-In)|Desc=Inbound rule to allow mDNS traffic.|EmbedCtxt=Opera Internet Browser|
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules@{D65A6FE7-0353-457B-A4AF-AE92C0557562} v2.25|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files\AVAST Software\SZBrowser\3.55.2393.561_1\SZBrowser.exe|Name=Opera Internet Browser (mDNS-In)|Desc=Inbound rule to allow mDNS traffic.|EmbedCtxt=Opera Internet Browser|
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeEstimated 0x62 0x41 0x18 0x3A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeHigh 0x62 0xA9 0xDC 0x9B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeLow 0x62 0xD9 0x53 0xD8 ...
---- EOF - GMER 2.2 ----
Code:
ATTFilter GMER 2.2.19882 - hxxp://www.gmer.net
Autostart scan 2017-03-01 04:59:46
Windows 6.2.9200
gupdate@ = "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
NVDisplay.ContainerLocalSystem@ = "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
Spooler@ = %SystemRoot%\System32\spoolsv.exe /*file not found*/
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe@DisableExceptionChainValidation = 3 /*file not found*/
HKLM\Software\Classes\.hta@ = C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} /*Contacts folder*/(null) =
@{E6FB5E20-DE35-11CF-9C87-00AA005127ED} /*WebCheck*/(null) =
@{2F603045-309F-11CF-9774-0020AFD0CFF6} /*Synaptics Control Panel*/%ProgramFiles%\Synaptics\SynTP\SynTPCpl.dll /*file not found*/ = %ProgramFiles%\Synaptics\SynTP\SynTPCpl.dll /*file not found*/
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\Program Files\NVIDIA Corporation\Display\nvui.dll = C:\Program Files\NVIDIA Corporation\Display\nvui.dll
@{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} /*NVIDIA Play On My TV Context Menu Extension*/%SystemRoot%\system32\nvshext.dll = %SystemRoot%\system32\nvshext.dll
@{A929C4CE-FD36-4270-B4F5-34ECAC5BD63C} /*NvAppShExt extension*/C:\WINDOWS\system32\nv3dappshext.dll = C:\WINDOWS\system32\nv3dappshext.dll
@{E97DEC16-A50D-49bb-AE24-CF682282E08D} /*OpenGLShExt extension*/C:\WINDOWS\system32\nv3dappshext.dll = C:\WINDOWS\system32\nv3dappshext.dll
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ >>>
igfxcui@{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =
NvCplDesktopContext@{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} = %SystemRoot%\system32\nvshext.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhxxp://go.microsoft.com/fwlink/p/?LinkId=255141 = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
@Start Pagehxxp://go.microsoft.com/fwlink/p/?LinkId=255141 = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
@Local PageC:\Windows\System32\blank.htm = C:\Windows\System32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehxxp://go.microsoft.com/fwlink/p/?LinkId=255141 = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
@Local Page%11%\blank.htm = %11%\blank.htm
---- EOF - GMER 2.2 ----
|
| | #2 |
![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse frst hätt ich auch gleich noch:
__________________Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 27-02-2017 01
durchgeführt von Dragonfly (Administrator) auf DRAGONFLY-PC (01-03-2017 05:57:50)
Gestartet von C:\Users\Dragonfly\Desktop
Geladene Profile: Dragonfly (Verfügbare Profile: Dragonfly & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Intel Corporation) C:\Windows\syswow64\IntelCpHeciSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ESET) C:\Users\Dragonfly\Desktop\eset_nod32_antivirus_live_installer.exe
(ESET) C:\Users\Dragonfly\AppData\Local\Temp\eset\bts.session\{02D83BBE-385E-D6F4-0C69-03CD7D2A9EF7}\eset_nod32_antivirus_live_installer.exe
(ESET) C:\Users\Dragonfly\AppData\Local\Temp\eset\bts.session\{02D83BBE-385E-D6F4-0C69-03CD7D2A9EF7}\BootHelper.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Keine Datei
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9d7e27a9-5756-47e5-95d0-70cb4968354e}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
FireFox:
========
FF DefaultProfile: 4178b7vw.default
FF ProfilePath: C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\4178b7vw.default [2017-03-01]
FF Extension: (uBlock Origin) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\4178b7vw.default\Extensions\uBlock0@raymondhill.net.xpi [2017-02-27]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-01] (Google Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default [2017-03-01]
CHR Extension: (Docs) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-01]
CHR Extension: (Google Drive) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-01]
CHR Extension: (YouTube) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-01]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-01]
CHR Extension: (Google Mail) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-01]
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2836296 2016-12-14] (ESET)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-02-10] (NVIDIA Corporation)
S2 Spooler; %SystemRoot%\System32\spoolsv.exe [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132272 2017-01-17] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15488 2017-01-17] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180544 2017-01-17] (ESET)
R1 epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [70960 2017-01-17] (ESET)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [181160 2017-02-28] (ESET)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-01-20] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2017-01-20] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [422656 2016-03-09] (Realsil Semiconductor Corporation)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [42184 2015-06-03] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
R3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [648872 2015-09-03] (Vimicro Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 uxlyquog; C:\Users\Dragonfly\AppData\Local\Temp\uxlyquog.sys [56584 2017-03-01] (GMER) [Datei ist nicht signiert] <==== ACHTUNG
U1 aswbdisk; kein ImagePath
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-03-01 05:38 - 2017-03-01 05:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-03-01 05:38 - 2017-03-01 05:38 - 00000000 ____D C:\Program Files\ESET
2017-03-01 05:11 - 2017-03-01 05:11 - 00000053 _____ C:\Users\Dragonfly\Desktop\gmer reg log.reg
2017-03-01 05:01 - 2017-03-01 05:01 - 00002692 _____ C:\Users\Dragonfly\Desktop\gmer autostart log.txt
2017-03-01 03:06 - 2017-03-01 05:15 - 00000000 _____ C:\Users\Dragonfly\Desktop\1onkxdyx.reg
2017-03-01 03:06 - 2017-03-01 05:15 - 00000000 _____ C:\Users\Dragonfly\Desktop\1onkxdyx.bat
2017-03-01 01:28 - 2017-03-01 01:28 - 00003506 _____ C:\WINDOWS\System32\Tasks\CrystalDiskInfo
2017-03-01 01:19 - 2017-03-01 01:19 - 00000000 ____D C:\Users\Dragonfly\Desktop\CrystalDiskInfo7_0_5-en
2017-03-01 01:11 - 2017-03-01 01:11 - 04874935 _____ C:\Users\Dragonfly\Desktop\CrystalDiskInfo7_0_5-en.zip
2017-03-01 00:22 - 2017-03-01 00:22 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2017-03-01 00:07 - 2017-03-01 00:07 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Google
2017-03-01 00:06 - 2017-03-01 00:06 - 00002264 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-01 00:06 - 2017-03-01 00:06 - 00002252 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-01 00:05 - 2017-03-01 00:10 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-03-01 00:05 - 2017-03-01 00:10 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-03-01 00:04 - 2017-03-01 00:04 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2017-03-01 00:02 - 2017-03-01 05:16 - 00000000 ____D C:\ProgramData\AVAST Software
2017-03-01 00:01 - 2017-03-01 00:02 - 06654960 _____ (AVAST Software) C:\Users\Public\Desktop\avast_free_antivirus_setup_online.exe
2017-03-01 00:01 - 2017-03-01 00:02 - 06654960 _____ (AVAST Software) C:\Users\Dragonfly\Desktop\avast_free_antivirus_setup_online.exe
2017-02-28 21:17 - 2017-02-28 21:17 - 00380928 _____ C:\Users\Dragonfly\Desktop\1onkxdyx.exe
2017-02-28 19:55 - 2017-02-28 20:10 - 00003131 _____ C:\Users\Dragonfly\Desktop\Fixlog.txt
2017-02-28 19:28 - 2017-02-28 19:28 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-02-28 19:28 - 2017-01-26 01:13 - 00103936 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-02-28 19:28 - 2017-01-26 01:12 - 00326656 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-02-28 19:28 - 2017-01-26 01:09 - 00322560 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-02-28 19:28 - 2017-01-26 01:09 - 00118272 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-02-28 15:35 - 2017-02-28 15:36 - 00013320 _____ C:\softwarelist.csv
2017-02-28 15:09 - 2017-03-01 05:57 - 00006875 _____ C:\Users\Dragonfly\Desktop\FRST.txt
2017-02-28 15:09 - 2017-03-01 05:31 - 00023583 _____ C:\Users\Dragonfly\Desktop\Addition.txt
2017-02-28 15:08 - 2017-02-28 15:09 - 02423296 _____ (Farbar) C:\Users\Dragonfly\Desktop\FRST64.exe
2017-02-28 13:43 - 2017-02-28 13:43 - 00181160 _____ (ESET) C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys
2017-02-28 01:36 - 2017-02-28 23:06 - 00007655 _____ C:\Users\Dragonfly\AppData\Local\resmon.resmoncfg
2017-02-28 00:54 - 2017-02-28 00:56 - 01139028 _____ C:\Users\Dragonfly\Desktop\eav_logs.zip
2017-02-27 19:39 - 2017-02-27 19:39 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-27 19:02 - 2017-02-27 19:02 - 00001210 _____ C:\Users\Dragonfly\Desktop\exset scanlog.txt
2017-02-27 18:39 - 2017-02-27 18:45 - 00862368 _____ (ESET) C:\Users\Dragonfly\Desktop\esetteslacryptdecryptor.exe
2017-02-27 18:36 - 2017-02-28 00:53 - 00992384 _____ (ESET) C:\Users\Dragonfly\Desktop\esetlogcollector_deu.exe
2017-02-27 18:03 - 2017-02-27 18:04 - 02991832 _____ (ESET) C:\Users\Dragonfly\Desktop\ERARemover_x64.exe
2017-02-27 17:55 - 2017-02-27 17:55 - 00284012 _____ C:\Users\Dragonfly\SysInspector-DRAGONFLY-PC-170227-173711.zip
2017-02-27 17:37 - 2017-02-27 17:37 - 00279126 _____ C:\Users\Dragonfly\Desktop\SysInspector-DRAGONFLY-PC-170227-164719.zip
2017-02-27 17:29 - 2017-02-27 17:29 - 06756992 _____ (ESET spol. s r.o.) C:\Users\Dragonfly\Desktop\ESETOnlineScanner_DEU.exe
2017-02-27 16:36 - 2017-02-27 16:36 - 02815619 _____ C:\Users\Dragonfly\Desktop\StoreLogs_2017-02-27_16-36-03.cab
2017-02-27 08:11 - 2017-02-10 20:29 - 14516664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2017-02-27 08:11 - 2017-02-10 03:33 - 04078008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-02-27 08:11 - 2017-02-10 03:33 - 00640272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2017-02-27 08:11 - 2017-02-10 03:33 - 00043556 _____ C:\WINDOWS\system32\nvinfo.pb
2017-02-27 06:32 - 2017-02-27 06:32 - 00000000 ____D C:\Users\Dragonfly\Desktop\Neuer Ordner (3)
2017-02-27 06:29 - 2017-02-27 06:29 - 00000000 ___RD C:\Users\Dragonfly\Desktop\-
2017-02-27 06:28 - 2017-02-27 06:28 - 00000000 __SHD C:\Users\Dragonfly\IntelGraphicsProfiles
2017-02-27 04:03 - 2017-02-28 18:51 - 00000000 ____D C:\Users\Dragonfly\Desktop\FRST-OlderVersion
2017-02-26 15:56 - 2017-02-26 15:56 - 01477706 _____ C:\Users\Dragonfly\Desktop\LoL Logs.zip
2017-02-26 15:54 - 2017-02-26 15:54 - 00003129 _____ C:\Users\Dragonfly\Desktop\Hextech Repair Tool.lnk
2017-02-26 15:54 - 2017-02-26 15:54 - 00000000 ____D C:\Program Files (x86)\Hextech Repair Tool
2017-02-26 15:52 - 2017-02-26 15:53 - 49008640 _____ C:\Users\Dragonfly\Desktop\Hextech Repair Tool.msi
2017-02-26 06:09 - 2017-02-27 21:30 - 00000000 ____D C:\WINDOWS\LastGood
2017-02-26 06:09 - 2017-02-26 06:09 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Chromium
2017-02-26 06:09 - 2017-01-20 19:39 - 00156608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-02-26 06:09 - 2017-01-20 19:39 - 00124352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-02-26 06:09 - 2017-01-20 19:39 - 00057792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-02-26 06:09 - 2017-01-20 14:36 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-02-26 05:39 - 2017-02-26 05:40 - 00876560 _____ (Microsoft Corporation) C:\Users\Dragonfly\Desktop\mssstool64.exe
2017-02-26 05:36 - 2017-02-27 17:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\ESET
2017-02-25 18:28 - 2017-02-26 06:09 - 00001485 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-02-25 18:28 - 2017-02-26 06:09 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA Corporation
2017-02-25 18:28 - 2017-02-25 18:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-02-25 18:28 - 2017-01-20 19:39 - 01872320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-02-25 18:28 - 2017-01-20 19:39 - 01755072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-02-25 18:28 - 2017-01-20 19:39 - 01464768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-02-25 18:28 - 2017-01-20 19:39 - 01317312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-02-25 18:28 - 2017-01-20 19:39 - 00120256 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-02-25 18:28 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2017-02-25 18:28 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2017-02-25 18:28 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2017-02-25 18:28 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2017-02-25 18:28 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2017-02-25 18:28 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2017-02-25 18:26 - 2017-02-25 18:26 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-02-25 18:25 - 2017-02-10 20:30 - 00048696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2017-02-25 18:25 - 2017-02-10 03:33 - 40192056 _____ C:\WINDOWS\system32\nvcompiler.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 35272760 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 34979384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 28242488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 23738944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 20012720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 19007016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 16871184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 14674896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 13815192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 11122728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 11019704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 09305984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 08990072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 03597128 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 03168192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 02717752 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 01983424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437866.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 01589696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437866.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 01052096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00991288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00959424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00946456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00910784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00721952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00687224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00609728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00576192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00573448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00515648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00499136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00447984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00207672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00182952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00177808 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00152064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2017-02-25 18:25 - 2017-02-10 03:33 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-02-25 18:25 - 2017-02-10 03:33 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-02-25 18:25 - 2017-01-20 19:39 - 00046016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-02-25 18:20 - 2017-02-25 18:22 - 400200032 _____ (NVIDIA Corporation) C:\Users\Dragonfly\Desktop\378.66-notebook-win10-64bit-international-whql.exe
2017-02-25 07:23 - 2017-03-01 05:57 - 00000000 ____D C:\FRST
2017-02-25 04:57 - 2017-02-25 04:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS
2017-02-25 04:57 - 2017-02-25 04:57 - 00000000 ____D C:\inetpub
2017-02-24 13:46 - 2017-02-24 13:46 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\CEF
2017-02-24 13:37 - 2017-03-01 05:30 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\CrashDumps
2017-02-16 23:08 - 2017-02-16 23:08 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Comms
2017-02-16 14:14 - 2017-02-16 14:14 - 00000000 ____D C:\Program Files (x86)\USB Camera
2017-02-11 00:42 - 2017-03-01 05:38 - 00000000 ____D C:\ProgramData\ESET
2017-02-10 23:39 - 2017-02-10 23:49 - 03139200 _____ (ESET) C:\Users\Dragonfly\Desktop\eset_nod32_antivirus_live_installer.exe
2017-02-10 23:35 - 2017-02-10 23:35 - 00001098 _____ C:\DelFix.txt
2017-02-10 19:25 - 2017-02-10 19:25 - 00066673 _____ C:\Users\Dragonfly\Desktop\Drogenkonsum – Junge Delfine lutschen giftige Kugelfische - Aktuell _ News _ SWR3.htm
2017-02-10 16:15 - 2017-02-10 16:15 - 00000000 ____D C:\Users\Dragonfly\Desktop\Drogenkonsum – Junge Delfine lutschen giftige Kugelfische - Aktuell _ News _ SWR3_files
2017-02-10 11:21 - 2017-02-10 00:13 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-02-06 15:14 - 2017-02-28 01:33 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\ElevatedDiagnostics
2017-02-02 21:34 - 2017-02-02 21:34 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Publishers
2017-02-01 17:32 - 2017-02-01 17:32 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\LolClient
2017-02-01 15:24 - 2017-03-01 05:36 - 00000000 ____D C:\Users\Dragonfly\AppData\LocalLow\Mozilla
2017-02-01 15:24 - 2017-02-01 15:30 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Mozilla
2017-02-01 15:24 - 2017-02-01 15:24 - 00001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-01 15:24 - 2017-02-01 15:24 - 00000993 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-02-01 15:24 - 2017-02-01 15:24 - 00000000 ____D C:\Users\Dragonfly\AppData\Roaming\Mozilla
2017-02-01 15:23 - 2017-02-28 07:20 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-02-01 15:13 - 2017-02-01 16:44 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\CyberGhost
2017-02-01 15:13 - 2017-02-01 15:13 - 00002071 _____ C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberGhost 6.lnk
2017-02-01 15:12 - 2017-02-01 16:43 - 00000000 ____D C:\Program Files\CyberGhost 6
2017-02-01 15:12 - 2017-02-01 15:12 - 00001769 _____ C:\Users\Dragonfly\Desktop\CyberGhost 6.lnk
2017-02-01 15:12 - 2017-02-01 15:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 6
2017-02-01 15:12 - 2017-02-01 15:12 - 00000000 ____D C:\Program Files\TAP-Windows
2017-02-01 14:57 - 2017-02-01 15:13 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\VirtualStore
2017-02-01 14:57 - 2017-02-01 14:57 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\ActiveSync
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-03-01 05:39 - 2017-01-23 20:55 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-03-01 05:39 - 2017-01-23 20:54 - 00000000 ____D C:\WINDOWS\INF
2017-03-01 05:36 - 2017-01-28 15:06 - 00004170 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B1242B03-C906-44C3-B246-7084CC370C3E}
2017-03-01 05:21 - 2017-01-23 21:30 - 01896352 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-01 05:21 - 2017-01-23 21:01 - 00818964 _____ C:\WINDOWS\system32\perfh007.dat
2017-03-01 05:21 - 2017-01-23 21:01 - 00166764 _____ C:\WINDOWS\system32\perfc007.dat
2017-03-01 05:16 - 2017-01-23 21:17 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-01 05:16 - 2017-01-23 21:13 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-01 00:50 - 2017-01-23 20:55 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-01 00:50 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-01 00:22 - 2017-01-23 21:23 - 00000000 ____D C:\Users\DefaultAppPool
2017-03-01 00:18 - 2017-01-23 20:33 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2017-03-01 00:06 - 2017-01-23 21:39 - 00000000 ____D C:\Program Files (x86)\Google
2017-02-28 14:57 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\Registration
2017-02-28 07:05 - 2017-01-23 21:23 - 00000000 ____D C:\Users\Dragonfly
2017-02-28 06:56 - 2017-01-24 01:47 - 00000000 ____D C:\EEK
2017-02-27 19:40 - 2017-01-24 14:28 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-27 09:48 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\rescache
2017-02-26 06:09 - 2017-01-23 21:17 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-02-26 06:09 - 2017-01-23 21:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-02-26 06:09 - 2017-01-23 21:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-02-25 23:03 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-25 18:32 - 2017-01-23 23:22 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\NVIDIA
2017-02-25 05:01 - 2017-01-23 20:43 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-25 04:57 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-02-25 04:57 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-02-21 22:42 - 2017-01-23 21:29 - 00000000 ____D C:\Users\Dragonfly\AppData\Local\Packages
2017-02-16 14:14 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\System
2017-02-10 03:33 - 2017-01-23 21:17 - 00512960 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2017-02-10 03:33 - 2017-01-23 21:17 - 00418752 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2017-02-09 23:57 - 2017-01-23 21:17 - 07791217 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-02-09 23:57 - 2017-01-23 21:17 - 06403640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-02-09 23:57 - 2017-01-23 21:17 - 02477504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-02-09 23:57 - 2017-01-23 21:17 - 01764408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-02-09 23:57 - 2017-01-23 21:17 - 00548288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-02-09 23:57 - 2017-01-23 21:17 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-02-09 23:57 - 2017-01-23 21:17 - 00146368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2017-02-09 23:57 - 2017-01-23 21:17 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-02-09 23:57 - 2017-01-23 21:17 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-02-06 20:45 - 2017-01-24 14:45 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 20:45 - 2017-01-24 14:45 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-03 19:43 - 2017-01-23 21:10 - 00000000 ____D C:\Windows.old
2017-02-01 17:53 - 2017-01-23 21:07 - 00000000 ____D C:\WINDOWS\Setup
2017-02-01 14:53 - 2017-01-23 20:55 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2017-02-28 01:36 - 2017-02-28 23:06 - 0007655 _____ () C:\Users\Dragonfly\AppData\Local\resmon.resmoncfg
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-03-01 04:37
==================== Ende von FRST.txt ============================
Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 27-02-2017 01
durchgeführt von Dragonfly (01-03-2017 05:58:08)
Gestartet von C:\Users\Dragonfly\Desktop
Windows 10 Home Version 1511 (X64) (2017-01-23 20:26:00)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-614321186-1851163967-905647231-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-614321186-1851163967-905647231-503 - Limited - Disabled)
Dragonfly (S-1-5-21-614321186-1851163967-905647231-1000 - Administrator - Enabled) => C:\Users\Dragonfly
Gast (S-1-5-21-614321186-1851163967-905647231-501 - Limited - Disabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Ansel (Version: 378.66 - NVIDIA Corporation) Hidden
CyberGhost 6 (HKLM\...\CyberGhost 6_is1) (Version: - CyberGhost S.R.L.)
ESET NOD32 Antivirus (HKLM\...\{4D33D02B-18D1-4125-8264-C4BD386CCBA8}) (Version: 10.0.390.0 - ESET, spol. s r.o.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Hextech Repair Tool (HKLM-x32\...\{7F9A97E6-E666-11E5-B582-B88687E82322}) (Version: 1.0.16 - Riot Games, Inc.)
League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games)
League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 3.15.0414.1 - Vimicro)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 51.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 51.0.1 (x64 en-US)) (Version: 51.0.1 - Mozilla)
NVIDIA GeForce Experience 3.3.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.3.0.95 - NVIDIA Corporation)
NVIDIA Grafiktreiber 378.66 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.66 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.3.0.95 - NVIDIA Corporation)
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.3.5.0 - NVIDIA Corporation)
NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0351 - NVIDIA Corporation)
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 3.3.0.95 - NVIDIA Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.9.5 - Synaptics Incorporated)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {23AFD280-1A1F-4F55-998F-911A13DE4F66} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-01] (Google Inc.)
Task: {28FC0728-9959-4D50-A5E3-C88BEC229B54} - System32\Tasks\CrystalDiskInfo => C:\Users\Dragonfly\Desktop\CrystalDiskInfo7_0_5-en\DiskInfo64.exe [2017-03-01] (Crystal Dew World)
Task: {4C6E8766-4902-4E41-8760-E78D95262EB9} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {B614065A-3335-4AB9-8DB2-B610E81F941D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-01] (Google Inc.)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2017-02-28 19:28 - 2017-02-09 23:57 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2017-02-28 14:57 - 2017-02-28 14:57 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-614321186-1851163967-905647231-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{FFF70B0A-5233-42D6-997B-CCE36FA31B32}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Wiederherstellungspunkte =========================
23-02-2017 12:59:06 Windows Update
25-02-2017 04:55:30 Windows Modules Installer
25-02-2017 07:02:17 Wiederherstellungsvorgang
26-02-2017 15:54:05 Installed Hextech Repair Tool
==================== Fehlerhafte Geräte im Gerätemanager =============
Name: Qualcomm Atheros AR3012 Bluetooth 4.0
Description: Qualcomm Atheros AR3012 Bluetooth 4.0
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Qualcomm Atheros Communications
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (03/01/2017 05:30:34 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: 1onkxdyx.exe, Version: 2.2.19882.0, Zeitstempel: 0x56e2cdca
Name des fehlerhaften Moduls: 1onkxdyx.exe, Version: 2.2.19882.0, Zeitstempel: 0x56e2cdca
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000624f2
ID des fehlerhaften Prozesses: 0xa24
Startzeit der fehlerhaften Anwendung: 0x01d292434e386dae
Pfad der fehlerhaften Anwendung: C:\Users\Dragonfly\Desktop\1onkxdyx.exe
Pfad des fehlerhaften Moduls: C:\Users\Dragonfly\Desktop\1onkxdyx.exe
Berichtskennung: 8c13cc49-3083-4bb2-ac85-9450112d494c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (03/01/2017 05:19:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.10586.672, Zeitstempel: 0x580ee8b2
Name des fehlerhaften Moduls: windows.immersiveshell.serviceprovider.dll, Version: 10.0.10586.0, Zeitstempel: 0x5632d657
Ausnahmecode: 0x80270233
Fehleroffset: 0x000000000002a639
ID des fehlerhaften Prozesses: 0x54
Startzeit der fehlerhaften Anwendung: 0x01d29242f8f16b93
Pfad der fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE
Pfad des fehlerhaften Moduls: C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
Berichtskennung: 228a5cb5-e225-45b9-bf57-3399d0e29827
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (03/01/2017 12:59:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.10586.672, Zeitstempel: 0x580ee8b2
Name des fehlerhaften Moduls: windows.immersiveshell.serviceprovider.dll, Version: 10.0.10586.0, Zeitstempel: 0x5632d657
Ausnahmecode: 0x80270233
Fehleroffset: 0x000000000002a639
ID des fehlerhaften Prozesses: 0xdd4
Startzeit der fehlerhaften Anwendung: 0x01d2921eb5256150
Pfad der fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE
Pfad des fehlerhaften Moduls: C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
Berichtskennung: ca8b76be-ec11-405c-97a1-cf63a4e309b0
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (03/01/2017 12:46:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.10586.672, Zeitstempel: 0x580ee8b2
Name des fehlerhaften Moduls: windows.immersiveshell.serviceprovider.dll, Version: 10.0.10586.0, Zeitstempel: 0x5632d657
Ausnahmecode: 0x80270233
Fehleroffset: 0x000000000002a639
ID des fehlerhaften Prozesses: 0xe34
Startzeit der fehlerhaften Anwendung: 0x01d2921ced62d11b
Pfad der fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE
Pfad des fehlerhaften Moduls: C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
Berichtskennung: fdc341e1-8c09-4ed6-b49e-0c0a17dc878c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (03/01/2017 12:20:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.10586.672, Zeitstempel: 0x580ee8b2
Name des fehlerhaften Moduls: windows.immersiveshell.serviceprovider.dll, Version: 10.0.10586.0, Zeitstempel: 0x5632d657
Ausnahmecode: 0x80270233
Fehleroffset: 0x000000000002a639
ID des fehlerhaften Prozesses: 0xb60
Startzeit der fehlerhaften Anwendung: 0x01d29219406325a2
Pfad der fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE
Pfad des fehlerhaften Moduls: C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
Berichtskennung: 1599fbee-2057-4d99-ba57-bda2979b8534
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (03/01/2017 12:10:47 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: IIS APPPOOL)
Description: Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen, gehen bei der Abmeldung verloren.
Error: (03/01/2017 12:10:47 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1515) (User: IIS APPPOOL)
Description: Dieses Benutzerprofil wurde gesichert. Bei der nächsten Anmeldung dieses Benutzers wird automatisch versucht, dieses gesicherte Profil zu verwenden.
Error: (03/01/2017 12:10:47 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1502) (User: IIS APPPOOL)
Description: Das lokal gespeicherte Profil kann nicht geladen werden. Mögliche Fehlerursachen sind nicht ausreichende Sicherheitsrechte oder ein beschädigtes lokales Profil.
Details - Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
Error: (03/01/2017 12:10:47 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT-AUTORITÄT)
Description: Die Registrierung konnte nicht geladen werden. Dieses Problem wird oft durch zuwenig Arbeitsspeicher oder nicht ausreichende Sicherheitsberechtigungen verursacht.
Details - Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
for C:\Users\DefaultAppPool\ntuser.dat
Error: (03/01/2017 12:09:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: MsiExec.exe, Version: 5.0.10586.0, Zeitstempel: 0x5632d7d4
Name des fehlerhaften Moduls: MSI44AB.tmp, Version: 10.0.386.0, Zeitstempel: 0x5850f6fd
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000018cb4
ID des fehlerhaften Prozesses: 0xe74
Startzeit der fehlerhaften Anwendung: 0x01d29217777330e6
Pfad der fehlerhaften Anwendung: C:\Windows\System32\MsiExec.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\Installer\MSI44AB.tmp
Berichtskennung: 1b12e4d8-26e1-4fbb-8967-be7183fd9cc6
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Systemfehler:
=============
Error: (03/01/2017 05:38:54 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (03/01/2017 05:17:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Spooler" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.
Error: (03/01/2017 05:16:30 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_3a656" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/01/2017 05:05:14 AM) (Source: Ntfs) (EventID: 55) (User: NT-AUTORITÄT)
Description: In der Dateisystemstruktur auf Volume "??" wurde eine Beschädigung erkannt.
In einer Indexstruktur des Dateisystems wurde eine Beschädigung gefunden. Die Dateireferenznummer ist 0x4000000001694. Der Name der Datei ist "\Windows\servicing\Packages". Das Attribut des beschädigten Indexes ist ":$I30:$INDEX_ALLOCATION".
Error: (03/01/2017 12:58:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Spooler" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.
Error: (03/01/2017 12:57:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_46425" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/01/2017 12:45:48 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Spooler" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.
Error: (03/01/2017 12:44:59 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_5faeb" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/01/2017 12:36:27 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070003 fehlgeschlagen: Microsoft Solitaire Collection
Error: (03/01/2017 12:36:22 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070003 fehlgeschlagen: Microsoft Advertising SDK for XAML
CodeIntegrity:
===================================
Date: 2017-02-25 04:57:52.270
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-02-23 19:41:13.041
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-02-22 12:34:02.940
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-02-15 13:20:17.729
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\base_nonnups\nod4263.dll.nup.raw because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-02-15 13:20:17.503
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\base_nonnups\nod4263.dll.nup.raw because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-02-15 13:20:17.269
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\base_nonnups\nod4263.dll.nup.raw because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-02-15 13:20:16.989
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\base_nonnups\nod4263.dll.nup.raw because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-02-15 13:20:16.798
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\base_nonnups\nod4263.dll.nup.raw because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-02-15 13:20:16.563
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\base_nonnups\nod4263.dll.nup.raw because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-02-11 00:44:27.755
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Prozentuale Nutzung des RAM: 19%
Installierter physikalischer RAM: 8053.6 MB
Verfügbarer physikalischer RAM: 6467.72 MB
Summe virtueller Speicher: 9333.6 MB
Verfügbarer virtueller Speicher: 8027.97 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:930.91 GB) (Free:854.23 GB) NTFS
Drive e: () (Fixed) (Total:0.5 GB) (Free:0.48 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 9BCA118F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=930.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=511 MB) - (Type=07 NTFS)
==================== Ende von Addition.txt ============================
|
| | #3 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse GMER einfach vergessen. Das Teil ist ab Windows 8 unbrauchbar.
__________________Viel wichtiger wären das ESET Log und eine genauere Beschreibung des eigentlichen Problems undnicht, dass irgendwelche angeblichen rootkits von veralteten tools gefunden wurden...
__________________ |
| | #4 |
![]() ![]() | re wie immer keine befunde gothic2 hab ich aber nie besessen. ich befürchte dass das wieder wie beim letzten mal wo sie mir helfen wollten enden wird. ich verstehe wenn sie sich nicht erneut damit befassen möchten. anscheinend werd ich mich wohl doch von meinem laptop verabschieden müssen. trotzdem noch kurze fehlerberschreibung: ständiges überhitzen, mausbewegung teilweise unberechenbar, kein zugriff auf viele programme, traskleiste wird angezeigt aber startmenue lässt sich nicht öffnen. heißt wenn ich den exporer öffnen will muss ich das über einen ordner auf dem desktop tun und den pc herunterfahren oder neustarten mit alt f4. außerdem funktionieren einige programme nicht mehr oder verschwinden sogar einfach. ich weiß nicht wie oft ich den invidia treiber schon installiert hab. und es entstehen überall neue ordner und datein. Code:
ATTFilter Log
Version der Signaturdatenbank: 15015 (20170301)
Datum: 01.03.2017 Uhrzeit: 13:31:45
Geprüfte Laufwerke, Ordner und Dateien: Arbeitsspeicher;Bootsektor;C:\Bootsektor;C:\;D:\Bootsektor;D:\;E:\Bootsektor;E:\
Arbeitsspeicher = C:\Program Files\ESET\ESET NOD32 Antivirus\Modules\em000_64\1014_new\em000_64.dll - Fehler beim Öffnen [4]
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Speech1.vdf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Speech2.vdf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Speech_Wegelagerer_deutsch.vdf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Textures.vdf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Textures_Fonts_Apostroph.vdf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Worlds.vdf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Credits.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Credits2.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Credits_Extro.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DragonAttack.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Extro_AllesWirdGut.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Extro_DJG.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Extro_KDF.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Extro_PAL.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Extro_Xardas.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = FishFood.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = intro.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = logo1.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = logo2.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = LoveScene.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = OrcAttack.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Ship.bik - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Alpenhorn.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Bass.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Brass.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Daduk.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_DragonIsland.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Flute.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Guitar.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Harp.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Metronom.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Organ.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Percussions.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Piano.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Rare.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLS_Strings.dls - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BAN_DayFgt.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BAN_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Default.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DI_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLC_DayFgt.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DLC_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = FRI_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Gamestart.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = KAS_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = KH_DayFgt.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = KH_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = LEU_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = LOB_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MAY_DayFgt.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MAY_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MI_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MO_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = NW_DayFgt.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = NW_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = NW_DayStd_A0.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = NW_DayStd_A1.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = NW_DayThr.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = NW_MonoTest.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = OWD_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = OWP_DayFgt.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = OWP_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = PIE_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = WOO_DayFgt.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = WOO_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = WOO_DayThr.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = XT_DayStd.sgt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Khorinis.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = NewWorld.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Xardas Tower.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Banditen.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _DragonIsland.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _DragonLocationFGT.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _DragonLocationStd.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Earth.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Friedhof.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Gamestart.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Graveyard.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Idylle.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Kaserne.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Khorinis.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Leuchtturm.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _LobardsHof.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Love.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Mayatempel.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Monastry.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Monastry_Indoor.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _NewWorld.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Oldcamp.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _OldWorld.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Orcs.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _OW_DragonLocation.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _OW_Path.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Pier.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Taverne.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Wood.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = _Xardas Tower.sty - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MssA3D.m3d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MssDS3D.m3d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MssDX7.m3d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MssEAX.m3d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MssRSX.m3d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MssSoft.m3d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CAMERA.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = FIGHT.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = GOTHIC.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MENU.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MUSIC.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = PARTICLEFX.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = SFX.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = VISUALFX.DAT - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = OuInfo.inf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = OU.BIN - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = OU.CSL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CAMERA.SRC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MENU.SRC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Music.src - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = particlefx.src - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = SFX.SRC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = VISUALFX.SRC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Caminst.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_defines.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_log.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_main.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_misc.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_opt.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_opt_audio.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_opt_controls.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_opt_ext.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_opt_game.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_opt_graphics.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_opt_video.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_savegame.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = menu_status.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = musicinst.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = PARTICLEFXENGINE.D - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Pfx.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = PFXMagic.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = SfxInst.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = SFXINSTSPEECH.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Visualfxinst.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Camera.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Caminst.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CLASSES.D - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = constants.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = FIGHT.D - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MENU.D - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Music.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = PARTICLEFXDEF.D - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Sfx.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = VISUALFX.D - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Bloodfly.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Crawler.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Demon.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Draconian.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Dragon.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DragonSnapper.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Dragon_Rock.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Giant_Bug.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Giant_Rat.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Gobbo.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Golem.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Harpie.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HumanS.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Irrlicht.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Lurker.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Meatbug.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Molerat.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Orc.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Scavenger.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Shadow.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Sheep.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Snapper.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Swampshark.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Troll.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Waran.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Wolf.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Zombie.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BARBQ_NW_MISC_SHEEP_01.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BARBQ_Scav.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BOOK_BLUE.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BSANVIL_OC.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BSCOOL_OC.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BSFIRE_OC.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BSSHARP_OC.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_NW_NORMAL_LOCKED.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_NW_NORMAL_OPEN.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_NW_RICH_LOCKED.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_NW_RICH_OPEN.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_OCCHESTLARGE.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_OCCHESTLARGELOCKED.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_OCCHESTMEDIUM.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_OCCHESTMEDIUMLOCKED.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_OCCRATELARGE.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTBIG_OCCRATELARGELOCKED.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTSMALL_NW_POOR_LOCKED.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTSMALL_NW_POOR_OPEN.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTSMALL_OCCHESTSMALL.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTSMALL_OCCHESTSMALLLOCKED.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTSMALL_OCCRATESMALL.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = CHESTSMALL_OCCRATESMALLLOCKED.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DOOR_NW_CITY_01.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DOOR_NW_DRAGONISLE_01.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DOOR_NW_DRAGONISLE_02.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DOOR_NW_NORMAL_01.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DOOR_NW_POOR_01.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DOOR_NW_RICH_01.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Door_Wooden.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = FIREPLACE_GROUND2.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = FIREPLACE_HIGH2.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = GRAVE_ORC_1.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = GRAVE_ORC_2.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = GRAVE_ORC_3.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = GRAVE_ORC_4.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HERB_PSI.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = LEVER_1_OC.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = PAN_OC.MDS - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = RMAKER_1.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = SMOKE_WATERPIPE.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = TOUCHPLATE_STONE.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = TURNSWITCH_BLOCK.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = VWHEEL_1_OC.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Firewaran.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Golem_Firegolem.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Golem_Icegolem.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_1hST1.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_1hST2.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_2hST1.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_2hST2.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_Acrobatic.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HumanS_Arrogance.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_Babe.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_BowT1.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_BowT2.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_CBowT1.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_CBowT2.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HumanS_Flee.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_Mage.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HumanS_Militia.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HumanS_Relaxed.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_Skeleton.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_Skeleton_Fly.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HumanS_Sprint.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = HumanS_Swim.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_Tired.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Humans_Torch.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Orc_Torch.mds - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = DIALOGCAMS.ZEN - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = lensflare.zen - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = LIGHTPRESETS.ZEN - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Reverb3.flt - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BinkW32.dll - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = BugslayerUtil.dll - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = gedialogs.dll - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = IMAGEHL2.DLL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = mallocwin32debug.dll - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = MSDBI.DLL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Mss32.dll - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = SHW32.DLL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Vdfs32g.dll - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Paths.d - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = KillHelp.exe - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Vdfs32g.exe - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = Gothic.INI - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = file_0000000D.bin - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\$Recycle.Bin\S-1-5-21-614321186-1851163967-905647231-1000\$RUI82YV\Gothic.2\Gothic2-Setup.exe = WISE = file_0000000E.bin - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\hiberfil.sys - Fehler beim Öffnen [4]
C:\pagefile.sys - Fehler beim Öffnen [4]
C:\swapfile.sys - Fehler beim Öffnen [4]
C:\System Volume Information\{0faf70ca-f998-11e6-b28f-208984e59db3}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]
C:\System Volume Information\{8bc4de37-fc32-11e6-b296-208984e59db3}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]
C:\System Volume Information\{9a63a854-fb09-11e6-b292-208984e59db3}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]
C:\System Volume Information\{9a63b75f-fb09-11e6-b292-208984e59db3}{3808876b-c176-4e48-b7ae-04046e6cc752} - Fehler beim Öffnen [4]
Bootsektor von Laufwerk D: - Fehler beim Öffnen [4]
D:\ - Fehler beim Öffnen [4]
Geprüfte Objekte: 366466
Erkannte Bedrohungen: 0
Abgeschlossen: 13:57:38 Benötigte Zeit: 1553 Sek. (00:25:53)
Hinweise:
[4] Objekt kann nicht geöffnet werden. Möglicherweise in Benutzung durch eine andere Anwendung oder das Betriebssystem.
|
| | #5 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse Das ist dann ja wohl eher ein Hardwareproblem. Ich verschiebe ins Hardwareforum.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #6 |
![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse ok danke. nur eine frage noch^^ Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 25-01-2017 01
durchgeführt von Dragonfly (25-01-2017 23:20:38) Run:1
Gestartet von C:\Users\Dragonfly\Desktop
Geladene Profile: Dragonfly & (Verfügbare Profile: Dragonfly)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
Shortcut: C:\Users\Dragonfly\Links\RecentPlaces.lnk -> L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ć ꀀz 匱卐뜥䟯ယ怂麌곫1
ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ
Systemordner 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀ⴀ㐀㘀䄀ⴀ㤀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀
*****************
C:\Users\Dragonfly\Links\RecentPlaces.lnk => erfolgreich verschoben
ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ => Fehler: Kein automatisierter Fix für diesen Eintrag gefunden.
Systemordner 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀ⴀ㐀㘀䄀ⴀ㤀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 => Fehler: Kein automatisierter Fix für diesen Eintrag gefunden.
==== Ende von Fixlog 23:20:38 ====Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 25-01-2017 01
durchgeführt von Dragonfly (25-01-2017 23:20:38) Run:1
Gestartet von C:\Users\Dragonfly\Desktop
Geladene Profile: Dragonfly & (Verfügbare Profile: Dragonfly)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
Shortcut: C:\Users\Dragonfly\Links\RecentPlaces.lnk -> L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ć ꀀz 匱卐뜥䟯ယ怂麌곫1
ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ
Systemordner 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀ⴀ㐀㘀䄀ⴀ㤀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀
*****************
C:\Users\Dragonfly\Links\RecentPlaces.lnk => erfolgreich verschoben
ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ => Fehler: Kein automatisierter Fix für diesen Eintrag gefunden.
Systemordner 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀ⴀ㐀㘀䄀ⴀ㤀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 => Fehler: Kein automatisierter Fix für diesen Eintrag gefunden.
==== Ende von Fixlog 23:20:38 ====
was ist davon zu halten? hat nix zu bedeuten wenn es nicht mehr angezeigt wird oder? |
| | #7 |
| Gesperrt ![]() ![]() ![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse Hast du mal den PC geöffnet und Staub darin ausgeblasen mit Druckluftspray oder mit einem kleinen Kompressor? Wie das geht siehst du auf Viedos hier: https://www.google.de/search?q=PC+mi...asen&tbm=vid&* |
| | #8 |
![]() ![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse Hast du bewusst einen Fix / Entfernen gestartet ? Der Scan wird via Untersuchen getriggert |
| | #9 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse Purzels Standardantwort
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #10 |
| /// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse Wenn man von nix Ahnung hat, bleiben nur hohle Sprechblasen übbrig, um irgendwie im Gespräch zu bleiben. Der begreift nix. Diese dümmliche Chip-Mine begreift nicht mal, wenn aufgefordert, mich mich zu Siezen, das zu akzeptieren ![]() Aber nebenbei: Wenn ich #6 sehe, frage ich mich, was der Thread hier zu suchen hatl
__________________ LG Der Felix Keine Hilfe per PN und E-Mail |
| | #11 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse Ich weiß nicht was das Log da zu suchen hat. Eine Entfernung bzw einen Fix hab ich nicht aufgegeben. Das hat der TO hier reingestellt als schon verschoben wurde.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #12 |
![]() ![]() | re sorry aber ich dachte anfangs ich könnte das möglicherweise selbst in den griff kriegen. pc sauber zu machen hat zu den dingen gehört die ich mir selbst zugetraut habe. mit frst umzugehen zu können gehört da zwar nicht mit dazu, aber versuchen wollte ich es trotzdem. die dazugehörige scanlog ist in meinem ersten post in diesem forum enthalten. nur weil mein internet grad stark zesiert wid wird, und ich in meinem lieblingsforum keine beiträge mehr verfasen kann weil ich egal mit welchem browser ich es versuche bevor ich das gewünschte thema annavigiert habe wieder ausgelogged bin noch mal ein post. sorry aber evtl hilft der ja weiter. grad ist es als wenn jemand live auf meinem pc rumgeistert. Code:
ATTFilter CODE]FF DefaultProfile: 4178b7vw.default
FF ProfilePath: C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\4178b7vw.default [2017-03-01]
FF Extension: (uBlock Origin) - C:\Users\Dragonfly\AppData\Roaming\Mozilla\Firefox\Profiles\4178b7vw.default\Extensions\uBlock0@raymondhill.net.xpi [2017-02-27]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-01] (Google Inc.)
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default [2017-03-01]
CHR Extension: (Docs) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-01]
CHR Extension: (Google Drive) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-01]
CHR Extension: (YouTube) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-01]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-01]
CHR Extension: (Google Mail) - C:\Users\Dragonfly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-01]
StartMenuInternet: (HKLM) OperaStable -
so lautet die letzte zeile richtig. sry Code:
ATTFilter [Device Install Log]
OS Version = 10.0.10586
Service Pack = 0.0
Suite = 0x0300
ProductType = 1
Architecture = amd64
[BeginLog]
[Boot Session: 2017/01/23 21:21:22.485]
>>> [Setup Import Driver Package - C:\WINDOWS\system32\spool\tools\Microsoft Print To PDF\prnms009.Inf]
>>> Section start 2017/01/23 21:24:48.011
cmd: C:\WINDOWS\System32\spoolsv.exe
sto: Driver package already imported as 'oem17.inf'.
<<< Section end 2017/01/23 21:24:48.136
<<< [Exit status: SUCCESS]
>>> [Setup Import Driver Package - C:\WINDOWS\system32\spool\tools\Microsoft XPS Document Writer\prnms001.Inf]
>>> Section start 2017/01/23 21:24:48.933
cmd: C:\WINDOWS\System32\spoolsv.exe
sto: Driver package already imported as 'oem9.inf'.
<<< Section end 2017/01/23 21:24:49.027
<<< [Exit status: SUCCESS]
>>> [Device Install (Hardware initiated) - SWD\IP_TUNNEL_VBUS\ISATAP_0]
>>> Section start 2017/01/23 21:33:38.688
dvi: {Build Driver List} 21:33:38.860
dvi: Searching for hardware ID(s):
dvi: *isatap
dvi: Searching for compatible ID(s):
dvi: swd\genericraw
dvi: swd\generic
dvi: Created Driver Node:
dvi: HardwareID - *ISATAP
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\nettun.inf_amd64_d43a855a82d8f170\nettun.inf
dvi: DevDesc - Microsoft-ISATAP-Adapter
dvi: Section - ISATAP.ndi
dvi: Rank - 0x00ff0000
dvi: Signer Score - INBOX
dvi: DrvDate - 06/21/2006
dvi: Version - 10.0.10586.0
dvi: Created Driver Node:
dvi: HardwareID - SWD\GenericRaw
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\c_swdevice.inf_amd64_eea068c3aba1e530\c_swdevice.inf
dvi: DevDesc - Generisches Softwaregerät
dvi: Section - SoftwareDevice
dvi: Rank - 0x00ff3000
dvi: Signer Score - INBOX
dvi: DrvDate - 06/21/2006
dvi: Version - 10.0.10586.0
dvi: {Build Driver List - exit(0x00000000)} 21:33:39.282
dvi: {DIF_SELECTBESTCOMPATDRV} 21:33:39.282
dvi: Default installer: Enter 21:33:39.313
dvi: {Select Best Driver}
dvi: Class GUID of device changed to: {4d36e972-e325-11ce-bfc1-08002be10318}.
dvi: Selected:
dvi: Description - [Microsoft-ISATAP-Adapter]
dvi: InfFile - [c:\windows\system32\driverstore\filerepository\nettun.inf_amd64_d43a855a82d8f170\nettun.inf]
dvi: Section - [ISATAP.ndi]
dvi: {Select Best Driver - exit(0x00000000)}
dvi: Default installer: Exit
dvi: {DIF_SELECTBESTCOMPATDRV - exit(0x00000000)} 21:33:39.329
ndv: {Core Device Install} 21:33:39.329
ndv: {Install Device - SWD\IP_TUNNEL_VBUS\ISATAP_0} 21:33:39.329
ndv: Parent device: SWD\IP_TUNNEL_VBUS\IP_TUNNEL_DEVICE_ROOT
sto: {Configure Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\nettun.inf_amd64_d43a855a82d8f170\nettun.inf}
sto: Source Filter = *isatap
inf: Class GUID = {4d36e972-e325-11ce-bfc1-08002be10318}
inf: Class Options = Configurable
inf: {Configure Driver: Microsoft ISATAP Adapter}
inf: Section Name = ISATAP.ndi
inf: {Add Service: tunnel}
inf: Start Type = 3
inf: Service Type = 1
inf: Error Control = 1
inf: Image Path = \SystemRoot\System32\drivers\tunnel.sys
inf: Display Name = Microsoft Tunnel Miniport Adapter Driver
inf: Group = NDIS
inf: Created new service 'tunnel'.
inf: {Add Service: exit(0x00000000)}
inf: Hardware Id = *ISATAP
inf: {Configure Driver Configuration: ISATAP.ndi}
inf: Service Name = tunnel
inf: Config Flags = 0x00000000
inf: {Configure Driver Configuration: exit(0x00000000)}
inf: {Configure Driver: exit(0x00000000)}
sto: {Configure Driver Package: exit(0x00000000)}
dvi: Install Device: Configuring device (nettun.inf:*isatap,ISATAP.ndi). 21:33:47.345
dvi: Install Device: Configuring device completed. 21:33:47.345
dvi: Install Device: Removing device sub-tree. 21:33:47.345
dvi: Install Device: Removing device sub-tree completed. 21:33:47.392
dvi: Install Device: Restarting device. 21:33:47.392
dvi: Install Device: Restarting device completed. 21:33:47.470
ndv: {Install Device - exit(0x00000000)} 21:33:47.517
ndv: {Core Device Install - exit(0x00000000)} 21:33:47.517
ndv: Waiting for device post-install to complete. 21:33:47.517
ndv: Device post-install completed. 21:33:47.876
<<< Section end 2017/01/23 21:33:47.876
<<< [Exit status: SUCCESS]
>>> [Device Install (Hardware initiated) - SWD\IP_TUNNEL_VBUS\Teredo_Tunnel_Device]
>>> Section start 2017/01/23 21:33:43.970
dvi: {Build Driver List} 21:33:43.985
dvi: Searching for hardware ID(s):
dvi: *teredo
dvi: Searching for compatible ID(s):
dvi: swd\genericraw
dvi: swd\generic
dvi: Created Driver Node:
dvi: HardwareID - *TEREDO
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\nettun.inf_amd64_d43a855a82d8f170\nettun.inf
dvi: DevDesc - Microsoft-Teredo-Tunneling-Adapter
dvi: Section - TEREDO.ndi
dvi: Rank - 0x00ff0000
dvi: Signer Score - INBOX
dvi: DrvDate - 06/21/2006
dvi: Version - 10.0.10586.0
dvi: Created Driver Node:
dvi: HardwareID - SWD\GenericRaw
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\c_swdevice.inf_amd64_eea068c3aba1e530\c_swdevice.inf
dvi: DevDesc - Generisches Softwaregerät
dvi: Section - SoftwareDevice
dvi: Rank - 0x00ff3000
dvi: Signer Score - INBOX
dvi: DrvDate - 06/21/2006
dvi: Version - 10.0.10586.0
dvi: {Build Driver List - exit(0x00000000)} 21:33:44.017
dvi: {DIF_SELECTBESTCOMPATDRV} 21:33:44.017
dvi: Default installer: Enter 21:33:44.017
dvi: {Select Best Driver}
dvi: Class GUID of device changed to: {4d36e972-e325-11ce-bfc1-08002be10318}.
dvi: Selected:
dvi: Description - [Microsoft-Teredo-Tunneling-Adapter]
dvi: InfFile - [c:\windows\system32\driverstore\filerepository\nettun.inf_amd64_d43a855a82d8f170\nettun.inf]
dvi: Section - [TEREDO.ndi]
dvi: {Select Best Driver - exit(0x00000000)}
dvi: Default installer: Exit
dvi: {DIF_SELECTBESTCOMPATDRV - exit(0x00000000)} 21:33:44.032
ndv: Waiting for previous device install to complete. 21:33:44.032
ndv: {Core Device Install} 21:33:47.517
ndv: {Install Device - SWD\IP_TUNNEL_VBUS\TEREDO_TUNNEL_DEVICE} 21:33:47.517
ndv: Parent device: SWD\IP_TUNNEL_VBUS\IP_TUNNEL_DEVICE_ROOT
sto: {Configure Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\nettun.inf_amd64_d43a855a82d8f170\nettun.inf}
sto: Source Filter = *teredo
inf: Class GUID = {4d36e972-e325-11ce-bfc1-08002be10318}
inf: Class Options = Configurable
inf: {Configure Driver: Microsoft Teredo Tunneling Adapter}
inf: Section Name = TEREDO.ndi
inf: {Add Service: tunnel}
inf: Start Type = 3
inf: Service Type = 1
inf: Error Control = 1
inf: Image Path = \SystemRoot\System32\drivers\tunnel.sys
inf: Display Name = Microsoft Tunnel Miniport Adapter Driver
inf: Group = NDIS
inf: Updated service 'tunnel'.
inf: {Add Service: exit(0x00000000)}
inf: Hardware Id = *TEREDO
inf: {Configure Driver Configuration: TEREDO.ndi}
inf: Service Name = tunnel
inf: Config Flags = 0x00000000
inf: {Configure Driver Configuration: exit(0x00000000)}
inf: {Configure Driver: exit(0x00000000)}
sto: {Configure Driver Package: exit(0x00000000)}
dvi: Install Device: Configuring device (nettun.inf:*teredo,TEREDO.ndi). 21:33:47.548
dvi: Install Device: Configuring device completed. 21:33:47.548
dvi: Install Device: Removing device sub-tree. 21:33:47.548
dvi: Install Device: Removing device sub-tree completed. 21:33:47.564
dvi: Install Device: Restarting device. 21:33:47.564
dvi: Install Device: Restarting device completed. 21:33:47.611
ndv: {Install Device - exit(0x00000000)} 21:33:47.611
ndv: {Core Device Install - exit(0x00000000)} 21:33:47.611
ndv: Waiting for device post-install to complete. 21:33:47.626
ndv: Device post-install completed. 21:33:48.439
<<< Section end 2017/01/23 21:33:48.470
<<< [Exit status: SUCCESS]
>>> [Device Install (DiInstallDevice) - USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000]
>>> Section start 2017/01/23 21:37:58.626
cmd: C:\WINDOWS\System32\svchost.exe -k netsvcs
ndv: Flags: 0x0000000a
dvi: Class GUID of device remains: {6bdd1fc6-810f-11d0-bec7-08002be2092f}.
sto: {Setup Import Driver Package: c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331avs.inf} 21:37:58.626
inf: Provider: Vimicro
inf: Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
inf: Driver Version: 04/14/2015,3.15.0612.1
inf: Catalog File: vm331avs.cat
pol: {Driver package policy check} 21:37:58.694
pol: {Driver package policy check - exit(0x00000000)} 21:37:58.695
sto: {Stage Driver Package: c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331avs.inf} 21:37:58.696
! inf: Needed section [DSHOWEXT.Registration] not found. Code = 1315, Line = 332
! inf: Needed section [DSHOWEXT.Registration] not found. Code = 1315, Line = 332
! inf: Needed section [DSHOWEXT.Registration] not found. Code = 1315, Line = 332
! inf: Needed section [DSHOWEXT.Registration] not found. Code = 1315, Line = 332
inf: {Query Configurability: c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331avs.inf} 21:37:58.808
! inf: Needed section [DSHOWEXT.Registration] not found. Code = 1315, Line = 332
! inf: Section [USBCamera_HD.Config.AddReg.VISTA64] referenced from DelReg and AddReg directive. Code = 1205, Line = 501
! inf: Section [USBCamera_HD.Config.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 432
! inf: Section [USBCamera_HD.Envirment.Addreg] referenced from DelReg and AddReg directive. Code = 1205, Line = 727
! inf: Section [USBCamera_HD.Prp.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 540
! inf: Section [USBCamera_HD.TWAIN.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 579
! inf: Section [USBCamera_HD.StillMnt.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 588
! inf: Section [USBCamera_HD.UnInstall.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 603
! inf: Found legacy CopyFiles operation with non-system target path (C:\Program Files (x86)\USB Camera) for 'VM331STI.EXE'. Code = 1307
! inf: Found legacy AddReg operation using non-relative key (HKLM\Software\WOW6432Node\ZSMC\USBCAMERA\ZC0331\BigDogPath). Code = 1305
! inf: Found legacy AddReg operation defining co-installers (CoInstallers32). Code = 1304
! inf: Needed section [DSHOWEXT.Registration] not found. Code = 1315, Line = 332
! inf: Section [USBCamera_VGA.Prp.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 2738
! inf: Driver package 'vm331avs.inf' is NOT configurable.
inf: {Query Configurability: exit(0x00000000)} 21:37:58.870
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331avs.cat' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331avs.cat'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331avs.inf' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331avs.inf'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\VM331STI.EXE' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\VM331STI.EXE'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331avs.rsf' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331avs.rsf'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331Rmv.ini' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331Rmv.ini'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\VmCoix64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\VmCoix64.dll'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\Keywest.dat' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\Keywest.dat'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331.lrc' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331.lrc'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\uninstal.iss' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\uninstal.iss'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\331prx64.ax' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\331prx64.ax'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\331RvX64.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\331RvX64.exe'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vmprp331.ax' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vmprp331.ax'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\VM331TWN.DS' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\VM331TWN.DS'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\vm331x64.sys' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331x64.sys'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\Language\1033.lrc' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\Language\1033.lrc'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\Language\2052.lrc' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\Language\2052.lrc'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\Language\1028.lrc' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\Language\1028.lrc'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\1be0e7e3-d74a-4737-808b-f5da0ba9a7cc\Language\3076.lrc' to 'C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\Language\3076.lrc'.
sto: {DRIVERSTORE IMPORT VALIDATE} 21:37:59.011
sig: {_VERIFY_FILE_SIGNATURE} 21:37:59.058
sig: Key = vm331avs.inf
sig: FilePath = C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331avs.inf
sig: Catalog = C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\vm331avs.cat
sig: Success: File is signed in catalog.
sig: {_VERIFY_FILE_SIGNATURE exit(0x00000000)} 21:37:59.058
sto: {DRIVERSTORE IMPORT VALIDATE: exit(0x00000000)} 21:37:59.167
sig: Signer Score = 0x0D000005
sig: Signer Name = Microsoft Windows Hardware Compatibility Publisher
sto: {DRIVERSTORE IMPORT BEGIN} 21:37:59.167
sto: {DRIVERSTORE IMPORT BEGIN: exit(0x00000000)} 21:37:59.167
cpy: {Copy Directory: C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}} 21:37:59.167
cpy: Target Path = C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12
cpy: {Copy Directory: C:\WINDOWS\System32\DriverStore\Temp\{d7ac14e9-a491-dc4f-8f86-6f4dd274ed84}\Language} 21:37:59.183
cpy: Target Path = C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\Language
cpy: {Copy Directory: exit(0x00000000)} 21:37:59.198
cpy: {Copy Directory: exit(0x00000000)} 21:37:59.198
idb: {Register Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331avs.inf} 21:37:59.198
idb: Created driver package object 'vm331avs.inf_amd64_b0ae606f74a1aa12' in DRIVERS database node.
idb: Created driver INF file object 'oem30.inf' in DRIVERS database node.
idb: Registered driver package 'vm331avs.inf_amd64_b0ae606f74a1aa12' with 'oem30.inf'.
idb: {Register Driver Package: exit(0x00000000)} 21:37:59.230
idb: {Publish Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331avs.inf} 21:37:59.230
idb: Activating driver package 'vm331avs.inf_amd64_b0ae606f74a1aa12'.
cpy: Published 'vm331avs.inf_amd64_b0ae606f74a1aa12\vm331avs.inf' to 'oem30.inf'.
! inf: Section [USBCamera_HD.Config.AddReg.VISTA64] referenced from DelReg and AddReg directive. Code = 1205, Line = 501
! inf: Section [USBCamera_HD.Config.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 432
! inf: Section [USBCamera_HD.Envirment.Addreg] referenced from DelReg and AddReg directive. Code = 1205, Line = 727
! inf: Section [USBCamera_HD.Prp.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 540
! inf: Section [USBCamera_HD.TWAIN.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 579
! inf: Section [USBCamera_HD.StillMnt.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 588
! inf: Section [USBCamera_HD.UnInstall.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 603
! inf: Section [USBCamera_VGA.Prp.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 2738
! idb: Driver INF match for 'oem30.inf' already exists under 'USB\VID_04F2&PID_B2E1&MI_00'.
idb: Indexed 26 device IDs for 'vm331avs.inf_amd64_b0ae606f74a1aa12'.
sto: Flushed driver database node 'DRIVERS'. Time = 0 ms
sto: Flushed driver database node 'SYSTEM'. Time = 0 ms
idb: {Publish Driver Package: exit(0x00000000)} 21:37:59.308
sto: {DRIVERSTORE IMPORT END} 21:37:59.323
sig: Installed catalog 'vm331avs.cat' as 'oem30.cat'.
sto: {DRIVERSTORE IMPORT END: exit(0x00000000)} 21:37:59.933
sto: {Stage Driver Package: exit(0x00000000)} 21:37:59.933
sto: {Setup Import Driver Package - exit (0x00000000)} 21:37:59.948
dvi: Searching for hardware ID(s):
dvi: usb\vid_04f2&pid_b35d&rev_7612&mi_00
dvi: usb\vid_04f2&pid_b35d&mi_00
dvi: Searching for compatible ID(s):
dvi: usb\class_0e&subclass_03&prot_00
dvi: usb\class_0e&subclass_03
dvi: usb\class_0e
dvi: Class GUID of device remains: {6bdd1fc6-810f-11d0-bec7-08002be2092f}.
dvi: {Plug and Play Service: Device Install for USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000}
ndv: Driver INF Path: C:\WINDOWS\INF\oem30.inf
ndv: Driver Node Name: vm331avs.inf:084de1efb6a06654:USBCamera_HD.Config.VISTA64:3.15.612.1:usb\vid_04f2&pid_b35d&mi_00
ndv: Driver Store Path: C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331avs.inf
dvi: Searching for hardware ID(s):
dvi: usb\vid_04f2&pid_b35d&rev_7612&mi_00
dvi: usb\vid_04f2&pid_b35d&mi_00
dvi: Searching for compatible ID(s):
dvi: usb\class_0e&subclass_03&prot_00
dvi: usb\class_0e&subclass_03
dvi: usb\class_0e
dvi: Class GUID of device changed to: {6bdd1fc6-810f-11d0-bec7-08002be2092f}.
ndv: {Core Device Install} 21:38:00.011
ndv: {Install Device - USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000} 21:38:00.011
ndv: Parent device: USB\VID_04F2&PID_B35D\0x0001
! ndv: Device class {6bdd1fc6-810f-11d0-bec7-08002be2092f} is not configurable.
dvi: {DIF_ALLOW_INSTALL} 21:38:00.042
dvi: Using exported function 'ClassInstall' in module 'C:\WINDOWS\system32\sti_ci.dll'.
dvi: Class installer == sti_ci.dll,ClassInstall
dvi: Class installer: Enter 21:38:00.058
dvi: Class installer: Exit
dvi: Default installer: Enter 21:38:00.058
dvi: Default installer: Exit
dvi: {DIF_ALLOW_INSTALL - exit(0xe000020e)} 21:38:00.058
dvi: {DIF_INSTALLDEVICEFILES} 21:38:00.058
dvi: Class installer: Enter 21:38:00.058
dvi: Class installer: Exit
dvi: Default installer: Enter 21:38:00.058
dvi: Default installer: Exit
dvi: {DIF_INSTALLDEVICEFILES - exit(0x00000000)} 21:38:00.089
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331x64.sys' to 'C:\WINDOWS\System32\Drivers\vm331avs.sys'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331avs.rsf' to 'C:\WINDOWS\System\vm331avs.rsf'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vmprp331.ax' to 'C:\WINDOWS\SysWOW64\vmprp331.ax'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331Rmv.ini' to 'C:\WINDOWS\SysWOW64\vm331Rmv.ini'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\331prx64.ax' to 'C:\WINDOWS\System32\331prx64.ax'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\VM331TWN.DS' to 'C:\WINDOWS\twain_32\VM331\VM331TWN.DS'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331.lrc' to 'C:\WINDOWS\twain_32\VM331\vm331.lrc'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\VM331STI.EXE' to 'C:\Program Files (x86)\USB Camera\VM331STI.EXE'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\331RvX64.exe' to 'C:\Program Files (x86)\USB Camera\vm331Rmv.exe'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331Rmv.ini' to 'C:\Program Files (x86)\USB Camera\vm331Rmv.ini'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\uninstal.iss' to 'C:\Program Files (x86)\USB Camera\uninstal.iss'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331Rmv.ini' to 'C:\WINDOWS\vm331Rmv.ini'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\Language\1028.lrc' to 'C:\WINDOWS\twain_32\VM331\1028.lrc'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\Language\1033.lrc' to 'C:\WINDOWS\twain_32\VM331\1033.lrc'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\Language\2052.lrc' to 'C:\WINDOWS\twain_32\VM331\2052.lrc'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\Language\3076.lrc' to 'C:\WINDOWS\twain_32\VM331\3076.lrc'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\Keywest.dat' to 'C:\WINDOWS\twain_32\VM331\Keywest.dat'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\vm331avs.inf_amd64_b0ae606f74a1aa12\VmCoix64.dll' to 'C:\WINDOWS\system32\VmCoinst.dll'.
dvi: {DIF_REGISTER_COINSTALLERS} 21:38:01.198
dvi: Reset Device: Resetting device configuration. 21:38:01.214
dvi: Reset Device: Resetting device configuration completed. 21:38:01.214
dvi: Class installer: Enter 21:38:01.214
dvi: Class installer: Exit
dvi: Default installer: Enter 21:38:01.214
dvi: Default installer: Exit
dvi: {DIF_REGISTER_COINSTALLERS - exit(0x00000000)} 21:38:01.214
dvi: {DIF_INSTALLINTERFACES} 21:38:01.230
dvi: Using exported function 'VmCoInstallEntryPoint' in module 'C:\WINDOWS\system32\VmCoinst.dll'.
dvi: CoInstaller 1 == VmCoinst.dll,VmCoInstallEntryPoint
dvi: CoInstaller 1: Enter 21:38:01.230
dvi: CoInstaller 1: Exit
dvi: Class installer: Enter 21:38:01.230
dvi: Class installer: Exit
dvi: Default installer: Enter 21:38:01.230
dvi: Default installer: Exit
dvi: {DIF_INSTALLINTERFACES - exit(0x00000000)} 21:38:01.230
dvi: {DIF_INSTALLDEVICE} 21:38:01.230
dvi: CoInstaller 1: Enter 21:38:01.230
dvi: CoInstaller 1: Exit
dvi: Class installer: Enter 21:38:01.230
dvi: {Install DEVICE}
dvi: {Writing Device Properties}
dvi: Strong Name=oem30.inf:084de1efb6a06654:USBCamera_HD.Config.VISTA64:3.15.612.1:usb\vid_04f2&pid_b35d&mi_00
dvi: {Writing Device Properties - Complete}
inf: AddService=vm331avs,0x00000002,USBCamera_HD.Config.ServiceInstall (vm331avs.inf line 655)
dvi: Add Service: Created service 'vm331avs'.
dvi: {Install DEVICE exit (0x00000000)}
sto: {Configure Driver Package: c:\windows\system32\driverstore\filerepository\vm331avs.inf_amd64_b0ae606f74a1aa12\vm331avs.inf}
sto: Source Filter = USBCamera_HD.Config.VISTA64
sto: Target Filter = USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000
inf: Class GUID = {6bdd1fc6-810f-11d0-bec7-08002be2092f}
! inf: Section [USBCamera_HD.Config.AddReg.VISTA64] referenced from DelReg and AddReg directive. Code = 1205, Line = 501
! inf: Section [USBCamera_HD.Config.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 432
! inf: Section [USBCamera_HD.Envirment.Addreg] referenced from DelReg and AddReg directive. Code = 1205, Line = 727
! inf: Section [USBCamera_HD.Prp.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 540
! inf: Section [USBCamera_HD.TWAIN.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 579
! inf: Section [USBCamera_HD.StillMnt.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 588
! inf: Section [USBCamera_HD.UnInstall.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 603
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
! inf: Section [USBCamera_VGA.Prp.NTamd64.AddReg] referenced from DelReg and AddReg directive. Code = 1205, Line = 2738
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Device: USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000}
inf: {Configure Device: exit(0x00000000)}
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
inf: {Configure Driver: Lenovo EasyCamera}
inf: Section Name = USBCamera_HD.Config.VISTA64
inf: {Configure Driver: exit(0x00000000)}
sto: {Configure Driver Package: exit(0x00000000)}
dvi: Install Device: Configuring device class. 21:38:02.683
dvi: Install Device: Configuring device class completed. 21:38:02.683
dvi: {Restarting Devices} 21:38:02.683
dvi: Query-remove: USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000
dvi: Restart: USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000
dvi: Restart verified: USB\VID_04F2&PID_B35D&MI_00\7&114AF5F&0&0000
dvi: {Restarting Devices exit} 21:38:02.855
dvi: Class installer: Exit
dvi: {DIF_INSTALLDEVICE - exit(0x00000000)} 21:38:02.855
dvi: {DIF_NEWDEVICEWIZARD_FINISHINSTALL} 21:38:02.902
dvi: CoInstaller 1: Enter 21:38:02.902
dvi: CoInstaller 1: Exit
dvi: Class installer: Enter 21:38:02.949
dvi: Class installer: Exit
dvi: Default installer: Enter 21:38:02.949
dvi: Default installer: Exit
dvi: {DIF_NEWDEVICEWIZARD_FINISHINSTALL - exit(0xe000020e)} 21:38:02.949
ndv: {Install Device - exit(0x00000000)} 21:38:02.980
ndv: {Core Device Install - exit(0x00000000)} 21:38:02.980
dvi: {DIF_DESTROYPRIVATEDATA} 21:38:02.980
dvi: CoInstaller 1: Enter 21:38:02.980
dvi: CoInstaller 1: Exit
dvi: Class installer: Enter 21:38:02.980
dvi: Class installer: Exit
dvi: Default installer: Enter 21:38:02.980
dvi: Default installer: Exit
dvi: {DIF_DESTROYPRIVATEDATA - exit(0xe000020e)} 21:38:02.980
ump: {Plug and Play Service: Device Install exit(00000000)}
dvi: {DIF_DESTROYPRIVATEDATA} 21:38:03.011
dvi: Class installer: Enter 21:38:03.011
dvi: Class installer: Exit
dvi: Default installer: Enter 21:38:03.027
dvi: Default installer: Exit
dvi: {DIF_DESTROYPRIVATEDATA - exit(0xe000020e)} 21:38:03.027
<<< Section end 2017/01/23 21:38:03.027
<<< [Exit status: SUCCESS]
>>> [Device Install (DiInstallDevice) - USB\VID_0BDA&PID_0129\20100201396000000]
>>> Section start 2017/01/23 21:38:18.872
cmd: C:\WINDOWS\System32\svchost.exe -k netsvcs
ndv: Flags: 0x0000000a
dvi: Class GUID of device changed to: {36fc9e60-c465-11cf-8056-444553540000}.
sto: {Setup Import Driver Package: c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\rtsuerx.inf} 21:38:18.872
inf: Provider: Realtek Semiconduct Corp.
inf: Class GUID: {36FC9E60-C465-11CF-8056-444553540000}
inf: Driver Version: 02/16/2016,10.0.10586.31222
inf: Catalog File: RtsUer64.cat
pol: {Driver package policy check} 21:38:18.872
pol: {Driver package policy check - exit(0x00000000)} 21:38:18.888
sto: {Stage Driver Package: c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\rtsuerx.inf} 21:38:18.890
inf: {Query Configurability: c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\rtsuerx.inf} 21:38:18.897
! inf: Found legacy AddReg operation using non-relative key (HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}). Code = 1305
! inf: Found legacy AddReg operation defining co-installers (CoInstallers32). Code = 1304
! inf: Driver package 'rtsuerx.inf' is NOT configurable.
inf: {Query Configurability: exit(0x00000000)} 21:38:18.906
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\RtCRX64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\RtCRX64.dll'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\RtCRU64.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\RtCRU64.exe'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\RtsUer.sys' to 'C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\RtsUer.sys'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\RtsUer64.cat' to 'C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\RtsUer64.cat'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\rtsuerx.inf' to 'C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\rtsuerx.inf'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\RsCRIcon.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\RsCRIcon.dll'.
flq: Copying 'c:\programdata\microsoft\windows\devicesoftwareupdates\3f01bed4-0f1f-4d6a-a2f4-aee880cb3e1e\SDRTCPRM.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\SDRTCPRM.dll'.
sto: {DRIVERSTORE IMPORT VALIDATE} 21:38:18.944
sig: {_VERIFY_FILE_SIGNATURE} 21:38:18.959
sig: Key = rtsuerx.inf
sig: FilePath = C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\rtsuerx.inf
sig: Catalog = C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}\RtsUer64.cat
sig: Success: File is signed in catalog.
sig: {_VERIFY_FILE_SIGNATURE exit(0x00000000)} 21:38:18.959
sto: {DRIVERSTORE IMPORT VALIDATE: exit(0x00000000)} 21:38:19.115
sig: Signer Score = 0x0D000005
sig: Signer Name = Microsoft Windows Hardware Compatibility Publisher
sto: {DRIVERSTORE IMPORT BEGIN} 21:38:19.115
sto: {DRIVERSTORE IMPORT BEGIN: exit(0x00000000)} 21:38:19.131
cpy: {Copy Directory: C:\WINDOWS\System32\DriverStore\Temp\{0d4ca0d2-d060-8944-84a4-4c221ae39beb}} 21:38:19.131
cpy: Target Path = C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716
cpy: {Copy Directory: exit(0x00000000)} 21:38:19.147
idb: {Register Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\rtsuerx.inf} 21:38:19.147
idb: Created driver package object 'rtsuerx.inf_amd64_08d25a4b06b38716' in SYSTEM database node.
idb: Created driver INF file object 'oem31.inf' in SYSTEM database node.
idb: Registered driver package 'rtsuerx.inf_amd64_08d25a4b06b38716' with 'oem31.inf'.
idb: {Register Driver Package: exit(0x00000000)} 21:38:19.147
idb: {Publish Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\rtsuerx.inf} 21:38:19.147
idb: Activating driver package 'rtsuerx.inf_amd64_08d25a4b06b38716'.
cpy: Published 'rtsuerx.inf_amd64_08d25a4b06b38716\rtsuerx.inf' to 'oem31.inf'.
idb: Indexed 75 device IDs for 'rtsuerx.inf_amd64_08d25a4b06b38716'.
sto: Flushed driver database node 'SYSTEM'. Time = 15 ms
idb: {Publish Driver Package: exit(0x00000000)} 21:38:19.178
sto: {DRIVERSTORE IMPORT END} 21:38:19.178
sig: Installed catalog 'RtsUer64.cat' as 'oem31.cat'.
sto: {DRIVERSTORE IMPORT END: exit(0x00000000)} 21:38:19.290
sto: {Stage Driver Package: exit(0x00000000)} 21:38:19.290
sto: {Setup Import Driver Package - exit (0x00000000)} 21:38:19.306
dvi: Searching for hardware ID(s):
dvi: usb\vid_0bda&pid_0129&rev_3960
dvi: usb\vid_0bda&pid_0129
dvi: Searching for compatible ID(s):
dvi: usb\class_ff&subclass_06&prot_50
dvi: usb\class_ff&subclass_06
dvi: usb\class_ff
dvi: Class GUID of device changed to: {36fc9e60-c465-11cf-8056-444553540000}.
dvi: {Plug and Play Service: Device Install for USB\VID_0BDA&PID_0129\20100201396000000}
ndv: Driver INF Path: C:\WINDOWS\INF\oem31.inf
ndv: Driver Node Name: rtsuerx.inf:b2fe481800604070:RSUER.UVSTOR:10.0.10586.31222:usb\vid_0bda&pid_0129
ndv: Driver Store Path: C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\rtsuerx.inf
dvi: Searching for hardware ID(s):
dvi: usb\vid_0bda&pid_0129&rev_3960
dvi: usb\vid_0bda&pid_0129
dvi: Searching for compatible ID(s):
dvi: usb\class_ff&subclass_06&prot_50
dvi: usb\class_ff&subclass_06
dvi: usb\class_ff
dvi: Class GUID of device changed to: {36fc9e60-c465-11cf-8056-444553540000}.
ndv: {Core Device Install} 21:38:19.321
ndv: {Install Device - USB\VID_0BDA&PID_0129\20100201396000000} 21:38:19.321
ndv: Parent device: USB\VID_8087&PID_0024\5&1a59d89a&0&1
dvi: {DIF_ALLOW_INSTALL} 21:38:19.337
dvi: Default installer: Enter 21:38:19.337
dvi: Default installer: Exit
dvi: {DIF_ALLOW_INSTALL - exit(0xe000020e)} 21:38:19.337
dvi: {DIF_INSTALLDEVICEFILES} 21:38:19.337
dvi: Default installer: Enter 21:38:19.337
dvi: Default installer: Exit
dvi: {DIF_INSTALLDEVICEFILES - exit(0x00000000)} 21:38:19.337
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\RtsUer.sys' to 'C:\WINDOWS\System32\Drivers\RtsUer.sys'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\SDRTCPRM.dll' to 'C:\WINDOWS\SysWOW64\sda\SDRTCPRM.dll'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\RtCRU64.exe' to 'C:\WINDOWS\RtCRU64.exe'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\RsCRIcon.dll' to 'C:\WINDOWS\SysWOW64\RsCRIcon.dll'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\rtsuerx.inf_amd64_08d25a4b06b38716\RtCRX64.dll' to 'C:\WINDOWS\system32\RtCRX64.dll'.
dvi: {DIF_REGISTER_COINSTALLERS} 21:38:19.665
dvi: Reset Device: Resetting device configuration. 21:38:19.665
dvi: Reset Device: Resetting device configuration completed. 21:38:19.665
dvi: Default installer: Enter 21:38:19.665
dvi: Default installer: Exit
dvi: {DIF_REGISTER_COINSTALLERS - exit(0x00000000)} 21:38:19.681
dvi: {DIF_INSTALLINTERFACES} 21:38:19.681
dvi: Using exported function 'RtCR_CoInstaller' in module 'C:\WINDOWS\system32\RtCRX64.dll'.
dvi: CoInstaller 1 == RtCRX64.dll,RtCR_CoInstaller
dvi: CoInstaller 1: Enter 21:38:19.681
dvi: CoInstaller 1: Exit
dvi: Default installer: Enter 21:38:19.681
dvi: Default installer: Exit
dvi: {DIF_INSTALLINTERFACES - exit(0x00000000)} 21:38:19.681
dvi: {DIF_INSTALLDEVICE} 21:38:19.681
dvi: CoInstaller 1: Enter 21:38:19.681
dvi: CoInstaller 1: Exit
dvi: Default installer: Enter 21:38:19.681
dvi: {Install DEVICE}
dvi: {Writing Device Properties}
dvi: Strong Name=oem31.inf:b2fe481800604070:RSUER.UVSTOR:10.0.10586.31222:usb\vid_0bda&pid_0129
dvi: {Writing Device Properties - Complete}
inf: AddService=RTSUER,0x00000002,UVSTOR_Service_Inst (rtsuerx.inf line 146)
dvi: Add Service: Created service 'RTSUER'.
dvi: {Install DEVICE exit (0x00000000)}
dvi: Install Device: Configuring device class. 21:38:19.696
dvi: Install Device: Configuring device class completed. 21:38:19.696
dvi: {Restarting Devices} 21:38:19.712
dvi: Restart: USB\VID_0BDA&PID_0129\20100201396000000
dvi: {Restarting Devices exit} 21:38:19.842
dvi: Default installer: Exit
dvi: CoInstaller 1: Enter (Post Processing) 21:38:19.842
dvi: CoInstaller 1: Exit (Post Processing)
dvi: {DIF_INSTALLDEVICE - exit(0x00000000)} 21:38:19.842
dvi: {DIF_NEWDEVICEWIZARD_FINISHINSTALL} 21:38:19.842
dvi: CoInstaller 1: Enter 21:38:19.842
dvi: CoInstaller 1: Exit
dvi: Default installer: Enter 21:38:19.842
dvi: Default installer: Exit
dvi: {DIF_NEWDEVICEWIZARD_FINISHINSTALL - exit(0xe000020e)} 21:38:19.842
ndv: {Install Device - exit(0x00000000)} 21:38:19.842
ndv: {Core Device Install - exit(0x00000000)} 21:38:19.842
dvi: {DIF_DESTROYPRIVATEDATA} 21:38:19.842
dvi: CoInstaller 1: Enter 21:38:19.842
dvi: CoInstaller 1: Exit
dvi: Default installer: Enter 21:38:19.857
dvi: Default installer: Exit
dvi: {DIF_DESTROYPRIVATEDATA - exit(0xe000020e)} 21:38:19.857
ump: {Plug and Play Service: Device Install exit(00000000)}
<<< Section end 2017/01/23 21:38:19.857
<<< [Exit status: SUCCESS]
>>> [Device and Driver Disk Cleanup Handler]
>>> Section start 2017/01/23 21:42:15.386
cmd: taskhostw.exe /RuntimeWide
set: Searching for not-recently detected devices that may be removed from the system.
set: Devices will be removed during this pass.
set: Devices removed: 0
set: Searching for unused drivers that may be removed from the system.
set: Drivers will be removed during this pass.
set: Recovery Timestamp: 01/24/2017 20:25:40:0607.
set: Driver packages removed: 0
set: Total size on disk: 0
<<< Section end 2017/01/23 21:42:45.732
<<< [Exit status: SUCCESS]
[Boot Session: 2017/01/23 21:55:38.485]
>>> [Device Install (DiShowUpdateDevice) - PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA&REV_A1\4&23704A70&0&0008]
>>> Section start 2017/01/23 23:11:55.013
cmd: "C:\WINDOWS\system32\mmc.exe" C:\WINDOWS\system32\devmgmt.msc
dvi: {DIF_UPDATEDRIVER_UI} 23:11:55.029
dvi: CoInstaller 1: Enter 23:11:55.029
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 23:11:55.029
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 23:11:55.044
dvi: Class installer: Exit
dvi: Default installer: Enter 23:11:55.044
dvi: Default installer: Exit
dvi: {DIF_UPDATEDRIVER_UI - exit(0xe000020e)} 23:11:55.044
ndv: {Update Driver Software Wizard for PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA&REV_A1\4&23704A70&0&0008}
sto: {Setup Import Driver Package: c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvltwu.inf} 23:14:25.541
inf: Provider: NVIDIA
inf: Class GUID: {4D36E968-E325-11CE-BFC1-08002BE10318}
inf: Driver Version: 08/01/2016,21.21.13.6909
inf: Catalog File: NV_DISP.CAT
sto: {Copy Driver Package: c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvltwu.inf} 23:14:27.167
sto: Driver Package = c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvltwu.inf
sto: Flags = 0x00000007
sto: Destination = C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}
sto: Copying driver package files to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvinit.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvinit.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdetx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdetx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\dbInstaller.exe' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\dbInstaller.exe'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvhda64.sys' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvhda64.sys'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvcompiler32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcompiler32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdebugdump.ex_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdebugdump.exe'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvcompiler64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcompiler64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvltwu.inf' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvltwu.inf'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvd3dum.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3dum.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdxgiwrapx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdxgiwrapx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvir3dgenco64.dll' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvir3dgenco64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nv-vk32.json' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nv-vk32.json'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nv-vk64.json' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nv-vk64.json'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvEncMFTH264x.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFTH264x.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvcuda32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuda32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\OpenCL32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\OpenCL32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvhdap64.dll' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvhdap64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvcuda64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuda64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\OpenCL64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\OpenCL64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NV_DISP.CAT' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NV_DISP.CAT'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdrsdb.bi_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdrsdb.bin'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvEncodeAPI64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncodeAPI64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvmcumd.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvmcumd.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvoglv32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglv32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvoglv64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglv64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\license.txt' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\license.txt'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvEncMFThevc.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFThevc.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdispgenco64.dll' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdispgenco64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvinitx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvinitx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvstusb.cat' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvstusb.cat'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NvIFROpenGL32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFROpenGL32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvhda64v.sys' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvhda64v.sys'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvstusb.inf' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvstusb.inf'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NvIFROpenGL64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFROpenGL64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvd3dumx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3dumx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvwgf2um.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvwgf2um.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\MCU.ex_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\MCU.exe'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvptxJitCompiler32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvptxJitCompiler32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvptxJitCompiler64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvptxJitCompiler64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvcuvid32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuvid32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvcuvid64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuvid64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvDecMFTMjpeg.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvDecMFTMjpeg.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\VulkanRT-Installer.exe' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\VulkanRT-Installer.exe'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvlddmkm.sy_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvlddmkm.sys'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvEncMFThevcx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFThevcx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvfatbinaryLoader32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvfatbinaryLoader32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvpciflt.sy_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvpciflt.sys'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvfatbinaryLoader64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvfatbinaryLoader64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvstusb64.sys' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvstusb64.sys'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NvCplSetupInt.exe' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvCplSetupInt.exe'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvwgf2umx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvwgf2umx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvml.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvml.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvopencl32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvopencl32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvopencl64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvopencl64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdispco64.dll' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdispco64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvd3d9wrap.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3d9wrap.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvumdshim.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvumdshim.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvDecMFTMjpegx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvDecMFTMjpegx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvidia-smi.ex_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvidia-smi.exe'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvhda.cat' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvhda.cat'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NvFBC.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvFBC.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvhda.inf' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvhda.inf'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvapi.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvapi.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdet.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdet.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NvIFR.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFR.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvinfo.pb' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvinfo.pb'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvoglshim32.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglshim32.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvoglshim64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglshim64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvdxgiwrap.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdxgiwrap.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvd3d9wrapx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3d9wrapx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvidia-smi.1.pd_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvidia-smi.1.pdf'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvumdshimx.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvumdshimx.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvEncMFTH264.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFTH264.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NvFBC64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvFBC64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvapi64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvapi64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvhdagenco64.dll' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvhdagenco64.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\nvEncodeAPI.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncodeAPI.dll'.
flq: Copying 'c:\users\dragon~1\appdata\local\temp\dmiwu\{4448a725-965d-459e-865d-89866d753b36}\NvIFR64.dl_' to 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFR64.dll'.
sto: {Copy Driver Package: exit(0x00000000)} 23:14:36.116
pol: {Driver package policy check} 23:14:41.671
pol: {Driver package policy check - exit(0x00000000)} 23:14:41.686
sto: {Stage Driver Package: C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvltwu.inf} 23:14:42.037
inf: {Query Configurability: C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvltwu.inf} 23:14:42.772
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1071
! inf: Found legacy RegisterDlls operation. Code = 1301
! inf: Found legacy CopyFiles operation with non-system target path (C:\Program Files\NVIDIA Corporation\Drs) for 'dbInstaller.exe'. Code = 1307
! inf: Found legacy DelFiles operation for 'MCU.exe'. Code = 1303
! inf: Found legacy DelService operation for 'nvkflt'. Code = 1303
! inf: Found legacy AddReg operation using non-relative key (HKLM\Software\NVIDIA Corporation\Global\DRS). Code = 1305
! inf: Found legacy DelReg operation. Code = 1302
! inf: Found legacy AddReg operation defining co-installers (CoInstallers32). Code = 1304
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1180
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1293
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1401
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1511
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1622
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1731
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1841
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1949
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2059
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2274
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2380
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2488
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2592
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2700
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2810
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2921
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3030
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3139
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3245
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3361
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3476
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3582
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3691
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3793
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3897
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3999
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4107
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4216
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4326
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4433
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4544
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4655
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4764
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4876
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4993
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5121
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5249
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5374
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5496
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5618
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5738
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5854
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5957
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6069
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6180
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6290
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6400
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6512
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6622
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6738
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6854
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6963
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7075
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7185
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7297
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7410
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7521
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7638
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7752
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8095
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8206
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8315
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8430
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8541
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8654
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8761
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8871
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8980
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9095
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9210
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9324
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9438
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9552
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9777
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9888
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9999
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10112
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10226
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10342
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10454
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10565
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10676
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10783
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 10893
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 11285
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 11361
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 12705
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 13550
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 14425
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 15241
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 16060
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 17879
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 19991
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 21062
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 21793
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 25498
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 26229
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 27759
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 28220
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7864
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 29129
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 29577
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 29693
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30270
! inf: Driver package 'nvltwu.inf' is NOT configurable.
inf: {Query Configurability: exit(0x00000000)} 23:14:43.279
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvinit.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvinit.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdetx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdetx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\dbInstaller.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\dbInstaller.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcompiler32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvcompiler32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdebugdump.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdebugdump.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcompiler64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvcompiler64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvltwu.inf' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvltwu.inf'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3dum.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvd3dum.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdxgiwrapx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdxgiwrapx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nv-vk32.json' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nv-vk32.json'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nv-vk64.json' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nv-vk64.json'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFTH264x.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvEncMFTH264x.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuda32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvcuda32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\OpenCL32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\OpenCL32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuda64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvcuda64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\OpenCL64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\OpenCL64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NV_DISP.CAT' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NV_DISP.CAT'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdrsdb.bin' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdrsdb.bin'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncodeAPI64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvEncodeAPI64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvmcumd.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvmcumd.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglv32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvoglv32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglv64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvoglv64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\license.txt' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\license.txt'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFThevc.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvEncMFThevc.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdispgenco64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdispgenco64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvinitx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvinitx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFROpenGL32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NvIFROpenGL32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFROpenGL64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NvIFROpenGL64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3dumx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvd3dumx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvwgf2um.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvwgf2um.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\MCU.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\MCU.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvptxJitCompiler32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvptxJitCompiler32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvptxJitCompiler64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvptxJitCompiler64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuvid32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvcuvid32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvcuvid64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvcuvid64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvDecMFTMjpeg.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvDecMFTMjpeg.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\VulkanRT-Installer.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\VulkanRT-Installer.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvlddmkm.sys' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvlddmkm.sys'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFThevcx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvEncMFThevcx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvfatbinaryLoader32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvfatbinaryLoader32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvpciflt.sys' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvpciflt.sys'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvfatbinaryLoader64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvfatbinaryLoader64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvCplSetupInt.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NvCplSetupInt.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvwgf2umx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvwgf2umx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvml.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvml.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvopencl32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvopencl32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvopencl64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvopencl64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdispco64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdispco64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3d9wrap.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvd3d9wrap.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvumdshim.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvumdshim.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvDecMFTMjpegx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvDecMFTMjpegx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvidia-smi.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvidia-smi.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvFBC.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NvFBC.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvapi.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvapi.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdet.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdet.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFR.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NvIFR.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvinfo.pb' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvinfo.pb'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglshim32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvoglshim32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvoglshim64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvoglshim64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvdxgiwrap.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvdxgiwrap.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvd3d9wrapx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvd3d9wrapx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvidia-smi.1.pdf' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvidia-smi.1.pdf'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvumdshimx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvumdshimx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncMFTH264.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvEncMFTH264.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvFBC64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NvFBC64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvapi64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvapi64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\nvEncodeAPI.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\nvEncodeAPI.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{fc74557d-0859-a947-9d68-52b1ea350962}\NvIFR64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{d6446a47-dbe2-044f-aee4-73f92f0b6473}\NvIFR64.dll'.
sto: {DRIVERSTORE IMPORT VALIDATE} 23:14:59.747
sig: {_VERIFY_FILE_SIGNATURE} 2
|
| | #13 |
![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse ich hab auf dem desktop den eset log collector ordner und da sind ein haufen komischer logdatein von denen ich nich weiß wo sie herkommen. die datei würd noch 20 mal so lange weiter gehen. das wäre der letzte abschnitt Code:
ATTFilter ! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 29988
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30113
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30221
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30451
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30566
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30680
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31023
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31135
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31247
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31361
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31700
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31812
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 32035
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 32151
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8006
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 32619
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 33073
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 33189
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34001
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34457
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34573
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34923
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 35038
! inf: Driver package 'nvlti.inf' is NOT configurable.
inf: {Query Configurability: exit(0x00000000)} 21:30:04.197
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvinit.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvinit.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdetx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdetx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\dbInstaller.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\dbInstaller.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvcompiler32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvcompiler32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdebugdump.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdebugdump.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvcompiler64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvcompiler64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvd3dum.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvd3dum.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdxgiwrapx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdxgiwrapx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nv-vk32.json' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nv-vk32.json'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nv-vk64.json' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nv-vk64.json'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvEncMFTH264x.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvEncMFTH264x.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvContainerSetup.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvContainerSetup.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvcuda32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvcuda32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\OpenCL32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\OpenCL32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvcuda64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvcuda64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\OpenCL64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\OpenCL64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NV_DISP.CAT' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NV_DISP.CAT'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdrsdb.bin' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdrsdb.bin'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvEncodeAPI64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvEncodeAPI64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvmcumd.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvmcumd.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvoglv32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvoglv32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvoglv64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvoglv64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\license.txt' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\license.txt'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvEncMFThevc.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvEncMFThevc.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdispgenco64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdispgenco64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvinitx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvinitx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvIFROpenGL32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvIFROpenGL32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvIFROpenGL64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvIFROpenGL64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvd3dumx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvd3dumx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvwgf2um.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvwgf2um.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\MCU.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\MCU.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvptxJitCompiler32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvptxJitCompiler32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvptxJitCompiler64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvptxJitCompiler64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvcuvid32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvcuvid32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvcuvid64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvcuvid64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvDecMFTMjpeg.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvDecMFTMjpeg.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\VulkanRT-Installer.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\VulkanRT-Installer.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvlddmkm.sys' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvlddmkm.sys'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvEncMFThevcx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvEncMFThevcx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvfatbinaryLoader32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvfatbinaryLoader32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvpciflt.sys' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvpciflt.sys'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvfatbinaryLoader64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvfatbinaryLoader64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvCplSetupInt.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvCplSetupInt.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvwgf2umx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvwgf2umx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvml.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvml.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvopencl32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvopencl32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvopencl64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvopencl64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdispco64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdispco64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvd3d9wrap.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvd3d9wrap.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvumdshim.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvumdshim.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvDecMFTMjpegx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvDecMFTMjpegx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvidia-smi.exe' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvidia-smi.exe'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvFBC.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvFBC.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvapi.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvapi.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdet.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdet.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvIFR.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvIFR.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvinfo.pb' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvinfo.pb'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvlti.inf' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvlti.inf'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvoglshim32.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvoglshim32.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvoglshim64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvoglshim64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvdxgiwrap.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvdxgiwrap.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvd3d9wrapx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvd3d9wrapx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvidia-smi.1.pdf' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvidia-smi.1.pdf'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvumdshimx.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvumdshimx.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvEncMFTH264.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvEncMFTH264.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvFBC64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvFBC64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvapi64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvapi64.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\nvEncodeAPI.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvEncodeAPI.dll'.
flq: Copying 'C:\Users\DRAGON~1\AppData\Local\Temp\{ca98f867-3a0a-cf47-8a57-3870f1c8d919}\NvIFR64.dll' to 'C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NvIFR64.dll'.
sto: {DRIVERSTORE IMPORT VALIDATE} 21:30:15.616
sig: {_VERIFY_FILE_SIGNATURE} 21:30:15.971
sig: Key = nvlti.inf
sig: FilePath = C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\nvlti.inf
sig: Catalog = C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}\NV_DISP.CAT
sig: Success: File is signed in catalog.
sig: {_VERIFY_FILE_SIGNATURE exit(0x00000000)} 21:30:16.042
sto: {DRIVERSTORE IMPORT VALIDATE: exit(0x00000000)} 21:30:21.943
sig: Signer Score = 0x0D000005
sig: Signer Name = Microsoft Windows Hardware Compatibility Publisher
sto: {DRIVERSTORE IMPORT BEGIN} 21:30:21.953
sto: {DRIVERSTORE IMPORT BEGIN: exit(0x00000000)} 21:30:21.954
cpy: {Copy Directory: C:\WINDOWS\System32\DriverStore\Temp\{a9c478e1-cca6-e141-b8e6-d2f18be23c09}} 21:30:21.955
cpy: Target Path = C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874
cpy: {Copy Directory: exit(0x00000000)} 21:30:22.118
idb: {Register Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvlti.inf} 21:30:22.121
idb: Created driver package object 'nvlti.inf_amd64_10adcfc1f8eba874' in DRIVERS database node.
idb: Created driver INF file object 'oem31.inf' in DRIVERS database node.
idb: Registered driver package 'nvlti.inf_amd64_10adcfc1f8eba874' with 'oem31.inf'.
idb: {Register Driver Package: exit(0x00000000)} 21:30:22.473
idb: {Publish Driver Package: C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvlti.inf} 21:30:22.473
idb: Activating driver package 'nvlti.inf_amd64_10adcfc1f8eba874'.
cpy: Published 'nvlti.inf_amd64_10adcfc1f8eba874\nvlti.inf' to 'oem31.inf'.
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1129
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1238
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1352
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1462
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1574
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1687
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1798
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 1910
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2020
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2132
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2348
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2454
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2562
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2666
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2774
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2885
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 2998
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3109
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3220
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3327
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3443
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3558
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3664
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3774
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3878
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 3984
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4088
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4198
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4309
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4421
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4530
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4643
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4756
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4867
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 4981
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5099
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5227
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5355
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5480
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5602
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5724
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5844
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 5961
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6066
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6180
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6293
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6405
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6517
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6631
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6743
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6861
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 6979
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7090
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7204
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7316
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7430
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7545
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7658
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7777
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 7893
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8238
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8351
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8462
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8579
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8692
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8807
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8916
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9028
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9139
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9256
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9373
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9489
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9810
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 9852
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 11706
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 12501
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 13447
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 14446
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 15390
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 16367
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 17365
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 18553
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 19899
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 21060
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 22215
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 23077
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 24158
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 25414
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 27190
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 28226
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 28711
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 28878
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 29469
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 29687
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 29988
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30113
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30221
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30451
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30566
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 30680
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31023
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31135
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31247
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31361
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31700
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 31812
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 32035
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 32151
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 8006
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 32619
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 33073
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 33189
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34001
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34457
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34573
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 34923
! inf: Legacy directive 'RegisterDlls' will be ignored. Code = 2222, Line = 35038
idb: Indexed 274 device IDs for 'nvlti.inf_amd64_10adcfc1f8eba874'.
sto: Flushed driver database node 'DRIVERS'. Time = 0 ms
sto: Flushed driver database node 'SYSTEM'. Time = 0 ms
idb: {Publish Driver Package: exit(0x00000000)} 21:30:23.323
sto: {DRIVERSTORE IMPORT END} 21:30:23.655
sig: Installed catalog 'NV_DISP.CAT' as 'oem31.cat'.
sto: {DRIVERSTORE IMPORT END: exit(0x00000000)} 21:30:24.071
sto: {Stage Driver Package: exit(0x00000000)} 21:30:24.147
sto: {Setup Import Driver Package - exit (0x00000000)} 21:30:24.232
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: Class GUID of device remains: {4d36e968-e325-11ce-bfc1-08002be10318}.
dvi: {Plug and Play Service: Device Install for PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA&REV_A1\4&23704A70&0&0008}
ndv: Driver INF Path: C:\WINDOWS\INF\oem31.inf
ndv: Driver Node Name: nvlti.inf:0f066de3af81f0d7:Section141:21.21.13.7866:pci\ven_10de&dev_1292&subsys_390417aa
ndv: Driver Store Path: C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvlti.inf
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: Class GUID of device changed to: {4d36e968-e325-11ce-bfc1-08002be10318}.
ndv: {Core Device Install} 21:30:25.274
ndv: {Install Device - PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA&REV_A1\4&23704A70&0&0008} 21:30:25.278
ndv: Parent device: PCI\VEN_8086&DEV_0151&SUBSYS_397717AA&REV_09\3&11583659&0&08
! ndv: Device class {4d36e968-e325-11ce-bfc1-08002be10318} is not configurable.
dvi: {DIF_ALLOW_INSTALL} 21:30:25.597
dvi: Using exported function 'DisplayClassInstaller' in module 'C:\WINDOWS\system32\DispCI.dll'.
dvi: Class installer == DispCI.dll,DisplayClassInstaller
dvi: Using exported function 'NvGenericCoInstall' in module 'C:\WINDOWS\system32\nvdispgenco6437866.dll'.
dvi: CoInstaller 1 == nvdispgenco6437866.dll,NvGenericCoInstall
dvi: Using exported function 'NVDisplayCoInstall' in module 'C:\WINDOWS\system32\nvdispco6437866.dll'.
dvi: CoInstaller 2 == nvdispco6437866.dll,NVDisplayCoInstall
dvi: CoInstaller 1: Enter 21:30:25.610
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:25.611
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:25.613
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:25.616
dvi: Default installer: Exit
dvi: {DIF_ALLOW_INSTALL - exit(0xe000020e)} 21:30:25.618
dvi: {DIF_INSTALLDEVICEFILES} 21:30:25.631
dvi: CoInstaller 1: Enter 21:30:25.632
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:25.633
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:25.634
dvi: {Build Driver List} 21:30:25.636
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: Created Driver Node:
dvi: HardwareID - PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_0221ce4ec0827f74\nvltwu.inf
dvi: DevDesc - NVIDIA GeForce GT 740M
dvi: Section - Section141
dvi: Rank - 0x00d10001
dvi: Signer Score - WHQL
dvi: DrvDate - 12/29/2016
dvi: Version - 21.21.13.7654
dvi: Created Driver Node:
dvi: HardwareID - PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvlti.inf
dvi: DevDesc - NVIDIA GeForce GT 740M
dvi: Section - Section141
dvi: Rank - 0x00d10001
dvi: Signer Score - WHQL
dvi: DrvDate - 02/09/2017
dvi: Version - 21.21.13.7866
dvi: Created Driver Node:
dvi: HardwareID - PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_7abb66182eb8ed83\nvltwu.inf
dvi: DevDesc - NVIDIA GeForce GT 740M
dvi: Section - Section141
dvi: Rank - 0x00d10001
dvi: Signer Score - WHQL
dvi: DrvDate - 08/01/2016
dvi: Version - 21.21.13.6909
dvi: {Build Driver List - exit(0x00000000)} 21:30:26.519
dvi: {Build Driver List} 21:30:26.521
dvi: Searching for hardware ID(s):
dvi: root\basicrender
dvi: Created Driver Node:
dvi: HardwareID - ROOT\BASICRENDER
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\basicrender.inf_amd64_84ca6086466df7c9\basicrender.inf
dvi: DevDesc - Microsoft Basic Render Driver
dvi: Section - BasicRender
dvi: Rank - 0x00fb0000
dvi: Signer Score - INBOX
dvi: DrvDate - 06/21/2006
dvi: Version - 10.0.10586.0
dvi: {Build Driver List - exit(0x00000000)} 21:30:26.632
dvi: {Build Driver List} 21:30:26.633
dvi: Searching for hardware ID(s):
dvi: pci\ven_8086&dev_0166&subsys_390417aa&rev_09
dvi: pci\ven_8086&dev_0166&subsys_390417aa
dvi: pci\ven_8086&dev_0166&cc_030000
dvi: pci\ven_8086&dev_0166&cc_0300
dvi: Searching for compatible ID(s):
dvi: pci\ven_8086&dev_0166&rev_09
dvi: pci\ven_8086&dev_0166
dvi: pci\ven_8086&cc_030000
dvi: pci\ven_8086&cc_0300
dvi: pci\ven_8086
dvi: pci\cc_030000
dvi: pci\cc_0300
dvi: Created Driver Node:
dvi: HardwareID - PCI\CC_0300
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\display.inf_amd64_c53a8b74688588fa\display.inf
dvi: DevDesc - Microsoft Basic Display Adapter
dvi: Section - MSBDA
dvi: Rank - 0x00fb2006
dvi: Signer Score - INBOX
dvi: DrvDate - 06/21/2006
dvi: Version - 10.0.10586.0
dvi: Created Driver Node:
dvi: HardwareID - PCI\VEN_8086&DEV_0166
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0d5be4a8324f3703\igdlh64.inf
dvi: DevDesc - Intel(R) HD Graphics 4000
dvi: Section - iIVBM_w10
dvi: Rank - 0x00d12001
dvi: Signer Score - WHQL
dvi: DrvDate - 12/21/2015
dvi: Version - 10.18.10.4358
dvi: {Build Driver List - exit(0x00000000)} 21:30:26.758
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:26.984
! inf: Empty Section! [nv_syswow64_RS_copyfiles]
dvi: Default installer: Exit
dvi: {DIF_INSTALLDEVICEFILES - exit(0x00000000)} 21:30:27.012
flq: File 'C:\Program Files\NVIDIA Corporation\Drs\dbInstaller.exe' pruned from copy.
flq: File 'C:\Program Files\NVIDIA Corporation\Drs\nvdrsdb.bin' pruned from copy.
flq: File 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\NvContainerSetup.exe' pruned from copy.
flq: File 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\NvCplSetupInt.exe' pruned from copy.
flq: File 'C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\detoured.dll' pruned from copy.
flq: File 'C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\nvd3d9wrap.dll' pruned from copy.
flq: File 'C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\nvdxgiwrap.dll' pruned from copy.
flq: File 'C:\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll' pruned from copy.
flq: File 'C:\Program Files\NVIDIA Corporation\coprocmanager\nvd3d9wrapx.dll' pruned from copy.
flq: File 'C:\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll' pruned from copy.
flq: File 'C:\Program Files\NVIDIA Corporation\license.txt' pruned from copy.
! flq: Copy target 'C:\Program Files\NVIDIA Corporation\NVSMI\MCU.exe' is also a Delete target, forcing COPYFLG_NOPRUNE.
! flq: Copy target 'C:\Program Files\NVIDIA Corporation\NVSMI\nvdebugdump.exe' is also a Delete target, forcing COPYFLG_NOPRUNE.
! flq: Copy target 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.1.pdf' is also a Delete target, forcing COPYFLG_NOPRUNE.
! flq: Copy target 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.exe' is also a Delete target, forcing COPYFLG_NOPRUNE.
! flq: Copy target 'C:\Program Files\NVIDIA Corporation\NVSMI\nvml.dll' is also a Delete target, forcing COPYFLG_NOPRUNE.
flq: File 'C:\Program Files\NVIDIA Corporation\OpenCL\OpenCL.dll' pruned from copy.
flq: File 'C:\Program Files\NVIDIA Corporation\OpenCL\OpenCL64.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys' pruned from copy.
flq: File 'C:\WINDOWS\system32\DRIVERS\nvpciflt.sys' pruned from copy.
flq: File 'C:\WINDOWS\system32\NvFBC64.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\NvIFR64.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\NvIFROpenGL.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nv-vk64.json' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvEncMFTH264.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvEncodeAPI64.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvapi64.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvcompiler.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvcuda.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvcuvid.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvd3dumx.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvfatbinaryLoader.dll' pruned from copy.
! flq: Copy target 'C:\WINDOWS\system32\nvinfo.pb' is also a Delete target, forcing COPYFLG_NOPRUNE.
flq: File 'C:\WINDOWS\system32\nvinitx.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvoglshim64.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvoglv64.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvopencl.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvptxJitCompiler.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvumdshimx.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvwgf2umx.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\NvFBC.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\NvIFR.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\NvIFROpenGL.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nv-vk32.json' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvEncMFTH264.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvEncodeAPI.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvapi.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvcompiler.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvcuda.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvcuvid.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvd3dum.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvfatbinaryLoader.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvinit.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvoglshim32.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvoglv32.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvopencl.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvptxJitCompiler.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvumdshim.dll' pruned from copy.
flq: File 'C:\WINDOWS\SysWow64\nvwgf2um.dll' pruned from copy.
flq: File 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\VulkanRT-Installer.exe' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvdispco6437866.dll' pruned from copy.
flq: File 'C:\WINDOWS\system32\nvdispgenco6437866.dll' pruned from copy.
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\MCU.exe'
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\MCU.exe'
flq: DeleteFile: success
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvdebugdump.exe'
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvdebugdump.exe'
flq: DeleteFile: success
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.1.pdf'
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.1.pdf'
flq: DeleteFile: success
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.exe'
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.exe'
flq: DeleteFile: success
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvml.dll'
flq: DeleteFile: 'C:\Program Files\NVIDIA Corporation\NVSMI\nvml.dll'
flq: DeleteFile: success
flq: DeleteFile: 'C:\WINDOWS\system32\DRIVERS\nvarch.sys'
flq: DeleteFile: 'C:\WINDOWS\system32\DRIVERS\nvarch.sys'
! flq: DeleteFile: FAILED!
flq: DeleteFile: 'C:\WINDOWS\system32\DRIVERS\nvgfx.sys'
flq: DeleteFile: 'C:\WINDOWS\system32\DRIVERS\nvgfx.sys'
! flq: DeleteFile: FAILED!
flq: DeleteFile: 'C:\WINDOWS\system32\DRIVERS\nvkflt.sys'
flq: DeleteFile: 'C:\WINDOWS\system32\DRIVERS\nvkflt.sys'
! flq: DeleteFile: FAILED!
flq: DeleteFile: 'C:\WINDOWS\system32\nvcuvenc.dll'
flq: DeleteFile: 'C:\WINDOWS\system32\nvcuvenc.dll'
! flq: DeleteFile: FAILED!
flq: DeleteFile: 'C:\WINDOWS\system32\nvencodemft.dll'
flq: DeleteFile: 'C:\WINDOWS\system32\nvencodemft.dll'
! flq: DeleteFile: FAILED!
flq: DeleteFile: 'C:\WINDOWS\system32\nvinfo.pb'
flq: DeleteFile: 'C:\WINDOWS\system32\nvinfo.pb'
flq: DeleteFile: success
flq: DeleteFile: 'C:\WINDOWS\SysWOW64\nvcuvenc.dll'
flq: DeleteFile: 'C:\WINDOWS\SysWOW64\nvcuvenc.dll'
! flq: DeleteFile: FAILED!
flq: DeleteFile: 'C:\WINDOWS\SysWOW64\nvencodemft.dll'
flq: DeleteFile: 'C:\WINDOWS\SysWOW64\nvencodemft.dll'
! flq: DeleteFile: FAILED!
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\MCU.exe' to 'C:\Program Files\NVIDIA Corporation\NVSMI\MCU.exe'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvdebugdump.exe' to 'C:\Program Files\NVIDIA Corporation\NVSMI\nvdebugdump.exe'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvidia-smi.1.pdf' to 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.1.pdf'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvidia-smi.exe' to 'C:\Program Files\NVIDIA Corporation\NVSMI\nvidia-smi.exe'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvml.dll' to 'C:\Program Files\NVIDIA Corporation\NVSMI\nvml.dll'.
flq: Copying 'C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_10adcfc1f8eba874\nvinfo.pb' to 'C:\WINDOWS\system32\nvinfo.pb'.
dvi: {DIF_REGISTER_COINSTALLERS} 21:30:38.817
dvi: Reset Device: Resetting device configuration. 21:30:38.817
dvi: Reset Device: Resetting device configuration completed. 21:30:38.818
dvi: CoInstaller 1: Enter 21:30:38.819
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:38.820
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:38.822
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:38.823
dvi: {DIF_DESTROYPRIVATEDATA} 21:30:38.824
dvi: CoInstaller 1: Enter 21:30:38.825
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:38.827
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:38.829
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:39.049
dvi: Default installer: Exit
dvi: {DIF_DESTROYPRIVATEDATA - exit(0xe000020e)} 21:30:39.050
dvi: Default installer: Exit
dvi: {DIF_REGISTER_COINSTALLERS - exit(0x00000000)} 21:30:39.052
dvi: {DIF_INSTALLINTERFACES} 21:30:39.052
dvi: Using exported function 'NvGenericCoInstall' in module 'C:\WINDOWS\system32\nvdispgenco6437866.dll'.
dvi: CoInstaller 1 == nvdispgenco6437866.dll,NvGenericCoInstall
dvi: Using exported function 'NVDisplayCoInstall' in module 'C:\WINDOWS\system32\nvdispco6437866.dll'.
dvi: CoInstaller 2 == nvdispco6437866.dll,NVDisplayCoInstall
dvi: CoInstaller 1: Enter 21:30:39.056
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:39.057
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:39.059
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:39.060
dvi: Default installer: Exit
dvi: {DIF_INSTALLINTERFACES - exit(0x00000000)} 21:30:39.061
dvi: {DIF_INSTALLDEVICE} 21:30:39.062
dvi: CoInstaller 1: Enter 21:30:39.062
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:39.082
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:40.204
inf: DelService=nvkflt,0x00000200 (oem31.inf line 9040)
dvi: Delete Services: Service 'nvkflt' does not exist.
inf: AddService=nvlddmkm,0x00000002,nv_nvlddmkm_serviceInstall,nv_nvlddmkm_eventlogging (oem31.inf line 9039)
dvi: Add Service: Modified existing service 'nvlddmkm'.
inf: AddService=nvpciflt,,nv_nvpciflt_serviceInstall (oem31.inf line 9041)
dvi: Add Service: Modified existing service 'nvpciflt'.
dvi: {Install DEVICE}
dvi: {Writing Device Properties}
dvi: Strong Name=oem31.inf:0f066de3af81f0d7:Section141:21.21.13.7866:pci\ven_10de&dev_1292&subsys_390417aa
dvi: {Writing Device Properties - Complete}
inf: DelService=nvkflt,0x00000200 (nvlti.inf line 9040)
dvi: Delete Services: Service 'nvkflt' does not exist.
inf: AddService=nvlddmkm,0x00000002,nv_nvlddmkm_serviceInstall,nv_nvlddmkm_eventlogging (nvlti.inf line 9039)
dvi: Add Service: Modified existing service 'nvlddmkm'.
inf: AddService=nvpciflt,,nv_nvpciflt_serviceInstall (nvlti.inf line 9041)
dvi: Add Service: Modified existing service 'nvpciflt'.
dvi: {Install DEVICE exit (0x00000000)}
dvi: Install Device: Configuring device class. 21:30:40.309
dvi: Install Device: Configuring device class completed. 21:30:40.309
dvi: {Restarting Devices} 21:30:40.310
dvi: Query-remove: PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA&REV_A1\4&23704A70&0&0008
dvi: Restart: PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA&REV_A1\4&23704A70&0&0008
dvi: Restart verified: PCI\VEN_10DE&DEV_1292&SUBSYS_390417AA&REV_A1\4&23704A70&0&0008
dvi: {Restarting Devices exit} 21:30:40.551
dvi: {Build Driver List} 21:30:40.552
dvi: Searching for hardware ID(s):
dvi: pci\ven_8086&dev_0166&subsys_390417aa&rev_09
dvi: pci\ven_8086&dev_0166&subsys_390417aa
dvi: pci\ven_8086&dev_0166&cc_030000
dvi: pci\ven_8086&dev_0166&cc_0300
dvi: Searching for compatible ID(s):
dvi: pci\ven_8086&dev_0166&rev_09
dvi: pci\ven_8086&dev_0166
dvi: pci\ven_8086&cc_030000
dvi: pci\ven_8086&cc_0300
dvi: pci\ven_8086
dvi: pci\cc_030000
dvi: pci\cc_0300
dvi: Created Driver Node:
dvi: HardwareID - PCI\CC_0300
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\display.inf_amd64_c53a8b74688588fa\display.inf
dvi: DevDesc - Microsoft Basic Display Adapter
dvi: Section - MSBDA
dvi: Rank - 0x00fb2006
dvi: Signer Score - INBOX
dvi: DrvDate - 06/21/2006
dvi: Version - 10.0.10586.0
dvi: Created Driver Node:
dvi: HardwareID - PCI\VEN_8086&DEV_0166
dvi: InfName - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0d5be4a8324f3703\igdlh64.inf
dvi: DevDesc - Intel(R) HD Graphics 4000
dvi: Section - iIVBM_w10
dvi: Rank - 0x00d12001
dvi: Signer Score - WHQL
dvi: DrvDate - 12/21/2015
dvi: Version - 10.18.10.4358
dvi: {Build Driver List - exit(0x00000000)} 21:30:40.645
dvi: Class installer: Exit
dvi: CoInstaller 2: Enter (Post Processing) 21:30:40.646
dvi: {Build Driver List} 21:30:40.649
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:40.741
dvi: CoInstaller 2: Exit (Post Processing)
dvi: CoInstaller 1: Enter (Post Processing) 21:30:40.743
dvi: {Build Driver List} 21:30:40.746
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:40.842
dvi: {DIF_PROPERTYCHANGE} 21:30:40.845
dvi: Default installer: Enter 21:30:40.846
dvi: {Change State}
dvi: Device Instance = 'PCI\VEN_8086&DEV_0151&SUBSYS_397717AA&REV_09\3&11583659&0&08'.
dvi: {DICS_PROPCHANGE, DICS_FLAG_CONFIGSPECIFIC}
dvi: {Change Device State - PCI\VEN_8086&DEV_0151&SUBSYS_397717AA&REV_09\3&11583659&0&08}
dvi: Restart Device: Config specific
dvi: {Change Device State - exit(0x00000000)}
dvi: {Change State - exit}
dvi: Default installer: Exit
dvi: {DIF_PROPERTYCHANGE - exit(0x00000000)} 21:30:41.169
dvi: CoInstaller 1: Exit (Post Processing)
dvi: {DIF_INSTALLDEVICE - exit(0x00000000)} 21:30:41.173
dvi: {DIF_NEWDEVICEWIZARD_FINISHINSTALL} 21:30:41.175
dvi: CoInstaller 1: Enter 21:30:41.177
dvi: {Build Driver List} 21:30:41.182
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:41.279
dvi: {Build Driver List} 21:30:41.280
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:41.374
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:41.377
dvi: {Build Driver List} 21:30:41.379
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:41.476
dvi: {Build Driver List} 21:30:41.477
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:41.565
dvi: {Build Driver List} 21:30:41.834
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:41.921
dvi: {Build Driver List} 21:30:41.926
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:42.015
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:42.020
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:42.022
dvi: Default installer: Exit
dvi: CoInstaller 2: Enter (Post Processing) 21:30:42.023
dvi: {Build Driver List} 21:30:42.025
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:42.113
dvi: CoInstaller 2: Exit (Post Processing)
dvi: CoInstaller 1: Enter (Post Processing) 21:30:42.115
dvi: {Build Driver List} 21:30:42.117
dvi: Searching for hardware ID(s):
dvi: pci\ven_10de&dev_1292&subsys_390417aa&rev_a1
dvi: pci\ven_10de&dev_1292&subsys_390417aa
dvi: pci\ven_10de&dev_1292&cc_030200
dvi: pci\ven_10de&dev_1292&cc_0302
dvi: Searching for compatible ID(s):
dvi: pci\ven_10de&dev_1292&rev_a1
dvi: pci\ven_10de&dev_1292
dvi: pci\ven_10de&cc_030200
dvi: pci\ven_10de&cc_0302
dvi: pci\ven_10de
dvi: pci\cc_030200
dvi: pci\cc_0302
dvi: {Build Driver List - exit(0x00000000)} 21:30:42.205
dvi: CoInstaller 1: Exit (Post Processing)
dvi: {DIF_NEWDEVICEWIZARD_FINISHINSTALL - exit(0xe000020e)} 21:30:42.207
ndv: {Install Device - exit(0x00000000)} 21:30:42.529
ndv: {Core Device Install - exit(0x00000000)} 21:30:42.530
dvi: {DIF_DESTROYPRIVATEDATA} 21:30:42.531
dvi: CoInstaller 1: Enter 21:30:42.531
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:42.533
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:42.534
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:42.535
dvi: Default installer: Exit
dvi: {DIF_DESTROYPRIVATEDATA - exit(0xe000020e)} 21:30:42.536
ump: {Plug and Play Service: Device Install exit(00000000)}
dvi: {DIF_DESTROYPRIVATEDATA} 21:30:42.542
dvi: CoInstaller 1: Enter 21:30:42.543
dvi: CoInstaller 1: Exit
dvi: CoInstaller 2: Enter 21:30:42.544
dvi: CoInstaller 2: Exit
dvi: Class installer: Enter 21:30:42.546
dvi: Class installer: Exit
dvi: Default installer: Enter 21:30:42.546
dvi: Default installer: Exit
dvi: {DIF_DESTROYPRIVATEDATA - exit(0xe000020e)} 21:30:42.548
<<< Section end 2017/02/27 21:30:42.549
<<< [Exit status: SUCCESS]
>>> [Device and Driver Disk Cleanup Handler]
>>> Section start 2017/02/28 00:52:02.377
cmd: taskhostw.exe
set: Searching for not-recently detected devices that may be removed from the system.
set: Devices will be removed during this pass.
set: Devices removed: 0
set: Searching for unused drivers that may be removed from the system.
set: Drivers will be removed during this pass.
set: Recovery Timestamp: 01/24/2017 20:25:40:0607.
set: Driver packages removed: 0
set: Total size on disk: 0
<<< Section end 2017/02/28 00:52:11.330
<<< [Exit status: SUCCESS]
|
| | #14 |
![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesse ich post einfach mal ausschnitte die mir interessant vor kommen... weiß halt leider nich ob das wirklich interessant^^ Code:
ATTFilter WARNING: PID: 4 - Failed to open process.
Handles: 872
Type: 3, Cnt: 13 ()
Type: 4, Cnt: 117 ()
Type: 5, Cnt: 42 ()
Type: 7, Cnt: 191 ()
Type: 8, Cnt: 31 ()
Type: 12, Cnt: 65 ()
Type: 13, Cnt: 1 ()
Type: 16, Cnt: 17 ()
Type: 21, Cnt: 2 ()
Type: 23, Cnt: 9 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 12 ()
Type: 31, Cnt: 171 ()
Type: 32, Cnt: 11 ()
Type: 34, Cnt: 22 ()
Type: 36, Cnt: 8 ()
Type: 37, Cnt: 14 ()
Type: 38, Cnt: 1 ()
Type: 39, Cnt: 102 ()
Type: 40, Cnt: 37 ()
Type: 46, Cnt: 3 ()
Type: 48, Cnt: 1 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 380 - Failed to open process.
Handles: 49
Type: 3, Cnt: 3 ()
Type: 7, Cnt: 3 ()
Type: 12, Cnt: 4 ()
Type: 17, Cnt: 6 ()
Type: 24, Cnt: 3 ()
Type: 29, Cnt: 3 ()
Type: 30, Cnt: 7 ()
Type: 31, Cnt: 10 ()
Type: 36, Cnt: 1 ()
Type: 39, Cnt: 1 ()
Type: 40, Cnt: 6 ()
Type: 43, Cnt: 2 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 500 - Failed to open process.
Handles: 453
Type: 3, Cnt: 8 ()
Type: 4, Cnt: 2 ()
Type: 7, Cnt: 32 ()
Type: 8, Cnt: 78 ()
Type: 12, Cnt: 35 ()
Type: 13, Cnt: 1 ()
Type: 16, Cnt: 6 ()
Type: 17, Cnt: 4 ()
Type: 20, Cnt: 1 ()
Type: 24, Cnt: 2 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 6 ()
Type: 31, Cnt: 3 ()
Type: 36, Cnt: 225 ()
Type: 39, Cnt: 5 ()
Type: 40, Cnt: 37 ()
Type: 43, Cnt: 6 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 612 - Failed to open process.
Handles: 86
Type: 3, Cnt: 2 ()
Type: 7, Cnt: 2 ()
Type: 8, Cnt: 1 ()
Type: 12, Cnt: 16 ()
Type: 15, Cnt: 2 ()
Type: 17, Cnt: 4 ()
Type: 20, Cnt: 2 ()
Type: 21, Cnt: 3 ()
Type: 24, Cnt: 2 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 8 ()
Type: 31, Cnt: 10 ()
Type: 39, Cnt: 12 ()
Type: 40, Cnt: 6 ()
Type: 43, Cnt: 14 ()
WARNING: Failed to create module snapshot. (5)
WARNING: PID: 628 - Failed to open process.
Handles: 480
Type: 3, Cnt: 8 ()
Type: 4, Cnt: 5 ()
Type: 7, Cnt: 24 ()
Type: 8, Cnt: 64 ()
Type: 12, Cnt: 34 ()
Type: 13, Cnt: 1 ()
Type: 16, Cnt: 4 ()
Type: 17, Cnt: 4 ()
Type: 20, Cnt: 1 ()
Type: 23, Cnt: 7 ()
Type: 24, Cnt: 2 ()
Type: 29, Cnt: 2 ()
Type: 30, Cnt: 6 ()
Type: 31, Cnt: 3 ()
Type: 36, Cnt: 273 ()
Type: 39, Cnt: 6 ()
Type: 40, Cnt: 30 ()
Type: 43, Cnt: 6 ()
WARNING: Failed to create module snapshot. (5)
winlogon.exe
PID: 704, Threads: 4, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 8460 K (Peak: 13428 K), CommitSize: 2004 K, PageFaults: 18599
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 212576 (5), Write: 160 (1), Other: 214784 (2690)
CmdLine: winlogon.exe
## Type: 3 -> Directory
## Type: 12 -> Event
## Type: 31 -> File
## Type: 40 -> ALPC Port
## Type: 29 -> IoCompletion
## Type: 24 -> TpWorkerFactory
## Type: 17 -> IRTimer
## Type: 43 -> DuplicateHandle error: 0x32
## Type: 15 -> Semaphore
## Type: 39 -> Key
## Type: 8 -> Thread
## Type: 20 -> WindowStation
## Type: 21 -> Desktop
## Type: 36 -> Section
## Type: 5 -> Token
## Type: 7 -> Process
## Type: 6 -> Job
Handles: 196
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 6 (Token)
Type: 6, Cnt: 1 (Job)
Type: 7, Cnt: 1 (Process)
Type: 8, Cnt: 4 (Thread)
Type: 12, Cnt: 45 (Event)
Type: 15, Cnt: 22 (Semaphore)
Type: 17, Cnt: 7 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 3 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 19 ()
Type: 31, Cnt: 4 (File)
Type: 36, Cnt: 3 (Section)
Type: 39, Cnt: 20 (Key)
Type: 40, Cnt: 15 (ALPC Port)
Type: 43, Cnt: 36 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF708750000 +610304 585728 10.0.10586.306 C:\WINDOWS\system32\winlogon.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0620000 +241664 230416 10.0.10586.0 C:\WINDOWS\system32\IMM32.DLL
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEABEF0000 +106496 80384 10.0.10586.672 C:\WINDOWS\system32\UXINIT.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEABCC0000 +614400 589312 10.0.10586.0 C:\WINDOWS\system32\UxTheme.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEABCA0000 +81920 58208 10.0.10586.306 C:\WINDOWS\SYSTEM32\dwminit.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\SspiCli.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 C:\WINDOWS\system32\apphelp.dll
0x00007FFEAB0B0000 +65536 43520 10.0.10586.63 C:\WINDOWS\SYSTEM32\usermgrcli.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEA7E10000 +110592 101776 10.0.10586.0 C:\WINDOWS\system32\MPR.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 C:\WINDOWS\system32\wkscli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\system32\netutils.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 C:\WINDOWS\system32\AUTHZ.dll
WARNING: PID: 740 - Failed to open process.
Handles: 254
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 21 (Token)
Type: 7, Cnt: 24 (Process)
Type: 8, Cnt: 5 (Thread)
Type: 12, Cnt: 45 (Event)
Type: 15, Cnt: 16 (Semaphore)
Type: 17, Cnt: 6 (IRTimer)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 33 ()
Type: 31, Cnt: 14 (File)
Type: 39, Cnt: 25 (Key)
Type: 40, Cnt: 38 (ALPC Port)
Type: 43, Cnt: 19 (?)
WARNING: Failed to create module snapshot. (5)
lsass.exe
PID: 756, Threads: 9, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 15060 K (Peak: 15972 K), CommitSize: 5500 K, PageFaults: 11035
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:00:00, UserTime: 00:00:01
IO - Read: 53166 (501), Write: 171359 (349), Other: 999326 (4470)
CmdLine: C:\WINDOWS\system32\lsass.exe
## Type: 13 -> Mutant
Handles: 1029
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 74 (Token)
Type: 7, Cnt: 42 (Process)
Type: 8, Cnt: 9 (Thread)
Type: 12, Cnt: 149 (Event)
Type: 13, Cnt: 1 (Mutant)
Type: 15, Cnt: 382 (Semaphore)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 57 ()
Type: 31, Cnt: 24 (File)
Type: 36, Cnt: 2 (Section)
Type: 39, Cnt: 64 (Key)
Type: 40, Cnt: 67 (ALPC Port)
Type: 43, Cnt: 137 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7A3F10000 +69632 57912 10.0.10586.589 C:\WINDOWS\system32\lsass.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEACF70000 +1429504 1388032 10.0.10586.713 C:\WINDOWS\system32\lsasrv.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\SspiCli.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEACE60000 +876544 849920 10.0.10586.494 C:\WINDOWS\SYSTEM32\samsrv.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\system32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\system32\NTASN1.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptprimitives.dll
0x000001C352290000 +12288 3072 10.0.10586.0 C:\WINDOWS\system32\msprivs.DLL
0x00007FFEACD70000 +86016 64000 10.0.10586.0 C:\WINDOWS\SYSTEM32\netprovfw.dll
0x00007FFEACD40000 +135168 109568 10.0.10586.0 C:\WINDOWS\system32\JOINUTIL.DLL
0x00007FFEACD10000 +151552 112128 10.0.10586.0 C:\WINDOWS\system32\negoexts.DLL
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEACC00000 +1024000 970752 10.0.10586.589 C:\WINDOWS\system32\kerberos.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\system32\CRYPTSP.dll
0x00007FFEACBB0000 +163840 152440 10.0.10586.0 C:\WINDOWS\system32\KerbClientShared.dll
0x00007FFEACB90000 +86016 70312 10.0.10586.0 C:\WINDOWS\system32\cryptdll.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEACAD0000 +380928 360288 10.0.10586.672 C:\WINDOWS\system32\msv1_0.DLL
0x00007FFEACAC0000 +49152 38792 10.0.10586.0 C:\WINDOWS\system32\NtlmShared.dll
0x00007FFEAC9E0000 +872448 847360 10.0.10586.589 C:\WINDOWS\system32\netlogon.DLL
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\system32\USERENV.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAC9A0000 +114688 97792 10.0.10586.0 C:\WINDOWS\system32\tspkg.DLL
0x00007FFEAC950000 +278528 238592 10.0.10586.0 C:\WINDOWS\system32\pku2u.DLL
0x00007FFEAC910000 +217088 197120 10.0.10586.0 C:\WINDOWS\system32\cloudAP.DLL
0x00007FFEAC8C0000 +270336 250880 10.0.10586.589 C:\WINDOWS\SYSTEM32\MicrosoftAccountCloudAP.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\SYSTEM32\DPAPI.DLL
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAC830000 +245760 222208 10.0.10586.0 C:\WINDOWS\system32\wdigest.DLL
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEAC790000 +110592 92160 10.0.10586.0 C:\WINDOWS\system32\PCPKsp.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEAC6C0000 +569344 549376 10.0.10586.0 C:\WINDOWS\system32\PCPTPM12.dll
0x00007FFEAC6B0000 +53248 42920 10.0.10586.0 C:\WINDOWS\system32\tbs.dll
0x00007FFEAC680000 +135168 116736 10.0.10586.0 C:\WINDOWS\system32\efslsaext.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\system32\netutils.dll
0x00007FFEAC630000 +217088 195072 10.0.10586.0 C:\WINDOWS\system32\dpapisrv.dll
0x00007FFEAC620000 +49152 29184 10.0.10586.0 C:\WINDOWS\system32\SspiSrv.dll
0x00007FFEAC550000 +274432 251392 10.0.10586.0 C:\WINDOWS\system32\scecli.DLL
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 C:\WINDOWS\system32\DNSAPI.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEA77A0000 +122880 111064 10.0.10586.420 C:\WINDOWS\system32\ncryptsslp.dll
0x00007FFEA7740000 +348160 325632 10.0.10586.0 C:\WINDOWS\system32\ncryptprov.dll
0x00007FFEA7710000 +163840 154976 10.0.10586.0 C:\WINDOWS\system32\dssenh.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEA76F0000 +81920 60928 10.0.10586.0 C:\WINDOWS\SYSTEM32\mskeyprotect.dll
0x00007FFEAA1B0000 +409600 400336 10.0.10586.0 C:\WINDOWS\SYSTEM32\wevtapi.dll
0x00007FFE9C3E0000 +380928 360448 10.0.10586.162 C:\Windows\System32\vaultsvc.dll
0x00007FFE9B180000 +77824 60416 10.0.10586.0 C:\WINDOWS\system32\efssvc.dll
0x00007FFE9ADF0000 +819200 797696 10.0.10586.0 C:\WINDOWS\system32\EFSCORE.dll
0x00007FFE9AEF0000 +94208 73216 10.0.10586.0 C:\WINDOWS\system32\FeClient.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 C:\WINDOWS\system32\AUTHZ.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 C:\WINDOWS\system32\iertutil.dll
0x00007FFE9ADB0000 +57344 34304 10.0.10586.0 C:\WINDOWS\system32\EFSUTIL.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 C:\WINDOWS\system32\DSROLE.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFE9AB00000 +135168 119296 10.0.10586.0 C:\WINDOWS\system32\edpauditapi.dll
0x00007FFEAC290000 +1015808 984576 10.0.10586.589 C:\WINDOWS\SYSTEM32\tdh.dll
0x00007FFE99FE0000 +49152 28672 0.0.0.0 C:\WINDOWS\SYSTEM32\efsext.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFE97680000 +143360 95232 10.0.10586.589 C:\Windows\System32\SecureTimeAggregator.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 C:\WINDOWS\system32\IPHLPAPI.DLL
0x00007FFE9DDB0000 +790528 766464 10.0.10586.713 C:\WINDOWS\SYSTEM32\fveapi.dll
0x00007FFE97550000 +192512 173056 10.0.10586.0 C:\Windows\System32\cryptnet.dll
0x00007FFEA9770000 +49152 28160 10.0.10586.0 C:\WINDOWS\SYSTEM32\secur32.dll
0x00007FFEAAB50000 +253952 240720 10.0.10586.0 C:\WINDOWS\system32\logoncli.dll
0x00007FFEAE5D0000 +376832 352256 10.0.10586.0 C:\WINDOWS\system32\WLDAP32.dll
svchost.exe
PID: 844, Threads: 20, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 18740 K (Peak: 19676 K), CommitSize: 6528 K, PageFaults: 10392
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 360212 (8), Write: 306812 (95), Other: 675228 (13862)
CmdLine: C:\WINDOWS\system32\svchost.exe -k DcomLaunch
## Type: 47 -> DuplicateHandle error: 0x32
## Type: 37 -> Session
## Type: 44 -> DuplicateHandle error: 0x32
## Type: 16 -> Timer
Handles: 642
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 9 (Token)
Type: 6, Cnt: 4 (Job)
Type: 7, Cnt: 12 (Process)
Type: 8, Cnt: 22 (Thread)
Type: 12, Cnt: 168 (Event)
Type: 13, Cnt: 6 (Mutant)
Type: 15, Cnt: 82 (Semaphore)
Type: 16, Cnt: 2 (Timer)
Type: 17, Cnt: 18 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 9 (TpWorkerFactory)
Type: 29, Cnt: 10 (IoCompletion)
Type: 30, Cnt: 34 ()
Type: 31, Cnt: 39 (File)
Type: 36, Cnt: 8 (Section)
Type: 37, Cnt: 4 (Session)
Type: 39, Cnt: 42 (Key)
Type: 40, Cnt: 63 (ALPC Port)
Type: 43, Cnt: 101 (?)
Type: 44, Cnt: 1 (?)
Type: 47, Cnt: 3 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAC3E0000 +131072 111616 10.0.10586.0 c:\windows\system32\umpnpmgr.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAC3B0000 +139264 113664 10.0.10586.0 c:\windows\system32\umpo.dll
0x00007FFEAC390000 +90112 67072 10.0.10586.0 C:\WINDOWS\SYSTEM32\umpoext.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAC290000 +1015808 984576 10.0.10586.589 C:\WINDOWS\SYSTEM32\tdh.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAC250000 +49152 34816 10.0.10586.0 C:\WINDOWS\SYSTEM32\HID.DLL
0x00007FFEAC160000 +929792 904704 10.0.10586.589 c:\windows\system32\rpcss.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 c:\windows\system32\SspiCli.dll
0x00007FFEAC040000 +610304 587776 10.0.10586.672 c:\windows\system32\bisrv.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAD0D0000 +102400 84992 10.0.10586.0 c:\windows\system32\EventAggregation.dll
0x00007FFEAC010000 +196608 178176 10.0.10586.122 c:\windows\system32\psmsrv.dll
0x00007FFEABFE0000 +172032 167336 10.0.10586.0 c:\windows\system32\RMCLIENT.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEABF20000 +770048 729600 10.0.10586.0 c:\windows\system32\lsm.dll
0x00007FFEABF10000 +49152 26624 10.0.10586.0 c:\windows\system32\SYSNTFY.dll
0x00007FFEABE60000 +577536 556032 10.0.10586.589 C:\WINDOWS\SYSTEM32\psmserviceexthost.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\WINDOWS\SYSTEM32\twinapi.appcore.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\System32\Userenv.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 c:\windows\system32\DEVOBJ.dll
0x00007FFEABB50000 +405504 380416 10.0.10586.420 c:\windows\system32\systemeventsbrokerserver.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFEABAE0000 +135168 111104 10.0.10586.0 c:\windows\system32\
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAC140000 +94208 79360 10.0.10586.0 c:\windows\system32\rpcepmap.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\sspicli.dll
0x00007FFEAC120000 +77824 65648 10.0.10586.0 C:\WINDOWS\system32\RpcRtRemote.dll
0x00007FFEAC160000 +929792 904704 10.0.10586.589 c:\windows\system32\rpcss.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9E130000 +421888 402432 10.0.10586.212 C:\WINDOWS\system32\fwpuclnt.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINSTA.dll
0x00007FFE93560000 +110592 98704 10.0.10586.0 C:\WINDOWS\SYSTEM32\capauthz.dll
0x00007FFEAB0B0000 +65536 43520 10.0.10586.63 C:\WINDOWS\SYSTEM32\usermgrcli.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
dwm.exe
PID: 984, Threads: 10, Owner: Window Manager\DWM-1
MEM - WrkSet: 42508 K (Peak: 58280 K), CommitSize: 33920 K, PageFaults: 1518938
TIME - Start 27.02.2017 19:07:41, KernelTime: 00:04:36, UserTime: 00:05:36
IO - Read: 1790 (91), Write: 0 (0), Other: 10246 (1087)
CmdLine: "dwm.exe"
## Type: 23 -> RawInputManager
## Type: 22 -> Composition
## Type: 51 -> DxgkSharedResource
Handles: 403
Type: 3, Cnt: 2 (Directory)
Type: 8, Cnt: 16 (Thread)
Type: 12, Cnt: 126 (Event)
Type: 13, Cnt: 4 (Mutant)
Type: 15, Cnt: 2 (Semaphore)
Type: 16, Cnt: 2 (Timer)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 2 (Desktop)
Type: 22, Cnt: 22 (Composition)
Type: 23, Cnt: 5 (RawInputManager)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 14 ()
Type: 31, Cnt: 10 (File)
Type: 36, Cnt: 60 (Section)
Type: 39, Cnt: 14 (Key)
Type: 40, Cnt: 21 (ALPC Port)
Type: 43, Cnt: 72 (?)
Type: 51, Cnt: 17 (DxgkSharedResource)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF6A4A80000 +77824 46592 10.0.10586.0 C:\WINDOWS\system32\dwm.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 C:\WINDOWS\system32\apphelp.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\gdi32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAB900000 +180224 148480 10.0.10586.0 C:\WINDOWS\SYSTEM32\dwmredir.dll
0x00007FFEAB290000 +1978368 1946112 10.0.10586.633 C:\WINDOWS\system32\dwmcore.dll
0x00007FFEAB480000 +929792 911640 10.0.10586.589 C:\WINDOWS\system32\dcomp.dll
0x00007FFEAB820000 +872448 838144 10.0.10586.589 C:\WINDOWS\SYSTEM32\udwm.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAB140000 +770048 754664 10.0.10586.672 C:\WINDOWS\system32\CoreMessaging.dll
0x00007FFEB0620000 +241664 230416 10.0.10586.0 C:\WINDOWS\system32\IMM32.DLL
0x00007FFEABCC0000 +614400 589312 10.0.10586.0 C:\WINDOWS\system32\uxtheme.dll
0x00007FFEAB0F0000 +90112 68608 10.0.10586.0 C:\WINDOWS\SYSTEM32\dwmghost.dll
0x00007FFEAB0C0000 +139264 107520 10.0.10586.0 C:\WINDOWS\system32\dwmapi.dll
0x00007FFEAA830000 +2785280 2773088 10.0.10586.589 C:\WINDOWS\system32\d3d11.dll
0x00007FFEAA780000 +663552 648256 10.0.10586.494 C:\WINDOWS\system32\dxgi.dll
0x00007FFEAA5C0000 +1773568 1777280 10.0.10586.713 C:\WINDOWS\system32\WindowsCodecs.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAA570000 +307200 285696 10.0.10586.672 C:\WINDOWS\System32\UIAnimation.dll
0x00007FFEAA170000 +204800 185856 0.0.0.0 C:\WINDOWS\SYSTEM32\ism32k.dll
0x00007FFEAA160000 +45056 32592 10.0.10586.0 C:\WINDOWS\system32\avrt.dll
0x00007FFEAA120000 +262144 242176 10.0.10586.0 C:\Windows\System32\Windows.Gaming.Input.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\CFGMGR32.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEAD0F0000 +626688 622912 10.0.10586.0 C:\WINDOWS\SYSTEM32\sxs.dll
0x00007FFEA8550000 +5525504 5503488 10.0.10586.672 C:\WINDOWS\system32\d2d1.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\WINDOWS\system32\XmlLite.dll
0x00007FFEA8490000 +167936 144184 10.0.10586.0 C:\WINDOWS\system32\Cabinet.dll
0x00007FFE859F0000 +2551808 2549456 10.0.10586.713 C:\WINDOWS\system32\d3d10warp.dll
0x00007FFE9E480000 +2572288 2555736 6.10.10586.672 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.672_none_a2d6b3cea53ff843\COMCTL32.dll
0x00007FFEA8AA0000 +12197888 12442464 10.18.10.4358 C:\WINDOWS\system32\igd10iumd64.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\system32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\system32\NTASN1.dll
0x00007FFEA9C00000 +4603904 4702968 10.18.10.4358 C:\WINDOWS\system32\igdusc64.dll
svchost.exe
PID: 88, Threads: 27, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 100640 K (Peak: 129756 K), CommitSize: 88392 K, PageFaults: 408557
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:01:01, UserTime: 00:01:13
IO - Read: 52165067 (555), Write: 34116621 (18486), Other: 165241712 (415436)
CmdLine: C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
## Type: 42 -> WmiGuid
Handles: 892
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 6 (Token)
Type: 6, Cnt: 2 (Job)
Type: 7, Cnt: 5 (Process)
Type: 8, Cnt: 43 (Thread)
Type: 12, Cnt: 245 (Event)
Type: 13, Cnt: 9 (Mutant)
Type: 15, Cnt: 42 (Semaphore)
Type: 16, Cnt: 4 (Timer)
Type: 17, Cnt: 10 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 5 (TpWorkerFactory)
Type: 29, Cnt: 8 (IoCompletion)
Type: 30, Cnt: 45 ()
Type: 31, Cnt: 58 (File)
Type: 36, Cnt: 12 (Section)
Type: 39, Cnt: 143 (Key)
Type: 40, Cnt: 36 (ALPC Port)
Type: 42, Cnt: 13 (WmiGuid)
Type: 43, Cnt: 201 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEABAC0000 +57344 36864 10.0.10586.0 c:\windows\system32\hidserv.dll
0x00007FFEAC250000 +49152 34816 10.0.10586.0 c:\windows\system32\HID.DLL
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEB0660000 +4362240 4387680 10.0.10586.589 C:\WINDOWS\system32\SETUPAPI.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 C:\WINDOWS\system32\DEVOBJ.dll
0x00007FFEADCD0000 +348160 341936 10.0.10586.672 C:\WINDOWS\system32\WINTRUST.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\ADVAPI32.dll
0x00007FFEAB9F0000 +659456 639488 10.0.10586.672 C:\WINDOWS\SYSTEM32\PortableDeviceApi.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEAB9D0000 +94208 73216 10.0.10586.672 C:\Windows\System32\portabledeviceconnectapi.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 c:\windows\system32\WTSAPI32.dll
0x00007FFEA8440000 +303104 275456 10.0.10586.122 c:\windows\system32\audioendpointbuilder.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEA7860000 +458752 440120 10.0.10586.0 c:\windows\system32\MMDevAPI.DLL
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 c:\windows\system32\PROPSYS.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFE9E1F0000 +2330624 2295808 10.0.10586.672 c:\windows\system32\wlansvc.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFE9E0E0000 +278528 238080 10.0.10586.0 c:\windows\system32\OneX.DLL
0x00007FFE9DF10000 +434176 412672 10.0.10586.122 c:\windows\system32\WLANMSM.DLL
0x00007FFE9E010000 +94208 72192 10.0.10586.494 c:\windows\system32\eappprxy.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFE9DE80000 +536576 463360 10.0.10586.122 c:\windows\system32\WLANSEC.dll
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFE9DFA0000 +122880 104448 10.0.10586.0 c:\windows\system32\wudfsvc.dll
0x00007FFE9C4D0000 +221184 200192 10.0.10586.672 c:\windows\system32\WUDFPlatform.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 c:\windows\system32\SspiCli.dll
0x00007FFE9DF90000 +49152 26112 10.0.10586.122 C:\WINDOWS\System32\wlansvcpal.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFE9AB50000 +544768 528736 10.0.10586.672 c:\windows\system32\pcasvc.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 c:\windows\system32\apphelp.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFE9A2B0000 +1105920 1088512 10.0.10586.0 c:\windows\system32\sysmain.dll
0x00007FFE99F40000 +139264 115200 10.0.10586.0 c:\windows\system32\trkwks.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 c:\windows\system32\AUTHZ.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFE9A6A0000 +32768 13312 10.0.10586.0 C:\WINDOWS\System32\TetheringIeProvider.dll
0x00007FFE99AA0000 +217088 189952 10.0.10586.122 C:\WINDOWS\System32\WiFiDisplay.dll
0x00007FFEAAB30000 +69632 45056 10.0.10586.0 c:\windows\system32\WMICLNT.dll
0x00007FFEAA1B0000 +409600 400336 10.0.10586.0 C:\WINDOWS\system32\wevtapi.dll
0x00007FFE99E00000 +139264 120832 10.0.10586.0 C:\WINDOWS\SYSTEM32\wlgpclnt.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 c:\windows\system32\DSROLE.dll
0x00007FFEABF10000 +49152 26624 10.0.10586.0 c:\windows\system32\SYSNTFY.dll
0x00007FFE9B250000 +348160 334736 10.0.10586.212 C:\WINDOWS\SYSTEM32\policymanager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 C:\WINDOWS\SYSTEM32\msvcp110_win.dll
0x00007FFEACC00000 +1024000 970752 10.0.10586.589 C:\WINDOWS\system32\kerberos.DLL
0x00007FFE98EF0000 +491520 471552 10.0.10586.306 C:\Windows\System32\NetSetupShim.dll
0x00007FFE98E60000 +126976 115040 10.0.10586.545 C:\Windows\System32\NetSetupApi.dll
0x00007FFE97F30000 +360448 338432 10.0.10586.212 c:\windows\system32\ncbservice.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFE97DE0000 +466944 445440 10.0.10586.633 c:\windows\system32\das.dll
0x00007FFEAB570000 +49152 26624 10.0.10586.0 C:\WINDOWS\SYSTEM32\bi.dll
0x00007FFE9B2B0000 +36864 18944 10.0.10586.0 C:\WINDOWS\SYSTEM32\httpprxc.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFE98E20000 +262144 242688 10.0.10586.0 C:\WINDOWS\System32\netprofm.dll
0x00007FFE98D90000 +57344 38912 10.0.10586.0 C:\WINDOWS\System32\npmproxy.dll
0x00007FFEAAFF0000 +782336 779384 10.0.10586.122 C:\Windows\System32\taskschd.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\Windows\System32\XmlLite.dll
0x00007FFE99EA0000 +45056 24576 10.0.10586.0 C:\WINDOWS\system32\SystemEventsBrokerClient.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEAFFB0000 +454656 442720 10.0.10586.0 C:\WINDOWS\system32\coml2.dll
0x00007FFE95AF0000 +278528 254464 10.0.10586.672 C:\Windows\System32\execmodelclient.dll
0x00007FFEAB140000 +770048 754664 10.0.10586.672 C:\Windows\System32\CoreMessaging.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFEA2DA0000 +167936 145408 10.0.10586.162 c:\windows\system32\dssvc.dll
0x00007FFE992E0000 +3117056 3078144 10.0.10586.212 c:\windows\system32\ESENT.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFE9A4C0000 +118784 100352 10.0.10586.0 c:\windows\system32\wdi.dll
0x00007FFEAB220000 +65536 45568 10.0.10586.0 C:\WINDOWS\system32\pcadm.dll
0x00007FFE9BD70000 +65536 50176 10.0.10586.0 C:\WINDOWS\system32\pcacli.dll
0x00007FFEA7E10000 +110592 101776 10.0.10586.0 C:\WINDOWS\system32\MPR.dll
0x00007FFE8AEF0000 +647168 617984 10.0.10586.589 c:\windows\system32\storsvc.dll
0x00007FFEA49D0000 +40960 20992 10.0.10586.0 c:\windows\system32\FLTLIB.DLL
0x00007FFEA29A0000 +106496 97640 10.0.10586.0 c:\windows\system32\bcd.dll
0x00007FFE91B50000 +712704 698208 10.0.10586.11 c:\windows\system32\WIMGAPI.DLL
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.DLL
0x00007FFE8D7A0000 +454656 436736 10.0.10586.672 C:\Windows\System32\AppXDeploymentClient.dll
0x00007FFE8E1D0000 +299008 277504 10.0.10586.0 C:\WINDOWS\system32\spp.dll
0x00007FFE9AC20000 +1581056 1558528 10.0.10586.589 C:\WINDOWS\system32\VSSAPI.DLL
0x00007FFE9A5B0000 +98304 70144 10.0.10586.589 C:\WINDOWS\system32\VssTrace.DLL
0x00007FFEA08A0000 +81920 61952 10.0.10586.672 C:\WINDOWS\system32\vss_ps.dll
0x00007FFE9E480000 +2572288 2555736 6.10.10586.672 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.672_none_a2d6b3cea53ff843\Comctl32.dll
0x000001DEC5960000 +12288 3072 10.0.10586.0 C:\WINDOWS\system32\SFC.DLL
0x00007FFEA54F0000 +69632 49152 10.0.10586.0 C:\WINDOWS\system32\sfc_os.DLL
0x00007FFEAD0F0000 +626688 622912 10.0.10586.0 C:\WINDOWS\system32\SXS.DLL
svchost.exe
PID: 364, Threads: 47, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 45908 K (Peak: 168384 K), CommitSize: 18440 K, PageFaults: 955208
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:09, UserTime: 00:00:13
IO - Read: 212432476 (16062), Write: 56179185 (767), Other: 3605667 (79568)
CmdLine: C:\WINDOWS\system32\svchost.exe -k netsvcs
Handles: 1571
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 32 (Token)
Type: 6, Cnt: 6 (Job)
Type: 7, Cnt: 30 (Process)
Type: 8, Cnt: 76 (Thread)
Type: 12, Cnt: 630 (Event)
Type: 13, Cnt: 33 (Mutant)
Type: 15, Cnt: 63 (Semaphore)
Type: 16, Cnt: 4 (Timer)
Type: 17, Cnt: 18 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 9 (TpWorkerFactory)
Type: 29, Cnt: 10 (IoCompletion)
Type: 30, Cnt: 122 ()
Type: 31, Cnt: 72 (File)
Type: 36, Cnt: 13 (Section)
Type: 39, Cnt: 60 (Key)
Type: 40, Cnt: 87 (ALPC Port)
Type: 42, Cnt: 12 (WmiGuid)
Type: 43, Cnt: 275 (?)
Type: 47, Cnt: 14 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEAB5E0000 +1363968 1339904 10.0.10586.420 c:\windows\system32\gpsvc.dll
0x00007FFEABF10000 +49152 26624 10.0.10586.0 c:\windows\system32\SYSNTFY.dll
0x00007FFEAB120000 +98304 80896 10.0.10586.0 c:\windows\system32\nlaapi.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 c:\windows\system32\DSROLE.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEAAF90000 +348160 328192 10.0.10586.212 c:\windows\system32\profsvc.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAAE90000 +1024000 1001472 10.0.10586.589 c:\windows\system32\schedsvc.dll
0x00007FFEAAE40000 +266240 243200 10.0.10586.672 c:\windows\system32\UBPM.dll
0x00007FFEAD0D0000 +102400 84992 10.0.10586.0 c:\windows\system32\EventAggregation.dll
0x00007FFEAAB90000 +159744 134656 10.0.10586.0 C:\WINDOWS\SYSTEM32\profsvcext.dll
0x00007FFEAE5D0000 +376832 352256 10.0.10586.0 C:\WINDOWS\system32\WLDAP32.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 c:\windows\system32\netutils.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEAAB50000 +253952 240720 10.0.10586.0 c:\windows\system32\logoncli.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAC500000 +299008 277504 10.0.10586.0 c:\windows\system32\AUTHZ.dll
0x00007FFEAAB30000 +69632 45056 10.0.10586.0 c:\windows\system32\WMICLNT.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\sspicli.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEAA480000 +937984 912384 10.0.10586.589 c:\windows\system32\usermgr.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEAA320000 +77824 59392 10.0.10586.0 c:\windows\system32\themeservice.dll
0x00007FFEAA2B0000 +450560 429056 10.0.10586.494 C:\WINDOWS\system32\taskcomp.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEAA260000 +266240 248832 10.0.10586.63 C:\Windows\System32\usermgrproxy.dll
0x00007FFEAA230000 +192512 173056 10.0.10586.0 C:\WINDOWS\SYSTEM32\WPTaskScheduler.dll
0x00007FFEAA220000 +53248 32256 10.0.10586.0 C:\WINDOWS\SYSTEM32\CSystemEventsBrokerClient.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 c:\windows\system32\WTSAPI32.dll
0x00007FFEABAD0000 +32768 13824 10.0.10586.0 c:\windows\system32\DABAPI.dll
0x00007FFEAA1B0000 +409600 400336 10.0.10586.0 C:\WINDOWS\SYSTEM32\wevtapi.dll
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 C:\WINDOWS\system32\PROPSYS.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 c:\windows\system32\wkscli.dll
0x00007FFEA99F0000 +188416 169984 10.0.10586.0 C:\WINDOWS\SYSTEM32\netjoin.dll
0x00007FFEACD40000 +135168 109568 10.0.10586.0 C:\WINDOWS\SYSTEM32\JoinUtil.dll
0x00007FFEA8530000 +94208 73216 10.0.10586.0 c:\windows\system32\sens.dll
0x00007FFEAB200000 +114688 95744 10.0.10586.212 c:\windows\system32\SAMLIB.dll
0x00007FFE9E030000 +630784 608768 10.0.10586.0 c:\windows\system32\shsvcs.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 c:\windows\system32\DEVOBJ.dll
0x00007FFE9DDB0000 +790528 766464 10.0.10586.713 c:\windows\system32\FVEAPI.dll
0x00007FFE9C470000 +335872 312832 10.0.10586.0 C:\Windows\System32\ProximityService.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFE9C3B0000 +184320 167936 10.0.10586.63 C:\WINDOWS\system32\ProximityCommon.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 C:\WINDOWS\system32\IPHLPAPI.DLL
0x00007FFE9DF80000 +36864 16896 10.0.10586.0 C:\WINDOWS\system32\ProximityCommonPal.dll
0x00007FFE9C3A0000 +65536 43520 10.0.10586.0 C:\WINDOWS\system32\ProximityServicePAL.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\firewallapi.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFEAC250000 +49152 34816 10.0.10586.0 c:\windows\system32\HID.DLL
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 c:\windows\system32\XmlLite.dll
0x00007FFE9B060000 +991232 957952 10.0.10586.672 c:\windows\system32\ikeext.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9E130000 +421888 402432 10.0.10586.212 c:\windows\system32\fwpuclnt.dll
0x00007FFE9ABE0000 +245760 225280 10.0.10586.0 c:\windows\system32\wbem\wmisvc.dll
0x00007FFE9A530000 +520192 471040 10.0.10586.589 C:\WINDOWS\SYSTEM32\wbemcomn.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 C:\WINDOWS\system32\dhcpcsvc6.DLL
0x00007FFE99EF0000 +311296 283136 10.0.10586.0 c:\windows\system32\srvsvc.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
0x00007FFE99CA0000 +995328 963072 10.0.10586.420 c:\windows\system32\iphlpsvc.dll
0x00007FFE99A60000 +81920 62464 10.0.10586.0 c:\windows\system32\rtutils.dll
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 C:\WINDOWS\system32\dhcpcsvc.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFE99E70000 +69632 45056 10.0.10586.0 C:\WINDOWS\system32\SSCORE.DLL
0x00007FFEB0660000 +4362240 4387680 10.0.10586.589 C:\WINDOWS\system32\setupapi.dll
0x00007FFE99DB0000 +266240 258280 10.0.10586.162 C:\WINDOWS\system32\sqmapi.dll
0x00007FFE99DA0000 +36864 13824 10.0.10586.71 C:\WINDOWS\SYSTEM32\sscoreext.dll
0x00007FFE99160000 +151552 128512 10.0.10586.420 C:\WINDOWS\system32\httpprxm.dll
0x00007FFE990E0000 +98304 79360 10.0.10586.420 C:\WINDOWS\system32\adhsvc.dll
0x00007FFE99060000 +131072 114176 10.0.10586.0 C:\WINDOWS\system32\mi.dll
0x00007FFE98F70000 +385024 231936 10.0.10586.0 C:\WINDOWS\system32\miutils.dll
0x00007FFE9B2B0000 +36864 18944 10.0.10586.0 C:\WINDOWS\SYSTEM32\httpprxc.dll
0x00007FFE98EC0000 +188416 165888 10.0.10586.0 C:\WINDOWS\system32\wmidcom.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFE98E20000 +262144 242688 10.0.10586.0 C:\WINDOWS\System32\netprofm.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 C:\WINDOWS\system32\WINHTTP.dll
0x00007FFE98DA0000 +335872 313344 10.0.10586.589 C:\WINDOWS\system32\RESUTILS.DLL
0x00007FFE98BF0000 +667648 649216 10.0.10586.589 C:\WINDOWS\system32\CLUSAPI.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\system32\ncrypt.dll
0x00007FFE98020000 +1114112 1097216 10.0.10586.672 c:\windows\system32\dosvc.dll
0x00007FFE9BF70000 +602112 562176 10.0.10586.0 c:\windows\system32\msvcp_win.dll
0x00007FFE8E540000 +921600 896512 10.0.10586.672 C:\Windows\System32\MbaeApiPublic.dll
0x00007FFE990C0000 +90112 80600 8.1.10586.17 C:\WINDOWS\SYSTEM32\wwapi.dll
0x00007FFE9AF40000 +888832 871776 10.0.10586.633 C:\WINDOWS\system32\drvstore.dll
0x00007FFE9B020000 +118784 99328 10.0.10586.0 C:\WINDOWS\system32\SPINF.dll
0x00007FFEA7710000 +163840 154976 10.0.10586.0 C:\WINDOWS\system32\dssenh.dll
0x00007FFEAA110000 +40960 31528 10.0.10586.0 c:\windows\system32\VERSION.dll
0x00007FFE9EB20000 +73728 56832 7.8.10586.0 C:\Windows\System32\BitsProxy.dll
0x00007FFE97770000 +524288 496640 10.0.10586.494 C:\WINDOWS\system32\webio.dll
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEA76F0000 +81920 60928 10.0.10586.0 C:\WINDOWS\SYSTEM32\mskeyprotect.dll
0x00007FFE97550000 +192512 173056 10.0.10586.0 C:\WINDOWS\system32\cryptnet.dll
0x00007FFEA77A0000 +122880 111064 10.0.10586.420 C:\WINDOWS\system32\ncryptsslp.dll
0x00007FFE9E820000 +98304 87840 10.0.10586.0 c:\windows\system32\DMCmnUtils.dll
0x00007FFE8E010000 +872448 848896 10.0.10586.545 C:\Windows\System32\wuapi.dll
0x00007FFE983F0000 +118784 94720 10.0.10586.0 c:\windows\system32\appinfo.dll
0x00007FFEAB930000 +495616 479744 10.0.10586.589 c:\windows\system32\apphelp.dll
0x00007FFEAB230000 +45056 27136 10.0.10586.0 c:\windows\system32\lfsvc.dll
0x00007FFE8DA40000 +1552384 1534464 10.0.10586.420 c:\windows\system32\LocationFramework.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFEA77C0000 +397312 390496 10.0.10586.306 c:\windows\system32\wlanapi.dll
0x00007FFE9BBF0000 +131072 108032 10.0.10586.0 C:\Windows\System32\LocationWinPalMisc.dll
0x00007FFE98800000 +225280 199168 10.0.10586.420 C:\Windows\System32\GnssAdapter.dll
0x00007FFEAB570000 +49152 26624 10.0.10586.0 C:\WINDOWS\SYSTEM32\bi.dll
0x00007FFE98B50000 +638976 619520 10.0.10586.589 C:\WINDOWS\SYSTEM32\efswrt.dll
0x00007FFE98B00000 +327680 305152 10.0.10586.672 C:\WINDOWS\SYSTEM32\edputil.dll
0x00007FFEAFFB0000 +454656 442720 10.0.10586.0 C:\WINDOWS\system32\coml2.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFEA5B20000 +200704 181248 10.0.10586.306 C:\WINDOWS\System32\shacct.dll
0x00007FFEA57A0000 +69632 47616 10.0.10586.0 C:\WINDOWS\system32\CredentialMigrationHandler.dll
WARNING: PID: 608 - Failed to open process.
Handles: 752
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 2 (Token)
Type: 8, Cnt: 57 (Thread)
Type: 12, Cnt: 276 (Event)
Type: 13, Cnt: 35 (Mutant)
Type: 15, Cnt: 59 (Semaphore)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 5 (IoCompletion)
Type: 30, Cnt: 48 ()
Type: 31, Cnt: 33 (File)
Type: 36, Cnt: 6 (Section)
Type: 39, Cnt: 76 (Key)
Type: 40, Cnt: 18 (ALPC Port)
Type: 43, Cnt: 120 (?)
WARNING: Failed to create module snapshot. (5)
svchost.exe
PID: 412, Threads: 10, Owner: NT-AUTORITÄT\Lokaler Dienst
MEM - WrkSet: 7156 K (Peak: 8088 K), CommitSize: 2212 K, PageFaults: 2271
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 0 (0), Write: 0 (0), Other: 10438 (443)
CmdLine: C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
Handles: 209
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 13 (Thread)
Type: 12, Cnt: 63 (Event)
Type: 15, Cnt: 5 (Semaphore)
Type: 16, Cnt: 2 (Timer)
Type: 17, Cnt: 9 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 24 ()
Type: 31, Cnt: 12 (File)
Type: 36, Cnt: 2 (Section)
Type: 39, Cnt: 11 (Key)
Type: 40, Cnt: 10 (ALPC Port)
Type: 43, Cnt: 44 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEAB730000 +180224 163840 10.0.10586.122 c:\windows\system32\timebrokerserver.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEABB10000 +262144 239104 10.0.10586.420 c:\windows\system32\BrokerLib.dll
0x00007FFEAB570000 +49152 26624 10.0.10586.0 C:\WINDOWS\SYSTEM32\bi.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE95AF0000 +278528 254464 10.0.10586.672 C:\Windows\System32\execmodelclient.dll
0x00007FFEAB140000 +770048 754664 10.0.10586.672 C:\Windows\System32\CoreMessaging.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\Windows\System32\twinapi.appcore.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\Windows\System32\bcrypt.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEA44D0000 +266240 239616 10.0.10586.0 c:\windows\system32\ssdpsrv.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 c:\windows\system32\dhcpcsvc6.DLL
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFE9A4B0000 +40960 20480 10.0.10586.0 C:\WINDOWS\system32\wshqos.dll
0x00007FFE9A000000 +32768 12800 10.0.10586.0 C:\WINDOWS\system32\wshtcpip.DLL
0x00007FFE99ED0000 +32768 12800 10.0.10586.0 C:\WINDOWS\system32\wship6.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\sspicli.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
svchost.exe
PID: 1056, Threads: 25, Owner: NT-AUTORITÄT\Lokaler Dienst
MEM - WrkSet: 27028 K (Peak: 28208 K), CommitSize: 16396 K, PageFaults: 34782
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:02, UserTime: 00:00:01
IO - Read: 24646364 (925), Write: 22565536 (815), Other: 1128976 (14820)
CmdLine: C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
## Type: 9 -> UserApcReserve
Handles: 791
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 7, Cnt: 1 (Process)
Type: 8, Cnt: 44 (Thread)
Type: 9, Cnt: 2 (UserApcReserve)
Type: 12, Cnt: 243 (Event)
Type: 13, Cnt: 4 (Mutant)
Type: 15, Cnt: 15 (Semaphore)
Type: 16, Cnt: 6 (Timer)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 62 ()
Type: 31, Cnt: 130 (File)
Type: 36, Cnt: 4 (Section)
Type: 39, Cnt: 34 (Key)
Type: 40, Cnt: 45 (ALPC Port)
Type: 42, Cnt: 5 (WmiGuid)
Type: 43, Cnt: 174 (?)
Type: 44, Cnt: 3 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\System32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEA9A40000 +1773568 1743872 10.0.10586.589 c:\windows\system32\wevtsvc.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\System32\sspicli.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFE9ED00000 +1089536 1053696 10.0.10586.672 c:\windows\system32\audiosrv.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEA7860000 +458752 440120 10.0.10586.0 c:\windows\system32\MMDevAPI.DLL
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 c:\windows\system32\DEVOBJ.dll
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 c:\windows\system32\PROPSYS.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\winsta.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFE9E8F0000 +630784 606720 10.0.10586.672 c:\windows\system32\wcmsvc.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9E840000 +380928 355840 10.0.10586.420 c:\windows\system32\dhcpcore.dll
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 c:\windows\system32\DNSAPI.dll
0x00007FFE9E440000 +229376 210432 10.0.10586.589 C:\WINDOWS\System32\wcmcsp.dll
0x00007FFEAAB30000 +69632 45056 10.0.10586.0 C:\WINDOWS\System32\WMICLNT.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\firewallapi.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\system32\fwbase.dll
0x00007FFE9E430000 +57344 37376 10.0.10586.589 C:\WINDOWS\SYSTEM32\cmintegrator.dll
0x00007FFE9E1A0000 +294912 267264 10.0.10586.420 C:\WINDOWS\System32\dhcpcore6.dll
0x00007FFEAB120000 +98304 80896 10.0.10586.0 C:\WINDOWS\SYSTEM32\nlaapi.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
0x00007FFE9DD60000 +307200 286720 10.0.10586.494 C:\Windows\System32\deviceaccess.dll
0x00007FFE9E990000 +557056 536256 10.0.10586.122 C:\WINDOWS\System32\audioses.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEA77C0000 +397312 390496 10.0.10586.306 C:\WINDOWS\System32\Wlanapi.dll
0x00000175EF4F0000 +20480 14848 10.0.10586.0 C:\WINDOWS\System32\Wlanhlp.dll
0x00007FFE99190000 +1351680 1319424 10.0.10586.672 C:\WINDOWS\SYSTEM32\wifinetworkmanager.dll
0x00007FFE99EA0000 +45056 24576 10.0.10586.0 C:\WINDOWS\SYSTEM32\SystemEventsBrokerClient.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFE9B250000 +348160 334736 10.0.10586.212 C:\WINDOWS\SYSTEM32\policymanager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 C:\WINDOWS\SYSTEM32\msvcp110_win.dll
0x00007FFE990C0000 +90112 80600 8.1.10586.17 C:\WINDOWS\SYSTEM32\wwapi.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 c:\windows\system32\dhcpcsvc6.DLL
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFE97F10000 +69632 52736 10.0.10586.11 C:\WINDOWS\SYSTEM32\TetheringClient.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\SYSTEM32\CRYPTSP.dll
0x00007FFE97D20000 +724992 704512 10.0.10586.672 C:\WINDOWS\system32\CellularAPI.dll
0x00007FFE98840000 +73728 55808 10.0.10586.17 C:\WINDOWS\system32\rilProxy.dll
0x00007FFE98010000 +32768 12288 10.0.10586.0 C:\WINDOWS\SYSTEM32\netwphelper.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFE97C80000 +184320 166400 10.0.10586.306 C:\WINDOWS\System32\SubscriptionMgr.dll
0x00007FFE97C20000 +139264 117760 10.0.10586.0 C:\WINDOWS\System32\wcmapi.dll
0x00007FFEABFE0000 +172032 167336 10.0.10586.0 C:\WINDOWS\System32\RMCLIENT.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 c:\windows\system32\CRYPTBASE.dll
0x00007FFE98000000 +45056 24576 10.0.10586.0 c:\windows\system32\lmhsvc.dll
0x00007FFE977F0000 +36864 17408 10.0.10586.0 c:\windows\system32\nrpsrv.DLL
0x00007FFE8D760000 +212992 190464 10.0.10586.420 c:\windows\system32\wscsvc.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 c:\windows\system32\netutils.dll
0x00007FFE987D0000 +69632 45056 10.0.10586.0 C:\WINDOWS\system32\wbem\wbemprox.dll
0x00007FFE9A530000 +520192 471040 10.0.10586.589 C:\WINDOWS\SYSTEM32\wbemcomn.dll
0x00007FFE98450000 +81920 62976 10.0.10586.0 C:\WINDOWS\system32\wbem\wbemsvc.dll
0x00007FFE98510000 +1007616 987648 10.0.10586.0 C:\WINDOWS\system32\wbem\fastprox.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 c:\windows\system32\WINHTTP.dll
0x00007FFEA9800000 +1622016 1500672 10.0.10586.589 c:\windows\system32\dbghelp.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 c:\windows\system32\wkscli.dll
0x00007FFE9D9F0000 +1802240 1804664 10.0.10586.63 C:\WINDOWS\System32\WMALFXGFXDSP.dll
0x00007FFE9C8A0000 +1101824 1092464 12.0.10586.589 C:\WINDOWS\SYSTEM32\mfplat.DLL
0x00007FFE9C440000 +176128 152376 12.0.10586.0 C:\WINDOWS\SYSTEM32\RTWorkQ.DLL
svchost.exe
PID: 1132, Threads: 23, Owner: NT-AUTORITÄT\Lokaler Dienst
MEM - WrkSet: 24476 K (Peak: 26364 K), CommitSize: 8056 K, PageFaults: 15596
TIME - Start 27.02.2017 19:07:42, KernelTime: 00:00:01, UserTime: 00:00:01
IO - Read: 1524 (42), Write: 900 (6), Other: 1344328 (22284)
CmdLine: C:\WINDOWS\system32\svchost.exe -k LocalService
Handles: 667
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 90 (Token)
Type: 7, Cnt: 7 (Process)
Type: 8, Cnt: 47 (Thread)
Type: 9, Cnt: 1 (UserApcReserve)
Type: 12, Cnt: 156 (Event)
Type: 13, Cnt: 57 (Mutant)
Type: 15, Cnt: 37 (Semaphore)
Type: 16, Cnt: 1 (Timer)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 39 ()
Type: 31, Cnt: 20 (File)
Type: 36, Cnt: 7 (Section)
Type: 39, Cnt: 24 (Key)
Type: 40, Cnt: 50 (ALPC Port)
Type: 43, Cnt: 113 (?)
Type: 47, Cnt: 1 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEA9780000 +499712 473088 2001.12.10941.16384 c:\windows\system32\es.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEA82A0000 +1703936 1661952 10.0.10586.633 c:\windows\system32\fntcache.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEA8270000 +167936 116224 10.0.10586.212 c:\windows\system32\FontProvider.dll
0x00007FFE9EE20000 +53248 30720 10.0.10586.0 c:\windows\system32\nsisvc.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 c:\windows\system32\winhttp.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 c:\windows\system32\IPHLPAPI.DLL
0x00007FFE9E810000 +45056 33104 10.0.10586.0 c:\windows\system32\WINNSI.DLL
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 c:\windows\system32\dhcpcsvc6.DLL
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 C:\WINDOWS\system32\DNSAPI.dll
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 c:\windows\system32\dhcpcsvc.DLL
0x00007FFE9AF10000 +40960 17408 10.0.10586.71 C:\Windows\System32\rasadhlp.dll
0x00007FFE9A4C0000 +118784 100352 10.0.10586.0 c:\windows\system32\wdi.dll
0x00007FFEAD0F0000 +626688 622912 10.0.10586.0 C:\WINDOWS\SYSTEM32\sxs.dll
0x00007FFE99EB0000 +98304 83968 10.0.10586.0 C:\WINDOWS\system32\perftrack.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFE98CA0000 +569344 547840 10.0.10586.0 c:\windows\system32\netprofmsvc.dll
0x00007FFEAB120000 +98304 80896 10.0.10586.0 c:\windows\system32\nlaapi.dll
0x00007FFE98D90000 +57344 38912 10.0.10586.0 C:\WINDOWS\System32\npmproxy.dll
0x00007FFE98AE0000 +81920 65536 10.0.10586.0 C:\WINDOWS\system32\WlanRadioManager.dll
0x00007FFEA77C0000 +397312 390496 10.0.10586.306 C:\WINDOWS\system32\wlanapi.dll
0x00007FFE98880000 +102400 82432 10.0.10586.0 C:\WINDOWS\system32\BthRadioMedia.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEABBC0000 +159744 149816 10.0.10586.0 C:\WINDOWS\system32\DEVOBJ.dll
0x00007FFE98860000 +122880 104448 10.0.10586.545 C:\WINDOWS\SYSTEM32\bluetoothapis.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEA5770000 +45056 22528 10.0.10586.0 c:\windows\system32\licensemanagersvc.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEA3540000 +1306624 1297760 10.0.10586.633 c:\windows\system32\LicenseManager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 c:\windows\system32\msvcp110_win.dll
0x00007FFEA57C0000 +90112 78040 10.0.10586.494 c:\windows\system32\CLIPC.dll
0x00007FFE975C0000 +729088 697344 10.0.10586.589 C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\Windows\System32\bcrypt.dll
0x00007FFE8E010000 +872448 848896 10.0.10586.545 C:\Windows\System32\wuapi.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEADCD0000 +348160 341936 10.0.10586.672 C:\WINDOWS\system32\WINTRUST.dll
0x00007FFE93360000 +135168 111104 10.0.10586.420 C:\Windows\System32\UpdatePolicy.dll
0x00007FFEAAAE0000 +65536 48128 10.0.10586.672 C:\Windows\System32\wups.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFEA28D0000 +806912 787456 10.0.10586.672 C:\Windows\System32\Windows.Web.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 C:\Windows\System32\iertutil.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFE963F0000 +724992 708608 10.0.10586.672 C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\Windows\System32\twinapi.appcore.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEA28B0000 +94208 74240 10.0.10586.0 C:\WINDOWS\SYSTEM32\msauserext.dll
0x00007FFEA1CB0000 +180224 146432 10.0.10586.162 C:\WINDOWS\SYSTEM32\AuthBroker.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 C:\WINDOWS\SYSTEM32\wkscli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\SYSTEM32\netutils.dll
0x00007FFE97770000 +524288 496640 10.0.10586.494 c:\windows\system32\webio.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 c:\windows\system32\SspiCli.dll
0x00007FFE9E130000 +421888 402432 10.0.10586.212 C:\WINDOWS\System32\fwpuclnt.dll
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEA76F0000 +81920 60928 0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\System32\netutils.dll
0x00007FFE967F0000 +704512 676352 10.0.10586.212 C:\WINDOWS\System32\wsdapi.dll
0x00007FFE96E90000 +69632 47616 10.0.10586.589 C:\WINDOWS\System32\deviceassociation.dll
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 C:\WINDOWS\System32\WINHTTP.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFE96680000 +1449984 1447776 10.0.10586.589 C:\WINDOWS\System32\webservices.dll
0x00007FFEAC0E0000 +204800 184320 10.0.10586.162 C:\WINDOWS\System32\fwbase.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFE96650000 +172032 153600 10.0.10586.0 C:\Windows\System32\FunDisc.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\Windows\System32\XmlLite.dll
0x00007FFE96E70000 +77824 61440 10.0.10586.0 C:\Windows\System32\fdPnp.dll
0x00007FFE988F0000 +122880 101888 3.5.2284.0 C:\Windows\System32\ATL.DLL
0x00007FFE9AF40000 +888832 871776 10.0.10586.633 C:\WINDOWS\system32\drvstore.dll
0x00007FFE98AA0000 +65536 44032 10.0.10586.122 C:\WINDOWS\system32\spool\PRTPROCS\x64\winprint.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\System32\USERENV.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAC260000 +147456 131248 10.0.10586.420 C:\WINDOWS\SYSTEM32\gpapi.dll
0x00007FFEAB110000 +40960 26408 10.0.10586.0 C:\WINDOWS\System32\DSROLE.dll
0x00007FFE96570000 +860160 841728 10.0.10586.633 C:\WINDOWS\System32\win32spl.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\System32\CRYPTSP.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\System32\WINSTA.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\System32\CRYPTBASE.dll
0x00007FFE98430000 +73728 52224 10.0.10586.0 C:\WINDOWS\System32\cscapi.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\System32\WTSAPI32.dll
svchost.exe
PID: 1996, Threads: 9, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 9080 K (Peak: 10052 K), CommitSize: 3752 K, PageFaults: 2822
TIME - Start 27.02.2017 19:07:53, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 564596 (144), Write: 0 (0), Other: 5462 (520)
CmdLine: C:\WINDOWS\system32\svchost.exe -k apphost
Handles: 132
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 8 (Thread)
Type: 12, Cnt: 32 (Event)
Type: 13, Cnt: 1 (Mutant)
Type: 15, Cnt: 2 (Semaphore)
Type: 17, Cnt: 6 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 3 (TpWorkerFactory)
Type: 29, Cnt: 5 (IoCompletion)
Type: 30, Cnt: 8 ()
Type: 31, Cnt: 10 (File)
Type: 36, Cnt: 2 (Section)
Type: 39, Cnt: 7 (Key)
Type: 40, Cnt: 6 (ALPC Port)
Type: 43, Cnt: 36 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFE9AB30000 +90112 64512 10.0.10586.0 c:\windows\system32\inetsrv\apphostsvc.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\ADVAPI32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\SYSTEM32\bcrypt.dll
0x00007FFE9A010000 +520192 504320 10.0.10586.0 c:\windows\system32\inetsrv\nativerd.dll
0x00007FFE9A460000 +315392 290304 10.0.10586.0 c:\windows\system32\inetsrv\iisutil.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\SYSTEM32\ncrypt.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\WINDOWS\SYSTEM32\XmlLite.dll
0x00007FFE99EE0000 +45056 24064 10.0.10586.0 C:\WINDOWS\SYSTEM32\ktmw32.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\SYSTEM32\NTASN1.dll
0x0000018F61EA0000 +241664 231424 10.0.10586.0 c:\windows\system32\inetsrv\IISRES.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\SYSTEM32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFE9AC20000 +1581056 1558528 10.0.10586.589 C:\WINDOWS\SYSTEM32\VSSAPI.DLL
0x00007FFE9A5B0000 +98304 70144 10.0.10586.589 C:\WINDOWS\SYSTEM32\VssTrace.DLL
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFE9A680000 +102400 79360 10.0.10586.0 C:\WINDOWS\SYSTEM32\samcli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\SYSTEM32\netutils.dll
0x00007FFEAB200000 +114688 95744 10.0.10586.212 C:\WINDOWS\SYSTEM32\SAMLIB.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFEA9780000 +499712 473088 2001.12.10941.16384 C:\WINDOWS\System32\ES.DLL
0x00007FFEAACB0000 +1597440 1603224 7.0.10586.672 C:\WINDOWS\System32\PROPSYS.dll
0x00007FFE99AF0000 +253952 233472 10.0.10586.0 C:\WINDOWS\system32\mlang.dll
svchost.exe
PID: 2004, Threads: 14, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 30268 K (Peak: 35192 K), CommitSize: 14220 K, PageFaults: 41844
TIME - Start 27.02.2017 19:07:53, KernelTime: 00:00:01, UserTime: 00:00:24
IO - Read: 13753808 (2662), Write: 32273 (2), Other: 516245 (14189)
CmdLine: C:\WINDOWS\System32\svchost.exe -k utcsvc
Handles: 397
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 5 (Token)
Type: 8, Cnt: 29 (Thread)
Type: 12, Cnt: 107 (Event)
Type: 13, Cnt: 5 (Mutant)
Type: 15, Cnt: 34 (Semaphore)
Type: 16, Cnt: 1 (Timer)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 4 (IoCompletion)
Type: 30, Cnt: 17 ()
Type: 31, Cnt: 9 (File)
Type: 36, Cnt: 8 (Section)
Type: 39, Cnt: 41 (Key)
Type: 40, Cnt: 11 (ALPC Port)
Type: 43, Cnt: 108 (?)
Type: 44, Cnt: 1 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\System32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFE9A960000 +1650688 1637216 10.0.10586.672 c:\windows\system32\diagtrack.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 c:\windows\system32\bcrypt.dll
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 c:\windows\system32\CRYPTSP.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 c:\windows\system32\XmlLite.dll
0x00007FFEA9A20000 +90112 78040 10.0.10586.212 C:\WINDOWS\system32\wkscli.dll
0x00007FFEAC670000 +49152 42352 10.0.10586.0 C:\WINDOWS\system32\netutils.dll
0x00007FFEAB0B0000 +65536 43520 10.0.10586.63 C:\WINDOWS\SYSTEM32\usermgrcli.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\Wtsapi32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINSTA.dll
0x00007FFE99100000 +393216 370688 10.0.10586.672 C:\WINDOWS\System32\diagtrack_win.dll
0x00007FFEAA070000 +655360 640976 10.0.10586.633 C:\WINDOWS\System32\wer.dll
0x00007FFE99080000 +245760 224256 10.0.14913.1002 C:\WINDOWS\System32\AEPIC.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEA54F0000 +69632 49152 10.0.10586.0 C:\WINDOWS\System32\sfc_os.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 C:\WINDOWS\SYSTEM32\iertutil.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\System32\CRYPTBASE.DLL
0x00007FFE9BC40000 +815104 791552 10.0.10586.672 c:\windows\system32\WINHTTP.dll
0x00007FFEADF20000 +94208 81144 10.0.10586.212 C:\WINDOWS\system32\Netapi32.dll
0x00007FFE9BD10000 +389120 368128 10.0.10586.0 C:\WINDOWS\SYSTEM32\DSREG.DLL
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\SYSTEM32\SspiCli.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\SYSTEM32\DPAPI.DLL
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 c:\windows\system32\USERENV.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE984E0000 +159744 134144 10.0.10586.0 C:\Windows\System32\CourtesyEngine.dll
0x00007FFE982E0000 +1052672 1036288 10.0.10586.672 C:\WINDOWS\System32\windowsperformancerecordercontrol.dll
0x00007FFEAFD50000 +114688 101776 10.0.10586.0 C:\WINDOWS\system32\imagehlp.dll
0x00007FFE9C120000 +2596864 2587696 6.30.10586.589 C:\Windows\System32\msxml6.dll
0x00007FFE975C0000 +729088 697344 10.0.10586.589 C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
0x00007FFE97580000 +258048 233472 10.0.10586.0 C:\WINDOWS\System32\FlightSettings.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEA7CD0000 +229376 219040 10.0.10586.0 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9DFE0000 +90112 67072 10.0.10586.420 C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL
0x00007FFE9DFC0000 +106496 86016 10.0.10586.420 C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL
0x00007FFE97770000 +524288 496640 10.0.10586.494 c:\windows\system32\webio.dll
0x00007FFEACB30000 +376832 357216 10.0.10586.420 C:\WINDOWS\system32\mswsock.dll
0x00007FFE9E810000 +45056 33104 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINNSI.DLL
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 c:\windows\system32\DNSAPI.dll
0x00007FFE9AF10000 +40960 17408 10.0.10586.71 C:\Windows\System32\rasadhlp.dll
0x00007FFEAC7B0000 +499712 479232 10.0.10586.306 C:\WINDOWS\system32\schannel.DLL
0x00007FFEA76F0000 +81920 60928 10.0.10586.0 C:\WINDOWS\SYSTEM32\mskeyprotect.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\SYSTEM32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\SYSTEM32\NTASN1.dll
0x00007FFEA77A0000 +122880 111064 10.0.10586.420 C:\WINDOWS\system32\ncryptsslp.dll
0x00007FFE97550000 +192512 173056 10.0.10586.0 C:\WINDOWS\System32\cryptnet.dll
0x00007FFE9B250000 +348160 334736 10.0.10586.212 C:\WINDOWS\System32\policymanager.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 C:\WINDOWS\System32\msvcp110_win.dll
0x00007FFE963F0000 +724992 708608 10.0.10586.672 C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
0x00007FFEABD60000 +1048576 1040792 10.0.10586.672 C:\Windows\System32\twinapi.appcore.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAA260000 +266240 248832 10.0.10586.63 C:\Windows\System32\usermgrproxy.dll
0x00007FFE96380000 +307200 288768 10.0.10586.162 C:\Windows\System32\vaultcli.dll
0x00007FFE98D30000 +77824 60928 10.0.10586.0 C:\WINDOWS\System32\srumapi.dll
0x00007FFEB0660000 +4362240 4387680 10.0.10586.589 C:\WINDOWS\system32\SETUPAPI.dll
0x00007FFE9B040000 +77824 57344 10.0.10586.0 C:\WINDOWS\System32\DEVRTL.dll
svchost.exe
PID: 2012, Threads: 6, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 15724 K (Peak: 21208 K), CommitSize: 4200 K, PageFaults: 15803
TIME - Start 27.02.2017 19:07:53, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 5841272 (1520), Write: 118896 (39), Other: 14570 (1470)
CmdLine: C:\WINDOWS\system32\svchost.exe -k appmodel
Handles: 181
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 16 (Thread)
Type: 12, Cnt: 48 (Event)
Type: 15, Cnt: 7 (Semaphore)
Type: 17, Cnt: 4 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 2 (TpWorkerFactory)
Type: 29, Cnt: 3 (IoCompletion)
Type: 30, Cnt: 9 ()
Type: 31, Cnt: 10 (File)
Type: 36, Cnt: 5 (Section)
Type: 39, Cnt: 7 (Key)
Type: 40, Cnt: 10 (ALPC Port)
Type: 43, Cnt: 54 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\user32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFE9A6B0000 +2764800 2746368 10.0.10586.589 c:\windows\system32\windows.staterepository.dll
0x00007FFE9A3C0000 +606208 587776 10.0.10586.0 c:\windows\system32\StateRepository.Core.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE99770000 +528384 506880 10.0.10586.589 c:\windows\system32\tileobjserver.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9B1B0000 +598016 594976 10.0.10586.0 c:\windows\system32\msvcp110_win.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFE9A0F0000 +1798144 1728000 11.0.10586.713 c:\windows\system32\urlmon.dll
0x00007FFE992E0000 +3117056 3078144 10.0.10586.212 c:\windows\system32\ESENT.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFE9C510000 +3702784 3692040 11.0.10586.713 c:\windows\system32\iertutil.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAC9C0000 +126976 113184 10.0.10586.0 C:\WINDOWS\system32\USERENV.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\system32\bcrypt.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEAB9B0000 +77824 64624 10.0.10586.0 C:\WINDOWS\SYSTEM32\wtsapi32.dll
0x00007FFEACD90000 +352256 332656 10.0.10586.0 C:\WINDOWS\SYSTEM32\WINSTA.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\system32\SspiCli.dll
0x00007FFE96990000 +4796416 4775424 10.0.10586.494 C:\Windows\System32\ActXPrxy.dll
svchost.exe
PID: 1156, Threads: 15, Owner: NT-AUTORITÄT\SYSTEM
MEM - WrkSet: 9796 K (Peak: 10800 K), CommitSize: 4232 K, PageFaults: 3359
TIME - Start 27.02.2017 19:07:54, KernelTime: 00:00:00, UserTime: 00:00:00
IO - Read: 736201 (171), Write: 47467 (1), Other: 14058 (839)
CmdLine: C:\WINDOWS\system32\svchost.exe -k iissvcs
Handles: 186
Type: 3, Cnt: 2 (Directory)
Type: 5, Cnt: 1 (Token)
Type: 8, Cnt: 9 (Thread)
Type: 12, Cnt: 38 (Event)
Type: 13, Cnt: 2 (Mutant)
Type: 15, Cnt: 12 (Semaphore)
Type: 17, Cnt: 8 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 4 (TpWorkerFactory)
Type: 29, Cnt: 8 (IoCompletion)
Type: 30, Cnt: 12 ()
Type: 31, Cnt: 12 (File)
Type: 36, Cnt: 8 (Section)
Type: 39, Cnt: 7 (Key)
Type: 40, Cnt: 7 (ALPC Port)
Type: 43, Cnt: 52 (?)
Type: 47, Cnt: 1 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF7246D0000 +53248 43944 10.0.10586.0 C:\WINDOWS\system32\svchost.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAC400000 +999424 994760 10.0.10586.0 C:\WINDOWS\SYSTEM32\ucrtbase.dll
0x00007FFE9A5D0000 +606208 579072 10.0.10586.0 c:\windows\system32\inetsrv\iisw3adm.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFEAAB50000 +253952 240720 10.0.10586.0 C:\WINDOWS\SYSTEM32\logoncli.dll
0x00007FFEA84C0000 +221184 215896 10.0.10586.0 C:\WINDOWS\SYSTEM32\XmlLite.dll
0x00007FFEABBF0000 +696320 686976 10.0.10586.212 C:\WINDOWS\SYSTEM32\DNSAPI.dll
0x00007FFEAE5C0000 +32768 24312 10.0.10586.0 C:\WINDOWS\system32\NSI.dll
0x00007FFE9A460000 +315392 290304 10.0.10586.0 c:\windows\system32\inetsrv\iisutil.dll
0x00007FFEAC750000 +200704 186496 10.0.10586.0 C:\WINDOWS\SYSTEM32\ntmarta.dll
0x00007FFEACF40000 +184320 175120 10.0.10586.589 C:\WINDOWS\SYSTEM32\SspiCli.dll
0x00007FFEAD190000 +167936 159640 10.0.10586.713 C:\WINDOWS\SYSTEM32\bcrypt.dll
0x00007FFE99FF0000 +49152 29696 10.0.10586.0 c:\windows\system32\inetsrv\W3TP.dll
0x00007FFE9A010000 +520192 504320 10.0.10586.0 c:\windows\system32\inetsrv\nativerd.dll
0x00007FFE99EE0000 +45056 24064 10.0.10586.0 C:\WINDOWS\SYSTEM32\ktmw32.dll
0x00007FFEACE30000 +159744 146744 10.0.10586.0 C:\WINDOWS\SYSTEM32\ncrypt.dll
0x00007FFEACDF0000 +237568 239592 10.0.10586.0 C:\WINDOWS\SYSTEM32\NTASN1.dll
0x000002634B3F0000 +241664 231424 10.0.10586.0 c:\windows\system32\inetsrv\IISRES.DLL
0x00007FFEACBE0000 +94208 81176 10.0.10586.0 C:\WINDOWS\SYSTEM32\CRYPTSP.dll
0x00007FFEAC870000 +212992 204048 10.0.10586.306 C:\WINDOWS\system32\rsaenh.dll
0x00007FFEACD00000 +45056 31072 10.0.10586.0 C:\WINDOWS\system32\CRYPTBASE.dll
0x00007FFEA9770000 +49152 28160 10.0.10586.0 C:\WINDOWS\system32\secur32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEB0490000 +684032 662704 2001.12.10941.16384 C:\WINDOWS\system32\clbcatq.dll
0x00007FFE99AF0000 +253952 233472 10.0.10586.0 C:\WINDOWS\system32\mlang.dll
0x00007FFEADA90000 +1867776 1848072 10.0.10586.672 C:\WINDOWS\system32\CRYPT32.dll
0x00007FFEAD2D0000 +65536 60440 10.0.10586.0 C:\WINDOWS\system32\MSASN1.dll
0x00007FFEAC8B0000 +40960 15872 10.0.10586.0 C:\WINDOWS\system32\DPAPI.DLL
0x00007FFE98B50000 +638976 619520 10.0.10586.589 C:\WINDOWS\SYSTEM32\efswrt.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\SHCORE.dll
0x00007FFEAA340000 +1269760 1270064 10.0.10586.589 C:\WINDOWS\SYSTEM32\wintypes.dll
0x00007FFE98B00000 +327680 305152 10.0.10586.672 C:\WINDOWS\SYSTEM32\edputil.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\shlwapi.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFE98D80000 +53248 30720 10.0.10586.0 C:\WINDOWS\SYSTEM32\HTTPAPI.dll
egui.exe
PID: 764, Threads: 8, Owner: Dragonfly-PC\Dragonfly
MEM - WrkSet: 38756 K (Peak: 40044 K), CommitSize: 21228 K, PageFaults: 14853
TIME - Start 27.02.2017 19:09:57, KernelTime: 00:00:00, UserTime: 00:00:02
IO - Read: 6663134 (133), Write: 0 (0), Other: 3022 (992)
CmdLine: "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
## Type: 30 -> DuplicateHandle error: 0x5
Handles: 245
Type: 3, Cnt: 2 (Directory)
Type: 8, Cnt: 10 (Thread)
Type: 12, Cnt: 56 (Event)
Type: 13, Cnt: 6 (Mutant)
Type: 15, Cnt: 12 (Semaphore)
Type: 16, Cnt: 1 (Timer)
Type: 17, Cnt: 4 (IRTimer)
Type: 20, Cnt: 2 (WindowStation)
Type: 21, Cnt: 1 (Desktop)
Type: 24, Cnt: 2 (TpWorkerFactory)
Type: 29, Cnt: 2 (IoCompletion)
Type: 30, Cnt: 6 ()
Type: 31, Cnt: 7 (File)
Type: 36, Cnt: 8 (Section)
Type: 39, Cnt: 17 (Key)
Type: 40, Cnt: 9 (ALPC Port)
Type: 43, Cnt: 100 (?)
Modules: (BaseAddr +BaseSize FileSize FileVersion Path)
0x00007FF754160000 +7127040 7091840 10.0.386.0 C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
0x00007FFEB0C40000 +1839104 1819208 10.0.10586.672 C:\WINDOWS\SYSTEM32\ntdll.dll
0x00007FFEAFF00000 +708608 705576 10.0.10586.589 C:\WINDOWS\system32\KERNEL32.DLL
0x00007FFEADD30000 +1998848 1997832 10.0.10586.589 C:\WINDOWS\system32\KERNELBASE.dll
0x00007FFEB0330000 +1400832 1399216 10.0.10586.713 C:\WINDOWS\system32\USER32.dll
0x00007FFEAE0A0000 +1597440 1594416 10.0.10586.753 C:\WINDOWS\system32\GDI32.dll
0x00007FFEAFD70000 +438272 430312 10.0.10586.420 C:\WINDOWS\system32\WS2_32.dll
0x00007FFEB0A90000 +372736 371360 10.0.10586.0 C:\WINDOWS\system32\sechost.dll
0x00007FFEAFDE0000 +1163264 1161120 10.0.10586.306 C:\WINDOWS\system32\RPCRT4.dll
0x00007FFEAFC30000 +1093632 1062912 10.0.10586.672 C:\WINDOWS\system32\COMDLG32.dll
0x00007FFEAE630000 +643072 633760 7.0.10586.0 C:\WINDOWS\system32\msvcrt.dll
0x00007FFEAE230000 +2609152 2607336 10.0.10586.672 C:\WINDOWS\system32\combase.dll
0x00007FFEADC60000 +434176 431296 10.0.10586.589 C:\WINDOWS\system32\bcryptPrimitives.dll
0x00007FFEAD380000 +741376 725776 10.0.10586.672 C:\WINDOWS\system32\shcore.dll
0x00007FFEAE040000 +335872 332104 10.0.10586.0 C:\WINDOWS\system32\SHLWAPI.dll
0x00007FFEAE6D0000 +22396928 22561256 10.0.10586.672 C:\WINDOWS\system32\SHELL32.dll
0x00007FFEADFF0000 +274432 264488 10.0.10586.0 C:\WINDOWS\system32\cfgmgr32.dll
0x00007FFEAD440000 +6574080 6605544 10.0.10586.672 C:\WINDOWS\system32\windows.storage.dll
0x00007FFEAE4B0000 +684032 671472 10.0.10586.63 C:\WINDOWS\system32\advapi32.dll
0x00007FFE9E480000 +2572288 2555736 6.10.10586.672 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.672_none_a2d6b3cea53ff843\COMCTL32.dll
0x00007FFEAD2E0000 +61440 45016 10.0.10586.0 C:\WINDOWS\system32\kernel.appcore.dll
0x00007FFEAD260000 +307200 294472 10.0.10586.0 C:\WINDOWS\system32\powrprof.dll
0x00007FFEAD2B0000 +81920 68752 10.0.10586.0 C:\WINDOWS\system32\profapi.dll
0x00007FFEAD2F0000 +548864 526336 10.0.10586.162 C:\WINDOWS\system32\FirewallAPI.dll
0x00007FFEADF20000 +94208 81144 10.0.10586.212 C:\WINDOWS\system32\NETAPI32.dll
0x00007FFEB0AF0000 +1323008 1322248 10.0.10586.672 C:\WINDOWS\system32\ole32.dll
0x00007FFEB0540000 +811008 799568 10.0.10586.589 C:\WINDOWS\system32\OLEAUT32.dll
0x00007FFE97800000 +49152 27136 10.0.10586.0 C:\WINDOWS\SYSTEM32\DAVHLPR.DLL
0x00007FFE9A0F0000 +1798144 1728000 11.0.10586.713 C:\WINDOWS\SYSTEM32\urlmon.dll
0x00007FFE95E50000 +147456 126976 10.0.10586.0 C:\WINDOWS\SYSTEM32\oledlg.dll
0x00007FFE95E80000 +4116480 4096128 10.0.1.0 C:\Program Files\ESET\ESET NOD32 Antivirus\sciter-x.dll
|
| | #15 |
![]() ![]() | eset sysinspektor und gmer finden rootkits, diverse prozesseCode:
ATTFilter [00:53:53.174] ESET Log Collector v2.3.1.0 (Aug 23 2016)
[00:53:53.174] Copyright (c) 1992-2016 ESET, spol. s r.o. All rights reserved.
[00:53:53.174]
[00:53:53.174] Detected product type: eav
[00:54:02.674] ==============================
[00:54:02.674] ESET logs collection mode: Filtered binary
[00:54:02.674] Number of days to collect target files and log records for: 30
[00:54:02.674] Targets: [X] Proc, [X] EvLogApp, [X] EvLogSys, [X] SetupAPI, [X] SysIn, [X] NetCnf, [X] WFPFil, [X] InstLog, [X] ProdCnf, [X] DirList, [X] Drivers, [X] QInfo, [ ] QFiles, [X] Warn, [X] Threat, [X] OnDem, [X] Hips, [X] Web, [X] Dev, [X] Diag
[00:54:02.674] Saving metadata to C:\Users\DRAGON~1\AppData\Local\Temp\met4FFE.tmp
[00:54:02.674] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met4FFE.tmp -> metadata.txt
[00:54:02.690] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met500F.tmp -> info.xml
[00:54:02.690] === Proc ===
[00:54:02.690] Exporting...
[00:54:06.003] OK
[00:54:06.003] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met5010.tmp -> Windows/Processes.txt
[00:54:06.003] === EvLogApp ===
[00:54:06.003] Exporting...
[00:54:08.690] OK
[00:54:08.690] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met5D01.tmp -> Windows/Logs/Application.xml
[00:54:08.690] === EvLogSys ===
[00:54:08.690] Exporting...
[00:54:09.448] OK
[00:54:09.448] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met6782.tmp -> Windows/Logs/System.xml
[00:54:09.448] === SetupAPI ===
[00:54:09.448] Adding file: C:\WINDOWS\Inf\setupapi.dev.log -> Windows/Logs/SetupAPI/setupapi.dev.log
[00:54:09.448] OK
[00:54:09.448] === SysIn ===
[00:54:09.604] SysInspector log is being generated...
[00:54:09.604] "C:\Program Files\ESET\ESET NOD32 Antivirus\SysInspector.exe" /silent /gen="C:\Users\DRAGON~1\AppData\Local\Temp\met6B0D.tmp.xml"
[00:55:59.968] SysInspector log created.
[00:55:59.968] OK
[00:55:59.968] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met6B0D.tmp.xml -> Config/SysInspector.xml
[00:55:59.968] === NetCnf ===
[00:55:59.968] Exporting...
[00:56:00.077] Saving text data to C:\Users\DRAGON~1\AppData\Local\Temp\met1AA2.tmp
[00:56:00.093] OK
[00:56:00.093] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met1AA2.tmp -> Config/network.txt
[00:56:00.093] === WFPFil ===
[00:56:00.093] Exporting...
[00:56:03.437] OK
[00:56:03.437] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met1AB3.tmp -> Config/WFPFilters.xml
[00:56:03.437] === InstLog ===
[00:56:03.437] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\eset\liveinstaller_20170210234217.log -> ESET/Installer/liveinstaller_20170210234217.log
[00:56:03.452] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\eset\liveinstaller_20170210234217_callback.log -> ESET/Installer/liveinstaller_20170210234217_callback.log
[00:56:03.484] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts\bootstrapper.log -> ESET/Installer/bts/bootstrapper.log
[00:56:03.515] === ProdCnf ===
[00:56:03.515] Exporting...
[00:56:03.702] Saving product configuration to file C:\Users\DRAGON~1\AppData\Local\Temp\met28CD.tmp
[00:56:03.702] OK
[00:56:03.702] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met28CD.tmp -> ESET/Config/product_conf.xml
[00:56:03.702] === DirList ===
[00:56:03.702] Exporting...
[00:56:03.718] OK
[00:56:03.718] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met28CE.tmp -> ESET/Config/data_dir_list.txt
[00:56:03.718] Exporting...
[00:56:03.734] OK
[00:56:03.734] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met28DF.tmp -> ESET/Config/install_dir_list.txt
[00:56:03.749] === Drivers ===
[00:56:03.749] Exporting...
[00:56:03.749] OK
[00:56:03.749] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met28FF.tmp -> ESET/Config/drivers.txt
[00:56:03.749] === QInfo ===
[00:56:03.749] Exporting...
[00:56:03.999] OK
[00:56:03.999] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2900.tmp -> ESET/Quarantine/quar_info.txt
[00:56:03.999] === Warn ===
[00:56:03.999] Exporting ESET log (warnlog.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met29FB.tmp
[00:56:04.031] OK
[00:56:04.031] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met29FB.tmp -> ESET/Logs/Common/warnlog.dat
[00:56:04.031] === Threat ===
[00:56:04.031] Exporting ESET log (virlog.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2A1C.tmp
[00:56:04.046] OK
[00:56:04.046] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2A1C.tmp -> ESET/Logs/Common/virlog.dat
[00:56:04.046] === OnDem ===
[00:56:04.046] Exporting ESET log (ndl1230.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2A2C.tmp
[00:56:04.109] OK
[00:56:04.109] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2A2C.tmp -> ESET/Logs/Common/eScan/ndl1230.dat
[00:56:04.109] Exporting ESET log (ndl14042.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2A6C.tmp
[00:56:04.156] OK
[00:56:04.156] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2A6C.tmp -> ESET/Logs/Common/eScan/ndl14042.dat
[00:56:04.156] Exporting ESET log (ndl14862.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2A9C.tmp
[00:56:04.218] OK
[00:56:04.218] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2A9C.tmp -> ESET/Logs/Common/eScan/ndl14862.dat
[00:56:04.218] Exporting ESET log (ndl21962.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2ADB.tmp
[00:56:04.281] OK
[00:56:04.281] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2ADB.tmp -> ESET/Logs/Common/eScan/ndl21962.dat
[00:56:04.281] Exporting ESET log (ndl4669.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2B1B.tmp
[00:56:04.343] OK
[00:56:04.343] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2B1B.tmp -> ESET/Logs/Common/eScan/ndl4669.dat
[00:56:04.343] Exporting ESET log (ndl6609.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2B5A.tmp
[00:56:04.390] OK
[00:56:04.390] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2B5A.tmp -> ESET/Logs/Common/eScan/ndl6609.dat
[00:56:04.390] Exporting ESET log (ndl8288.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2B8A.tmp
[00:56:04.468] OK
[00:56:04.468] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2B8A.tmp -> ESET/Logs/Common/eScan/ndl8288.dat
[00:56:04.468] Exporting ESET log (ndl9145.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2BD9.tmp
[00:56:04.531] OK
[00:56:04.531] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2BD9.tmp -> ESET/Logs/Common/eScan/ndl9145.dat
[00:56:04.531] === Hips ===
[00:56:04.531] Exporting ESET log (hipslog.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2C19.tmp
[00:56:04.546] OK
[00:56:04.546] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2C19.tmp -> ESET/Logs/Common/hipslog.dat
[00:56:04.546] === Web ===
[00:56:04.546] Exporting ESET log (urllog.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2C29.tmp
[00:56:04.546] OK
[00:56:04.546] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2C29.tmp -> ESET/Logs/Net/urllog.dat
[00:56:04.546] === Dev ===
[00:56:04.546] Exporting ESET log (devctrllog.dat) as filtered binary to file C:\Users\DRAGON~1\AppData\Local\Temp\met2C2A.tmp
[00:56:04.562] OK
[00:56:04.562] Adding file: C:\Users\DRAGON~1\AppData\Local\Temp\met2C2A.tmp -> ESET/Logs/Common/devctrllog.dat
[00:56:04.562] === Diag ===
[00:56:04.562] ===
[00:56:04.671] Saving text data to C:\Users\DRAGON~1\AppData\Local\Temp\met2CA8.tmp
Code:
ATTFilter xó›Ï8 Ô ÀU‘ÒgÇ U‘ÒÀU‘Ò ÜÏ‹c¸ $ sc4Ò <?xml version="1.0" encoding="utf-8"?>
<SCANSTATISTICS>
<NODE NAME="PATHS" VALUE="QQByAGIAZQBpAHQAcwBzAHAAZQBpAGMAaABlAHIAfABDADoAXABCAG8AbwB0AHMAZQBrAHQAbwByAHwAQwA6AFwAAAA=" TYPE="BINARY" />
<NODE NAME="TASKID" VALUE="FFFFFFFF" TYPE="DWORD" />
<NODE NAME="TASKTYPE" VALUE="6" TYPE="DWORD" />
<NODE NAME="SCANNERID" VALUE="1010100" TYPE="DWORD" />
<NODE NAME="USERNAME" VALUE="RAByAGEAZwBvAG4AZgBsAHkALQBQAEMAXABEAHIAYQBnAG8AbgBmAGwAeQAAAA==" TYPE="BINARY" />
<NODE NAME="TOTAL" VALUE="24B" TYPE="DWORD" />
<NODE NAME="INFECTED" VALUE="0" TYPE="DWORD" />
<NODE NAME="CLEANED" VALUE="0" TYPE="DWORD" />
<NODE NAME="STATUS" VALUE="1" TYPE="DWORD" />
<NODE NAME="STARTTIME" VALUE="58AD7D45" TYPE="ULONGLONG" />
<NODE NAME="ENDTIME" VALUE="58AD7D48" TYPE="ULONGLONG" />
</SCANSTATISTICS>
ÜÏ‹cº $ #,c4Ò Š 'N D A r b e i t s s p e i c h e r | C : \ B o o t s e k t o r | C : \ 'N " 1 4 9 7 7 ( 2 0 1 7 0 2 2 2 ) 'F E}*X E ÜÏ‹c² $ ÃÒy4Ò ‚ ü:F *E íE ìE d ŠE ì, ‰E êE € ÀE ¿E ÐE ºE ¾N C : ÃE E A ÜÏ‹cx $ ô„6Ò H 'E 'E 'E 'E 'E K 'F E}*X 'F H}*X E
Code:
ATTFilter xó›Ï8 % ãY >ŒU‘Ò QU‘Ò>ŒU‘Ò% ÜÏ‹c÷ $ š7ô ÷ƒÒ <?xml version="1.0" encoding="utf-8"?>
<SCANSTATISTICS>
<NODE NAME="PATHS" VALUE="QwA6AFwAAAA=" TYPE="BINARY" />
<NODE NAME="TASKID" VALUE="FFFFFFFF" TYPE="DWORD" />
<NODE NAME="TASKTYPE" VALUE="9" TYPE="DWORD" />
<NODE NAME="SCANNERID" VALUE="1010107" TYPE="DWORD" />
<NODE NAME="TOTAL" VALUE="5AD09" TYPE="DWORD" />
<NODE NAME="INFECTED" VALUE="0" TYPE="DWORD" />
<NODE NAME="CLEANED" VALUE="0" TYPE="DWORD" />
<NODE NAME="STATUS" VALUE="6" TYPE="DWORD" />
<NODE NAME="STARTTIME" VALUE="589E5060" TYPE="ULONGLONG" />
<NODE NAME="ENDTIME" VALUE="589E6363" TYPE="ULONGLONG" />
</SCANSTATISTICS>
ÜÏ‹c~ $ ökõ ÷ƒÒ N 'N C : \ 'N " 1 4 9 1 8 ( 2 0 1 7 0 2 1 0 ) 'F `PžX E ÜÏ‹cô $ £$á.øƒÒ À íE ìE d ü:F E «F ŠE ' A Ì A Ì ‰E êE € ÀE ¿E ÐE ºE ¾N ( C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ A p p D a t a \ L o c a l \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r p 4 z q 6 n j . d e f a u l t \ c a c h e 2 \ e n t r i e s \ A 6 C 4 0 7 A 5 7 4 1 5 4 0 2 C A 8 9 1 A F D 2 9 D 1 1 F B 8 B 9 7 8 C 4 F 5 E ÃE E A Z A f A f hE A 4þÿÿ A 4þÿÿ‰E ÐE ºE YN
# c w s E ’ ŠE ' íE ìE d ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N f i l e . s w f A Îýÿÿ A šÿÿÿ E ÜÏ‹cä $ ¦ 4nøƒÒ n íE ìE ü:F ž: E 0 ÂE ÁE «F ã9 A z A z ‰E êE € ÀE ¿E ÐE ºE ¾N Î C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ D o c u m e n t s \ E i g e n e B i l d e r \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A †þÿÿ A †þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F a E «F a ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A æýÿÿ A `ÿÿÿ E ÜÏ‹cÚ $ ƒ,ç„øƒÒ d íE ìE ü:F š8 E 0 ÂE ÁE «F Ñ7 A p A p ‰E êE € ÀE ¿E ÐE ºE ¾N Ä C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ D o c u m e n t s \ P r o j e c t s \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A þÿÿ A þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A ðýÿÿ A `ÿÿÿ E ÜÏ‹cê $ ôY•–øƒÒ t íE ìE ü:F ‡8 E 0 ÂE ÁE «F Á7 A € A € ‰E êE € ÀE ¿E ÐE ºE ¾N Ô C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ D o c u m e n t s \ P r o j e c t s - K o p i e \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A €þÿÿ A €þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A àýÿÿ A `ÿÿÿ E ÜÏ‹cî $ æªøƒÒ x íE ìE ü:F o6 E 0 ÂE ÁE «F º5 A „ A „ ‰E êE € ÀE ¿E ÐE ºE ¾N Ø C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ E i g e n e D a t e i e n \ E i g e n e B i l d e r \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A |þÿÿ A |þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A Üýÿÿ A `ÿÿÿ E ÜÏ‹cä $ "¡¿øƒÒ n íE ìE ü:F !7 E 0 ÂE ÁE «F a6 A z A z ‰E êE € ÀE ¿E ÐE ºE ¾N Î C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ E i g e n e D a t e i e n \ P r o j e c t s \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A †þÿÿ A †þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A æýÿÿ A `ÿÿÿ E ÜÏ‹cô $ 0TŽÑøƒÒ ~ íE ìE ü:F ˜6 E 0 ÂE ÁE «F â5 A Š A Š ‰E êE € ÀE ¿E ÐE ºE ¾N Þ C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ E i g e n e D a t e i e n \ P r o j e c t s - K o p i e \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A vþÿÿ A vþÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A Öýÿÿ A `ÿÿÿ E ÜÏ‹c $ ñ¤ûøƒÒ Î íE ìE d ü:F E «F ŠE ' A Ú A Ú ‰E êE € ÀE ¿E ÐE ºE ¾N 6 C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ L o k a l e E i n s t e l l u n g e n \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r p 4 z q 6 n j . d e f a u l t \ c a c h e 2 \ e n t r i e s \ A 6 C 4 0 7 A 5 7 4 1 5 4 0 2 C A 8 9 1 A F D 2 9 D 1 1 F B 8 B 9 7 8 C 4 F 5 E ÃE E A Z A f A f hE A &þÿÿ A &þÿÿ‰E ÐE ºE YN
# c w s E ’ ŠE ' íE ìE d ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N f i l e . s w f A Àýÿÿ A šÿÿÿ E ÜÏ‹cÆ $
V!ùƒÒ
P íE ìE ü:F Ô8 E 0 ÂE ÁE «F 8 A \ A \ ‰E êE € ÀE ¿E ÐE ºE ¾N ° C : \ D o c u m e n t s a n d S e t t i n g s \ D r a g o n f l y \ P i c t u r e s \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A ¤þÿÿ A ¤þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A þÿÿ A `ÿÿÿ E ÜÏ‹cþ $ .]ŠLùƒÒ Ê íE ìE d ü:F E «F ŠE ' A Ö A Ö ‰E êE € ÀE ¿E ÐE ºE ¾N 2 C : \ D o k u m e n t e u n d E i n s t e l l u n g e n \ D r a g o n f l y \ A p p D a t a \ L o c a l \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r p 4 z q 6 n j . d e f a u l t \ c a c h e 2 \ e n t r i e s \ A 6 C 4 0 7 A 5 7 4 1 5 4 0 2 C A 8 9 1 A F D 2 9 D 1 1 F B 8 B 9 7 8 C 4 F 5 E ÃE E A Z A f A f hE A *þÿÿ A *þÿÿ‰E ÐE ºE YN
# c w s E ’ ŠE ' íE ìE d ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N f i l e . s w f A Äýÿÿ A šÿÿÿ E ÜÏ‹cî $ ¶¡o€ùƒÒ x íE ìE ü:F ä7 E 0 ÂE ÁE «F 7 A „ A „ ‰E êE € ÀE ¿E ÐE ºE ¾N Ø C : \ D o k u m e n t e u n d E i n s t e l l u n g e n \ D r a g o n f l y \ D o c u m e n t s \ E i g e n e B i l d e r \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A |þÿÿ A |þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A Üýÿÿ A `ÿÿÿ E ÜÏ‹cä $
ju–ùƒÒ
n íE ìE ü:F ñ7 E 0 ÂE ÁE «F 87 A z A z ‰E êE € ÀE ¿E ÐE ºE ¾N Î C : \ D o k u m e n t e u n d E i n s t e l l u n g e n \ D r a g o n f l y \ D o c u m e n t s \ P r o j e c t s \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A †þÿÿ A †þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A æýÿÿ A `ÿÿÿ E ÜÏ‹cô $ ±Ä$§ùƒÒ ~ íE ìE ü:F ¬8 E 0 ÂE ÁE «F è7 A Š A Š ‰E êE € ÀE ¿E ÐE ºE ¾N Þ C : \ D o k u m e n t e u n d E i n s t e l l u n g e n \ D r a g o n f l y \ D o c u m e n t s \ P r o j e c t s - K o p i e \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A vþÿÿ A vþÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A Öýÿÿ A `ÿÿÿ E ÜÏ‹cø $
?»ùƒÒ ‚ íE ìE ü:F •8 E 0 ÂE ÁE «F ×7 A Ž A Ž ‰E êE € ÀE ¿E ÐE ºE ¾N â C : \ D o k u m e n t e u n d E i n s t e l l u n g e n \ D r a g o n f l y \ E i g e n e D a t e i e n \ E i g e n e B i l d e r \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A rþÿÿ A rþÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A Òýÿÿ A `ÿÿÿ E ÜÏ‹cî $ «°yÐùƒÒ x íE ìE ü:F õ8 E 0 ÂE ÁE «F *8 A „ A „ ‰E êE € ÀE ¿E ÐE ºE ¾N Ø C : \ D o k u m e n t e u n d E i n s t e l l u n g e n \ D r a g o n f l y \ E i g e n e D a t e i e n \ P r o j e c t s \ B i l d e r \ T e a m S p e a k 3 - C l i e n t - w i n 3 2 - 3 . 0 . 9 . 2 . e x e ÃE E A ” A A hE A |þÿÿ A |þÿÿ‰E ÐE ºE YN D # n s i s : v e r = 8 ; m o d e = m e r g e ; s f x = 1 0 4 9 6 0 E š íE ìE ü:F E «F ‰E ÁE ºE ÀE ¿E ¾N " p a c k a g e _ i n s t . e x e A Üýÿÿ A `ÿÿÿ E ÜÏ‹cþ $ j¼¼áùƒÒ ˆ íE ìE ü:F ª7 E 0 ÂE ÁE «F ß6 A ” A ” ‰
Code:
ATTFilter xó›Ï8 À( î= U‘ÒC U‘Òî= U‘Ò ÜÏ‹c $ ܺ‡¾éÒ _ 'N " 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F ; ÂE @ ÁE «F V ŸF üZ²X B . ÆYuw8mÓO1 Ôñu¿ÇžB ö,4ÂÆ¬µ=CzÂc–øTƒŽ_„ E á MN J @ A p p l i c U n w n t . W i n 3 2 / D o w n l o a d S p o n s o r . C OC ‰E ÄN Z C : \ P r o g r a m F i l e s \ M o z i l l a F i r e f o x \ f i r e f o x . e x e êE € ÀE ¿E ºE ¾N z h t t p : / / w w w . c h i p . d e / d o w n l o a d e r ? l a s t c h a n g e = 2 9 0 9 2 0 0 9 1 7 1 5 & p i d = c h i p d e r e d e s i g n & c i d = 5 4 3 9 7 4 9 6 & e u i d = f 0 9 0 d 9 b 9 b 0 0 5 0 8 4 c 2 f 4 1 3 8 6 e & s o u r c e = B L U B 2 & b r o w s e r = f i r e f o x & r e f = & t i d = 3 9 0 0 9 & t n a m e = A n t i - S p y w a r e & v = o c t 2 0 1 5 ÃE E A ÜÏ‹c# $ íÄÅÃéÒ ó 'N " 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F <" ÂE @ ÁE ¾N C : \ U s e r s \ D r a g o n f l y \ A p p D a t a \ L o c a l \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r p 4 z q 6 n j . d e f a u l t \ c a c h e 2 \ e n t r i e s \ D 4 E A 9 D F 9 8 6 6 8 6 7 1 A 7 E 1 4 3 D 7 B 4 E D 9 1 B 0 E C F 8 1 4 A 8 D «F ª ŸF üZ²X B . ÆYuw8mÓO1 Ôñu¿ÇžB pöŒ%¸À_ÊõYv¯”J⚌õ E á MN J @ A p p l i c U n w n t . W i n 3 2 / D o w n l o a d S p o n s o r . C OC ‰E ÄN Z C : \ P r o g r a m F i l e s \ M o z i l l a F i r e f o x \ f i r e f o x . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹c# $ x.,×éÒ ó 'N " 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F I ÂE @ ÁE ¾N C : \ U s e r s \ D r a g o n f l y \ A p p D a t a \ L o c a l \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r p 4 z q 6 n j . d e f a u l t \ c a c h e 2 \ e n t r i e s \ D 4 E A 9 D F 9 8 6 6 8 6 7 1 A 7 E 1 4 3 D 7 B 4 E D 9 1 B 0 E C F 8 1 4 A 8 D «F í ŸF üZ²X B . ÆYuw8mÓO1 Ôñu¿ÇžB pöŒ%¸À_ÊõYv¯”J⚌õ E ¡ MN J @ A p p l i c U n w n t . W i n 3 2 / D o w n l o a d S p o n s o r . C OC ‰E ÄN Z C : \ P r o g r a m F i l e s \ M o z i l l a F i r e f o x \ f i r e f o x . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹c $ u²äØéÒ _ 'N " 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F w
ÂE @ ÁE «F ‘ ŸF 4[²X B . ÆYuw8mÓO1 Ôñu¿ÇžB Ä< ,=@mR³„âçße E á MN J @ A p p l i c U n w n t . W i n 3 2 / D o w n l o a d S p o n s o r . C OC ‰E ÄN Z C : \ P r o g r a m F i l e s \ M o z i l l a F i r e f o x \ f i r e f o x . e x e êE € ÀE ¿E ºE ¾N z h t t p : / / w w w . c h i p . d e / d o w n l o a d e r ? l a s t c h a n g e = 2 9 0 9 2 0 0 9 1 7 1 5 & p i d = c h i p d e r e d e s i g n & c i d = 5 4 3 9 7 4 9 6 & e u i d = f 0 9 0 d 9 b 9 b 0 0 5 0 8 4 c 2 f 4 1 3 8 6 e & s o u r c e = B L U B 2 & b r o w s e r = f i r e f o x & r e f = & t i d = 3 9 0 0 9 & t n a m e = A n t i - S p y w a r e & v = o c t 2 0 1 5 ÃE E A ÜÏ‹c $ Ç¢ÄÙéÒ × 'N " 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F Ñ ÂE @ ÁE ¾N C : \ U s e r s \ D r a g o n f l y \ A p p D a t a \ L o c a l \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r p 4 z q 6 n j . d e f a u l t \ c a c h e 2 \ e n t r i e s \ D 4 E A 9 D F 9 8 6 6 8 6 7 1 A 7 E 1 4 3 D 7 B 4 E D 9 1 B 0 E C F 8 1 4 A 8 D «F
ŸF üZ²X B . ÆYuw8mÓO1 Ôñu¿Ç E ! MN J @ A p p l i c U n w n t . W i n 3 2 / D o w n l o a d S p o n s o r . C OC ‰E ÄN Z C : \ P r o g r a m F i l e s \ M o z i l l a F i r e f o x \ f i r e f o x . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹c $ ^bâéÒ _ 'N " 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F Å* ÂE @ ÁE «F ï ŸF <[²X B . ÆYuw8mÓO1 Ôñu¿ÇžB <;€vå¿ÿ‘u'×þ³ÇK?Ÿ* E á MN J @ A p p l i c U n w n t . W i n 3 2 / D o w n l o a d S p o n s o r . C OC ‰E ÄN Z C : \ P r o g r a m F i l e s \ M o z i l l a F i r e f o x \ f i r e f o x . e x e êE € ÀE ¿E ºE ¾N z h t t p : / / w w w . c h i p . d e / d o w n l o a d e r ? l a s t c h a n g e = 2 9 0 9 2 0 0 9 1 7 1 5 & p i d = c h i p d e r e d e s i g n & c i d = 5 4 3 9 7 4 9 6 & e u i d = f 0 9 0 d 9 b 9 b 0 0 5 0 8 4 c 2 f 4 1 3 8 6 e & s o u r c e = B L U B 2 & b r o w s e r = f i r e f o x & r e f = & t i d = 3 9 0 0 9 & t n a m e = A n t i - S p y w a r e & v = o c t 2 0 1 5 ÃE E A ÜÏ‹c+ $ @¥ýãéÒ û 'N " 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE ü:F }
œE ÂE F ÁE ¾N C : \ U s e r s \ D r a g o n f l y \ A p p D a t a \ L o c a l \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r p 4 z q 6 n j . d e f a u l t \ c a c h e 2 \ e n t r i e s \ D 4 E A 9 D F 9 8 6 6 8 6 7 1 A 7 E 1 4 3 D 7 B 4 E D 9 1 B 0 E C F 8 1 4 A 8 D «F - ŸF üZ²X B . ÆYuw8mÓO1 Ôñu¿ÇžB ,iÚ^쌨$ ÅÊaÍÚýCi E õ MN J @ A p p l i c U n w n t . W i n 3 2 / D o w n l o a d S p o n s o r . C OC ‰E ÄN Z C : \ P r o g r a m F i l e s \ M o z i l l a F i r e f o x \ f i r e f o x . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹c… $ `°pÆnÒ U 'N " 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F _ ŒE ŠE å. ÂE ÁE ¾N € E : \ $ R E C Y C L E . B I N \ $ R F K 5 W O Y \ S o f t o n i c D o w n l o a d e r _ f o r _ h e r o - e d i t o r . e x e «F ŸF ÙýO B ì[m΂ïû‡°¹VFÝí땞B ðͬæcQÀ¸n8ЈáÍJí¥’ E à MN L @ A p p l i c U n w n t . W i n 3 2 / S o f t o n i c D o w n l o a d e r OC ‰E ÄN 0 C : \ W i n d o w s \ e x p l o r e r . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹cu $ “âStoÒ E 'N " 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F … ŒE ŠE å. ÂE ÁE ¾N z E : \ $ R E C Y C L E . B I N \ $ R F K 5 W O Y \ P r o g r a m m e x e s \ P D F C o n v e r t e r S e t u p . e x e «F v ŸF Ñ›N B ì[m΂ïû‡°¹VFÝí땞B Í‘uøleeo£O[:ëܹ’‘”ó E à MN B @ A p p l i c U n w n t . W i n 3 2 / I n s t a l l C o r e . D OC ‰E ÄN 0 C : \ W i n d o w s \ e x p l o r e r . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹cu $ §|JuoÒ E 'N " 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F Z ŒE ŠE å. ÂE ÁE ¾N z E : \ $ R E C Y C L E . B I N \ $ R F K 5 W O Y \ P r o g r a m m e x e s \ P D F C o n v e r t e r S e t u p . e x e «F X ŸF Ñ›N B ì[m΂ïû‡°¹VFÝí땞B Í‘uøleeo£O[:ëܹ’‘”ó E MN B @ A p p l i c U n w n t . W i n 3 2 / I n s t a l l C o r e . D OC ‰E ÄN 0 C : \ W i n d o w s \ e x p l o r e r . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹cu $
¢§FvoÒ
E 'N " 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F _ ŒE ŠE å. ÂE ÁE ¾N z E : \ $ R E C Y C L E . B I N \ $ R F K 5 W O Y \ P r o g r a m m e x e s \ P D F C o n v e r t e r S e t u p . e x e «F \ ŸF Ñ›N B ì[m΂ïû‡°¹VFÝí땞B Í‘uøleeo£O[:ëܹ’‘”ó E MN B @ A p p l i c U n w n t . W i n 3 2 / I n s t a l l C o r e . D OC ‰E ÄN 0 C : \ W i n d o w s \ e x p l o r e r . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹cu $ Y™7woÒ E 'N " 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F a ŒE ŠE å. ÂE ÁE ¾N z E : \ $ R E C Y C L E . B I N \ $ R F K 5 W O Y \ P r o g r a m m e x e s \ P D F C o n v e r t e r S e t u p . e x e «F ^ ŸF Ñ›N B ì[m΂ïû‡°¹VFÝí땞B Í‘uøleeo£O[:ëܹ’‘”ó E MN B @ A p p l i c U n w n t . W i n 3 2 / I n s t a l l C o r e . D OC ‰E ÄN 0 C : \ W i n d o w s \ e x p l o r e r . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹c… $ x€ŸyoÒ U 'N " 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F ŒE ŠE å. ÂE ÁE ¾N € E : \ $ R E C Y C L E . B I N \ $ R F K 5 W O Y \ S o f t o n i c D o w n l o a d e r _ f o r _ h e r o - e d i t o r . e x e «F ŸF ÙýO B ì[m΂ïû‡°¹VFÝí땞B ðͬæcQÀ¸n8ЈáÍJí¥’ E MN L @ A p p l i c U n w n t . W i n 3 2 / S o f t o n i c D o w n l o a d e r OC ‰E ÄN 0 C : \ W i n d o w s \ e x p l o r e r . e x e È2E êE € ÀE ¿E ºE ÃE E A ÜÏ‹c… $
Ä£yoÒ
U 'N " 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) îN . D r a g o n f l y - P C \ D r a g o n f l y íE ìE
ü:F ŒE ŠE å. ÂE ÁE ¾N € E : \ $ R E C Y C L E . B I N \ $ R F K 5 W O Y \ S o f t o n i c D o w n l o a d e r _ f o r _ h e r o - e d i t o r . e x e «F ŸF ÙýO B ì[m΂ïû‡°¹VFÝí땞B ðͬæcQÀ¸n8ЈáÍJí¥’ E MN L @ A p p l i c U n w n t . W i n 3 2 / S o f t o n i c D o w n l o a d e r OC ‰E ÄN 0 C : \ W i n d o w s \ e x p l o r e r . e x e È2E êE € ÀE ¿E ºE ÃE E A
Code:
ATTFilter xó›Ï8 L ) #yû
U‘ÒÛý
U‘Ò#yû
U‘ÒL ÜÏ‹cŒ $ 3Çä*÷ƒÒ H 1 $ { V e r s i o n } = 1 4 9 1 8 ( 2 0 1 7 0 2 1 0 ) ÜÏ‹cŒ $ héá{\„Ò H 1 $ { V e r s i o n } = 1 4 9 1 9 ( 2 0 1 7 0 2 1 1 ) ÜÏ‹cŒ $ æ:¸ e„Ò H 1 $ { V e r s i o n } = 1 4 9 2 0 ( 2 0 1 7 0 2 1 1 ) ÜÏ‹cŒ $ a.†‡†„Ò H 1 $ { V e r s i o n } = 1 4 9 2 1 ( 2 0 1 7 0 2 1 1 ) ÜÏ‹cŒ $
H‹'·„Ò H 1 $ { V e r s i o n } = 1 4 9 2 2 ( 2 0 1 7 0 2 1 1 ) ÜÏ‹cŒ $ §ÒÀä…Ò H 1 $ { V e r s i o n } = 1 4 9 2 3 ( 2 0 1 7 0 2 1 2 ) ÜÏ‹cŒ $ u~-)…Ò H 1 $ { V e r s i o n } = 1 4 9 2 4 ( 2 0 1 7 0 2 1 2 ) ÜÏ‹cŒ $ >É`íS…Ò H 1 $ { V e r s i o n } = 1 4 9 2 5 ( 2 0 1 7 0 2 1 2 ) ÜÏ‹cŒ $ €VWÛ}…Ò H 1 $ { V e r s i o n } = 1 4 9 2 6 ( 2 0 1 7 0 2 1 2 ) ÜÏ‹cŒ $ Ø¢µ»Ï…Ò H 1 $ { V e r s i o n } = 1 4 9 2 7 ( 2 0 1 7 0 2 1 3 ) ÜÏ‹cŒ $
c؈è…Ò
H 1 $ { V e r s i o n } = 1 4 9 2 8 ( 2 0 1 7 0 2 1 3 ) ÜÏ‹cŒ $ ¼BËnù…Ò H 1 $ { V e r s i o n } = 1 4 9 2 9 ( 2 0 1 7 0 2 1 3 ) ÜÏ‹cŒ $ å†ëx†Ò H 1 $ { V e r s i o n } = 1 4 9 3 0 ( 2 0 1 7 0 2 1 3 ) ÜÏ‹cŒ $
¾?ã2†Ò
H 1 $ { V e r s i o n } = 1 4 9 3 1 ( 2 0 1 7 0 2 1 3 ) ÜÏ‹cŒ $ m*ª'š†Ò H 1 $ { V e r s i o n } = 1 4 9 3 3 ( 2 0 1 7 0 2 1 4 ) ÜÏ‹cŒ $ ÿ3éu¶†Ò H 1 $ { V e r s i o n } = 1 4 9 3 4 ( 2 0 1 7 0 2 1 4 ) ÜÏ‹cŒ $
“O8Ç†Ò H 1 $ { V e r s i o n } = 1 4 9 3 5 ( 2 0 1 7 0 2 1 4 ) ÜÏ‹cŒ $ ˜§i”÷†Ò H 1 $ { V e r s i o n } = 1 4 9 3 6 ( 2 0 1 7 0 2 1 4 ) ÜÏ‹cŒ $ ‡Zþÿ†Ò H 1 $ { V e r s i o n } = 1 4 9 3 7 ( 2 0 1 7 0 2 1 4 ) ÜÏ‹cŒ $ <L.‡Ò H 1 $ { V e r s i o n } = 1 4 9 3 8 ( 2 0 1 7 0 2 1 4 ) ÜÏ‹cŒ $ 4·è(„‡Ò H 1 $ { V e r s i o n } = 1 4 9 3 9 ( 2 0 1 7 0 2 1 5 ) ÜÏ‹cŒ $ ?A^¨Æ‡Ò H 1 $ { V e r s i o n } = 1 4 9 4 0 ( 2 0 1 7 0 2 1 5 ) ÜÏ‹cŒ $ x£ò™Õ‡Ò H 1 $ { V e r s i o n } = 1 4 9 4 2 ( 2 0 1 7 0 2 1 5 ) ÜÏ‹cŒ $ Ò™ÆFVˆÒ H 1 $ { V e r s i o n } = 1 4 9 4 6 ( 2 0 1 7 0 2 1 6 ) ÜÏ‹cŒ $
©¤6xˆÒ H 1 $ { V e r s i o n } = 1 4 9 4 7 ( 2 0 1 7 0 2 1 6 ) ÜÏ‹cŒ $ x¢”ˆÒ H 1 $ { V e r s i o n } = 1 4 9 4 8 ( 2 0 1 7 0 2 1 6 ) ÜÏ‹cŒ $ ^4˜«ˆÒ H 1 $ { V e r s i o n } = 1 4 9 4 9 ( 2 0 1 7 0 2 1 6 ) ÜÏ‹cŒ $ €ÝÓ+‰Ò H 1 $ { V e r s i o n } = 1 4 9 5 2 ( 2 0 1 7 0 2 1 7 ) ÜÏ‹cŒ $ ½ûñ<‰Ò H 1 $ { V e r s i o n } = 1 4 9 5 3 ( 2 0 1 7 0 2 1 7 ) ÜÏ‹cŒ $ ÏÖÖ1g‰Ò H 1 $ { V e r s i o n } = 1 4 9 5 4 ( 2 0 1 7 0 2 1 7 ) ÜÏ‹cŒ $ þÞ@¯Å‰Ò H 1 $ { V e r s i o n } = 1 4 9 5 5 ( 2 0 1 7 0 2 1 7 ) ÜÏ‹cŒ $ ó/jüŠÒ H 1 $ { V e r s i o n } = 1 4 9 5 8 ( 2 0 1 7 0 2 1 8 ) ÜÏ‹cŒ $ ç˜Ü,ŠÒ H 1 $ { V e r s i o n } = 1 4 9 5 9 ( 2 0 1 7 0 2 1 8 ) ÜÏ‹cŒ $ ! åø›ªŠÒ ! H 1 $ { V e r s i o n } = 1 4 9 6 1 ( 2 0 1 7 0 2 1 9 ) ÜÏ‹cŒ $ " ×ðŠÒ " H 1 $ { V e r s i o n } = 1 4 9 6 2 ( 2 0 1 7 0 2 1 9 ) ÜÏ‹cŒ $ # AÎÍ:‹Ò # H 1 $ { V e r s i o n } = 1 4 9 6 3 ( 2 0 1 7 0 2 1 9 ) ÜÏ‹cŒ $ $ H
|‹Ò $ H 1 $ { V e r s i o n } = 1 4 9 6 6 ( 2 0 1 7 0 2 2 0 ) ÜÏ‹cŒ $ % 9ø\ž‹Ò % H 1 $ { V e r s i o n } = 1 4 9 6 7 ( 2 0 1 7 0 2 2 0 ) ÜÏ‹cŒ $ & b¶Ç¸Â‹Ò & H 1 $ { V e r s i o n } = 1 4 9 6 8 ( 2 0 1 7 0 2 2 0 ) ÜÏ‹cŒ $ ' ;a5ŒÒ ' H 1 $ { V e r s i o n } = 1 4 9 6 9 ( 2 0 1 7 0 2 2 0 ) ÜÏ‹cŒ $ ( ÁšÛ†ŒÒ ( H 1 $ { V e r s i o n } = 1 4 9 7 0 ( 2 0 1 7 0 2 2 1 ) ÜÏ‹cŒ $ ) íJÚ3=ŒÒ ) H 1 $ { V e r s i o n } = 1 4 9 7 1 ( 2 0 1 7 0 2 2 1 ) ÜÏ‹cŒ $ * ÂpõnGŒÒ * H 1 $ { V e r s i o n } = 1 4 9 7 2 ( 2 0 1 7 0 2 2 1 ) ÜÏ‹cŒ $ + »!¹YŒÒ + H 1 $ { V e r s i o n } = 1 4 9 7 3 ( 2 0 1 7 0 2 2 1 ) ÜÏ‹cŒ $ , $Í#ë†ŒÒ , H 1 $ { V e r s i o n } = 1 4 9 7 4 ( 2 0 1 7 0 2 2 1 ) ÜÏ‹cŒ $ - PÚK>ÿŒÒ - H 1 $ { V e r s i o n } = 1 4 9 7 7 ( 2 0 1 7 0 2 2 2 ) ÜÏ‹cŒ $ . —ÎSîÒ . H 1 $ { V e r s i o n } = 1 4 9 7 8 ( 2 0 1 7 0 2 2 2 ) ÜÏ‹cŒ $ / J9‹3Ò / H 1 $ { V e r s i o n } = 1 4 9 7 9 ( 2 0 1 7 0 2 2 2 ) ÜÏ‹cŒ $ 0 »~NÒ 0 H 1 $ { V e r s i o n } = 1 4 9 8 0 ( 2 0 1 7 0 2 2 2 ) ÜÏ‹cŒ $ 1 Eª¬¢Ò 1 H 1 $ { V e r s i o n } = 1 4 9 8 2 ( 2 0 1 7 0 2 2 3 ) ÜÏ‹cŒ $ 2 Ú¼™ÇÒ 2 H 1 $ { V e r s i o n } = 1 4 9 8 3 ( 2 0 1 7 0 2 2 3 ) ÜÏ‹cŒ $ 3 ›ôSåÙÒ 3 H 1 $ { V e r s i o n } = 1 4 9 8 4 ( 2 0 1 7 0 2 2 3 ) ÜÏ‹cŒ $ 4 øh=pôÒ 4 H 1 $ { V e r s i o n } = 1 4 9 8 5 ( 2 0 1 7 0 2 2 3 ) ÜÏ‹cŒ $ 5 Ä#3ßŽÒ 5 H 1 $ { V e r s i o n } = 1 4 9 8 6 ( 2 0 1 7 0 2 2 3 ) ÜÏ‹cŒ $ 6 ÃèjŽÒ 6 H 1 $ { V e r s i o n } = 1 4 9 8 7 ( 2 0 1 7 0 2 2 3 ) ÜÏ‹cŒ $ 7 åyÆjsŽÒ 7 H 1 $ { V e r s i o n } = 1 4 9 8 8 ( 2 0 1 7 0 2 2 4 ) ÜÏ‹cŒ $ 8 êêÛ…ŽÒ 8 H 1 $ { V e r s i o n } = 1 4 9 8 9 ( 2 0 1 7 0 2 2 4 ) ÜÏ‹cŒ $ 9 ¶í±¤ŽÒ 9 H 1 $ { V e r s i o n } = 1 4 9 9 0 ( 2 0 1 7 0 2 2 4 ) ÜÏ‹cŒ $ : "yܸŽÒ : H 1 $ { V e r s i o n } = 1 4 9 9 1 ( 2 0 1 7 0 2 2 4 ) ÜÏ‹cT $ ; O>MžÀŽÒ ; 3 ÜÏ‹cŒ $ < Þ´ê‘ÜŽÒ < H 1 $ { V e r s i o n } = 1 4 9 9 2 ( 2 0 1 7 0 2 2 4 ) ÜÏ‹cŒ $ = É`ÂÒ = H 1 $ { V e r s i o n } = 1 4 9 9 3 ( 2 0 1 7 0 2 2 4 ) ÜÏ‹cŒ $ > @q™GÒ > H 1 $ { V e r s i o n } = 1 4 9 9 4 ( 2 0 1 7 0 2 2 5 ) ÜÏ‹cŒ $ ? .în#bÒ ? H 1 $ { V e r s i o n } = 1 4 9 9 5 ( 2 0 1 7 0 2 2 5 ) ÜÏ‹cŒ $ @ ¼øñ†Ò @ H 1 $ { V e r s i o n } = 1 4 9 9 6 ( 2 0 1 7 0 2 2 5 ) ÜÏ‹cŒ $ A Zêë³Ò A H 1 $ { V e r s i o n } = 1 4 9 9 7 ( 2 0 1 7 0 2 2 5 ) ÜÏ‹cŒ $ B bô0
Ò B H 1 $ { V e r s i o n } = 1 4 9 9 8 ( 2 0 1 7 0 2 2 6 ) ÜÏ‹cŒ $ C £µ®:Ò C H 1 $ { V e r s i o n } = 1 4 9 9 9 ( 2 0 1 7 0 2 2 6 ) ÜÏ‹cŒ $ D Y£¸ÌPÒ D H 1 $ { V e r s i o n } = 1 5 0 0 0 ( 2 0 1 7 0 2 2 6 ) ÜÏ‹cŒ $ E lÍ+ƒÒ E H 1 $ { V e r s i o n } = 1 5 0 0 1 ( 2 0 1 7 0 2 2 6 ) ÜÏ‹cŒ $ F r¹ÛŽ·Ò F H 1 $ { V e r s i o n } = 1 5 0 0 2 ( 2 0 1 7 0 2 2 7 ) ÜÏ‹cŒ $ G áßuçÒ G H 1 $ { V e r s i o n } = 1 5 0 0 3 ( 2 0 1 7 0 2 2 7 ) ÜÏ‹cŒ $ H kx¡Þ‘Ò H H 1 $ { V e r s i o n } = 1 5 0 0 4 ( 2 0 1 7 0 2 2 7 ) ÜÏ‹cŒ $ I U쌶‘Ò I H 1 $ { V e r s i o n } = 1 5 0 0 5 ( 2 0 1 7 0 2 2 7 ) ÜÏ‹cŒ $ J \×<‘Ò J H 1 $ { V e r s i o n } = 1 5 0 0 6 ( 2 0 1 7 0 2 2 7 ) ÜÏ‹cŒ $ K Ü̘äQ‘Ò K H 1 $ { V e r s i o n } = 1 5 0 0 7 ( 2 0 1 7 0 2 2 7 )
Code:
ATTFilter ANDLE (1076) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Closing MSIHANDLE (1076) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Creating MSIHANDLE (1077) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Closing MSIHANDLE (1077) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Creating MSIHANDLE (1078) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Closing MSIHANDLE (1078) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Creating MSIHANDLE (1079) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Closing MSIHANDLE (1079) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Creating MSIHANDLE (1080) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:415]: Closing MSIHANDLE (1080) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Creating MSIHANDLE (1081) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Closing MSIHANDLE (1081) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Creating MSIHANDLE (1082) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Closing MSIHANDLE (1082) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Creating MSIHANDLE (1083) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Closing MSIHANDLE (1083) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Creating MSIHANDLE (1084) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Closing MSIHANDLE (1084) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Creating MSIHANDLE (1085) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Closing MSIHANDLE (1085) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Creating MSIHANDLE (1086) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Closing MSIHANDLE (1086) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Creating MSIHANDLE (1087) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:416]: Closing MSIHANDLE (1087) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Creating MSIHANDLE (1088) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Closing MSIHANDLE (1088) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Creating MSIHANDLE (1089) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Closing MSIHANDLE (1089) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Creating MSIHANDLE (1090) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Closing MSIHANDLE (1090) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Creating MSIHANDLE (1091) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Closing MSIHANDLE (1091) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Creating MSIHANDLE (1092) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Closing MSIHANDLE (1092) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Creating MSIHANDLE (1093) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Closing MSIHANDLE (1093) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Creating MSIHANDLE (1094) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:417]: Closing MSIHANDLE (1094) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1095) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1095) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1096) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1096) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1097) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1097) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1098) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1098) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1099) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1099) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1100) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1100) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1101) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1101) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Creating MSIHANDLE (1102) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:418]: Closing MSIHANDLE (1102) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Creating MSIHANDLE (1103) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Closing MSIHANDLE (1103) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Creating MSIHANDLE (1104) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Closing MSIHANDLE (1104) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Creating MSIHANDLE (1105) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Closing MSIHANDLE (1105) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:20:419]: Doing action: eplgOutlookInstall
Action ended 00:42:20: WriteRegistryValues. Return value 1.
MSI (c) (10:EC) [00:42:20:419]: Creating MSIHANDLE (1106) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Closing MSIHANDLE (1106) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Creating MSIHANDLE (1107) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:419]: Closing MSIHANDLE (1107) of type 790531 for thread 4844
Action start 00:42:20: eplgOutlookInstall.
MSI (c) (10:EC) [00:42:20:420]: Creating MSIHANDLE (1108) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:420]: Closing MSIHANDLE (1108) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:420]: Creating MSIHANDLE (1109) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:420]: Closing MSIHANDLE (1109) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:420]: Creating MSIHANDLE (1110) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:420]: Closing MSIHANDLE (1110) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:420]: Creating MSIHANDLE (1111) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:420]: Closing MSIHANDLE (1111) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:20:425]: Doing action: SetCADataShellExtInstall
Action ended 00:42:20: eplgOutlookInstall. Return value 1.
MSI (c) (10:EC) [00:42:20:424]: Creating MSIHANDLE (1112) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:424]: Closing MSIHANDLE (1112) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:425]: Creating MSIHANDLE (1113) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:20:425]: Closing MSIHANDLE (1113) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:20:425]: PROPERTY CHANGE: Adding InstSuppShellExtInstall property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll'.
Code:
ATTFilter === Verbose logging started: 11.02.2017 00:42:17 Build type: SHIP UNICODE 5.00.10011.00 Calling process: C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eset_nod32_antivirus_live_installer.exe ===
MSI (c) (10:0C) [00:42:17:885]: Resetting cached policy values
MSI (c) (10:0C) [00:42:17:885]: Machine policy value 'Debug' is 0
MSI (c) (10:0C) [00:42:17:885]: ******* RunEngine:
******* Product: C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi
******* Action:
******* CommandLine: **********
MSI (c) (10:0C) [00:42:17:885]: Client-side and UI is none or basic: Running entire install on the server.
MSI (c) (10:0C) [00:42:17:885]: Grabbed execution mutex.
MSI (c) (10:0C) [00:42:17:886]: Cloaking enabled.
MSI (c) (10:0C) [00:42:17:886]: Attempting to enable all disabled privileges before calling Install on Server
MSI (c) (10:0C) [00:42:17:886]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (38:D4) [00:42:17:918]: Running installation inside multi-package transaction C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi
MSI (s) (38:D4) [00:42:17:918]: Grabbed execution mutex.
MSI (s) (38:9C) [00:42:17:978]: Resetting cached policy values
MSI (s) (38:9C) [00:42:17:978]: Machine policy value 'Debug' is 0
MSI (s) (38:9C) [00:42:17:978]: ******* RunEngine:
******* Product: C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi
******* Action:
******* CommandLine: **********
MSI (s) (38:9C) [00:42:17:979]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (38:9C) [00:42:17:979]: Setting cached product context: machine assigned for product: 07E577C8197A8AD4CB3CA67B31F64448
MSI (s) (38:9C) [00:42:17:979]: Using cached product context: machine assigned for product: 07E577C8197A8AD4CB3CA67B31F64448
MSI (s) (38:9C) [00:42:17:979]: Setting cached product context: machine assigned for product: 1af2a8da7e60d0b429d7e6453b3d0182
MSI (s) (38:9C) [00:42:17:979]: Using cached product context: machine assigned for product: 1af2a8da7e60d0b429d7e6453b3d0182
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: 21EE4A31AE32173319EEFE3BD6FDFFE3
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: 21EE4A31AE32173319EEFE3BD6FDFFE3
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: 22BEFC8F7E2A1793E9ADB411DEFE1C58
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: 22BEFC8F7E2A1793E9ADB411DEFE1C58
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: 36C92ABAD22B8F54AB02C7E81FB7E526
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: 36C92ABAD22B8F54AB02C7E81FB7E526
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: 62DBF9290209B993A9A757D1160F9B24
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: 62DBF9290209B993A9A757D1160F9B24
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: 6E8D947A316B3EB3F8F540C548BE2AB9
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: 6E8D947A316B3EB3F8F540C548BE2AB9
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: 93BAD29AC2E44034A96BCB446EB8552E
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: 93BAD29AC2E44034A96BCB446EB8552E
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: 9eab5ec6ac3d99b498a1d16c1c815acf
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: 9eab5ec6ac3d99b498a1d16c1c815acf
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: A91FFE89BA03B4E49B340FB6C136BE8F
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: A91FFE89BA03B4E49B340FB6C136BE8F
MSI (s) (38:9C) [00:42:17:980]: Setting cached product context: machine assigned for product: c1c4f01781cc94c4c8fb1542c0981a2a
MSI (s) (38:9C) [00:42:17:980]: Using cached product context: machine assigned for product: c1c4f01781cc94c4c8fb1542c0981a2a
MSI (s) (38:9C) [00:42:17:981]: Setting cached product context: machine assigned for product: DF77865CBEB67174183B2145AFF17DCF
MSI (s) (38:9C) [00:42:17:981]: Using cached product context: machine assigned for product: DF77865CBEB67174183B2145AFF17DCF
MSI (s) (38:9C) [00:42:17:981]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038
MSI (s) (38:9C) [00:42:17:983]: SRSetRestorePoint skipped for this transaction.
MSI (s) (38:9C) [00:42:17:984]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 3: 2
MSI (c) (10:EC) [00:42:17:981]: Creating MSIHANDLE (163) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:17:981]: Closing MSIHANDLE (163) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:17:995]: File will have security applied from OpCode.
MSI (c) (10:EC) [00:42:17:994]: Creating MSIHANDLE (164) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:17:994]: Closing MSIHANDLE (164) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:18:075]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi' against software restriction policy
MSI (s) (38:9C) [00:42:18:102]: SOFTWARE RESTRICTION POLICY: C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi has a digital signature
MSI (s) (38:9C) [00:42:18:535]: SOFTWARE RESTRICTION POLICY: C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (38:9C) [00:42:18:536]: Creating MSIHANDLE (1) of type 790542 for thread 6300
MSI (s) (38:9C) [00:42:18:536]: MSCOREE not loaded loading copy from system32
MSI (s) (38:9C) [00:42:18:766]: End dialog not enabled
MSI (s) (38:9C) [00:42:18:766]: Original package ==> C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi
MSI (s) (38:9C) [00:42:18:766]: Package we're running from ==> C:\WINDOWS\Installer\250b4f3b.msi
MSI (s) (38:9C) [00:42:18:771]: APPCOMPAT: Compatibility mode property overrides found.
MSI (s) (38:9C) [00:42:18:771]: APPCOMPAT: looking for appcompat database entry with ProductCode '{4D33D02B-18D1-4125-8264-C4BD386CCBA8}'.
MSI (s) (38:9C) [00:42:18:771]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (38:9C) [00:42:18:980]: Machine policy value 'TransformsSecure' is 0
MSI (s) (38:9C) [00:42:18:980]: User policy value 'TransformsAtSource' is 0
MSI (s) (38:9C) [00:42:18:981]: Machine policy value 'DisablePatch' is 0
MSI (s) (38:9C) [00:42:18:981]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (38:9C) [00:42:18:981]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (38:9C) [00:42:18:981]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (38:9C) [00:42:18:981]: Enabling baseline caching for this transaction since all active patches are MSI 3.0 style MSPs or at least one MSI 3.0 minor update patch is active
MSI (c) (10:EC) [00:42:18:074]: Creating MSIHANDLE (165) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:18:074]: Closing MSIHANDLE (165) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:18:983]: APPCOMPAT: looking for appcompat database entry with ProductCode '{4D33D02B-18D1-4125-8264-C4BD386CCBA8}'.
MSI (s) (38:9C) [00:42:18:983]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (38:9C) [00:42:18:983]: Transforms are not secure.
MSI (s) (38:9C) [00:42:18:984]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\Users\DRAGON~1\AppData\Local\Temp\eset\liveinstaller_20170210234217.log'.
MSI (s) (38:9C) [00:42:18:984]: Command Line: CHECK_NEW_VERSION=0 IGNORE_CONFLICTS=1 REBOOT=R PROTECTED_SERVICE_ENABLED=1 CFG_LIVEGRID_ENABLED=1 CFG_POTENTIALLYUNWANTED_ENABLED=1 MSI_GUI_PROCESS_ID=7696 ANALYTICS_DISABLE=1 ADMINCFG=C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\cfg.xml DISTRIBUTION_PACKAGE=C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\dpkg.xml CURRENTDIRECTORY=C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5} CLIENTUILEVEL=3 MSICLIENTUSESEXTERNALUI=1 CLIENTPROCESSID=7696
MSI (s) (38:9C) [00:42:18:984]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{B87F747B-C11D-4A22-9DCE-A0157C10CEB5}'.
MSI (s) (38:9C) [00:42:18:984]: Product Code passed to Engine.Initialize: ''
MSI (s) (38:9C) [00:42:18:984]: Product Code from property table before transforms: '{4D33D02B-18D1-4125-8264-C4BD386CCBA8}'
MSI (s) (38:9C) [00:42:18:984]: Product Code from property table after transforms: '{4D33D02B-18D1-4125-8264-C4BD386CCBA8}'
MSI (s) (38:9C) [00:42:18:984]: Product not registered: beginning first-time install
MSI (s) (38:9C) [00:42:18:984]: Product {4D33D02B-18D1-4125-8264-C4BD386CCBA8} is not managed.
MSI (s) (38:9C) [00:42:18:984]: MSI_LUA: Credential prompt not required, user is an admin
MSI (s) (38:9C) [00:42:18:984]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (38:9C) [00:42:18:985]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (38:9C) [00:42:18:985]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (38:9C) [00:42:18:985]: Adding new sources is allowed.
MSI (s) (38:9C) [00:42:18:985]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:985]: Package name extracted from package path: 'eav_nt64_deu.msi'
MSI (s) (38:9C) [00:42:18:986]: Package to be registered: 'eav_nt64_deu.msi'
MSI (c) (10:EC) [00:42:18:983]: Creating MSIHANDLE (166) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:18:983]: Closing MSIHANDLE (166) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:18:988]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (38:9C) [00:42:18:988]: Machine policy value 'DisableMsi' is 0
MSI (s) (38:9C) [00:42:18:988]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (38:9C) [00:42:18:988]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (38:9C) [00:42:18:988]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (38:9C) [00:42:18:988]: Running product '{4D33D02B-18D1-4125-8264-C4BD386CCBA8}' with elevated privileges: Product is assigned.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Modifying CHECK_NEW_VERSION property. Its current value is '1'. Its new value: '0'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding IGNORE_CONFLICTS property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'R'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding PROTECTED_SERVICE_ENABLED property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding CFG_LIVEGRID_ENABLED property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding CFG_POTENTIALLYUNWANTED_ENABLED property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding MSI_GUI_PROCESS_ID property. Its value is '7696'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding ANALYTICS_DISABLE property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding ADMINCFG property. Its value is 'C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\cfg.xml'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding DISTRIBUTION_PACKAGE property. Its value is 'C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\dpkg.xml'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding MSICLIENTUSESEXTERNALUI property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:988]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '7696'.
MSI (s) (38:9C) [00:42:18:988]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0
MSI (s) (38:9C) [00:42:18:988]: RESTART MANAGER: Disabled by MSIRESTARTMANAGERCONTROL property; Windows Installer will use the built-in FilesInUse functionality.
MSI (s) (38:9C) [00:42:18:992]: PROPERTY CHANGE: Adding MsiSystemRebootPending property. Its value is '1'.
MSI (s) (38:9C) [00:42:18:992]: TRANSFORMS property is now:
MSI (s) (38:9C) [00:42:18:992]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (s) (38:9C) [00:42:18:994]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming
MSI (s) (38:9C) [00:42:18:995]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\Favorites
MSI (s) (38:9C) [00:42:18:996]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Network Shortcuts
MSI (s) (38:9C) [00:42:18:997]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\Documents
MSI (s) (38:9C) [00:42:18:998]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
MSI (s) (38:9C) [00:42:18:999]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Recent
MSI (s) (38:9C) [00:42:19:000]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\SendTo
MSI (s) (38:9C) [00:42:19:001]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Templates
MSI (s) (38:9C) [00:42:19:001]: SHELL32::SHGetFolderPath returned: C:\ProgramData
MSI (s) (38:9C) [00:42:19:002]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Local
MSI (s) (38:9C) [00:42:19:003]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\Pictures
MSI (s) (38:9C) [00:42:19:005]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (38:9C) [00:42:19:006]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (38:9C) [00:42:19:007]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
MSI (s) (38:9C) [00:42:19:008]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu
MSI (s) (38:9C) [00:42:19:009]: SHELL32::SHGetFolderPath returned: C:\Users\Public\Desktop
MSI (s) (38:9C) [00:42:19:011]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (38:9C) [00:42:19:012]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (38:9C) [00:42:19:013]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
MSI (s) (38:9C) [00:42:19:014]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\AppData\Roaming\Microsoft\Windows\Start Menu
MSI (s) (38:9C) [00:42:19:015]: SHELL32::SHGetFolderPath returned: C:\Users\Dragonfly\Desktop
MSI (s) (38:9C) [00:42:19:016]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Templates
MSI (s) (38:9C) [00:42:19:016]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (38:9C) [00:42:19:017]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (38:9C) [00:42:19:022]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.
MSI (s) (38:9C) [00:42:19:022]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.
MSI (s) (38:9C) [00:42:19:022]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (38:9C) [00:42:19:022]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (38:9C) [00:42:19:023]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Microsoft'.
MSI (s) (38:9C) [00:42:19:023]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (38:9C) [00:42:19:023]: PROPERTY CHANGE: Adding COMPANYNAME property. Its value is 'Microsoft'.
MSI (s) (38:9C) [00:42:19:023]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\WINDOWS\Installer\250b4f3b.msi'.
MSI (s) (38:9C) [00:42:19:023]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eav_nt64_deu.msi'.
MSI (s) (38:9C) [00:42:19:023]: Machine policy value 'MsiDisableEmbeddedUI' is 0
MSI (s) (38:9C) [00:42:19:023]: EEUI - Disabling MsiEmbeddedUI due to existing external or embedded UI
MSI (s) (38:9C) [00:42:19:023]: EEUI - Disabling MsiEmbeddedUI for service because it's not a quiet/basic install
MSI (s) (38:9C) [00:42:19:024]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (38:9C) [00:42:19:024]: Machine policy value 'DisableRollback' is 0
MSI (s) (38:9C) [00:42:19:024]: User policy value 'DisableRollback' is 0
MSI (s) (38:9C) [00:42:19:024]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
MSI (s) (38:9C) [00:42:19:024]: PROPERTY CHANGE: Adding MsiUISourceResOnly property. Its value is '1'.
=== Logging started: 11.02.2017 00:42:19 ===
MSI (c) (10:EC) [00:42:19:024]: Creating MSIHANDLE (167) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:024]: Closing MSIHANDLE (167) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:024]: Creating MSIHANDLE (168) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:024]: Closing MSIHANDLE (168) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:024]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038
MSI (s) (38:9C) [00:42:19:024]: APPCOMPAT: [DetectVersionLaunchCondition] Launch condition already passes.
MSI (s) (38:9C) [00:42:19:027]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (38:9C) [00:42:19:027]: Doing action: INSTALL
MSI (c) (10:EC) [00:42:19:024]: Creating MSIHANDLE (169) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:024]: Closing MSIHANDLE (169) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:028]: Creating MSIHANDLE (170) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:028]: Closing MSIHANDLE (170) of type 790531 for thread 4844
Action start 00:42:19: INSTALL.
MSI (c) (10:EC) [00:42:19:028]: Creating MSIHANDLE (171) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:028]: Closing MSIHANDLE (171) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:028]: Running ExecuteSequence
MSI (s) (38:9C) [00:42:19:028]: Doing action: LaunchConditions
MSI (c) (10:EC) [00:42:19:029]: Creating MSIHANDLE (172) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:029]: Closing MSIHANDLE (172) of type 790531 for thread 4844
Action start 00:42:19: LaunchConditions.
MSI (c) (10:EC) [00:42:19:029]: Creating MSIHANDLE (173) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:029]: Closing MSIHANDLE (173) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:029]: Doing action: FindRelatedProducts
Action ended 00:42:19: LaunchConditions. Return value 1.
MSI (c) (10:EC) [00:42:19:029]: Creating MSIHANDLE (174) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:029]: Closing MSIHANDLE (174) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:030]: Creating MSIHANDLE (175) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:030]: Closing MSIHANDLE (175) of type 790531 for thread 4844
Action start 00:42:19: FindRelatedProducts.
MSI (c) (10:EC) [00:42:19:030]: Creating MSIHANDLE (176) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:030]: Closing MSIHANDLE (176) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:030]: Skipping action: AdminRightsError (condition is false)
MSI (s) (38:9C) [00:42:19:030]: Skipping action: DowngradeError (condition is false)
MSI (s) (38:9C) [00:42:19:030]: Doing action: InstSuppMigrateDirectoryPaths
Action ended 00:42:19: FindRelatedProducts. Return value 1.
MSI (c) (10:EC) [00:42:19:030]: Creating MSIHANDLE (177) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:030]: Closing MSIHANDLE (177) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:030]: Creating MSIHANDLE (178) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:031]: Closing MSIHANDLE (178) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:033]: Creating MSIHANDLE (2) of type 790542 for thread 6300
MSI (s) (38:34) [00:42:19:034]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI5352.tmp, Entrypoint: MigrateDirectoryPaths
MSI (s) (38:58) [00:42:19:035]: Generating random cookie.
MSI (s) (38:58) [00:42:19:039]: Created Custom Action Server with PID 6224 (0x1850).
MSI (s) (38:58) [00:42:19:060]: Running as a service.
MSI (s) (38:58) [00:42:19:065]: Hello, I'm your 64bit Impersonated custom action server.
MSI (s) (38!98) [00:42:19:098]: Creating MSIHANDLE (3) of type 790531 for thread 6296
Action start 00:42:19: InstSuppMigrateDirectoryPaths.
MSI (c) (10:EC) [00:42:19:031]: Creating MSIHANDLE (179) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:031]: Closing MSIHANDLE (179) of type 790531 for thread 4844
MSI (s) (38!98) [00:42:19:099]: Closing MSIHANDLE (3) of type 790531 for thread 6296
MSI (s) (38!98) [00:42:19:099]: Creating MSIHANDLE (4) of type 790531 for thread 6296
ESET: Entering CA InstSupp!MigrateDirectoryPaths (limited: no)
MSI (c) (10:EC) [00:42:19:098]: Creating MSIHANDLE (180) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:098]: Closing MSIHANDLE (180) of type 790531 for thread 4844
MSI (s) (38!98) [00:42:19:099]: Closing MSIHANDLE (4) of type 790531 for thread 6296
MSI (s) (38:34) [00:42:19:100]: Closing MSIHANDLE (2) of type 790542 for thread 6300
ESET: Returing from CA InstSupp!MigrateDirectoryPaths with status 0 (duration: 0.0)
MSI (c) (10:EC) [00:42:19:099]: Creating MSIHANDLE (181) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:099]: Closing MSIHANDLE (181) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:100]: Doing action: SetAPPDATADIR
Action ended 00:42:19: InstSuppMigrateDirectoryPaths. Return value 1.
MSI (c) (10:EC) [00:42:19:100]: Creating MSIHANDLE (182) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:100]: Closing MSIHANDLE (182) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:101]: Creating MSIHANDLE (183) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:101]: Closing MSIHANDLE (183) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:101]: PROPERTY CHANGE: Adding APPDATADIR property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus'.
Action start 00:42:19: SetAPPDATADIR.
MSI (c) (10:EC) [00:42:19:101]: Creating MSIHANDLE (184) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:101]: Closing MSIHANDLE (184) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:101]: Doing action: SetAPPDATADIR_ORIG
Action ended 00:42:19: SetAPPDATADIR. Return value 1.
MSI (c) (10:EC) [00:42:19:101]: Creating MSIHANDLE (185) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:101]: Closing MSIHANDLE (185) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:101]: Creating MSIHANDLE (186) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:102]: Closing MSIHANDLE (186) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:102]: PROPERTY CHANGE: Adding APPDATADIR_ORIG property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus'.
Action start 00:42:19: SetAPPDATADIR_ORIG.
MSI (c) (10:EC) [00:42:19:102]: Creating MSIHANDLE (187) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:102]: Closing MSIHANDLE (187) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:102]: Doing action: SetAPPDIR
Action ended 00:42:19: SetAPPDATADIR_ORIG. Return value 1.
MSI (c) (10:EC) [00:42:19:102]: Creating MSIHANDLE (188) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:102]: Closing MSIHANDLE (188) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:102]: Creating MSIHANDLE (189) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:102]: Closing MSIHANDLE (189) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:103]: PROPERTY CHANGE: Adding APPDIR property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus'.
Action start 00:42:19: SetAPPDIR.
MSI (c) (10:EC) [00:42:19:103]: Creating MSIHANDLE (190) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:103]: Closing MSIHANDLE (190) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:103]: Doing action: SetAPPDIR_ORIG
Action ended 00:42:19: SetAPPDIR. Return value 1.
MSI (c) (10:EC) [00:42:19:103]: Creating MSIHANDLE (191) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:103]: Closing MSIHANDLE (191) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:103]: Creating MSIHANDLE (192) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:103]: Closing MSIHANDLE (192) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:103]: PROPERTY CHANGE: Adding APPDIR_ORIG property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus'.
Action start 00:42:19: SetAPPDIR_ORIG.
MSI (c) (10:EC) [00:42:19:103]: Creating MSIHANDLE (193) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:103]: Closing MSIHANDLE (193) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:104]: Doing action: SetARPINSTALLLOCATION
Action ended 00:42:19: SetAPPDIR_ORIG. Return value 1.
MSI (c) (10:EC) [00:42:19:104]: Creating MSIHANDLE (194) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:104]: Closing MSIHANDLE (194) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:104]: Creating MSIHANDLE (195) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:104]: Closing MSIHANDLE (195) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:104]: PROPERTY CHANGE: Adding ARPINSTALLLOCATION property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus'.
Action start 00:42:19: SetARPINSTALLLOCATION.
MSI (c) (10:EC) [00:42:19:104]: Creating MSIHANDLE (196) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:104]: Closing MSIHANDLE (196) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:104]: Skipping action: SetARPNOREMOVE (condition is false)
MSI (s) (38:9C) [00:42:19:104]: Doing action: SetDESKTOPDIR
Action ended 00:42:19: SetARPINSTALLLOCATION. Return value 1.
MSI (c) (10:EC) [00:42:19:104]: Creating MSIHANDLE (197) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:104]: Closing MSIHANDLE (197) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:105]: Creating MSIHANDLE (198) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:105]: Closing MSIHANDLE (198) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:105]: PROPERTY CHANGE: Adding DESKTOPDIR property. Its value is 'C:\Users\Public\Desktop\'.
Action start 00:42:19: SetDESKTOPDIR.
MSI (c) (10:EC) [00:42:19:105]: Creating MSIHANDLE (199) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:105]: Closing MSIHANDLE (199) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:105]: Doing action: SetMODULEDIR_ORIG
Action ended 00:42:19: SetDESKTOPDIR. Return value 1.
MSI (c) (10:EC) [00:42:19:105]: Creating MSIHANDLE (200) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:105]: Closing MSIHANDLE (200) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:105]: Creating MSIHANDLE (201) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:106]: Closing MSIHANDLE (201) of type 790531 for thread 4844
Action start 00:42:19: SetMODULEDIR_ORIG.
MSI (c) (10:EC) [00:42:19:106]: Creating MSIHANDLE (202) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:106]: Closing MSIHANDLE (202) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:106]: Doing action: SetMODULEDIR
Action ended 00:42:19: SetMODULEDIR_ORIG. Return value 1.
MSI (c) (10:EC) [00:42:19:106]: Creating MSIHANDLE (203) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:106]: Closing MSIHANDLE (203) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:106]: Creating MSIHANDLE (204) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:106]: Closing MSIHANDLE (204) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:106]: PROPERTY CHANGE: Adding MODULEDIR property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Modules\'.
Action start 00:42:19: SetMODULEDIR.
MSI (c) (10:EC) [00:42:19:106]: Creating MSIHANDLE (205) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:106]: Closing MSIHANDLE (205) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:107]: Doing action: SetSHORTCUTDIR
Action ended 00:42:19: SetMODULEDIR. Return value 1.
MSI (c) (10:EC) [00:42:19:107]: Creating MSIHANDLE (206) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:107]: Closing MSIHANDLE (206) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:107]: Creating MSIHANDLE (207) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:107]: Closing MSIHANDLE (207) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:107]: PROPERTY CHANGE: Adding SHORTCUTDIR property. Its value is 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET\ESET NOD32 Antivirus'.
Action start 00:42:19: SetSHORTCUTDIR.
MSI (c) (10:EC) [00:42:19:107]: Creating MSIHANDLE (208) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:107]: Closing MSIHANDLE (208) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:107]: Skipping action: Win64ErrorMessage (condition is false)
MSI (s) (38:9C) [00:42:19:107]: Doing action: AppSearch
Action ended 00:42:19: SetSHORTCUTDIR. Return value 1.
MSI (c) (10:EC) [00:42:19:107]: Creating MSIHANDLE (209) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:107]: Closing MSIHANDLE (209) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:107]: Creating MSIHANDLE (210) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:108]: Closing MSIHANDLE (210) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:108]: Note: 1: 2205 2: 3: AppSearch
MSI (s) (38:9C) [00:42:19:108]: Note: 1: 2228 2: 3: AppSearch 4: SELECT `Property`, `Signature_` FROM `AppSearch`
Action start 00:42:19: AppSearch.
MSI (c) (10:EC) [00:42:19:108]: Creating MSIHANDLE (211) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:108]: Closing MSIHANDLE (211) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:108]: Doing action: CCPSearch
Action ended 00:42:19: AppSearch. Return value 0.
MSI (c) (10:EC) [00:42:19:108]: Creating MSIHANDLE (212) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:108]: Closing MSIHANDLE (212) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:108]: Creating MSIHANDLE (213) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:109]: Closing MSIHANDLE (213) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:109]: Note: 1: 2205 2: 3: CCPSearch
MSI (s) (38:9C) [00:42:19:109]: Note: 1: 2228 2: 3: CCPSearch 4: SELECT `Signature_` FROM `CCPSearch`
Action start 00:42:19: CCPSearch.
MSI (c) (10:EC) [00:42:19:109]: Creating MSIHANDLE (214) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:109]: Closing MSIHANDLE (214) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:109]: Doing action: RMCCPSearch
Action ended 00:42:19: CCPSearch. Return value 0.
MSI (c) (10:EC) [00:42:19:109]: Creating MSIHANDLE (215) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:109]: Closing MSIHANDLE (215) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:109]: Creating MSIHANDLE (216) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:109]: Closing MSIHANDLE (216) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:109]: Note: 1: 2205 2: 3: CCPSearch
MSI (s) (38:9C) [00:42:19:109]: Note: 1: 2228 2: 3: CCPSearch 4: SELECT `Signature_` FROM `CCPSearch`
Action start 00:42:19: RMCCPSearch.
MSI (c) (10:EC) [00:42:19:109]: Creating MSIHANDLE (217) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:109]: Closing MSIHANDLE (217) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:110]: Doing action: ValidateProductID
Action ended 00:42:19: RMCCPSearch. Return value 0.
MSI (c) (10:EC) [00:42:19:110]: Creating MSIHANDLE (218) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:110]: Closing MSIHANDLE (218) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:110]: Creating MSIHANDLE (219) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:110]: Closing MSIHANDLE (219) of type 790531 for thread 4844
Action start 00:42:19: ValidateProductID.
MSI (c) (10:EC) [00:42:19:110]: Creating MSIHANDLE (220) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:110]: Closing MSIHANDLE (220) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:110]: Doing action: InstSuppLoadInstallIni
Action ended 00:42:19: ValidateProductID. Return value 1.
MSI (c) (10:EC) [00:42:19:110]: Creating MSIHANDLE (221) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:110]: Closing MSIHANDLE (221) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:111]: Creating MSIHANDLE (222) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:111]: Closing MSIHANDLE (222) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:113]: Creating MSIHANDLE (5) of type 790542 for thread 6300
MSI (s) (38:1C) [00:42:19:113]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI53A1.tmp, Entrypoint: caLoadInstallIni
MSI (s) (38!28) [00:42:19:133]: Creating MSIHANDLE (6) of type 790531 for thread 1064
Action start 00:42:19: InstSuppLoadInstallIni.
MSI (c) (10:EC) [00:42:19:111]: Creating MSIHANDLE (223) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:111]: Closing MSIHANDLE (223) of type 790531 for thread 4844
MSI (s) (38!28) [00:42:19:133]: Closing MSIHANDLE (6) of type 790531 for thread 1064
MSI (s) (38!28) [00:42:19:133]: Creating MSIHANDLE (7) of type 790531 for thread 1064
ESET: Entering CA InstSupp!caLoadInstallIni (limited: no)
MSI (c) (10:EC) [00:42:19:133]: Creating MSIHANDLE (224) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:133]: Closing MSIHANDLE (224) of type 790531 for thread 4844
MSI (s) (38!28) [00:42:19:134]: Closing MSIHANDLE (7) of type 790531 for thread 1064
MSI (s) (38!28) [00:42:19:134]: Creating MSIHANDLE (8) of type 790531 for thread 1064
ESET: INI file: C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\install.ini
MSI (c) (10:EC) [00:42:19:134]: Creating MSIHANDLE (225) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:134]: Closing MSIHANDLE (225) of type 790531 for thread 4844
MSI (s) (38!28) [00:42:19:134]: Closing MSIHANDLE (8) of type 790531 for thread 1064
ESET: Returing from CA InstSupp!caLoadInstallIni with status 1627 (duration: 0.0)
MSI (c) (10:EC) [00:42:19:134]: Creating MSIHANDLE (226) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:134]: Closing MSIHANDLE (226) of type 790531 for thread 4844
MSI (s) (38:1C) [00:42:19:136]: Closing MSIHANDLE (5) of type 790542 for thread 6300
CustomAction InstSuppLoadInstallIni returned actual error code 1603 but will be translated to success due to continue marking
MSI (c) (10:EC) [00:42:19:136]: Creating MSIHANDLE (227) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:136]: Closing MSIHANDLE (227) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:137]: Doing action: CostInitialize
Action ended 00:42:19: InstSuppLoadInstallIni. Return value 1.
MSI (c) (10:EC) [00:42:19:137]: Creating MSIHANDLE (228) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:137]: Closing MSIHANDLE (228) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:137]: Creating MSIHANDLE (229) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:137]: Closing MSIHANDLE (229) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:137]: Machine policy value 'MaxPatchCacheSize' is 10
MSI (s) (38:9C) [00:42:19:137]: Baseline: Sorting baselines for {4D33D02B-18D1-4125-8264-C4BD386CCBA8}.
MSI (s) (38:9C) [00:42:19:137]: Baseline: New baseline 10.0.390 from transaction.
MSI (s) (38:9C) [00:42:19:137]: Baseline: Sorted order Native: Order 0.
MSI (s) (38:9C) [00:42:19:137]: Baseline Data Table:
MSI (s) (38:9C) [00:42:19:137]: ProductCode: {4D33D02B-18D1-4125-8264-C4BD386CCBA8} Version: 10.0.390 Attributes: 0 PatchId: Native BaselineId: -2147483648 Order: 0
MSI (s) (38:9C) [00:42:19:137]: Baseline File Table:
MSI (s) (38:9C) [00:42:19:138]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'C:\'.
MSI (s) (38:9C) [00:42:19:138]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (38:9C) [00:42:19:138]: Note: 1: 2205 2: 3: Patch
MSI (s) (38:9C) [00:42:19:138]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (38:9C) [00:42:19:138]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (38:9C) [00:42:19:138]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (38:9C) [00:42:19:138]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (38:9C) [00:42:19:138]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (38:9C) [00:42:19:138]: Delta compression fallback method for this product transaction is 'MSI 2.0 legacy obsolescence'
MSI (s) (38:9C) [00:42:19:139]: Note: 1: 2205 2: 3: Patch
Action start 00:42:19: CostInitialize.
MSI (c) (10:EC) [00:42:19:137]: Creating MSIHANDLE (230) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:137]: Closing MSIHANDLE (230) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:139]: Doing action: FileCost
Action ended 00:42:19: CostInitialize. Return value 1.
MSI (c) (10:EC) [00:42:19:139]: Creating MSIHANDLE (231) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:139]: Closing MSIHANDLE (231) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:139]: Creating MSIHANDLE (232) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:139]: Closing MSIHANDLE (232) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:139]: Note: 1: 2205 2: 3: MsiAssembly
MSI (s) (38:9C) [00:42:19:140]: Note: 1: 2205 2: 3: Class
MSI (s) (38:9C) [00:42:19:140]: Note: 1: 2205 2: 3: Extension
MSI (s) (38:9C) [00:42:19:140]: Note: 1: 2205 2: 3: TypeLib
Action start 00:42:19: FileCost.
MSI (c) (10:EC) [00:42:19:139]: Creating MSIHANDLE (233) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:139]: Closing MSIHANDLE (233) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:140]: Doing action: CostFinalize
Action ended 00:42:19: FileCost. Return value 1.
MSI (c) (10:EC) [00:42:19:140]: Creating MSIHANDLE (234) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:140]: Closing MSIHANDLE (234) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:140]: Creating MSIHANDLE (235) of type 790531 for thread 4844
MSI (c) (10:EC) [00:42:19:140]: Closing MSIHANDLE (235) of type 790531 for thread 4844
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (38:9C) [00:42:19:141]: Note: 1: 2205 2: 3: Patch
MSI (s) (38:9C) [00:42:19:141]: Note: 1: 2205 2: 3: Condition
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'C:\'.
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Modifying SHORTCUTDIR property. Its current value is 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET\ESET NOD32 Antivirus'. Its new value: 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET\ESET NOD32 Antivirus\'.
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Modifying APPDATADIR property. Its current value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus'. Its new value: 'C:\ProgramData\ESET\ESET NOD32 Antivirus\'.
MSI (s) (38:9C) [00:42:19:141]: PROPERTY CHANGE: Adding InstallerDIR property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\Installer\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding UpdfilesDIR property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding SupportRequestsDir property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\SupportRequests\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding StatsDir property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\Stats\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding OldfilesDir property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\Oldfiles\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding LogsDir property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\Logs\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding eScanDir property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\Logs\eScan\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding LicenseDir property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\License\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding CharonDir property. Its value is 'C:\ProgramData\ESET\ESET NOD32 Antivirus\Charon\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Modifying APPDIR property. Its current value is 'C:\Program Files\ESET\ESET NOD32 Antivirus'. Its new value: 'C:\Program Files\ESET\ESET NOD32 Antivirus\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding HelpDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Help\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding DriversDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding Epfwtdr4DIR property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\epfwtdr4\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding EamonNTDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eamon4\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding EamonDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eamon\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding EpfwwfprDIR property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\epfwwfpr\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding EpfwtdirDIR property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\epfwtdir\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding EhdrvDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\ehdrv\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding EelamDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding DevmonDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\edevmon\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding EamonMiniFilterDir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eamonm\'.
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding x86Dir property. Its value is 'C:\Program Files\ESET\ESET NOD32 Antivirus\x86\'.
MSI (s) (38:9C) [00:42:19:142]: Target path resolution complete. Dumping Directory table...
MSI (s) (38:9C) [00:42:19:142]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: TARGETDIR , Object: C:\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: WindowsFolder , Object: C:\WINDOWS\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: ACTIVATION_LICENSE , Object: NULL
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: COBRANDING , Object: NULL
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: DESKTOPDIR , Object: C:\Users\Public\Desktop\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: SHORTCUTDIR , Object: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET\ESET NOD32 Antivirus\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: APPDATADIR , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: InstallerDIR , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\Installer\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: UpdfilesDIR , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: SupportRequestsDir , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\SupportRequests\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: StatsDir , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\Stats\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: OldfilesDir , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\Oldfiles\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: LogsDir , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\Logs\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: eScanDir , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\Logs\eScan\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: LicenseDir , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\License\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: CharonDir , Object: C:\ProgramData\ESET\ESET NOD32 Antivirus\Charon\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: ProgramFiles64Folder , Object: C:\Program Files\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: MODULEDIR , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Modules\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: APPDIR , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: HelpDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Help\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: DriversDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: Epfwtdr4DIR , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\epfwtdr4\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: EamonNTDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eamon4\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: EamonDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eamon\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: EpfwwfprDIR , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\epfwwfpr\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: EpfwtdirDIR , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\epfwtdir\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: EhdrvDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\ehdrv\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: EelamDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: DevmonDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\edevmon\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: EamonMiniFilterDir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eamonm\
MSI (s) (38:9C) [00:42:19:142]: Dir (target): Key: x86Dir , Object: C:\Program Files\ESET\ESET NOD32 Antivirus\x86\
MSI (s) (38:9C) [00:42:19:142]: PROPERTY CHANGE: Adding INSTALLLEVEL property. Its value is '1'.
MSI (s) (38:9C) [00:42:19:142]: Note: 1: 2205 2: 3: MsiAssembly
MSI (s) (38:9C) [00:42:19:142]: Note: 1: 2228 2: 3: MsiAssembly 4: SELECT `MsiAssembly`.`Attributes`, `MsiAssembly`.`File_Application`, `MsiAssembly`.`File_Manifest`, `Component`.`KeyPath` FROM `MsiAssembly`, `Component` WHERE `MsiAssembly`.`Component_` = `Component`.`Component` AND `MsiAssembly`.`Component_` = ?
Action start 00:42:19: CostFinalize.
Code:
ATTFilter >>>>>>>>>>>>>>>>>>>>>>> BEGIN >>>>>>>>>>>>>>>>>>>>>>>
[2017.02.10 22:49:29] BTS inf Command Line: "C:\Users\DRAGON~1\AppData\Local\Temp\eset\bts.session\{02D83BBE-2882-CF3B-692C-C8E9BD2086E5}\eset_nod32_antivirus_live_installer.exe" --bts-container 7312 "C:\Users\Dragonfly\Desktop\eset_nod32_antivirus_live_installer.exe"
[2017.02.10 22:49:29] BTS inf Instance lock successfully acquired.
[2017.02.10 22:49:29] BTS inf Running Product: ESET Live Installer 10.0.19.0
[2017.02.10 22:49:29] BTS inf ENTERING sequence 'entry'.
[2017.02.10 22:49:29] BTS inf TASK: Dumping file 'Plugin.cab'.
[2017.02.10 22:49:29] BTS inf TASK: Dumping file 'Core.cab'.
[2017.02.10 22:49:29] BTS inf TASK: Dumping file 'ResMain.cab'.
[2017.02.10 22:49:29] BTS inf TASK: Dumping file 'ResLiveInstaller.cab'.
[2017.02.10 22:49:29] BTS inf TASK: Dumping file 'cfg.xml'.
[2017.02.10 22:49:29] BTS inf TASK: Dumping file 'eguiDistributor.dll'.
[2017.02.10 22:49:29] BTS inf TASK: Dumping file 'dpkg.xml'.
[2017.02.10 22:49:29] BTS inf TASK: Extracting file 'Core.cab'.
[2017.02.10 22:49:29] BTS inf TASK: Extracting file 'Plugin.cab'.
[2017.02.10 22:49:29] BTS inf TASK: Extracting file 'ResMain.cab'.
[2017.02.10 22:49:30] BTS inf TASK: Extracting file 'ResLiveInstaller.cab'.
[2017.02.10 22:49:30] BTS inf TASK: Checking integrity of file 'BootHelper.exe'.
[2017.02.10 22:49:30] BTS inf TASK: Checking integrity of file 'sciter-x.dll'.
[2017.02.10 22:49:30] BTS inf TASK: Checking integrity of file 'plgSciterBase.dll'.
[2017.02.10 22:49:30] BTS inf TASK: Checking integrity of file 'plgLiveInstaller.dll'.
[2017.02.10 22:49:30] BTS inf TASK: Executing sequence 'eli'.
[2017.02.10 22:49:30] BTS inf ENTERING sequence 'eli'.
[2017.02.10 22:49:30] BTS inf TASK: Executing file 'BootHelper.exe'.
[2017.02.10 22:49:30] BTS inf TASK: Loading library 'sciter-x.dll'.
[2017.02.10 22:49:30] BTS inf TASK: Loading library 'plgSciterBase.dll'.
[2017.02.10 22:49:30] BTS inf TASK: Loading library 'plgLiveInstaller.dll'.
[2017.02.10 22:49:31] BTS inf TASK: Calling library function 'plgSciterBase.dll!PluginExtProc'.
[2017.02.10 22:49:31] BTS inf TASK: Calling library function 'plgLiveInstaller.dll!PluginExtProc'.
[2017.02.10 22:49:31] BTS inf TASK: Calling library function 'plgSciterBase.dll!PluginExtProc'.
[2017.02.10 22:49:31] ELI inf Versioncheck thread started.
[2017.02.10 22:49:31] ELI inf Reading unauthenticated attribute.
[2017.02.10 22:49:31] ELI inf Unauthenticated attribute not present or empty.
[2017.02.10 23:42:17] ELI inf Reading unauthenticated attribute.
[2017.02.10 23:42:17] ELI inf Unauthenticated attribute not present or empty.
[2017.02.10 23:42:50] ELI inf Installation finished successfully.
[2017.02.10 23:42:58] BTS inf TASK: Calling library function 'plgLiveInstaller.dll!PluginExtProc'.
[2017.02.10 23:42:58] BTS inf Changing Return Code to 0x00000000 (0).
[2017.02.10 23:42:58] BTS inf TASK: Calling library function 'plgSciterBase.dll!PluginExtProc'.
[2017.02.10 23:42:58] BTS inf TASK: Unloading library 'plgLiveInstaller.dll'.
[2017.02.10 23:42:58] BTS inf TASK: Unloading library 'plgSciterBase.dll'.
[2017.02.10 23:42:58] BTS inf LEAVING sequence 'eli'.
[2017.02.10 23:42:58] BTS inf LEAVING sequence 'entry'.
[2017.02.10 23:42:59] BTS inf The final Return Code is 0x00000000 (0).
>>>>>>>>>>>>>>>>>>>>>>>> END >>>>>>>>>>>>>>>>>>>>>>>>
|
![]() |
| Themen zu eset sysinspektor und gmer finden rootkits, diverse prozesse |
| anschluss, au_.exe, avast, diverse, down, eset sysinspektor, explorer.exe, gmerrootkitscan, google, helper, laptop, logfiles, microsoft, programme, prozess, prozesse, registry, rootkit, scan, secure, server, shutdown, software, svchost.exe, system, system32, temp, wmi |