FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-02-2021 01
Ran by Baal (administrator) on WIN-GPE7CHGD8F4 (MEDION E2050 2391) (09-02-2021 14:26:33)
Running from C:\Users\Administrator\Downloads
Loaded Profiles: Baal
Platform: Windows 10 Pro Version 20H2 19042.685 (X64) Language: Englisch (Vereinigte Staaten)
Default browser: Opera
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\9.2.2.2501\AdskLicensingService\AdskLicensingService.exe
(Bitsum LLC -> Bitsum LLC) C:\Program Files\Process Lasso\ProcessGovernor.exe
(Bitsum LLC -> Bitsum LLC) C:\Program Files\Process Lasso\ProcessLasso.exe
(Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(Glarysoft LTD -> Glarysoft Ltd) [File not signed] C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe
(Glarysoft LTD -> Glarysoft Ltd) [File not signed] C:\Program Files (x86)\Glarysoft\Malware Hunter\mhtray.exe
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glarysoft\Malware Hunter\Cloudscan\MHCloudSvc.exe
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glarysoft\Malware Hunter\PCBooster.exe
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glarysoft\Malware Hunter\QuickSearch.exe
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\MemfilesService.exe
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\x64ProcessAssistSvc.exe
(Henry++) [File not signed] C:\Program Files\Mem Reduct\memreduct.exe
(Locktime Software s.r.o. -> Locktime Software) C:\Program Files\Locktime Software\NetLimiter 4\NLSvc.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Malwarebytes Inc -> MalwareBytes) C:\Windows\System32\config\systemprofile\AppData\LocalLow\IGDump\wqqjronxecuhixisskyzijykfxjwjsnf\ig.exe
(McAfee, Inc. -> McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc. -> McAfee, LLC) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc. -> McAfee, LLC) C:\Windows\System32\mfevtps.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\CSP\3.9.121.0\McCSPServiceHost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHOST.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe <2>
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\ModuleCore\ProtectedModuleHost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\VSCore_20_9\mcapexe.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\MAT\McPvTray.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NETGEAR -> ) C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvaei.inf_amd64_8024d97d167d7438\Display.NvContainer\NVDisplay.Container.exe <2>
(Opera Software AS -> Opera Software) C:\Users\Administrator\AppData\Local\Programs\Opera\73.0.3856.344\opera.exe <17>
(Opera Software AS -> Opera Software) C:\Users\Administrator\AppData\Local\Programs\Opera\73.0.3856.344\opera_crashreporter.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(VMware, Inc. -> ) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [664872 2020-03-04] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [119000 2020-11-18] (VMware, Inc. -> VMware, Inc.)
HKLM-x32\...\Run: [Autodesk Genuine Service ] => C:\Users\Administrator\AppData\Local\Programs\Autodesk\Genuine Service\GenuineService.exe [1077864 2020-01-02] (Autodesk, Inc. -> Autodesk)
HKLM-x32\...\Run: [MalTray] => C:\Program Files (x86)\Glarysoft\Malware Hunter\mhtray.exe [982448 2021-02-09] (Glarysoft LTD -> Glarysoft Ltd) [File not signed]
HKLM\...\Policies\Explorer: [SettingsPageVisibility] hide:maps;cortana;cortana-language;windowsinsider;windowsinsider-optin;windowsdefender;findmydevice
HKLM\...\Policies\Explorer: [DisableThumbnails] 0
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Administrator\AppData\Local\Microsoft\Teams\Update.exe [2453688 2021-01-27] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [Mem Reduct] => C:\Program Files\Mem Reduct\memreduct.exe [309248 2019-02-10] (Henry++) [File not signed]
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [NetLimiter] => C:\Program Files\Locktime Software\NetLimiter 4\nlclientapp.exe [82336 2019-07-16] (Locktime Software s.r.o. -> Locktime Software)
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32440376 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [Discord] => C:\Users\Administrator\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [Opera Browser Assistant] => C:\Users\Administrator\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3366040 2021-01-14] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [Spotify] => C:\Users\Administrator\AppData\Roaming\Spotify\Spotify.exe [25972968 2021-01-28] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3412696 2021-02-08] (Valve -> Valve Corporation)
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Policies\Explorer: [DisableThumbnails] 0
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {18ACF0AA-B6A1-4F08-8436-271B0CCB0C1E} - System32\Tasks\McAfee\McAfee DAT Built in test => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.0.12.663\mcdatrep.exe [1889696 2021-01-27] (McAfee, Inc. -> McAfee, LLC.)
Task: {20B9EB87-C1CF-4C44-9141-E86132B99C6A} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [993400 2020-10-30] (McAfee, LLC -> McAfee, LLC)
Task: {265F1BFC-573C-4DF5-A8FD-1D10B437C381} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [26913848 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {2D2DC7D0-1E13-4CD3-930F-8C7AB677DC9E} - System32\Tasks\GMHAutoScan => C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe [2441136 2021-02-09] (Glarysoft LTD -> Glarysoft Ltd) [File not signed]
Task: {30AFC6CE-2FAB-4A52-9CAB-4745932BF9AA} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [993400 2020-10-30] (McAfee, LLC -> McAfee, LLC)
Task: {3BDA7B93-7CA4-49C2-87AC-DCE6E23BA69A} - System32\Tasks\Opera scheduled Autoupdate 1611763329 => C:\Users\Administrator\AppData\Local\Programs\Opera\launcher.exe [1776280 2021-01-14] (Opera Software AS -> Opera Software)
Task: {4B4418FE-4644-4A8D-9CD4-AA3FE95D1105} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22993288 2021-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {4D769CD0-4EDF-489F-AB89-5084EA3817A8} - System32\Tasks\Process Lasso Management Console (GUI) => C:\Program Files\Process Lasso\processlasso.exe [1627544 2020-07-08] (Bitsum LLC -> Bitsum LLC)
Task: {55812086-D6D1-4973-8D3C-851291442941} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {57848288-2ADE-444C-A084-9C6033711D0C} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {600FFD5B-E6E5-42FF-ABC4-817B21AA72D8} - System32\Tasks\Uninstaller_SkipUac_Baal => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [6594048 2021-01-06] (IObit) [File not signed]
Task: {639E5A12-04A3-43FB-A850-3ECF3D9FE10F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5199272 2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D17C0DA-69ED-4FAE-AE73-134C31473D7D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5199272 2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {70FA7427-862F-4482-8DCB-7FA5CEC5C707} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22993288 2021-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {84C9F231-8CBB-4256-8921-88A75082CE77} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8F05EF4B-55C4-4760-B16B-BD822BFA7BAC} - System32\Tasks\Process Lasso Core Engine Only => C:\Program Files\Process Lasso\processgovernor.exe [1165208 2020-07-08] (Bitsum LLC -> Bitsum LLC)
Task: {9047CA02-5DEB-45D0-951A-716D18F5A796} - System32\Tasks\GMHSkipUAC => C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe [2441136 2021-02-09] (Glarysoft LTD -> Glarysoft Ltd) [File not signed]
Task: {92CD423D-1E56-4FD0-9903-76109D260AF9} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\1.5.132\DADUpdater.exe [4054696 2021-01-18] (McAfee, LLC -> McAfee, LLC)
Task: {94F27786-57AF-4BE2-BF31-B6CA4FF68CC0} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {99B00CEC-5B7C-4462-AD1D-77993B6B8C44} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4623976 2020-10-19] (McAfee, LLC -> McAfee, LLC)
Task: {A143C432-668D-46EE-A8FF-FF9516E424C3} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B16CCB4B-A293-4665-92D5-C1F6D36386AB} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B5106A81-119A-426B-981C-F0DE3460A717} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142184 2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {B67449F4-31C2-4ED7-BF00-9F9926113981} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142184 2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {C3BD96AC-480B-47D5-B0D9-C336B19241B3} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [736704 2020-11-03] (McAfee, LLC -> McAfee, LLC)
Task: {C8A2E27B-6506-4CFD-BC47-7396A8A6EA93} - System32\Tasks\Opera scheduled assistant Autoupdate 1611763334 => C:\Users\Administrator\AppData\Local\Programs\Opera\launcher.exe [1776280 2021-01-14] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Administrator\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {DECE4499-7C21-4709-BC5E-276ACF6997FF} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {EB5F88E8-8A83-4CE6-BAB5-4D41837F959D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {EBFDAC75-528C-4874-A841-41A500D4107C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301176 2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F298F764-E7A5-494B-A2C9-C12B356BDD9C} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [754104 2021-01-07] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {F61C054E-D337-4DA3-8D18-308E64D3AF3F} - System32\Tasks\StartIsBack health check => C:\Program Files (x86)\StartIsBack\startscreen.exe [70984 2020-12-24] (Stanislav Zinukhov -> www.startisback.com)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{07d491a1-f939-4cac-b1b5-cbd0682a4ca2}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{d60cc1f7-7cd6-4872-8a16-c89a0b00708f}: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF HKLM\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSKHKLM => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2021-01-27] [Legacy] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2020-11-04] (McAfee, LLC -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
Opera:
=======
OPR Profile: C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable [2021-02-09]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-02-09]
OPR Extension: (uBlock Origin) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2021-01-27]
StartMenuInternet: (HKU\S-1-5-21-1186616812-1126677590-2245216935-500) OperaStable - "C:\Users\Administrator\AppData\Local\Programs\Opera\Launcher.exe"
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1046904 2020-03-04] (Autodesk, Inc. -> Autodesk Inc.)
R2 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [16926864 2019-08-08] (Autodesk, Inc. -> Autodesk)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8902024 2021-01-22] (Microsoft Corporation -> Microsoft Corporation)
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [287720 2020-12-31] (NVIDIA Corporation -> NVIDIA)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-02-08] (Malwarebytes Inc -> Malwarebytes)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [958216 2021-02-05] (McAfee, LLC -> McAfee, LLC)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_20_9\McApExe.exe [779592 2020-11-04] (McAfee, LLC -> McAfee, LLC)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\3.9.121.0\\McCSPServiceHost.exe [2785184 2020-11-04] (McAfee, LLC -> McAfee, LLC)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [646248 2020-09-14] (McAfee, Inc. -> McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [646248 2020-09-14] (McAfee, Inc. -> McAfee, LLC)
R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [646248 2020-09-14] (McAfee, Inc. -> McAfee, LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1589976 2020-10-30] (McAfee, LLC -> McAfee, LLC)
R2 nlsvc; C:\Program Files\Locktime Software\NetLimiter 4\NLSvc.exe [309664 2019-07-16] (Locktime Software s.r.o. -> Locktime Software)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [4215368 2020-10-19] (McAfee, LLC -> McAfee, LLC)
R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15221296 2020-11-18] (VMware, Inc. -> )
R2 WSWNA3100; C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [316120 2014-08-19] (NETGEAR -> )
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvaei.inf_amd64_8024d97d167d7438\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvaei.inf_amd64_8024d97d167d7438\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-10-04] (Bluestack Systems, Inc -> Bluestack System Inc.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [75704 2020-09-22] (McAfee, Inc. -> McAfee, LLC)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153312 2021-02-08] (Malwarebytes Corporation -> Malwarebytes)
S3 GUMHFilters; C:\Program Files (x86)\Glarysoft\Malware Hunter\Native\winxp_x64\GUMHFilter.sys [41232 2020-11-23] (Glarysoft LTD -> Glarysoft Ltd)
S1 GUSBootStartup; C:\Windows\System32\drivers\GUSBootStartup.sys [28936 2021-02-09] (Glarysoft LTD -> Glarysoft Ltd)
R3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [218960 2020-05-26] (McAfee, LLC -> McAfee, Inc.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [220600 2021-02-08] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2021-02-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [198248 2021-02-09] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [77496 2021-02-09] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248992 2021-02-08] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [142440 2021-02-09] (Malwarebytes Inc -> Malwarebytes)
R2 McPvDrv; C:\Windows\system32\drivers\McPvDrv.sys [89096 2020-05-26] (McAfee, LLC -> McAfee, LLC)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [531896 2020-09-22] (McAfee, Inc. -> McAfee, LLC)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [385464 2020-09-22] (McAfee, Inc. -> McAfee, LLC)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [85944 2020-09-22] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, LLC)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [522168 2020-09-22] (McAfee, Inc. -> McAfee, LLC)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [1019832 2020-09-22] (McAfee, Inc. -> McAfee, LLC)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [603072 2020-09-17] (McAfee, Inc. -> McAfee LLC.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [107968 2020-09-17] (McAfee, Inc. -> McAfee LLC.)
R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [116664 2020-09-22] (McAfee, Inc. -> McAfee, LLC)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [252344 2020-09-22] (McAfee, Inc. -> McAfee, LLC)
R0 nldrv; C:\Windows\System32\drivers\nldrv.sys [178944 2019-07-16] (Locktime Software s.r.o. -> Locktime Software)
S3 NPF; C:\Windows\system32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc. -> CACE Technologies, Inc.)
R0 SCMNdisP; C:\Windows\System32\DRIVERS\scmndisp.sys [25312 2007-01-20] (NETGEAR -> Windows (R) Codename Longhorn DDK provider)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [204544 2020-11-11] (RH Software Ltd -> Ray Hinchliffe)
R1 vmkbd3; C:\Windows\system32\DRIVERS\vmkbd.sys [60344 2020-11-18] (VMware, Inc. -> VMware, Inc.)
R2 VMnetBridge; C:\Windows\system32\DRIVERS\vmnetbridge.sys [68544 2020-11-18] (VMware, Inc. -> VMware, Inc.)
R0 vsock; C:\Windows\System32\DRIVERS\vsock.sys [105912 2020-08-11] (VMware, Inc. -> VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-x64.sys [54592 2020-08-12] (VMware, Inc. -> VMware, Inc.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
U3 cbdhsvc_59ed3; no ImagePath
U4 Sense; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-02-09 14:12 - 2021-02-09 14:12 - 000077496 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2021-02-09 14:11 - 2021-02-09 14:11 - 000198248 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2021-02-09 14:11 - 2021-02-09 14:11 - 000142440 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2021-02-09 14:08 - 2021-02-09 14:27 - 000025786 _____ C:\Users\Administrator\Downloads\FRST.txt
2021-02-09 14:06 - 2021-02-09 14:27 - 000000000 ____D C:\FRST
2021-02-09 14:05 - 2021-02-09 14:05 - 002297344 _____ (Farbar) C:\Users\Administrator\Downloads\FRST64.exe
2021-02-09 14:04 - 2021-02-09 14:04 - 000000000 ___HD C:\$GlaryQuarantine
2021-02-09 13:00 - 2021-02-09 13:00 - 000003826 _____ C:\Windows\system32\Tasks\GMHAutoScan
2021-02-09 12:44 - 2021-02-09 14:13 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\GlarySoft
2021-02-09 12:43 - 2021-02-09 12:43 - 000028936 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUSBootStartup.sys
2021-02-09 12:43 - 2021-02-09 12:43 - 000003060 _____ C:\Windows\system32\Tasks\GMHSkipUAC
2021-02-09 12:43 - 2021-02-09 12:43 - 000000000 ____D C:\Program Files (x86)\Glarysoft
2021-02-09 12:26 - 2021-02-09 12:26 - 000000000 ___HD C:\Users\Administrator\MicrosoftEdgeBackups
2021-02-09 12:11 - 2021-02-09 12:22 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\IObit
2021-02-09 12:11 - 2021-02-09 12:11 - 000002950 _____ C:\Windows\system32\Tasks\Uninstaller_SkipUac_Baal
2021-02-09 12:11 - 2021-02-09 12:11 - 000001338 _____ C:\Users\Administrator\Desktop\IObit Uninstaller.lnk
2021-02-09 12:11 - 2021-02-09 12:11 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\IObit
2021-02-09 12:11 - 2021-02-09 12:11 - 000000000 ____D C:\Program Files (x86)\IObit
2021-02-09 12:07 - 2021-02-09 12:26 - 000000000 ____D C:\Users\Administrator\AppData\Local\MicrosoftEdge
2021-02-08 22:38 - 2021-02-08 22:39 - 000000000 ____D C:\Users\Administrator\Desktop\NosVipClient
2021-02-08 21:45 - 2021-02-08 22:38 - 272431467 _____ C:\Users\Administrator\Downloads\NosVipClient.zip
2021-02-08 17:12 - 2021-02-08 17:12 - 000000000 ____D C:\Users\Administrator\AppData\Local\OO Software
2021-02-08 13:50 - 2021-02-08 13:50 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
2021-02-08 13:00 - 2020-11-11 11:17 - 000204544 _____ (Ray Hinchliffe) C:\Windows\system32\Drivers\SIVX64.sys
2021-02-08 12:51 - 2021-01-15 20:54 - 000000000 ____D C:\Users\Administrator\Desktop\integrity_verification
2021-02-08 12:51 - 2021-01-15 19:51 - 000000000 ____D C:\Users\Administrator\Desktop\tron
2021-02-08 12:44 - 2021-02-08 12:51 - 544388001 _____ (Igor Pavlov) C:\Users\Administrator\Downloads\Tron v11.1.6 (2021-01-15).exe
2021-02-08 12:41 - 2021-02-08 12:41 - 000220600 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2021-02-08 12:28 - 2021-02-08 12:53 - 000001572 _____ C:\Windows\SysWOW64\tmp.reg
2021-02-08 12:28 - 2021-02-08 12:53 - 000000691 _____ C:\Users\Administrator\AppData\Roaming\GetValue.vbs
2021-02-08 12:28 - 2021-02-08 12:53 - 000000035 _____ C:\Users\Administrator\AppData\Roaming\SetValue.bat
2021-02-08 12:28 - 2021-02-08 12:53 - 000000000 _____ C:\Windows\SysWOW64\tmp.txt
2021-02-08 12:22 - 2021-02-08 12:53 - 000000000 ____D C:\Users\Administrator\Downloads\SmitfraudFix
2021-02-08 12:22 - 2009-06-02 11:17 - 000075776 _____ C:\Windows\SysWOW64\WS2Fix.exe
2021-02-08 12:22 - 2008-12-12 01:57 - 000078336 _____ (S!Ri.URZ) C:\Windows\SysWOW64\Agent.OMZ.Fix.exe
2021-02-08 12:22 - 2008-11-29 18:58 - 000082944 _____ (S!Ri.URZ) C:\Windows\SysWOW64\IEDFix.C.exe
2021-02-08 12:22 - 2008-10-01 15:51 - 000087552 _____ (S!Ri.URZ) C:\Windows\SysWOW64\VACFix.exe
2021-02-08 12:22 - 2008-09-20 12:45 - 000080384 _____ (S!Ri.URZ) C:\Windows\SysWOW64\o4Patch.exe
2021-02-08 12:22 - 2008-08-18 12:19 - 000082432 _____ (S!Ri.URZ) C:\Windows\SysWOW64\404Fix.exe
2021-02-08 12:22 - 2008-05-18 21:40 - 000082944 _____ (S!Ri.URZ) C:\Windows\SysWOW64\IEDFix.exe
2021-02-08 12:22 - 2007-09-06 00:22 - 000289144 _____ (S!Ri) C:\Windows\SysWOW64\VCCLSID.exe
2021-02-08 12:22 - 2006-12-01 06:20 - 000079360 _____ (SteelWerX) C:\Windows\SysWOW64\swxcacls.exe
2021-02-08 12:22 - 2006-08-29 19:43 - 000135168 _____ (SteelWerX) C:\Windows\SysWOW64\swreg.exe
2021-02-08 12:22 - 2006-04-27 17:49 - 000288417 _____ (S!Ri) C:\Windows\SysWOW64\SrchSTS.exe
2021-02-08 12:22 - 2006-01-09 10:36 - 000040960 _____ C:\Windows\SysWOW64\swsc.exe
2021-02-08 12:22 - 2004-07-31 18:50 - 000051200 _____ C:\Windows\SysWOW64\dumphive.exe
2021-02-08 12:22 - 2003-06-05 21:13 - 000053248 _____ (hxxp://www.beyondlogic.org) C:\Windows\SysWOW64\Process.exe
2021-02-08 12:13 - 2021-02-08 12:13 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbam
2021-02-08 12:12 - 2021-02-08 12:41 - 000248992 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2021-02-08 12:12 - 2021-02-08 12:11 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2021-02-08 12:12 - 2021-02-08 12:11 - 000019912 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2021-02-07 18:23 - 2021-02-07 18:23 - 000001128 _____ C:\Users\Administrator\Desktop\RubyTale.exe - Verknüpfung.lnk
2021-02-07 10:18 - 2021-02-07 10:18 - 000002141 _____ C:\Users\Administrator\Desktop\Taoists.lnk
2021-02-05 23:57 - 2021-02-06 00:03 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\NosWings
2021-02-05 23:54 - 2021-02-05 23:55 - 000000000 ____D C:\Program Files\dotnet
2021-02-05 23:53 - 2021-02-05 23:53 - 000002106 _____ C:\Users\Administrator\Desktop\NosWings Launcher.exe - Verknüpfung.lnk
2021-02-05 11:34 - 2021-02-05 11:34 - 000131323 _____ C:\Users\Administrator\Downloads\Geschichte_1_BRD_Zusammenbruchgesellschaft_Deutschland 1945.pdf
2021-02-05 08:35 - 2021-02-05 08:35 - 000416427 _____ C:\Users\Administrator\Downloads\01-AB GG-Preis.pdf
2021-02-05 08:35 - 2021-02-05 08:35 - 000121993 _____ C:\Users\Administrator\Downloads\02_ÜA Marktgleichgewicht.pdf
2021-02-05 08:34 - 2021-02-05 08:34 - 000140889 _____ C:\Users\Administrator\Downloads\Lösungen_NachfrageEL_29.01.2021 (1).pdf
2021-02-04 20:52 - 2021-02-04 20:53 - 029352480 _____ (TeamViewer Germany GmbH) C:\Users\Administrator\Downloads\TeamViewer_Setup.exe
2021-02-04 20:25 - 2021-02-04 20:25 - 000000000 ____D C:\Windows\SysWOW64\BTPLConfig
2021-02-04 11:47 - 2021-02-04 12:18 - 000001604 _____ C:\Users\Administrator\Desktop\Neues Textdokument (7).txt
2021-02-04 11:44 - 2021-02-04 11:44 - 000225524 _____ C:\Users\Administrator\Downloads\Einzelunternehmen.zip
2021-02-04 11:44 - 2021-02-04 11:44 - 000225524 _____ C:\Users\Administrator\Desktop\Einzelunternehmen.zip
2021-02-04 11:44 - 2021-02-04 10:44 - 000000000 ____D C:\Users\Administrator\Desktop\Einzelunternehmen
2021-02-04 09:40 - 2021-02-04 09:40 - 000112529 _____ C:\Users\Administrator\Downloads\19_BSV_AG.pdf
2021-02-04 08:42 - 2021-02-04 08:43 - 006455520 _____ (EnigmaSoft Limited) C:\Users\Administrator\Downloads\SpyHunter-Installer.exe
2021-02-04 08:42 - 2021-02-04 08:42 - 002086424 _____ (Malwarebytes) C:\Users\Administrator\Downloads\MBSetup-092170.092170-consumer.exe
2021-02-04 08:27 - 2021-02-04 08:27 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbarw
2021-02-04 08:24 - 2021-02-08 12:25 - 000000000 ____D C:\Program Files\Malwarebytes
2021-02-03 21:25 - 2021-02-09 12:15 - 000000000 ____D C:\Windows\ShellNew
2021-02-03 21:23 - 2021-02-03 21:24 - 012298408 _____ (AutoIt Team) C:\Users\Administrator\Downloads\autoit-v3-setup.exe
2021-02-03 21:16 - 2021-02-03 21:16 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Pecado
2021-02-03 18:02 - 2021-02-03 18:02 - 000000000 ____D C:\Users\Administrator\Desktop\Windows
2021-02-03 16:22 - 2021-02-07 18:47 - 000000000 ____D C:\Users\Administrator\Desktop\things
2021-02-03 14:33 - 2021-02-03 14:33 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\dnSpy
2021-02-03 14:28 - 2021-02-03 14:32 - 000003875 _____ C:\Users\Administrator\Desktop\settings.xml
2021-02-03 14:27 - 2021-02-03 14:27 - 001301159 _____ C:\Users\Administrator\Downloads\Extreme.Injector.v3.7.3.-.by.master131.rar
2021-02-03 14:23 - 2021-02-03 11:43 - 001742336 _____ () C:\Users\Administrator\Desktop\EWSF.dll
2021-02-03 14:23 - 2020-02-14 21:36 - 001686016 _____ C:\Users\Administrator\Desktop\Main.dll
2021-02-03 14:22 - 2021-02-03 14:23 - 000000000 ____D C:\Users\Administrator\Desktop\EWSF EMM
2021-02-03 14:22 - 2021-02-03 14:22 - 004461471 _____ C:\Users\Administrator\Downloads\multiDLL injector.rar
2021-02-03 14:12 - 2021-02-03 14:12 - 000001128 _____ C:\Users\Administrator\Desktop\EastMile.exe - Verknüpfung.lnk
2021-02-03 14:06 - 2021-02-03 14:16 - 000000000 ____D C:\Users\Administrator\Desktop\NosByte - Kopie
2021-02-03 14:03 - 2021-02-03 14:03 - 000000000 ____D C:\Users\Administrator\AppData\Local\dnSpy
2021-02-03 14:02 - 2021-02-03 14:03 - 000000000 ____D C:\Users\Administrator\Downloads\dnSpy-net-win64
2021-02-03 14:01 - 2021-02-03 14:02 - 085810042 _____ C:\Users\Administrator\Downloads\dnSpy-net-win64.zip
2021-02-03 13:57 - 2021-02-03 13:57 - 001687914 _____ C:\Users\Administrator\Desktop\EWSF.EWS
2021-02-03 13:53 - 2021-02-08 13:52 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Notepad++
2021-02-03 13:53 - 2021-02-03 14:21 - 000000000 ____D C:\Users\Administrator\Desktop\EWSF NV
2021-02-03 13:53 - 2021-02-03 13:54 - 000000000 ____D C:\Users\Administrator\Desktop\EWSF EM
2021-02-03 13:53 - 2021-02-03 13:53 - 000000000 ____D C:\Program Files\Notepad++
2021-02-03 13:52 - 2021-02-03 13:53 - 002846896 _____ C:\Users\Administrator\Downloads\npp.7.Installer.x64.exe
2021-02-03 13:52 - 2021-02-03 13:52 - 000001586 _____ C:\Users\Administrator\Desktop\EastMile.exe - Verknüpfung (3).lnk
2021-02-03 13:47 - 2021-02-08 22:49 - 000020236 _____ C:\Users\Administrator\Desktop\NT.txt
2021-02-03 13:44 - 2021-02-03 13:44 - 000001218 _____ C:\Users\Administrator\Desktop\EastMile.exe - Verknüpfung (2).lnk
2021-02-03 13:42 - 2021-02-08 16:43 - 000000728 _____ C:\Users\Administrator\Desktop\Manager.exe - Verknüpfung.lnk
2021-02-03 13:37 - 2020-10-10 11:00 - 003492936 _____ (Entwell) C:\Users\Administrator\Desktop\EastMile.exe
2021-02-03 11:40 - 2021-02-09 12:15 - 000000000 ____D C:\Program Files (x86)\Eastmile Client
2021-02-03 11:38 - 2021-02-03 11:38 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Eastmile
2021-02-03 11:27 - 2021-02-03 11:37 - 085181928 _____ (Eastmile) C:\Users\Administrator\Downloads\EastmileSetup.exe
2021-02-03 10:13 - 2021-02-03 10:13 - 000000000 ____D C:\Users\Administrator\Documents\vroid
2021-02-03 10:13 - 2021-02-03 10:13 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\pixiv
2021-02-03 10:10 - 2021-02-03 10:12 - 428566936 _____ (pixiv Inc. ) C:\Users\Administrator\Downloads\VRoidStudio-v0.12.1-win.exe
2021-02-03 08:54 - 2021-02-03 08:54 - 000000000 _____ C:\Users\Administrator\Desktop\Neues Textdokument (6).txt
2021-02-03 08:33 - 2021-02-04 15:14 - 000011500 _____ C:\Users\Administrator\Desktop\Microsoft Excel-Arbeitsblatt (neu).xlsx
2021-02-02 13:22 - 2021-02-02 13:22 - 2966290432 _____ C:\Users\Administrator\Downloads\Unconfirmed 618904.crdownload
2021-02-02 11:28 - 2021-02-02 11:28 - 000142263 _____ C:\Users\Administrator\Downloads\18_+£b Maschinenstd.pdf
2021-02-02 05:28 - 2021-02-02 05:28 - 000000000 ____D C:\Users\Andere\AppData\Local\PeerDistRepub
2021-02-02 02:13 - 2021-02-02 02:13 - 045092380 _____ C:\Users\Andere\Downloads\SpaceHDR#1.zip
2021-02-02 02:05 - 2021-02-02 02:05 - 045133648 _____ C:\Users\Andere\Downloads\dirty_concrete_4k_jpg.zip
2021-02-01 23:01 - 2021-02-01 23:01 - 000000000 ____D C:\Users\Administrator\Documents\xgen
2021-02-01 22:57 - 2021-02-01 22:59 - 000000000 ____D C:\Users\Administrator\Documents\maya
2021-02-01 22:57 - 2021-02-01 22:57 - 000000000 ____D C:\Users\Administrator\AppData\Local\AdSSO
2021-02-01 21:48 - 2021-02-01 21:48 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\.mono
2021-02-01 21:47 - 2021-02-01 21:47 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\miHoYo
2021-02-01 20:42 - 2021-02-01 20:42 - 000000000 ____D C:\Users\Administrator\AppData\Local\miHoYo
2021-02-01 20:41 - 2021-02-07 09:57 - 000000000 ____D C:\Program Files\Genshin Impact
2021-02-01 20:41 - 2021-02-03 08:33 - 000001054 _____ C:\Users\Administrator\Desktop\Genshin Impact.lnk
2021-02-01 20:40 - 2021-02-01 20:41 - 124657792 _____ (miHoYo) C:\Users\Administrator\Downloads\GenshinImpact_install_20210122160343.exe
2021-02-01 18:10 - 2021-02-01 18:10 - 000000000 ____D C:\Users\Administrator\AppData\Local\Ghostrunner
2021-02-01 18:03 - 2021-02-01 18:03 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer
2021-02-01 18:03 - 2021-02-01 18:03 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2021-02-01 18:03 - 2021-02-01 18:03 - 000000000 ____D C:\Program Files (x86)\MSBuild
2021-02-01 18:02 - 2021-02-01 18:02 - 000000000 ____D C:\Program Files\Reference Assemblies
2021-02-01 18:02 - 2021-02-01 18:02 - 000000000 ____D C:\Program Files\MSBuild
2021-02-01 17:04 - 2020-12-30 03:56 - 000000000 ____D C:\Users\Administrator\Desktop\Ghostrunner.v32091.GOG
2021-02-01 12:23 - 2021-02-01 12:23 - 000483602 _____ C:\Users\Administrator\Downloads\OneDrive_1_1.2.2021.zip
2021-02-01 11:49 - 2021-02-03 18:38 - 000000471 _____ C:\Users\Administrator\Desktop\Neues Textdokument (5).txt
2021-02-01 11:23 - 2021-02-01 12:24 - 000223269 _____ C:\Users\Administrator\Desktop\17 BAB und Kostenträgerzeitblatt.pdf
2021-02-01 11:23 - 2021-02-01 12:24 - 000142263 _____ C:\Users\Administrator\Desktop\18_+£b Maschinenstd.pdf
2021-02-01 11:23 - 2021-02-01 12:24 - 000117624 _____ C:\Users\Administrator\Desktop\16_+ÜbKR.pdf
2021-02-01 11:01 - 2021-02-01 11:01 - 000119668 _____ C:\Users\Administrator\Downloads\SA1_FSJ_ Fa_Kö (1).pdf
2021-02-01 11:00 - 2021-02-01 11:00 - 000132066 _____ C:\Users\Administrator\Downloads\Argumente.pdf
2021-02-01 10:57 - 2021-02-01 10:57 - 000000000 ____D C:\Users\Administrator\Desktop\FSJ
2021-02-01 10:56 - 2021-02-01 10:56 - 000093439 _____ C:\Users\Administrator\Downloads\FSJ.zip
2021-02-01 09:39 - 2021-02-01 09:39 - 000140889 _____ C:\Users\Administrator\Downloads\Lösungen_NachfrageEL_29.01.2021.pdf
2021-02-01 08:10 - 2021-02-02 10:44 - 000000734 _____ C:\Users\Administrator\Desktop\Neues Textdokument (4).txt
2021-02-01 08:10 - 2021-02-01 08:04 - 000020013 _____ C:\Users\Administrator\Desktop\Exercise – Translation.pdf
2021-02-01 08:04 - 2021-02-01 08:04 - 000020013 _____ C:\Users\Administrator\Downloads\Exercise – Translation.pdf
2021-02-01 08:00 - 2021-02-01 08:00 - 015683242 _____ C:\Users\Administrator\Downloads\02 Aufgaben zu den Wahrscheinlichkeitsverteilungen.pdf
2021-01-31 19:07 - 2021-01-31 19:41 - 1063004405 _____ C:\Users\Administrator\Downloads\Ghostrunner.v32091.GOG.part1.rar
2021-01-31 19:07 - 2021-01-31 19:27 - 1063004405 _____ C:\Users\Administrator\Downloads\Ghostrunner.v32091.GOG.part2.rar
2021-01-31 19:07 - 2021-01-31 19:13 - 2540367956 _____ C:\Users\Administrator\Downloads\Ghostrunner.v32091.GOG.part3.rar
2021-01-31 17:01 - 2021-01-31 17:01 - 000150912 _____ C:\Users\Andere\Downloads\Extractinator.fbx
2021-01-31 16:03 - 2021-01-31 16:03 - 000000000 ____D C:\Users\Andere\Documents\xgen
2021-01-31 14:08 - 2021-01-31 14:08 - 000000000 _____ C:\Users\Administrator\Desktop\Neues Textdokument (3).txt
2021-01-31 12:52 - 2021-01-31 12:52 - 000006595 _____ C:\Users\Administrator\Desktop\Stunden.xlsx
2021-01-30 12:01 - 2021-01-30 12:01 - 000000000 ____D C:\Users\Administrator\Downloads\Mount.&.Blade.II.Bannerlord.Steam.Rip-InsaneRamZes
2021-01-30 08:45 - 2021-02-01 18:10 - 000000000 ____D C:\Users\Administrator\AppData\Local\UnrealEngine
2021-01-30 08:45 - 2021-01-30 08:45 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Goldberg SteamEmu Saves
2021-01-30 08:45 - 2021-01-30 08:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\COVOID20
2021-01-29 23:01 - 2021-01-29 23:01 - 000000000 ____D C:\Users\Andere\Downloads\licenses-da1fa3eec9cfd51cba59
2021-01-29 22:51 - 2021-01-29 22:51 - 000003719 _____ C:\Users\Andere\Downloads\licenses-da1fa3eec9cfd51cba59.zip
2021-01-29 22:50 - 2021-01-29 22:50 - 000000000 ____D C:\Users\Andere\Documents\Allegorithmic
2021-01-29 22:50 - 2021-01-29 22:50 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Allegorithmic
2021-01-29 22:50 - 2021-01-29 22:50 - 000000000 ____D C:\Users\Andere\AppData\Local\Allegorithmic
2021-01-29 22:34 - 2021-01-29 22:40 - 1546084360 _____ (Allegorithmic ) C:\Users\Andere\Downloads\Substance_Painter-7.1.0-804-msvc14-x64-standard.exe
2021-01-29 15:04 - 2021-01-29 15:31 - 419745637 _____ C:\Users\Administrator\Downloads\COVID.20.Early.Access.zip
2021-01-29 14:33 - 2021-01-29 14:33 - 002048790 _____ C:\Users\Administrator\Downloads\SpeedAutoClicker-v1.6.2.zip
2021-01-29 14:33 - 2021-01-29 14:33 - 000000000 ____D C:\Users\Administrator\AppData\Local\fabi.me
2021-01-29 14:13 - 2021-01-29 14:13 - 000000000 ____D C:\Users\Administrator\AppData\Local\DrvVideo
2021-01-29 12:45 - 2021-01-29 12:45 - 000000000 ____D C:\Users\Administrator\Documents\Benutzerdefinierte Office-Vorlagen
2021-01-29 12:43 - 2021-01-29 12:43 - 000208755 _____ C:\Users\Administrator\Downloads\SA1_FSJ_ Fa_Kö.pdf
2021-01-29 12:35 - 2021-01-29 12:35 - 000093423 _____ C:\Users\Administrator\Downloads\OneDrive_2_29.1.2021.zip
2021-01-29 12:14 - 2021-02-08 14:27 - 000000000 ____D C:\Program Files\Microsoft Office
2021-01-29 12:14 - 2021-01-29 12:14 - 000000000 ____D C:\Program Files\Microsoft Office 15
2021-01-29 11:44 - 2021-02-05 12:46 - 000006759 _____ C:\Users\Administrator\Desktop\Neues Textdokument (2).txt
2021-01-29 11:43 - 2021-01-29 11:43 - 000261729 _____ C:\Users\Administrator\Downloads\USA bis 1945_10_Die USA im Zweiten Weltkrieg_AB zum Film.pdf
2021-01-29 11:30 - 2021-02-02 13:16 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\files
2021-01-29 11:30 - 2021-01-29 11:30 - 000000000 ____D C:\Users\Administrator\AppData\Local\AdvinstAnalytics
2021-01-29 11:30 - 2021-01-29 11:30 - 000000000 ____D C:\Program Files (x86)\OInstall
2021-01-29 09:26 - 2021-01-29 09:26 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Shugasu
2021-01-29 09:25 - 2021-01-29 09:25 - 000000222 _____ C:\Users\Administrator\Desktop\Idling to Rule the Gods.url
2021-01-29 09:25 - 2021-01-29 09:25 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2021-01-29 09:22 - 2021-01-29 09:22 - 000000000 ____D C:\Users\Administrator\AppData\Local\Steam
2021-01-29 09:20 - 2021-02-09 14:15 - 000000000 ____D C:\Program Files (x86)\Steam
2021-01-29 09:19 - 2021-01-29 09:19 - 001573568 _____ C:\Users\Administrator\Downloads\SteamSetup.exe
2021-01-29 09:18 - 2021-01-29 09:18 - 000599902 _____ C:\Users\Administrator\Downloads\OneDrive_1_29.1.2021.zip
2021-01-29 08:04 - 2021-01-29 08:04 - 000199077 _____ C:\Users\Administrator\Downloads\M an Eltern_Verlängerung des Distanzunterrichts.pdf
2021-01-28 21:26 - 2021-01-28 21:30 - 000000000 ____D C:\Users\Administrator\Desktop\COVID-20
2021-01-28 16:16 - 2021-02-03 08:33 - 000002161 _____ C:\Users\Administrator\Desktop\Werewolf Online.lnk
2021-01-28 14:00 - 2021-01-28 14:00 - 000910677 _____ C:\Users\Administrator\Downloads\BWR Förderkurs.zip
2021-01-28 14:00 - 2021-01-28 14:00 - 000000000 ____D C:\Users\Administrator\Desktop\BWR Förderkurs
2021-01-28 13:54 - 2021-01-28 13:54 - 000003944 _____ C:\Windows\system32\Tasks\BlueStacksHelper
2021-01-28 13:44 - 2021-01-28 13:51 - 000000000 ____D C:\Program Files\BlueStacks
2021-01-28 13:40 - 2021-01-28 13:43 - 000000000 ____D C:\Users\Administrator\AppData\Local\BlueStacksSetup
2021-01-28 13:40 - 2021-01-28 13:43 - 000000000 ____D C:\Users\Administrator\AppData\Local\Bluestacks
2021-01-28 13:40 - 2021-01-28 13:40 - 001232960 _____ (BlueStack Systems Inc.) C:\Users\Administrator\Downloads\BlueStacksInstaller_4.260.0.1032_native_917903eb0bb4e81980ee9f78a7c69bbb.exe
2021-01-28 12:09 - 2021-01-28 12:09 - 000058367 _____ C:\Users\Administrator\Downloads\Gesetzestexte Firma.pdf
2021-01-28 10:42 - 2021-01-28 12:09 - 000000000 ____D C:\Users\Administrator\Desktop\Firma
2021-01-28 10:42 - 2021-01-28 10:42 - 000216340 _____ C:\Users\Administrator\Downloads\Handelsregister.zip
2021-01-28 10:42 - 2021-01-28 10:42 - 000000000 ____D C:\Users\Administrator\Desktop\Handelsregister
2021-01-28 10:41 - 2021-01-28 10:42 - 000067024 _____ C:\Users\Administrator\Downloads\Firma.zip
2021-01-28 09:52 - 2021-02-01 14:29 - 000000000 ____D C:\Users\Administrator\AppData\Local\Spotify
2021-01-28 09:52 - 2021-02-01 12:46 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Spotify
2021-01-28 09:52 - 2021-01-28 09:52 - 000001908 _____ C:\Users\Administrator\Desktop\Spotify.lnk
2021-01-28 09:52 - 2021-01-28 09:52 - 000001894 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2021-01-28 09:51 - 2021-01-28 09:51 - 067415024 _____ (Spotify Ltd) C:\Users\Administrator\Downloads\SpotifyFullSetup.exe
2021-01-28 09:51 - 2021-01-28 09:51 - 000000000 ____D C:\Users\Administrator\AppData\Local\Comms
2021-01-28 09:04 - 2021-01-28 09:04 - 000234351 _____ C:\Users\Administrator\Downloads\OneDrive_1_28.1.2021.zip
2021-01-28 08:29 - 2021-01-28 08:29 - 000112295 _____ C:\Users\Administrator\Downloads\USA bis 1945_9 b_Weltwirtschaftskrise und New Deal_Tafelbild unter Berücksichtigung der Auswirkungen auf Deutschland.pdf
2021-01-28 08:04 - 2021-01-28 09:04 - 000214113 _____ C:\Users\Administrator\Desktop\Angabe_Übung.pdf
2021-01-28 08:04 - 2021-01-28 09:04 - 000019976 _____ C:\Users\Administrator\Desktop\Angabe.xlsx
2021-01-28 07:46 - 2021-01-28 08:16 - 000002625 _____ C:\Users\Administrator\Desktop\Neues Textdokument.txt
2021-01-28 07:46 - 2021-01-28 07:46 - 000090376 _____ C:\Users\Administrator\Downloads\USA bis 1945_9 a_Weltwirtschaftskrise und New Deal_Einstieg_Fragen zum Film.pdf
2021-01-27 22:51 - 2021-01-27 22:51 - 000000000 ____D C:\Users\Administrator\Documents\Virtual Machines
2021-01-27 20:47 - 2021-01-27 22:47 - 968556544 _____ C:\Users\Administrator\Desktop\BlackWindowV2.iso
2021-01-27 20:43 - 2021-01-27 20:43 - 000000000 ____D C:\Windows\pss
2021-01-27 17:21 - 2021-02-03 07:47 - 000000000 __RSD C:\Users\Andere\Documents\McAfee-Tresore
2021-01-27 17:21 - 2021-01-27 17:21 - 000000000 ____D C:\Users\Andere\AppData\Local\McAfee File Lock
2021-01-27 17:17 - 2021-01-27 17:18 - 000000000 ____D C:\Users\Andere\AppData\Roaming\PotPlayerMini64
2021-01-27 17:17 - 2021-01-27 17:17 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Daum
2021-01-27 17:17 - 2021-01-27 17:17 - 000000000 _____ C:\Users\Administrator\Desktop\19.txt
2021-01-27 17:15 - 2021-01-27 17:15 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\PotPlayerMini64
2021-01-27 17:15 - 2021-01-27 17:15 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\NVIDIA
2021-01-27 17:15 - 2021-01-27 17:15 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Daum
2021-01-27 17:15 - 2021-01-27 17:15 - 000000000 ____D C:\Program Files\DAUM
2021-01-27 17:03 - 2021-02-07 19:27 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\obs-studio
2021-01-27 17:02 - 2021-02-03 08:33 - 000001451 _____ C:\Users\Administrator\Desktop\Opera-Browser.lnk
2021-01-27 17:02 - 2021-01-27 17:03 - 000000000 ____D C:\Program Files\obs-studio
2021-01-27 17:02 - 2021-01-27 17:02 - 075607864 _____ (obsproject.com) C:\Users\Administrator\Downloads\OBS-Studio-26.1.1-Full-Installer-x64.exe
2021-01-27 17:02 - 2021-01-27 17:02 - 000004490 _____ C:\Windows\system32\Tasks\Opera scheduled assistant Autoupdate 1611763334
2021-01-27 17:02 - 2021-01-27 17:02 - 000004242 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1611763329
2021-01-27 17:02 - 2021-01-27 17:02 - 000001515 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera-Browser.lnk
2021-01-27 17:02 - 2021-01-27 17:02 - 000000000 ____D C:\Users\Administrator\AppData\Local\Opera Software
2021-01-27 17:01 - 2021-01-27 17:01 - 002405080 _____ (Opera Software) C:\Users\Administrator\Downloads\OperaSetup.exe
2021-01-27 17:01 - 2021-01-27 17:01 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Opera Software
2021-01-27 12:15 - 2021-01-27 15:56 - 000000000 ____D C:\Users\Administrator\.megabasterd7.40
2021-01-27 12:15 - 2021-01-27 12:15 - 000000000 ____D C:\Users\Administrator\.megabasterd_old_backups
2021-01-27 12:12 - 2021-01-27 12:13 - 079910363 _____ C:\Users\Administrator\Downloads\MegaBasterdWINDOWS_7.40_portable.zip
2021-01-27 11:29 - 2021-01-27 11:29 - 000000000 ____D C:\Windows\CSC
2021-01-27 11:25 - 2021-02-09 12:54 - 000000000 ____D C:\Windows\Minidump
2021-01-27 08:41 - 2021-01-27 08:41 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Mechanistry
2021-01-27 08:31 - 2020-05-26 00:11 - 000218960 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2021-01-27 08:30 - 2021-02-09 14:14 - 000000000 __RSD C:\Users\Administrator\Documents\McAfee-Tresore
2021-01-27 08:30 - 2021-01-27 08:30 - 000000000 ____D C:\Users\Administrator\AppData\Local\McAfee File Lock
2021-01-27 08:30 - 2020-05-26 00:12 - 000089096 _____ (McAfee, LLC) C:\Windows\system32\Drivers\McPvDrv.sys
2021-01-27 08:29 - 2021-01-27 08:35 - 738041074 _____ C:\Users\Administrator\Downloads\timberborn.rar
2021-01-27 08:29 - 2021-01-27 08:29 - 000003346 _____ C:\Windows\system32\Tasks\McAfeeLogon
2021-01-27 08:28 - 2021-02-08 21:16 - 000000000 ____D C:\Windows\system32\Tasks\McAfee
2021-01-27 08:28 - 2021-01-27 09:28 - 000003710 _____ C:\Windows\system32\Tasks\McAfee Remediation (Prepare)
2021-01-27 08:27 - 2021-01-27 08:42 - 000000000 ____D C:\Program Files (x86)\McAfee
2021-01-27 08:27 - 2021-01-27 08:31 - 000000000 ____D C:\Program Files\McAfee
2021-01-27 08:27 - 2021-01-27 08:28 - 000000000 ____D C:\Program Files\McAfee.com
2021-01-27 08:27 - 2021-01-27 08:27 - 000000000 ____D C:\Program Files\Common Files\AV
2021-01-27 08:25 - 2021-01-27 08:31 - 000000000 ____D C:\Program Files\Common Files\McAfee
2021-01-27 08:25 - 2021-01-27 08:25 - 071087152 _____ (McAfee, LLC) C:\Users\Administrator\Downloads\McAfee_Installer_serial_zWqVEGfvPnAxblsHhHuOGw2_key_affid_850_akey.exe
2021-01-27 08:25 - 2020-09-14 14:01 - 000579040 _____ (McAfee, LLC) C:\Windows\system32\mfevtps.exe
2021-01-27 08:21 - 2021-02-09 01:30 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\discord
2021-01-27 08:21 - 2021-02-03 08:33 - 000002285 _____ C:\Users\Administrator\Desktop\Discord.lnk
2021-01-27 08:21 - 2021-01-27 08:21 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2021-01-27 08:20 - 2021-01-27 08:21 - 000000000 ____D C:\Users\Administrator\AppData\Local\Discord
2021-01-27 08:20 - 2021-01-27 08:20 - 068822328 _____ (Discord Inc.) C:\Users\Administrator\Downloads\DiscordSetup.exe
2021-01-27 08:10 - 2021-01-27 08:10 - 000000000 ____D C:\Users\Andere\AppData\Roaming\NVIDIA
2021-01-27 07:19 - 2021-01-26 22:19 - 000000000 ____D C:\Users\Andere\AppData\Local\AdSSO
2021-01-27 07:09 - 2021-02-09 14:15 - 000000000 ____D C:\Program Files\CCleaner
2021-01-27 07:09 - 2021-02-03 20:45 - 000004210 _____ C:\Windows\system32\Tasks\CCleaner Update
2021-01-27 07:09 - 2021-01-27 07:09 - 030584912 _____ (Piriform Software Ltd) C:\Users\Administrator\Downloads\ccsetup576.exe
2021-01-27 07:09 - 2021-01-27 07:09 - 000002886 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC
2021-01-27 07:02 - 2021-01-27 07:02 - 000000000 ____D C:\Users\Administrator\Downloads\C2F98634-0139-4EB2-B26C-821D090559CC
2021-01-27 06:57 - 2021-01-27 06:57 - 000000850 _____ C:\Users\Andere\Desktop\Mem Reduct.lnk
2021-01-27 06:57 - 2021-01-27 06:57 - 000000000 ____D C:\Users\Andere\AppData\Roaming\VMware
2021-01-27 06:57 - 2021-01-27 06:57 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mem Reduct
2021-01-27 06:57 - 2021-01-27 06:57 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Locktime
2021-01-27 06:57 - 2021-01-27 06:57 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Henry++
2021-01-27 06:57 - 2021-01-27 06:57 - 000000000 ____D C:\Users\Andere\AppData\Local\VMware
2021-01-27 06:55 - 2021-01-27 06:55 - 000000000 ____D C:\Users\Andere\AppData\Roaming\ProcessLasso
2021-01-27 06:48 - 2021-01-27 06:48 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Locktime
2021-01-27 06:48 - 2021-01-27 06:48 - 000000000 ____D C:\Program Files\Locktime Software
2021-01-27 06:47 - 2021-02-03 19:34 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\VMware
2021-01-27 06:47 - 2021-02-03 19:34 - 000000000 ____D C:\Users\Administrator\AppData\Local\VMware
2021-01-27 06:47 - 2020-11-18 06:53 - 000110696 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
2021-01-27 06:47 - 2020-11-18 06:53 - 000060344 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmkbd.sys
2021-01-27 06:47 - 2020-08-11 09:25 - 000048224 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
2021-01-27 06:47 - 2020-08-11 09:25 - 000044128 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
2021-01-27 06:47 - 2020-08-11 09:24 - 000105912 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
2021-01-27 06:46 - 2021-01-27 06:46 - 000001024 _____ C:\Windows\SysWOW64\%TMP%
2021-01-27 06:46 - 2020-11-18 07:01 - 001305304 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
2021-01-27 06:46 - 2020-11-18 06:59 - 000422104 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2021-01-27 06:46 - 2020-11-18 06:59 - 000379440 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2021-01-27 06:46 - 2020-11-18 06:59 - 000119736 _____ (VMware, Inc.) C:\Windows\system32\vnetinst.dll
2021-01-27 06:46 - 2020-11-18 06:59 - 000045664 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
2021-01-27 06:46 - 2020-10-01 18:46 - 000085448 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
2021-01-27 06:45 - 2021-01-27 06:45 - 001667630 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2021-01-27 06:45 - 2021-01-27 06:45 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Locktime Software
2021-01-27 06:45 - 2021-01-27 06:45 - 000000000 ____D C:\Program Files\Common Files\VMware
2021-01-27 06:45 - 2021-01-27 06:45 - 000000000 ____D C:\Program Files (x86)\VMware
2021-01-27 06:38 - 2021-01-27 06:38 - 000003106 _____ C:\Windows\system32\Tasks\Process Lasso Management Console (GUI)
2021-01-27 06:38 - 2021-01-27 06:38 - 000003096 _____ C:\Windows\system32\Tasks\Process Lasso Core Engine Only
2021-01-27 06:37 - 2021-01-27 06:39 - 000000000 ____D C:\Program Files\Process Lasso
2021-01-27 06:37 - 2021-01-27 06:38 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\ProcessLasso
2021-01-27 06:37 - 2021-01-27 06:37 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Henry++
2021-01-27 06:36 - 2021-02-03 08:33 - 000000894 _____ C:\Users\Administrator\Desktop\Mem Reduct.lnk
2021-01-27 06:36 - 2021-01-27 06:36 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mem Reduct
2021-01-27 06:36 - 2021-01-27 06:36 - 000000000 ____D C:\Program Files\Mem Reduct
2021-01-27 06:29 - 2021-02-04 08:33 - 000000000 ____D C:\Users\Administrator\AppData\Local\CrashDumps
2021-01-27 06:24 - 2021-02-01 22:57 - 000000000 ____D C:\Users\Administrator\AppData\Local\Autodesk
2021-01-27 06:24 - 2021-01-27 07:02 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Autodesk
2021-01-27 06:24 - 2021-01-26 23:11 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Autodesk Installer
2021-01-27 06:22 - 2021-02-02 18:45 - 000000000 ____D C:\Users\Andere\AppData\Local\CrashDumps
2021-01-27 06:18 - 2021-01-27 06:18 - 000000424 _____ C:\Users\Andere\Desktop\Dieser PC.lnk
2021-01-27 06:17 - 2021-02-02 01:54 - 000000000 ____D C:\Users\Andere\Documents\maya
2021-01-27 06:17 - 2021-01-29 22:46 - 000000000 ____D C:\Program Files\Allegorithmic
2021-01-27 06:17 - 2021-01-27 06:17 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Arnold for Maya 2020
2021-01-27 06:17 - 2021-01-27 06:17 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared
2021-01-27 06:16 - 2021-01-27 06:16 - 000000000 ____D C:\Program Files (x86)\Autodesk
2021-01-27 06:15 - 2021-01-29 22:50 - 000000000 ____D C:\Users\Andere\AppData\Local\D3DSCache
2021-01-27 06:01 - 2021-01-26 23:13 - 000000000 ____D C:\Program Files\Autodesk
2021-01-27 06:00 - 2021-01-27 06:50 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Autodesk Installer
2021-01-27 06:00 - 2021-01-26 22:27 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Autodesk
2021-01-27 05:59 - 2021-01-31 18:35 - 000000000 ____D C:\Users\Andere\AppData\Local\Autodesk
2021-01-27 05:59 - 2021-01-27 05:59 - 008699096 _____ (Autodesk, Inc.) C:\Users\Andere\Downloads\Autodesk_Maya_2020_ML_Windows_64bit_di_en-US_setup_webinstall.exe
2021-01-27 05:52 - 2021-01-29 22:27 - 000000000 ____D C:\Users\Andere\AppData\Local\PlaceholderTileLogoFolder
2021-01-27 05:50 - 2021-01-27 06:22 - 000000000 ____D C:\Users\Andere\AppData\Local\StartIsBack
2021-01-27 05:50 - 2021-01-27 05:50 - 000000000 ____D C:\Users\Andere\AppData\Local\CEF
2021-01-27 05:50 - 2021-01-27 05:50 - 000000000 ____D C:\Users\Andere\ansel
2021-01-27 05:49 - 2021-02-04 20:54 - 000000000 ____D C:\Users\Andere
2021-01-27 05:49 - 2021-01-29 22:50 - 000000000 ____D C:\Users\Andere\AppData\Local\NVIDIA
2021-01-27 05:49 - 2021-01-27 19:19 - 000000000 ____D C:\Users\Andere\AppData\Local\Packages
2021-01-27 05:49 - 2021-01-27 05:51 - 000000000 ____D C:\Users\Andere\AppData\Local\NVIDIA Corporation
2021-01-27 05:49 - 2021-01-27 05:49 - 000000020 ___SH C:\Users\Andere\ntuser.ini
2021-01-27 05:49 - 2021-01-27 05:49 - 000000000 ___RD C:\Users\Andere\3D Objects
2021-01-27 05:49 - 2021-01-27 05:49 - 000000000 ____D C:\Users\Andere\AppData\Roaming\Adobe
2021-01-27 05:49 - 2021-01-27 05:49 - 000000000 ____D C:\Users\Andere\AppData\Local\VirtualStore
2021-01-27 05:49 - 2021-01-27 05:49 - 000000000 ____D C:\Users\Andere\AppData\Local\ConnectedDevicesPlatform
2021-01-27 05:49 - 2019-11-27 00:11 - 000001580 _____ C:\Users\Andere\Desktop\Ghost Toolbox.lnk
2021-01-27 05:37 - 2021-01-28 09:33 - 000000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA Corporation
2021-01-27 05:37 - 2021-01-27 05:37 - 000000000 ____D C:\Users\Administrator\AppData\Local\CEF
2021-01-27 05:37 - 2021-01-27 05:37 - 000000000 ____D C:\Users\Administrator\ansel
2021-01-27 05:37 - 2021-01-26 22:26 - 000000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA
2021-01-27 05:35 - 2021-01-27 05:35 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2021-01-27 05:35 - 000004106 _____ C:\Windows\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2021-01-27 05:35 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2021-01-27 05:35 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2021-01-27 05:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2021-01-27 05:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2021-01-27 05:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2021-01-27 05:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-01-27 05:35 - 2020-12-31 15:01 - 002797552 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2021-01-27 05:35 - 2020-12-31 15:01 - 002154984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2021-01-27 05:35 - 2020-12-31 15:01 - 001294832 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2021-01-27 05:35 - 2020-12-31 15:01 - 000069608 _____ C:\Windows\system32\FvSDK_x64.dll
2021-01-27 05:35 - 2020-12-31 15:01 - 000058344 _____ C:\Windows\SysWOW64\FvSDK_x86.dll
2021-01-27 05:34 - 2021-01-27 05:35 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2021-01-27 05:34 - 2021-01-27 05:34 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2021-01-27 05:34 - 2020-12-31 15:01 - 000169272 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2021-01-27 05:34 - 2020-12-31 15:01 - 000145208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2021-01-27 05:34 - 2020-12-31 15:01 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2021-01-27 05:32 - 2020-12-31 15:01 - 000135408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2021-01-27 05:32 - 2020-12-31 15:01 - 000069840 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2021-01-27 05:32 - 2020-12-31 15:01 - 000067456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2021-01-27 05:32 - 2020-12-31 15:01 - 000050592 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\NvModuleTracker.sys
2021-01-27 05:32 - 2020-12-31 15:01 - 000038640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
2021-01-27 05:31 - 2021-02-08 13:51 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-01-27 05:31 - 2021-01-04 15:49 - 001855192 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2021-01-27 05:31 - 2021-01-04 15:49 - 001855192 _____ C:\Windows\system32\vulkaninfo.exe
2021-01-27 05:31 - 2021-01-04 15:49 - 001435864 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-01-27 05:31 - 2021-01-04 15:49 - 001435864 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2021-01-27 05:31 - 2021-01-04 15:49 - 000948952 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2021-01-27 05:31 - 2021-01-04 15:49 - 000948952 _____ C:\Windows\SysWOW64\vulkan-1.dll
2021-01-27 05:31 - 2021-01-04 15:48 - 001454488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2021-01-27 05:31 - 2021-01-04 15:48 - 001193880 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2021-01-27 05:31 - 2021-01-04 15:48 - 001094880 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2021-01-27 05:31 - 2021-01-04 15:48 - 001094880 _____ C:\Windows\system32\vulkan-1.dll
2021-01-27 05:31 - 2021-01-04 15:46 - 001512856 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2021-01-27 05:31 - 2021-01-04 15:46 - 001165720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2021-01-27 05:31 - 2021-01-04 15:46 - 000690072 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2021-01-27 05:31 - 2021-01-04 15:46 - 000680856 _____ C:\Windows\system32\nvofapi64.dll
2021-01-27 05:31 - 2021-01-04 15:46 - 000673688 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2021-01-27 05:31 - 2021-01-04 15:46 - 000610712 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2021-01-27 05:31 - 2021-01-04 15:46 - 000559000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2021-01-27 05:31 - 2021-01-04 15:46 - 000548248 _____ C:\Windows\SysWOW64\nvofapi.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 008262552 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 007393176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 005631896 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 004612504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 002731928 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 002104216 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 001589144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 000813976 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 000657816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2021-01-27 05:31 - 2021-01-04 15:45 - 000447384 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2021-01-27 05:31 - 2021-01-04 15:44 - 000850840 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2021-01-27 05:31 - 2021-01-04 15:43 - 007115280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2021-01-27 05:31 - 2021-01-04 15:43 - 006071032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2021-01-27 05:31 - 2020-12-31 15:01 - 000084159 _____ C:\Windows\system32\nvinfo.pb
2021-01-27 05:30 - 2021-02-03 22:41 - 000744476 _____ C:\Windows\system32\perfh007.dat
2021-01-27 05:30 - 2021-02-03 22:41 - 000151252 _____ C:\Windows\system32\perfc007.dat
2021-01-27 05:30 - 2021-01-27 05:29 - 000306166 _____ C:\Windows\system32\perfi007.dat
2021-01-27 05:30 - 2021-01-27 05:29 - 000040520 _____ C:\Windows\system32\perfd007.dat
2021-01-27 05:29 - 2021-02-03 18:02 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-01-27 05:29 - 2021-02-03 18:02 - 000000000 ____D C:\Program Files\Windows Defender
2021-01-27 05:29 - 2021-02-03 18:02 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2021-01-27 05:29 - 2021-01-27 05:29 - 000000000 ____D C:\Windows\SysWOW64\de
2021-01-27 05:29 - 2021-01-27 05:29 - 000000000 ____D C:\Windows\system32\de
2021-01-27 05:28 - 2021-02-08 12:54 - 000000000 ____D C:\Users\Administrator\AppData\Local\D3DSCache
2021-01-27 05:26 - 2021-01-27 05:27 - 000000000 ____D C:\Windows\SysWOW64\directx
2021-01-27 05:17 - 2021-02-03 08:33 - 000002414 _____ C:\Users\Administrator\Desktop\Microsoft Teams.lnk
2021-01-27 05:17 - 2021-01-27 05:17 - 000002422 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-01-27 05:17 - 2021-01-27 05:17 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Teams
2021-01-27 05:16 - 2021-01-27 08:21 - 000000000 ____D C:\Users\Administrator\AppData\Local\SquirrelTemp
2021-01-27 05:15 - 2021-01-27 05:17 - 661510840 _____ (NVIDIA Corporation) C:\Users\Administrator\Downloads\461.09-desktop-win10-64bit-international-dch-whql.exe
2021-01-27 05:13 - 2021-01-27 05:13 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_bcmwlhigh664_01009.Wdf
2021-01-27 05:13 - 2007-01-20 03:24 - 000025312 ____R (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\SCMNdisP.sys
2021-01-27 05:12 - 2021-01-27 05:12 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2021-01-27 05:12 - 2021-01-27 05:12 - 000000000 ____D C:\Program Files (x86)\NETGEAR
2021-01-27 05:12 - 2015-02-11 07:04 - 001255672 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcmwlhigh664.sys
2021-01-27 05:12 - 2015-02-11 07:04 - 000096600 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll
2021-01-27 05:12 - 2015-02-11 05:46 - 003900928 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2021-01-27 05:12 - 2015-02-11 05:46 - 003566592 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2021-01-27 05:12 - 2010-02-03 20:21 - 000281104 _____ (CACE Technologies, Inc.) C:\Windows\SysWOW64\wpcap.dll
2021-01-27 05:12 - 2010-02-03 20:21 - 000096784 _____ (CACE Technologies, Inc.) C:\Windows\SysWOW64\Packet.dll
2021-01-27 05:12 - 2010-02-03 20:21 - 000053299 _____ C:\Windows\SysWOW64\pthreadVC.dll
2021-01-27 05:12 - 2010-02-03 20:21 - 000047632 _____ (CACE Technologies, Inc.) C:\Windows\system32\Drivers\npf.sys
2021-01-27 05:10 - 2021-01-27 05:10 - 000000000 ____D C:\Users\Administrator\AppData\Local\PlaceholderTileLogoFolder
2021-01-27 05:00 - 2021-01-27 05:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\StartIsBack
2021-01-27 05:00 - 2021-01-27 05:00 - 000003444 _____ C:\Windows\system32\Tasks\StartIsBack health check
2021-01-27 05:00 - 2021-01-27 05:00 - 000000000 ____D C:\Users\Administrator\AppData\Local\PeerDistRepub
2021-01-27 05:00 - 2021-01-27 05:00 - 000000000 ____D C:\Program Files (x86)\StartIsBack
2021-01-27 04:59 - 2021-02-09 12:06 - 000000000 ____D C:\Users\Administrator\AppData\Local\Packages
2021-01-27 04:59 - 2021-01-27 04:59 - 000000000 ___RD C:\Users\Administrator\3D Objects
2021-01-27 04:59 - 2021-01-27 04:59 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2021-01-27 04:59 - 2021-01-27 04:59 - 000000000 ____D C:\Program Files\CPUID
2021-01-27 04:58 - 2021-02-09 14:09 - 000000000 ____D C:\Users\Administrator
2021-01-27 04:58 - 2021-01-27 06:07 - 000000000 ____D C:\Users\Administrator\AppData\Local\ConnectedDevicesPlatform
2021-01-27 04:58 - 2021-01-27 04:58 - 000000020 ___SH C:\Users\Administrator\ntuser.ini
2021-01-27 04:58 - 2019-11-27 00:11 - 000001580 _____ C:\Users\Administrator\Desktop\Ghost Toolbox.lnk
2021-01-27 04:31 - 2021-01-27 04:31 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2021-01-26 22:27 - 2021-01-26 22:27 - 000000000 ____D C:\Users\Andere\Downloads\D93E01D9-AF6E-32E9-ACA2-61D9E92563C1
2021-01-26 22:27 - 2021-01-26 22:27 - 000000000 ____D C:\Users\Andere\Downloads\C2F98634-0139-4EB2-B26C-821D090559CC
2021-01-26 22:27 - 2021-01-26 22:27 - 000000000 ____D C:\Users\Andere\Downloads\8CB8DFA4-EB0A-427B-9CFC-3FF046DA9115
2021-01-26 22:26 - 2021-01-26 22:26 - 000000000 ____D C:\Users\Administrator\AppData\Local\cache
2021-01-26 22:26 - 2021-01-26 22:26 - 000000000 ____D C:\Users\Administrator\AppData\Local\AutodeskDesktopApp
2021-01-26 22:24 - 2021-01-29 22:50 - 000000000 ____D C:\Users\Andere\AppData\Local\cache
2021-01-26 22:24 - 2021-01-26 22:24 - 000000000 ____D C:\Users\Andere\AppData\Local\AutodeskDesktopApp
2021-01-26 22:23 - 2021-01-26 22:23 - 000001906 _____ C:\Users\Andere\Desktop\AutodeskDesktopApp.exe.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-02-09 14:25 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2021-02-09 14:11 - 2020-12-22 05:07 - 000294872 _____ C:\Windows\system32\FNTCACHE.DAT
2021-02-09 14:11 - 2020-12-22 05:07 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-02-09 14:11 - 2020-12-12 19:54 - 000008192 ___SH C:\DumpStack.log.tmp
2021-02-09 14:09 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2021-02-09 14:03 - 2020-12-22 05:07 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-02-09 12:46 - 2020-12-21 12:44 - 000000000 ____D C:\Program Files\7-Zip
2021-02-09 12:15 - 2019-12-21 22:02 - 000000000 __SHD C:\AI_RecycleBin
2021-02-09 12:06 - 2020-12-21 12:46 - 000000000 ____D C:\Program Files\WindowsApps
2021-02-09 12:05 - 2020-12-21 12:44 - 000000000 ____D C:\Ghost Toolbox
2021-02-08 22:40 - 2020-11-06 22:32 - 000000000 ____D C:\Users\Administrator\Desktop\NosVoid
2021-02-08 16:53 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2021-02-08 14:27 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-02-08 13:54 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2021-02-08 13:53 - 2020-12-22 05:06 - 000000000 ____D C:\Windows\Panther
2021-02-08 12:12 - 2019-12-07 10:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2021-02-08 00:05 - 2020-12-05 17:34 - 000000000 ___RD C:\Sandbox
2021-02-04 13:04 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2021-02-04 08:33 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\LiveKernelReports
2021-02-03 22:41 - 2020-12-22 05:17 - 001731910 _____ C:\Windows\system32\PerfStringBackup.INI
2021-02-03 18:01 - 2019-12-07 10:03 - 000032768 _____ C:\Windows\system32\config\ELAM
2021-02-03 14:24 - 2020-12-31 19:24 - 000000000 ____D C:\Users\Administrator\Desktop\NosByte
2021-02-01 18:03 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\MUI
2021-02-01 18:03 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\MUI
2021-02-01 17:31 - 2020-12-04 19:26 - 000000000 ____D C:\GOG Games
2021-01-29 14:33 - 2019-07-05 09:17 - 002232320 _____ (fabi.me) C:\Users\Administrator\Desktop\SpeedAutoClicker.exe
2021-01-27 06:11 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\PrintDialog
2021-01-27 05:29 - 2019-12-07 10:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2021-01-27 05:29 - 2019-12-07 10:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\SysWOW64\winrm
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\SysWOW64\WCN
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\SysWOW64\slmgr
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\system32\winrm
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\system32\WCN
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\system32\slmgr
2021-01-27 05:29 - 2019-12-07 10:50 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\F12
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\dsc
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Com
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemApps
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Sysprep
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\migwiz
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Com
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\IME
2021-01-27 05:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2021-01-27 05:29 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2021-01-27 05:17 - 2019-12-07 10:52 - 000000000 ____D C:\Windows\OCR
2021-01-27 05:00 - 2019-12-07 10:18 - 000000000 ____D C:\Windows\Setup
2021-01-27 04:28 - 2019-12-07 10:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2021-01-24 22:08 - 2019-12-07 10:54 - 000005678 _____ C:\Windows\system32\OEMDefaultAssociations.xml
2021-01-18 01:14 - 2020-12-14 11:29 - 000000000 ____D C:\Users\Andere\Desktop\maya
2021-01-14 20:25 - 2020-07-17 12:43 - 000000000 ___HD C:\$WinREAgent
==================== Files in the root of some directories ========
2021-02-08 12:28 - 2021-02-08 12:53 - 000000691 _____ () C:\Users\Administrator\AppData\Roaming\GetValue.vbs
2021-02-08 12:28 - 2021-02-08 12:53 - 000000035 _____ () C:\Users\Administrator\AppData\Roaming\SetValue.bat
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ======================== --- --- ---
--- --- ---
[CODE]Additional
FRST Logfile:
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version: 08-02-2021 01
Ran by Baal (09-02-2021 14:28:36)
Running from C:\Users\Administrator\Downloads
Windows 10 Pro Version 20H2 19042.685 (X64) (2021-01-27 03:58:15)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Andere (S-1-5-21-1186616812-1126677590-2245216935-1000 - Administrator - Enabled) => C:\Users\Andere
Baal (S-1-5-21-1186616812-1126677590-2245216935-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-1186616812-1126677590-2245216935-503 - Limited - Disabled)
Guest (S-1-5-21-1186616812-1126677590-2245216935-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1186616812-1126677590-2245216935-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: McAfee VirusScan (Enabled - Up to date) {9D4501E6-72F6-2877-C789-89AF6F535B2C}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
FW: McAfee Firewall (Enabled) {A57E80C3-3899-292F-ECD6-209A91801C57}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 19.00 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1900-000001000000}) (Version: 19.00.00.0 - Igor Pavlov)
Allegorithmic Substance Painter 7.1.0 (HKLM\...\{33C3E9E2-0675-4196-9019-28AB9C5E9BB0}_is1) (Version: 7.1.0 - Allegorithmic)
Autodesk Desktop App (HKLM-x32\...\Autodesk Desktop App) (Version: 8.0.0.46 - Autodesk)
Autodesk Genuine Service (HKLM-x32\...\{54A00624-3EF9-49A2-92A9-7244EADD0212}) (Version: 3.2.18 - Autodesk)
Autodesk Genuine Service (HKLM-x32\...\{BF7A2FE6-C943-4C1E-A2CA-729AD1474E9B}) (Version: 3.1.15 - Autodesk)
Autodesk Maya 2020 (HKLM\...\{0EBFFCF6-F972-4D40-863F-E673B5C38236}) (Version: 20.4.0.1627 - Autodesk) Hidden
Autodesk Maya 2020 (HKLM\...\{C2F98634-0139-4EB2-B26C-821D090559CC}) (Version: 2020.4.0.1627 - Autodesk, Inc.)
Autodesk Single Sign On Component (HKLM\...\{7F0FE09D-E25D-4C59-A1AA-DB17153FC353}) (Version: 11.3.0.1803 - Autodesk)
Bifrost Extension 2.0.3.0 for Maya 2020 (HKLM\...\{0BAD8879-2A6C-43DC-B8BC-9FE8AD80C75B}) (Version: 2.0.3.0 - Autodesk)
BlueStacks App Player (HKLM\...\BlueStacks) (Version: 4.260.0.1032 - BlueStack Systems, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.76 - Piriform)
CPUID CPU-Z 1.94 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.94 - CPUID, Inc.)
Discord (HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Discord) (Version: 0.0.309 - Discord Inc.)
Genshin Impact (HKLM\...\Genshin Impact) (Version: 2.6.1.0 - miHoYo Co.,Ltd)
Ghostrunner (HKLM-x32\...\1957528513_is1) (Version: 32091_417 - GOG.com)
Ghostrunner pre-order KATANA DLC (HKLM-x32\...\2009792833_is1) (Version: 32091_417 - GOG.com)
Ghostrunner Winter Pack (HKLM-x32\...\1596358146_is1) (Version: 32091_417 - GOG.com)
IObit Uninstaller 10.2.0.15 (HKLM-x32\...\IObit Uninstaller_is1) (Version: 10.2.0.15 - lrepacks.ru)
Malware Hunter 1.116.0.708 (HKLM-x32\...\Malware Hunter) (Version: 1.116.0.708 - Glarysoft Ltd)
Malwarebytes version 4.3.0.98 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.3.0.98 - Malwarebytes)
McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 16.0 R29 - McAfee, LLC)
Mem Reduct (HKLM\...\memreduct) (Version: 3.3.5 - Henry++)
Microsoft Office Professional Plus 2019 - de-de (HKLM\...\ProPlus2019Retail - de-de) (Version: 16.0.13628.20274 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Teams) (Version: 1.3.00.34662 - Microsoft Corporation)
Microsoft Visual Basic/C++ Runtime (x86) (HKLM-x32\...\{C5E3A69D-D391-45A6-A8FB-00B01E2B010D}) (Version: 1.1.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508 (HKLM-x32\...\{6913e92a-b64e-41c9-a5e6-cef39207fe89}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.25.28508 (HKLM-x32\...\{65e650ff-30be-469d-b63a-418d71ea1765}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29805 (HKLM\...\{29A1747B-007E-4BB0-A4BE-D6B855C2C56D}) (Version: 14.28.29805 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29805 (HKLM\...\{50FF98A9-6C60-4DF2-AE02-C48AED35B59B}) (Version: 14.28.29805 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29805 (HKLM-x32\...\{09A8B65F-2B67-4C5C-8FD8-D3EB60F4121D}) (Version: 14.28.29805 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29805 (HKLM-x32\...\{00DC6825-CBC7-4179-AA10-829FA349A6B9}) (Version: 14.28.29805 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{47C2CCDB-7A04-3797-992B-A84D3E90258F}) (Version: 10.0.60833 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 5.0.2 (x64) (HKLM-x32\...\{e25469ba-a07f-4864-afff-d34d3e78a406}) (Version: 5.0.2.29613 - Microsoft Corporation)
MtoA for Maya 2020 (HKU\S-1-5-21-1186616812-1126677590-2245216935-1000\...\MtoA2020) (Version: 4.0.0 - Solid Angle)
NETGEAR WNA3100 wireless USB 2.0 driver (HKLM-x32\...\{C2425F91-1F7B-4037-9A05-9F290184798D}) (Version: 2.2.0.2 - NETGEAR)
NetLimiter 4 (HKLM\...\{D8EB2152-FF07-4BA1-8361-0A64CBCFA58F}) (Version: 4.0.50.0 - Locktime Software) Hidden
NetLimiter 4 (HKLM-x32\...\NetLimiter 4 4.0.50.0) (Version: 4.0.50.0 - Locktime Software)
Notepad++ (HKLM\...\Notepad++) (Version: 7 - Notepad++ Team)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.27 - NVIDIA Corporation) Hidden
NVIDIA FrameView SDK 1.1.4923.29214634 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29214634 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.20.5.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.5.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 461.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 461.09 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.40 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
NvModuleTracker (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver) (Version: 6.14.24033.38719 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 26.1.1 - OBS Project)
Opera Stable 73.0.3856.344 (HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Opera 73.0.3856.344) (Version: 73.0.3856.344 - Opera Software)
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 210127 - Kakao Corp.)
Process Lasso (HKLM-x32\...\ProcessLasso) (Version: 9.8.2.2 - Bitsum)
Spotify (HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB)
StartIsBack++ (HKLM-x32\...\StartIsBack) (Version: 2.9.8 - startisback.com)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Substance in Maya 2020-2.0.3 (HKLM\...\{47209805-a05c-4af2-b34b-459745022023}_is1) (Version: 2.0.3 - Adobe)
Sweet Paranoia (HKLM\...\Sweet Paranoia) (Version: - niivu)
UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
UltraUXThemePatcher (HKLM-x32\...\UltraUXThemePatcher) (Version: 4.0.0.0 - Manuel Hoefs (Zottel))
WebAdvisor von McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.194 - McAfee, LLC)
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.960.0_x64__56jybvy8sckqj [2021-01-27] (NVIDIA Corp.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1186616812-1126677590-2245216935-500_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Administrator\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20289.5\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2016-09-21] (Notepad++ -> )
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => -> No File
ContextMenuHandlers1: [Glarysoft MalwareHunter] -> {EA847F47-97F1-4D78-AB99-C63CA1C327F0} => C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\MHContextHandlerx64.dll [2020-11-23] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => C:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2020-11-04] (McAfee, LLC -> McAfee, LLC)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => -> No File
ContextMenuHandlers2: [Glarysoft MalwareHunter] -> {EA847F47-97F1-4D78-AB99-C63CA1C327F0} => C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\MHContextHandlerx64.dll [2020-11-23] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers2-x32: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => C:\Program Files (x86)\VMware\VMware Workstation\vmdkShellExt.dll [2020-11-18] (VMware, Inc. -> VMware, Inc.)
ContextMenuHandlers2: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => C:\Program Files (x86)\VMware\VMware Workstation\x64\vmdkShellExt64.dll [2020-11-18] (VMware, Inc. -> VMware, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-02-08] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nvaei.inf_amd64_8024d97d167d7438\nvshext.dll [2021-01-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Glarysoft MalwareHunter] -> {EA847F47-97F1-4D78-AB99-C63CA1C327F0} => C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\MHContextHandlerx64.dll [2020-11-23] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-02-08] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => C:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2020-11-04] (McAfee, LLC -> McAfee, LLC)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2021-01-27 05:12 - 2015-02-27 05:19 - 000380928 _____ () [File not signed] C:\Program Files (x86)\NETGEAR\WNA3100\WifiLib.dll
2021-01-27 05:12 - 2011-06-22 01:04 - 000229376 _____ (Broadcom Corporation) [File not signed] C:\Program Files (x86)\NETGEAR\WNA3100\wps_api.dll
2020-12-04 07:56 - 2021-02-09 12:49 - 000709040 _____ (Glarysoft LTD -> Glarysoft Ltd) [File not signed] C:\Program Files (x86)\Glarysoft\Malware Hunter\Register.dll
2019-02-21 21:00 - 2019-02-21 21:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2020-01-31] (IObit Information Technology -> IObit)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2021-02-05] (McAfee, LLC -> McAfee, LLC)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2021-02-05] (McAfee, LLC -> McAfee, LLC)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-02-01] (Microsoft Corporation -> Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll [2020-11-04] (McAfee, LLC -> McAfee, LLC)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2020-11-04] (McAfee, LLC -> McAfee, LLC)
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\sharepoint.com -> hxxps://by0813-files.sharepoint.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 10:14 - 2021-02-08 17:12 - 000089730 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\VMware\VMware Workstation\bin\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files\Process Lasso\;C:\Program Files\dotnet\
HKU\S-1-5-21-1186616812-1126677590-2245216935-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Local\Microsoft\Windows\Themes\GHOST NOI\DesktopBackground\img0_2560x160330 2021 03.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi 2: VMware Bridge Protocol -> vmware_bridge (enabled)
Wi-Fi 2: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)
VMware Network Adapter VMnet1: VMware Bridge Protocol -> vmware_bridge (disabled)
VMware Network Adapter VMnet1: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)
Ethernet: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)
Ethernet: VMware Bridge Protocol -> vmware_bridge (enabled)
VMware Network Adapter VMnet8: VMware Bridge Protocol -> vmware_bridge (disabled)
VMware Network Adapter VMnet8: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)
Wi-Fi: VMware Bridge Protocol -> vmware_bridge (enabled)
Wi-Fi: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run32: => "Autodesk Desktop App"
HKLM\...\StartupApproved\Run32: => "Autodesk Genuine Service "
HKLM\...\StartupApproved\Run32: => "vmware-tray.exe"
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\StartupApproved\Run: => "NetLimiter"
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1186616812-1126677590-2245216935-500\...\StartupApproved\Run: => "Spotify"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [Microsoft-Windows-Unified-Telemetry-Client] => (Block) C:\Windows\system32\svchost.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{3056C7F9-756D-480E-A1D8-BCE0AD205217}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{A81DA307-C5C1-4FDD-BA40-5487DB3F067F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{AB1D3287-0FAA-4E34-8F65-4C3902C42E16}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{EEE25865-1319-48F6-BAE3-DB97AB986A61}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{9E6F220A-D7A5-4630-B2F7-236D585086F0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{95C3A1F1-ED62-48F2-A614-0E0203486BEE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BA17C29B-AC3F-4CA2-A40D-AC7C7A441D87}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe (McAfee, LLC -> McAfee, LLC)
FirewallRules: [{60CBD4CF-A2ED-44E0-803E-F7801F018DBB}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, LLC -> McAfee, LLC)
FirewallRules: [{19386911-D3F7-4891-87EF-8B2A51351C06}] => (Allow) C:\Users\Administrator\AppData\Local\Programs\Opera\73.0.3856.344\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{39D42345-858E-48B6-BACE-038A29BD3677}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
FirewallRules: [{F3CF5447-04D2-4C1E-8963-F7D5912CE3C7}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{009E662E-AA97-4654-93C1-7DEE03F8E756}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{EF886F54-25BA-4AA7-BA5D-E3454C55E9E8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{3A8B880E-D202-4E92-BE57-509E3950D26E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
==================== Restore Points =========================
==================== Faulty Device Manager Devices ============
Name: SM-Bus-Controller
Description: SM-Bus-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: PCI-Kommunikationscontroller (einfach)
Description: PCI-Kommunikationscontroller (einfach)
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: ========================
Application errors:
==================
System errors:
=============
Error: (02/09/2021 02:15:48 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Delivery Optimization" wurde nicht richtig gestartet.
Error: (02/09/2021 02:13:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "GUMHFilters" wurde aufgrund folgenden Fehlers nicht gestartet:
Die digitale Signatur dieser Datei kann nicht überprüft werden. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um böswillige Software aus einer unbekannten Quelle handelt, installiert.
Error: (02/09/2021 02:09:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "VMware Workstation Server" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Restart the service.
Error: (02/09/2021 02:09:20 PM) (Source: DCOM) (EventID: 10010) (User: WIN-GPE7CHGD8F4)
Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (02/09/2021 02:09:20 PM) (Source: DCOM) (EventID: 10010) (User: WIN-GPE7CHGD8F4)
Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (02/09/2021 02:09:20 PM) (Source: DCOM) (EventID: 10010) (User: WIN-GPE7CHGD8F4)
Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (02/09/2021 02:09:20 PM) (Source: DCOM) (EventID: 10010) (User: WIN-GPE7CHGD8F4)
Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (02/09/2021 02:09:20 PM) (Source: DCOM) (EventID: 10010) (User: WIN-GPE7CHGD8F4)
Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
CodeIntegrity:
===================================
Date: 2021-02-09 14:17:37.5590000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Microsoft signing level requirements.
Date: 2021-02-09 14:17:37.5370000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Microsoft signing level requirements.
Date: 2021-02-09 14:16:41.9880000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2021-02-09 14:16:41.9710000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2021-02-09 14:16:41.9500000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2021-02-09 14:16:41.9330000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2021-02-09 14:16:41.9180000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2021-02-09 14:16:41.9040000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume5\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. H81EM2W08.308 08/25/2014
Motherboard: MEDION H81H3-EM2
Processor: Intel(R) Core(TM) i3-4160 CPU @ 3.60GHz
Percentage of memory in use: 32%
Total physical RAM: 8144.43 MB
Available physical RAM: 5493.42 MB
Total Virtual: 16336.43 MB
Available Virtual: 9787.27 MB
==================== Drives ================================
Drive c: (Windows 10 Compact) (Fixed) (Total:868.44 GB) (Free:467.29 GB) NTFS
Drive d: (Games) (Fixed) (Total:59.99 GB) (Free:59.81 GB) NTFS
\\?\Volume{7e0d0ba7-4d45-4f09-bba8-c2a183a9c282}\ () (Fixed) (Total:0.49 GB) (Free:0.18 GB) NTFS
\\?\Volume{052015cb-7a85-4771-87fd-7a4ddba78144}\ () (Fixed) (Total:0.54 GB) (Free:0.06 GB) NTFS
\\?\Volume{5fdf47c6-21ec-44d2-99f2-4bee43d151da}\ () (Fixed) (Total:0.82 GB) (Free:0.42 GB) NTFS
\\?\Volume{47ea8986-068d-4982-a02e-081c6663b764}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ======================= --- --- ---
--- --- ---
Hoffe passt so. Sorry für die Umstände aber kenne mich halt nicht aus sonst würde ich versuchen alles selbst lösen :/ |