Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Virenprogramm lässt sich nicht mehr installieren (https://www.trojaner-board.de/176383-virenprogramm-laesst-mehr-installieren.html)

Kanso 25.02.2016 20:51

Virenprogramm lässt sich nicht mehr installieren
 
Guten Abend,

heute Morgen hat sich mein Computer ohne Vorwarnung von selbst ausgeschaltet. Danach lies sich mein Virenprogramm (benutze Norton Security) nicht mehr öffnen bzw. ich konnte mich nicht mehr anmelden. Also habe ich den Support von Norton kontaktiert. Dort hat sich ein Mitarbeiter Zugang zu meinem Desktop verschafft um das Problem zu lösen. Nach mehrmaligen Versuchen das Programm neu zu installieren kam immer eine Fehlermeldung, dass mein PC evtl. infiziert ist und deshalb keine Neuinstallation möglich ist. Ein Techniker von Norton will sich morgen nochmal bei mir melden. Aber vielleicht lässt sich das Problem ja von euch irgendwie lösen, befürchte mittlerweile auch mein PC hat sich irgendwas eingefangen, auch wenn ich sonst eigentlich keine weiteren Probleme habe. Danke schonmal für die Hilfe.

Gruß Kanso

Larusso 26.02.2016 07:46

http://www.trojaner-board.de/69886-a...-beachten.html

Kanso 26.02.2016 09:47

Alles klar hier die Logfiles.

FRST.txt

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:24-02-2016
durchgeführt von Admin (Administrator) auf ADMIN-PC (26-02-2016 09:37:05)
Gestartet von C:\Users\Admin\Desktop
Geladene Profile: Admin (Verfügbare Profile: Admin & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.16941.0_x64__8wekyb3d8bbwe\Video.UI.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.201.11370.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [402344 2015-12-19] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-01-31] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-03-12] (Intel Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [896632 2015-07-22] (BlueStack Systems, Inc.)
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-16] (InstallShield Software Corporation)
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [175368 2016-02-09] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK-Konfigurationstool.lnk [2014-02-28]
ShortcutTarget: TP-LINK-Konfigurationstool.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK-Konfigurationstool\TWCU.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{38fa8d64-1429-4eb3-94d0-479866b2cb77}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-988284940-210793992-766847566-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-988284940-210793992-766847566-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-988284940-210793992-766847566-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.de/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll => Keine Datei
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll => Keine Datei

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-15] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2011-04-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2015-06-19] (Pando Networks)
FF Plugin HKU\S-1-5-21-988284940-210793992-766847566-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-988284940-210793992-766847566-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-09-10] ()
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\searchplugins\safesearch.xml [2015-06-25]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\adblockpopups@jessehakanen.net.xpi [2015-05-29]
FF Extension: NoScript - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-02-12]
FF Extension: WOT - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-12-09]
FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433784 2015-06-16] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413304 2015-06-16] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [831096 2015-07-21] (BlueStack Systems, Inc.)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-31] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7220792 2016-01-30] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-12] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373160 2015-12-19] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-12] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-12] (NVIDIA Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [145528 2015-06-16] (BlueStack Systems)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2016-02-25] (Symantec Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2014-06-19] ()
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [3870464 2015-10-01] (Realtek Semiconductor Corporation                          )
R3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation)
R3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation)
R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation)
R3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation)
R4 SRTSPX; C:\Windows\system32\drivers\NSx64\1605040.018\SRTSPX64.SYS [50936 2015-09-23] (Symantec Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 condrv; System32\drivers\condrv.sys [X]
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-02-26 09:37 - 2016-02-26 09:37 - 00015621 _____ C:\Users\Admin\Desktop\FRST.txt
2016-02-26 09:35 - 2016-02-26 09:37 - 00000000 ____D C:\FRST
2016-02-26 09:34 - 2016-02-26 09:34 - 02371072 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2016-02-26 05:36 - 2016-02-26 05:38 - 00000000 ____D C:\Program Files (x86)\Norton Security
2016-02-26 05:36 - 2016-02-26 05:36 - 00001364 _____ C:\Users\Admin\Desktop\Norton-Installationsdateien.lnk
2016-02-26 05:36 - 2016-02-26 05:36 - 00000000 ____D C:\WINDOWS\system32\Drivers\NSx64
2016-02-26 05:35 - 2016-02-26 05:36 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader(2).exe
2016-02-26 05:30 - 2016-02-26 09:36 - 00362550 _____ C:\WINDOWS\ntbtlog.txt
2016-02-26 05:28 - 2016-02-26 05:28 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (2).exe
2016-02-26 05:12 - 2016-02-26 05:14 - 00412020 _____ C:\WINDOWS\Minidump\022616-17640-01.dmp
2016-02-25 11:37 - 2016-02-25 11:37 - 00000432 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp.bat
2016-02-25 11:37 - 2016-02-25 11:37 - 00000357 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp_r.bat
2016-02-25 11:33 - 2016-02-25 11:36 - 00000000 ____D C:\Program Files (x86)\LogMeIn Rescue RC - 0bfdcd33-f52c-4b3b-a4a7-71770fabb626
2016-02-25 11:28 - 2016-02-26 05:42 - 00000000 ____D C:\ProgramData\Norton
2016-02-25 11:28 - 2016-02-26 05:42 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-02-25 11:28 - 2016-02-26 05:38 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-02-25 11:22 - 2016-02-25 11:23 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool(2).exe
2016-02-25 11:17 - 2016-02-25 11:17 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (10).lnk
2016-02-25 11:15 - 2016-02-25 11:15 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (1).exe
2016-02-25 11:13 - 2016-02-25 11:13 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool(1).exe
2016-02-25 11:10 - 2016-02-25 11:10 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (9).lnk
2016-02-25 10:51 - 2016-02-25 10:51 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (8).lnk
2016-02-25 10:48 - 2016-02-25 10:48 - 00000000 __SHD C:\found.000
2016-02-25 10:40 - 2016-02-25 10:40 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (7).lnk
2016-02-25 10:37 - 2016-02-25 10:37 - 00002286 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (6).lnk
2016-02-25 10:29 - 2016-02-25 11:26 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-25 10:29 - 2016-02-25 10:29 - 00002286 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (5).lnk
2016-02-25 10:28 - 2016-02-25 10:28 - 00000000 ____D C:\WINDOWS\pss
2016-02-25 10:17 - 2016-02-25 10:17 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (4).lnk
2016-02-25 10:07 - 2016-02-26 05:31 - 00000000 ____D C:\NPE
2016-02-25 10:07 - 2016-02-25 10:07 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (3).lnk
2016-02-25 10:05 - 2016-02-26 05:33 - 00000000 ____D C:\Users\Admin\AppData\Local\NPE
2016-02-25 10:05 - 2016-02-25 10:05 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE.exe
2016-02-25 10:02 - 2016-02-25 10:02 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader (1).exe
2016-02-25 09:58 - 2016-02-26 05:21 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3CF3C132-6859-4994-8DAC-3B31CD8D194C}
2016-02-25 09:57 - 2016-02-25 09:57 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (2).lnk
2016-02-25 09:54 - 2016-02-25 09:55 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool.exe
2016-02-25 09:48 - 2016-02-25 09:48 - 00000248 _____ C:\rescue.info
2016-02-25 09:46 - 2016-02-25 09:46 - 01857576 _____ (LogMeIn, Inc.) C:\Users\Admin\Downloads\Support-LogMeInRescue.exe
2016-02-25 09:46 - 2016-02-25 09:46 - 00002324 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk
2016-02-25 09:46 - 2016-02-25 09:46 - 00000000 ____D C:\Users\Admin\AppData\Local\LogMeIn Rescue Applet
2016-02-24 21:57 - 2016-02-24 21:57 - 00000000 ____D C:\Users\Admin\AppData\LocalLow\HuniePot
2016-02-24 21:55 - 2016-02-24 21:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HuniePop [GOG.com]
2016-02-16 00:11 - 2016-02-16 00:11 - 00002202 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2016-02-16 00:10 - 2016-02-16 00:10 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-02-16 00:10 - 2016-02-09 06:04 - 00111672 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-02-16 00:09 - 2016-02-09 09:25 - 42983480 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 37616184 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 31119296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 24944064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 21201784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 20741880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17631304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17224664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17175248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17116936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02541504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02187712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00950328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00882232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00745408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00689600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00541000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00445728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00383424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00379448 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00378968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00348216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00317144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00153392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-02-14 10:24 - 2016-02-14 10:26 - 00353028 _____ C:\WINDOWS\Minidump\021416-29546-01.dmp
2016-02-12 06:29 - 2016-02-24 09:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-09 19:52 - 2016-01-29 07:57 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-09 19:52 - 2016-01-29 07:33 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-02-09 19:52 - 2016-01-27 07:15 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-02-09 19:52 - 2016-01-27 07:15 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-02-09 19:52 - 2016-01-27 07:01 - 07476064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-02-09 19:52 - 2016-01-27 07:01 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-02-09 19:52 - 2016-01-27 07:01 - 01819720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-02-09 19:52 - 2016-01-27 06:59 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-09 19:52 - 2016-01-27 06:57 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-02-09 19:52 - 2016-01-27 06:57 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-09 19:52 - 2016-01-27 06:57 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-09 19:52 - 2016-01-27 06:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-02-09 19:52 - 2016-01-27 06:55 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-02-09 19:52 - 2016-01-27 06:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-02-09 19:52 - 2016-01-27 06:54 - 00295264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-02-09 19:52 - 2016-01-27 06:46 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-09 19:52 - 2016-01-27 06:46 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-09 19:52 - 2016-01-27 06:45 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-02-09 19:52 - 2016-01-27 06:45 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-02-09 19:52 - 2016-01-27 06:44 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-09 19:52 - 2016-01-27 06:44 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-09 19:52 - 2016-01-27 06:43 - 00359776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-02-09 19:52 - 2016-01-27 06:37 - 01998176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-02-09 19:52 - 2016-01-27 06:37 - 00576352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-02-09 19:52 - 2016-01-27 06:21 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-09 19:52 - 2016-01-27 06:15 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-02-09 19:52 - 2016-01-27 06:13 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-02-09 19:52 - 2016-01-27 06:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-02-09 19:52 - 2016-01-27 06:11 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-09 19:52 - 2016-01-27 06:10 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-02-09 19:52 - 2016-01-27 06:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-09 19:52 - 2016-01-27 06:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-09 19:52 - 2016-01-27 06:08 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-09 19:52 - 2016-01-27 06:07 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-02-09 19:52 - 2016-01-27 06:04 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-02-09 19:52 - 2016-01-27 06:04 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-09 19:52 - 2016-01-27 06:03 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-02-09 19:52 - 2016-01-27 06:02 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-09 19:52 - 2016-01-27 06:01 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-09 19:52 - 2016-01-27 05:59 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-09 19:52 - 2016-01-27 05:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-02-09 19:52 - 2016-01-27 05:57 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-02-09 19:52 - 2016-01-27 05:55 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-02-09 19:52 - 2016-01-27 05:55 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-02-09 19:52 - 2016-01-27 05:54 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-02-09 19:52 - 2016-01-27 05:52 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 02230784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 01504768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-09 19:52 - 2016-01-27 05:49 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-02-09 19:52 - 2016-01-27 05:48 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-02-09 19:52 - 2016-01-27 05:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-09 19:52 - 2016-01-27 05:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-09 19:52 - 2016-01-27 05:41 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-02-09 19:52 - 2016-01-27 05:39 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-02-09 19:52 - 2016-01-27 05:38 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-02-09 19:52 - 2016-01-27 05:38 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-02-09 19:52 - 2016-01-27 05:37 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-02-09 19:52 - 2016-01-27 05:36 - 02757120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-02-09 19:52 - 2016-01-27 05:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-09 19:52 - 2016-01-27 05:31 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-03 19:18 - 2016-02-03 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher® 3 - Wild Hunt [GOG.com]
2016-02-02 19:33 - 2016-02-02 19:35 - 10026464 _____ C:\Users\Admin\Downloads\Worlds Apart (Sami Zayn)_Megalouis100v4.m4a
2016-01-31 12:53 - 2016-02-08 00:23 - 00000000 ____D C:\Users\Admin\Documents\Broken Sword - Director's Cut
2016-01-31 12:19 - 2016-01-31 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broken Sword - Director's Cut [GOG.com]
2016-01-31 01:02 - 2016-01-23 04:31 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436175.dll
2016-01-31 01:02 - 2016-01-23 04:31 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436175.dll
2016-01-29 19:10 - 2016-01-29 19:10 - 00000000 ____D C:\Users\Admin\Documents\League of Legends
2016-01-29 19:03 - 2016-02-25 09:55 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-01-29 18:55 - 2016-01-29 18:55 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader(1).exe
2016-01-29 17:44 - 2016-01-29 17:44 - 00102616 _____ (Symantec Corporation) C:\WINDOWS\SMSS-PFRO5d7c.tmp
2016-01-27 19:53 - 2016-01-16 07:37 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-01-27 19:53 - 2016-01-16 07:36 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-27 19:53 - 2016-01-16 07:36 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-01-27 19:53 - 2016-01-16 07:34 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-27 19:53 - 2016-01-16 07:24 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-01-27 19:53 - 2016-01-16 07:23 - 08728920 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-01-27 19:53 - 2016-01-16 07:23 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-27 19:53 - 2016-01-16 07:23 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-27 19:53 - 2016-01-16 07:23 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-01-27 19:53 - 2016-01-16 07:23 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-27 19:53 - 2016-01-16 07:23 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-01-27 19:53 - 2016-01-16 07:21 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-01-27 19:53 - 2016-01-16 07:20 - 06971752 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-01-27 19:53 - 2016-01-16 07:20 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-01-27 19:53 - 2016-01-16 07:20 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-01-27 19:53 - 2016-01-16 07:20 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-01-27 19:53 - 2016-01-16 07:19 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-01-27 19:53 - 2016-01-16 07:19 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-01-27 19:53 - 2016-01-16 07:12 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-01-27 19:53 - 2016-01-16 07:09 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-01-27 19:53 - 2016-01-16 07:08 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-01-27 19:53 - 2016-01-16 07:08 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-01-27 19:53 - 2016-01-16 06:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-01-27 19:53 - 2016-01-16 06:45 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-27 19:53 - 2016-01-16 06:44 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-01-27 19:53 - 2016-01-16 06:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-01-27 19:53 - 2016-01-16 06:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-01-27 19:53 - 2016-01-16 06:43 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-01-27 19:53 - 2016-01-16 06:42 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-27 19:53 - 2016-01-16 06:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-01-27 19:53 - 2016-01-16 06:41 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-01-27 19:53 - 2016-01-16 06:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-01-27 19:53 - 2016-01-16 06:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-01-27 19:53 - 2016-01-16 06:40 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-01-27 19:53 - 2016-01-16 06:39 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-01-27 19:53 - 2016-01-16 06:38 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-01-27 19:53 - 2016-01-16 06:38 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-01-27 19:53 - 2016-01-16 06:38 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-01-27 19:53 - 2016-01-16 06:38 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-01-27 19:53 - 2016-01-16 06:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-01-27 19:53 - 2016-01-16 06:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-01-27 19:53 - 2016-01-16 06:37 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-01-27 19:53 - 2016-01-16 06:37 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-01-27 19:53 - 2016-01-16 06:36 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-01-27 19:53 - 2016-01-16 06:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2016-01-27 19:53 - 2016-01-16 06:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-01-27 19:53 - 2016-01-16 06:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-01-27 19:53 - 2016-01-16 06:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-01-27 19:53 - 2016-01-16 06:35 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-01-27 19:53 - 2016-01-16 06:35 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-01-27 19:53 - 2016-01-16 06:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-01-27 19:53 - 2016-01-16 06:34 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-01-27 19:53 - 2016-01-16 06:34 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-01-27 19:53 - 2016-01-16 06:34 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-01-27 19:53 - 2016-01-16 06:34 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-27 19:53 - 2016-01-16 06:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-01-27 19:53 - 2016-01-16 06:33 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-01-27 19:53 - 2016-01-16 06:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-01-27 19:53 - 2016-01-16 06:33 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-01-27 19:53 - 2016-01-16 06:32 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-01-27 19:53 - 2016-01-16 06:32 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-01-27 19:53 - 2016-01-16 06:31 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-01-27 19:53 - 2016-01-16 06:31 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-01-27 19:53 - 2016-01-16 06:31 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-01-27 19:53 - 2016-01-16 06:31 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-01-27 19:53 - 2016-01-16 06:31 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-01-27 19:53 - 2016-01-16 06:30 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-01-27 19:53 - 2016-01-16 06:30 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-01-27 19:53 - 2016-01-16 06:30 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-01-27 19:53 - 2016-01-16 06:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-01-27 19:53 - 2016-01-16 06:30 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-01-27 19:53 - 2016-01-16 06:29 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-01-27 19:53 - 2016-01-16 06:29 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-01-27 19:53 - 2016-01-16 06:28 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-01-27 19:53 - 2016-01-16 06:28 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-27 19:53 - 2016-01-16 06:28 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-01-27 19:53 - 2016-01-16 06:28 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-01-27 19:53 - 2016-01-16 06:27 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-01-27 19:53 - 2016-01-16 06:26 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-01-27 19:53 - 2016-01-16 06:26 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-01-27 19:53 - 2016-01-16 06:26 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-01-27 19:53 - 2016-01-16 06:26 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-27 19:53 - 2016-01-16 06:25 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-01-27 19:53 - 2016-01-16 06:25 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-01-27 19:53 - 2016-01-16 06:25 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-01-27 19:53 - 2016-01-16 06:24 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-01-27 19:53 - 2016-01-16 06:24 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-01-27 19:53 - 2016-01-16 06:24 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-01-27 19:53 - 2016-01-16 06:24 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-01-27 19:53 - 2016-01-16 06:23 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-01-27 19:53 - 2016-01-16 06:23 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-01-27 19:53 - 2016-01-16 06:21 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-01-27 19:53 - 2016-01-16 06:20 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-01-27 19:53 - 2016-01-16 06:20 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-27 19:53 - 2016-01-16 06:20 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-01-27 19:53 - 2016-01-16 06:20 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-01-27 19:53 - 2016-01-16 06:19 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-01-27 19:53 - 2016-01-16 06:19 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-01-27 19:53 - 2016-01-16 06:19 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-01-27 19:53 - 2016-01-16 06:19 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-01-27 19:53 - 2016-01-16 06:18 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-27 19:53 - 2016-01-16 06:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-01-27 19:53 - 2016-01-16 06:16 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-01-27 19:53 - 2016-01-16 06:16 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-01-27 19:53 - 2016-01-16 06:15 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-01-27 19:53 - 2016-01-16 06:14 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-01-27 19:53 - 2016-01-16 06:14 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-01-27 19:53 - 2016-01-16 06:11 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-02-26 05:36 - 2015-12-03 04:01 - 02091230 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-26 05:36 - 2015-10-30 19:35 - 00889534 _____ C:\WINDOWS\system32\perfh007.dat
2016-02-26 05:36 - 2015-10-30 19:35 - 00197858 _____ C:\WINDOWS\system32\perfc007.dat
2016-02-26 05:36 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-02-26 05:31 - 2015-12-03 03:57 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-02-26 05:30 - 2015-12-03 04:17 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-26 05:30 - 2015-12-03 03:58 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-26 05:30 - 2015-10-30 08:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-02-26 05:30 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-02-26 05:12 - 2015-12-04 19:37 - 00000000 ____D C:\WINDOWS\Minidump
2016-02-26 05:12 - 2014-03-07 16:29 - 890432205 _____ C:\WINDOWS\MEMORY.DMP
2016-02-25 20:43 - 2014-10-15 18:28 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2016-02-25 20:39 - 2015-03-05 20:41 - 00000000 ____D C:\GOG Games
2016-02-25 20:39 - 2015-03-05 20:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-02-25 20:39 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-02-25 20:36 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieUserList
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieSiteList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieUserList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieSiteList
2016-02-25 09:03 - 2015-12-03 04:01 - 00000000 ____D C:\Users\Admin
2016-02-25 08:44 - 2015-08-06 20:56 - 00000000 __SHD C:\Users\Admin\IntelGraphicsProfiles
2016-02-24 20:23 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-24 18:56 - 2015-06-01 19:35 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2016-02-23 19:56 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-22 01:16 - 2015-10-30 07:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-02-21 23:27 - 2015-01-27 10:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-21 00:02 - 2014-02-10 11:42 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SoftGrid Client
2016-02-20 22:15 - 2014-08-10 22:06 - 00000000 ____D C:\Program Files (x86)\Steam
2016-02-16 00:11 - 2015-12-03 03:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-16 00:11 - 2014-02-26 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-02-14 10:24 - 2015-01-26 02:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-13 20:35 - 2014-02-10 12:11 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-13 20:32 - 2014-02-10 12:11 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-12 02:22 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2016-02-10 19:34 - 2015-08-06 20:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-10 10:37 - 2015-10-30 19:47 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-10 07:27 - 2015-09-22 23:03 - 12478528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-02-09 22:20 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-02-09 09:25 - 2015-09-22 23:03 - 19779648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 14115136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 03649576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 03231544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 00035832 _____ C:\WINDOWS\system32\nvinfo.pb
2016-02-09 06:29 - 2015-12-03 03:57 - 06368824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 02992064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 02561472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 01263040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-02-09 06:29 - 2015-12-03 03:57 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-02-09 06:29 - 2014-11-24 17:02 - 00530368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-02-09 06:29 - 2014-11-24 17:02 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-02-07 23:20 - 2015-05-20 16:56 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
2016-02-07 20:41 - 2014-04-12 17:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2016-02-06 15:58 - 2015-12-03 03:57 - 06154909 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-02-03 20:01 - 2015-10-30 08:26 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-02-03 20:01 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-31 12:19 - 2014-08-31 18:56 - 00466456 _____ (Creative Labs) C:\WINDOWS\system32\wrap_oal.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00444952 _____ (Creative Labs) C:\WINDOWS\SysWOW64\wrap_oal.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\system32\OpenAL32.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\SysWOW64\OpenAL32.dll
2016-01-31 01:02 - 2015-12-03 03:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-01-29 18:55 - 2015-07-25 17:47 - 00000000 ____D C:\Users\Public\Downloads\Norton
2016-01-29 17:37 - 2015-12-03 03:57 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2016-02-25 11:37 - 2016-02-25 11:37 - 0000432 _____ () C:\Users\Admin\AppData\Local\LMIR0001.tmp.bat
2016-02-25 11:37 - 2016-02-25 11:37 - 0000357 _____ () C:\Users\Admin\AppData\Local\LMIR0001.tmp_r.bat
2015-12-03 03:57 - 2015-12-03 03:57 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


ACHTUNG: ==> Auf den BCD konnte nicht zugegriffen werden.


LastRegBack: 2016-02-17 09:32

==================== Ende von FRST.txt ============================

Addition.txt

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:24-02-2016
durchgeführt von Admin (2016-02-26 09:37:59)
Gestartet von C:\Users\Admin\Desktop
Windows 10 Pro Version 1511 (X64) (2015-12-03 03:22:42)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Admin (S-1-5-21-988284940-210793992-766847566-1000 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-988284940-210793992-766847566-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-988284940-210793992-766847566-503 - Limited - Disabled)
Gast (S-1-5-21-988284940-210793992-766847566-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-988284940-210793992-766847566-1003 - Limited - Enabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

1954 Alcatraz (HKLM-x32\...\Steam App 255280) (Version:  - Daedalic Entertainment)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassins Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.03 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.03 - Ubisoft)
Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Baldur's Gate -  The Original Saga (German) (HKLM-x32\...\GOGPACKBALDURSGATE1_is1) (Version: 2.0.0.20 - GOG.com)
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BioShock (HKLM-x32\...\Steam App 7670) (Version:  - 2K Boston)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
Broken Sword - Director's Cut (HKLM-x32\...\1207658900_is1) (Version: 2.1.0.16 - GOG.com)
Dark Souls: Prepare to Die Edition (HKLM-x32\...\Steam App 211420) (Version:  - FromSoftware)
DARK SOULS™ II (HKLM-x32\...\Steam App 236430) (Version:  - FromSoftware, Inc)
Darksiders (HKLM-x32\...\Steam App 50620) (Version:  - Vigil Games)
DarksidersInstaller (HKLM-x32\...\{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}) (Version: 1.00.1000 - Ihr Firmenname)
Deus Ex: Human Revolution - Director's Cut (HKLM-x32\...\Steam App 238010) (Version:  - Eidos Montreal)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
DVD Architect Studio 5.0 (HKLM-x32\...\{E42939AE-9660-11E2-9A0D-F04DA23A5C58}) (Version: 5.0.178 - Sony)
Dxtory version 2.0.130 (HKLM-x32\...\Dxtory2.0_is1) (Version: 2.0.130 - ExKode Co. Ltd.)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version:  - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
FINAL FANTASY XIV: A Realm Reborn (HKLM-x32\...\Steam App 39210) (Version:  - SQUARE ENIX)
Geheimakte Tunguska (HKLM-x32\...\{3B416FDA-CB3E-4514-9616-763E5B0D1140}) (Version: 1.03.02 - Deep Silver)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
GOG.com Downloader version 3.6.0 (HKLM-x32\...\{456A5815-604D-4D72-94DF-346D2B978A59}_is1) (Version: 3.6.0 - GOG.com)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
How to Survive (HKLM-x32\...\Steam App 250400) (Version:  - )
HuniePop (HKLM-x32\...\1443428641_is1) (Version: 2.0.0.1 - GOG.com)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4331 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.0.1083 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.63463 - Intel Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Leisure Suit Larry - Reloaded (HKLM-x32\...\1207659243_is1) (Version: 2.1.0.11 - GOG.com)
Magic Bullet QuickLooks for Movie Studio 64 bit (HKLM-x32\...\InstallShield_{03B2F2B1-247A-4216-997F-2BE0372FFEC9}) (Version: 1.4.3 - Ihr Firmenname)
Magic Bullet QuickLooks for Movie Studio 64 bit (Version: 1.4.3 - Ihr Firmenname) Hidden
MagicYUV Lossless Video Codec version 1.0 (HKLM-x32\...\{90410593-E0EB-4F9B-B984-65BEA8F07B91}_is1) (Version: 1.0 - INNOMAGIC, Ltd.)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Metro 2033 (HKLM-x32\...\Steam App 43110) (Version:  - 4A Games)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.6122.5000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.6129.5001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MKVToolNix 7.5.0 (64bit) (HKLM-x32\...\MKVToolNix) (Version: 7.5.0 - Moritz Bunkus)
Movie Studio Platinum 12.0 (64-bit) (HKLM\...\{6C3C3A70-958D-11E2-B0E5-F04DA23A5C58}) (Version: 12.0.896 - Sony)
Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 44.0.2.5884 - Mozilla)
MSI Afterburner 4.1.0 (HKLM-x32\...\Afterburner) (Version: 4.1.0 - MSI Co., LTD)
NewBlue VideoFX for Sony Vegas MSPPS (HKLM\...\NewBlue VideoFX for Sony Vegas MSPPS) (Version: 2.0 - NewBlue)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.53.2 - Black Tree Gaming)
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.91 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.9.1.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.9.1.22 - NVIDIA Corporation)
NVIDIA Grafiktreiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.91 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA PhysX (Legacy) (HKLM-x32\...\{6F9D5A0B-202C-4161-BC7F-0664EA39E7E7}) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
ON_OFF Charge 2 B13.0403.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE)
ON_OFF Charge 2 B13.0403.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Papers, Please (HKLM-x32\...\1207659209_is1) (Version: 2.5.0.11 - GOG.com)
PhotoFiltre 7 (HKU\S-1-5-21-988284940-210793992-766847566-1000\...\PhotoFiltre 7) (Version:  - )
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.)
Rayman Origins (HKLM-x32\...\Steam App 207490) (Version:  - UBIart Montpellier)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 6.3.0 (HKLM-x32\...\RTSS) (Version: 6.3.0 - Unwinder)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\...\Steam App 2700) (Version:  - Frontier)
Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version:  - Ascaron)
SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.9.1.22 - NVIDIA Corporation) Hidden
Sid Meier's Civilization IV (HKLM-x32\...\Steam App 3900) (Version:  - Firaxis Games)
Sony Vocal Eraser (HKLM-x32\...\Sony Vocal Eraser_is1) (Version: 1.00 - iZotope, Inc.)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{BC7B099E-4643-11E3-9A41-F04DA23A5C58}) (Version: 10.0.252 - Sony)
South Park™: The Stick of Truth™ (HKLM-x32\...\Steam App 213670) (Version:  - Obsidian Entertainment)
Spelunky (HKLM-x32\...\Steam App 239350) (Version:  - )
State of Decay (HKLM-x32\...\Steam App 241540) (Version:  - Undead Labs)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
TeamSpeak 3 Client (HKU\S-1-5-21-988284940-210793992-766847566-1000\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)
The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version:  - Edmund McMillen and Florian Himsl)
The Binding of Isaac: Rebirth (HKLM-x32\...\Steam App 250900) (Version:  - Nicalis, Inc.)
The Last Remnant (HKLM-x32\...\Steam App 23310) (Version:  - SQUARE ENIX)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.12.1.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.12.1.0 - GOG.com)
The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\...\Hearts of Stone_is1) (Version: 1.12.1.0 - GOG.com)
The Wolf Among Us (HKLM-x32\...\Steam App 250320) (Version:  - Telltale Games)
Torchlight (HKLM-x32\...\Steam App 41500) (Version:  - Runic Games)
TP-LINK 300Mbps Wireless USB Adapter Treiber (HKLM-x32\...\{852E893E-E4FD-45BB-8B17-72ADDF686974}) (Version: 1.3.1 - TP-LINK)
TP-LINK-Konfigurationstool (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Tropico (HKLM-x32\...\Steam App 33520) (Version:  - PopTop Software)
Two Worlds: Epic Edition (HKLM-x32\...\Steam App 1930) (Version:  - Reality Pump Studios)
Unity Web Player (HKU\S-1-5-21-988284940-210793992-766847566-1000\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR 5.10 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.1 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {02A600D9-1622-4911-9725-509354AEEC6E} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {0D117D4E-EE80-429D-9B8F-D88A92248012} - System32\Tasks\{A7EDC86C-AC88-4B0D-8EBF-801BB3377055} => pcalua.exe -a "C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Prerequisites\vcredist_x64.exe" -d "C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Prerequisites"
Task: {0E38147A-4851-42DC-9070-354ABDEA17FC} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {17C1BB3F-9616-44CB-922F-FF23AE97B1C0} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {1AC1141E-5152-4088-903E-CA244D117CC3} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {1F12A9F8-7D8D-4065-B944-4AEA70A1E4D3} - System32\Tasks\{F1F9B1E2-1649-459F-8D19-CE3F57076C12} => pcalua.exe -a "C:\Users\Admin\Downloads\chromeinstall-8u31 (1).exe" -d C:\Users\Admin\Downloads
Task: {27010340-37CF-488A-BE23-11555D46A73B} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {2DB268B3-0211-4F20-A876-262F2EEAD600} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {2F4F6831-28EB-427C-968C-08B0E3E853D5} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {3B0FA0E6-512C-4CB7-86BF-2CA54168DC9E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-02-13] (Microsoft Corporation)
Task: {40F43CEE-3685-41BD-BD05-D3E30DDF1876} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {4184E456-B813-43F0-9B55-96D23C9CD64C} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {41C95DAF-DDF2-405F-A8C4-7C2A140FA0E7} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {4EBCE7C4-AC84-4EAF-B36A-56BD4FF4205A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {5A65B13D-C7DD-442B-BC9F-E849177D96B1} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {5B136352-F75E-4BE9-8434-23C71C470FAC} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {5DC6463A-620C-498C-B8CC-3F26CD93C061} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {6D44F053-69EA-461A-ABFA-2E9FC7A0C0A4} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {6E01809B-A6A1-48BD-B4CA-115117903BF4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {6FC1A9A9-FC4E-40C5-A882-8E0B53ECC4D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {734D0CE1-F91D-46C2-AEF6-86D2515E6550} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {73907E84-CF68-44D4-BC7D-C426518C8A13} - System32\Tasks\{459661D1-D2F6-419D-ADE9-E7E05FD0DA52} => pcalua.exe -a C:\ProgramData\HealthAlert\uninstall.exe -c /kb=y /ic=1
Task: {75DDAAA5-05CE-48D1-917F-D076DB6B8997} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {7CD1B924-1215-4D6F-B79B-0807B81C65DD} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {927B26A2-EDC4-4E89-A784-2709B910E102} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {975DC5FC-0BF4-4734-A115-4331365C7EC0} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {9B842312-0CD7-412B-9771-E75313F50259} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {A3A38E1E-FA91-4361-A90B-CB608B7FE192} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {ABF95328-BD1A-4C58-AA4C-7D9E44654241} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {ADAA0D57-05AF-4D42-97A2-CA60B486A4FD} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {B0297718-FC73-4D55-A112-237A0A2FA275} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {BCF1AC20-C954-415B-90EB-09B341F654CA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {DA3C86F9-5E29-40D8-8035-3E189AC2D6E3} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DEADD6EE-4754-42BF-96F9-AF94B6F06D4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E04234EA-61B8-4CE5-B5DF-08E264BCF2FC} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {E5FA8F18-29CC-41E7-BDEC-EC7888343D95} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {EDACD965-B245-4FD8-8F97-275FB23FECAB} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {F1A14AE5-8D99-4F21-9EEF-F5C2007E7C6B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {F855E92F-2699-4DE3-AF41-951E76CED339} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-03 03:57 - 2016-02-09 06:29 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-12-03 19:37 - 2015-11-22 11:47 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 19:37 - 2015-11-22 11:47 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-01-21 20:31 - 2016-01-21 20:32 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-17 20:43 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-12-17 20:43 - 2015-12-07 05:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-12 20:52 - 2016-01-05 02:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-12 20:52 - 2016-01-05 02:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-27 19:53 - 2016-01-16 06:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-27 19:53 - 2016-01-16 06:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-02-05 20:15 - 2016-02-05 20:15 - 00015872 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.201.11370.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-02-05 20:15 - 2016-02-05 20:15 - 14869504 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.201.11370.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2015-11-19 18:55 - 2015-11-19 18:56 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.201.11370.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2016-01-21 20:31 - 2016-01-21 20:32 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 20:31 - 2016-01-21 20:32 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-03-30 22:38 - 2016-01-12 05:43 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\ProgramData\TEMP:8CE646EE

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2015-01-26 20:44 - 00000027 ____N C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1      localhost

==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-988284940-210793992-766847566-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\Pictures\Wallpaper\the_witcher_3_wild_hunt_wallpaper_3-1920x1200.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
HKLM\...\StartupApproved\StartupFolder: => "TP-LINK-Konfigurationstool.lnk"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\StartupApproved\Run: => "Dxtory Update Checker 2.0"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{6E420D0A-379E-4325-997B-5705899CAC39}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe
FirewallRules: [{B96ABC35-9B8B-4784-A9DB-0C1EA97B9030}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe
FirewallRules: [{0F6FC0BD-FCD4-42C7-B4AA-5BC87EE1A220}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
FirewallRules: [{B314AF56-BBF0-45AF-8C29-039C4BD429B8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
FirewallRules: [{256921F5-44A9-4B3A-BD2B-2A570C22DE55}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{57D125E4-42FB-44D2-A0EE-0F02B56DFC57}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F971CB50-BA99-4142-B8DF-8B89A8E07B33}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{E7D8D473-00F7-4EE1-9530-60C4A0F4C150}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{4925243F-FBE6-44B7-A975-BCCB0C180AF7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{30FDAB68-6C8E-4A7B-AA22-CCEA454D4F1A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{506017D7-8AC0-4E6C-A834-C122FCF909C4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds_RADEON.exe
FirewallRules: [{795906C9-BC9B-49FA-8325-C7C8870C2EF3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds_RADEON.exe
FirewallRules: [{E9A061A9-73B5-482C-997D-862ACF115145}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds.exe
FirewallRules: [{F4EBEA40-A7D8-43C7-AE9D-778C4CA5D7CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds.exe
FirewallRules: [{65C91C97-F856-4271-9C73-C98B7567A801}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{360AEBC8-A0BE-4E94-8A33-AE6EAEC656E8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{315E15EB-B4F1-43E8-A4E6-402275B529A5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FF509E52-645D-4365-84AD-FB0C261C9868}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C5998C02-632D-43E9-90CA-60097EF8E86A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{991121E2-9026-4743-B7E5-7A8E55384142}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{86DF2C1A-1739-488B-875A-1AC9DB9C5060}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{6064EF51-4B50-4444-B1A4-EFA61BFF49F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{1B15FC00-36FB-4A93-AE32-9647175F8F76}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{DC722C51-C46D-40EC-8668-E362EAE276B6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\HowToSurvive.exe
FirewallRules: [{C3A04E99-322D-46E9-B9BD-703483A7B189}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\HowToSurvive.exe
FirewallRules: [{0F98958F-E861-40DD-BDC6-995B42040165}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\Detect.exe
FirewallRules: [{36EB300B-5DA7-4BF0-90A6-F1DE17CD6573}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\Detect.exe
FirewallRules: [{49455361-4214-40EC-B265-FC6266F267D5}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe
FirewallRules: [{3956483D-656F-4265-BDA2-02173B16C080}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe
FirewallRules: [{D307758E-88ED-41D1-BA4D-784FC8711CA3}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe
FirewallRules: [{83F8AF97-7FB9-454C-A591-89EB18A99069}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe
FirewallRules: [{711528E3-97F2-4F8A-9EA5-082E57617A17}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\UPlayBrowser.exe
FirewallRules: [{C5046C9C-B48A-4D3C-AE86-93A41B7D5923}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\UPlayBrowser.exe
FirewallRules: [{7DB14810-4D82-4530-8D15-AC1FCBB8292F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{D2A93941-11DF-48F6-860B-F94D40812543}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{43838B64-8209-499B-ADF7-50A08698FC1C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{04679FA5-74EB-4F69-9CF8-D680702FF885}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [TCP Query User{AA756576-BAC1-4E66-88B8-E0048499E0E2}C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [UDP Query User{D89FE854-8AF1-4764-9460-3B065BD66B94}C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [{3248C1A6-D190-4F12-8664-CE8FC448256F}] => (Block) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [{3C04B63A-6BE8-44F6-9601-3F5512BD4BD5}] => (Block) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [{C5EB114E-20B2-4E5A-A3C0-42DB2A0E0E3B}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe
FirewallRules: [{B3BEF09D-7E43-474E-B668-25C680E2C25F}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe
FirewallRules: [{E739C62B-55ED-493C-8218-9EA012051BBD}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{1DDA49CF-21C4-4183-902F-D13104F301A1}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2C3D6D71-6A44-4A80-B2A7-219C1420825F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{D560325B-8725-48E5-8ABC-2E1FF99FCE98}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{E48773F8-4DF5-4A58-A166-1B312C9269EF}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe
FirewallRules: [{412CA1BF-B6E1-4713-B8FB-7EBC424876D0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe
FirewallRules: [{2D959B1C-9A0A-4CAC-A4FC-75936D9D49F2}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRMP.exe
FirewallRules: [{C0F791F9-DF54-4563-8410-219F17F6D25F}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRMP.exe
FirewallRules: [{6CE64287-2232-4D23-AE8C-292D1C5D4F93}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe
FirewallRules: [{4E8BD3CA-B72A-4C48-A323-F5A3B2EBF83E}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe
FirewallRules: [{00AB475C-77DB-4C57-B574-1D524BA5CA20}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Binding Of Isaac\Isaac.exe
FirewallRules: [{9AAD1A10-DA90-478C-9C63-08C7D8B02EC8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Binding Of Isaac\Isaac.exe
FirewallRules: [{090A43EF-2DD9-4261-990A-CAFE332D8E92}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\SinglePlayer\Binaries\Win32\BatmanOrigins.exe
FirewallRules: [{2102550E-749E-41E2-8FEE-B7EBBD08C1CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\SinglePlayer\Binaries\Win32\BatmanOrigins.exe
FirewallRules: [{4BCFAB4F-2B9D-45DE-B077-F08168D5D67C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\Online\Binaries\Win32\BatmanOriginsOnline.exe
FirewallRules: [{E42C92D2-79D8-4882-87F6-3B1B1594FDE7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\Online\Binaries\Win32\BatmanOriginsOnline.exe
FirewallRules: [TCP Query User{C1109CDB-71AE-439E-B1C2-50213C8C7A5B}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [UDP Query User{83D4C6C7-813C-44E2-B75B-C4BE83A4CB62}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [{36973D42-9A1C-4CFE-BF4D-E518212F5373}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ValveTestApp207490\Rayman Origins.exe
FirewallRules: [{7D9C5840-7C9D-46DF-B0A2-BC21610BF4A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ValveTestApp207490\Rayman Origins.exe
FirewallRules: [{C879E974-3CD9-40F1-9C30-303E9B43905F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{C7E055CB-D40D-4E27-B447-69B9B33F8345}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{12825260-A3BB-45E7-9C28-A1420FF60F33}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{997E46D0-78E6-4A77-8D4F-3A92C07FE6B0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{CFB6F006-D750-49A3-BAE0-6BDFB7E2AC9C}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{6B5F1130-E279-488D-AE55-A2DAE030F088}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{CEED23D0-3A11-4786-864D-3081A7F322BE}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{DE762189-4EF7-4EC1-A60F-21B017CB8085}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{6D55673B-0FF9-4D59-A9A2-9F7BDF50B34C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
FirewallRules: [{A2B93ADD-9986-4733-9E48-06254363C283}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
FirewallRules: [{9E681173-7A4C-46C3-86A6-A36B1C2B5BA3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{05AA5451-BEE9-4D9E-94C0-0B0EC6026DC5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{7D4D3518-150E-4447-B19A-4B0748E50D4B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Spelunky\Spelunky.exe
FirewallRules: [{AF8D2895-5885-495F-9C5B-E3B660A1F778}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Spelunky\Spelunky.exe
FirewallRules: [TCP Query User{A544BD62-14C2-4259-AAEF-022952556857}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [UDP Query User{3909E355-B5FB-4A27-9199-194854704AAD}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [{545D9B8D-9953-4CB7-8C25-D73B6336E07A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{29E901E5-DBD7-43C3-A1BC-B594CC13EA25}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{3259E222-4518-4F5A-8904-4EE437F4BBFB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{0F2CF57D-DE06-430D-82E2-7174208088DC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{1F3813EE-F4C8-49CB-8E88-BD546DB1DA23}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{6E7F3C96-0F1D-4656-9A5C-740C8216C7D9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{C9ACFBFE-A603-4442-A109-BCD1CC90A1DD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{05C428E6-A1B0-451B-B550-113694555C8E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{460DC9FE-CE1D-4C6B-B70E-1703B62E80E1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{4E52E920-FB9E-4B2F-85DE-B8FBBB13529B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{286BEAE6-98AE-4193-BA0D-534FE8742A51}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{C22367D4-EBB9-418D-B4E8-5F73846A2869}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{BC8E747A-F61E-4EB5-84D4-E88C3716963C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{7DC3F700-62CA-4230-B7C6-F13844A6B5B2}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{BFCBE96B-6F69-480B-8884-A8212FEEAC8A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{9FFD4D7B-09F4-4441-ACF9-B3D8D37FE1B2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{871626AC-BD7C-4745-A16B-45EE7A67EB03}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{42F54F3E-40B8-4B0B-823A-B3B14CEFC3BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{E97DDFC4-E97B-4704-B17D-FD5020048649}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Torchlight\Torchlight.exe
FirewallRules: [{52B0886E-3621-49AD-964F-D4A2E707BE12}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Torchlight\Torchlight.exe
FirewallRules: [{F41E3239-CD33-4579-B34B-0AAF256F6C55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{D430042B-5DF0-418A-880D-9230DBE275EF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{2B96A400-FD44-4DFD-9CFC-D29F6FB58F7D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metro 2033\metro2033.exe
FirewallRules: [{D793FCDF-0842-4FBC-90D7-B0973680D2EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metro 2033\metro2033.exe
FirewallRules: [TCP Query User{4BCF5F21-C99A-478A-95FD-4A0869F00131}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [UDP Query User{9E1EF25B-113D-422A-A4F8-11CBCA584F82}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [{3F675CC0-3184-4393-894F-B4B33B351994}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{129A599D-446F-40B7-A918-9B2D3D6375EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{20ECE902-9A57-4F70-8E04-4C88E2419E05}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Last Remnant\Binaries\TLR.exe
FirewallRules: [{2D848495-1A91-4179-8CBB-3866ED0E0C34}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Last Remnant\Binaries\TLR.exe
FirewallRules: [{BA367573-7B8F-4777-8AB5-864A549D3CFB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{CF00F149-60EB-48EB-92C5-AF5CB3E8B370}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{02A409DB-0A4D-415A-B68D-E2C8AD421B30}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{7A43CD6B-4116-4279-9B1A-29C245724E88}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{B063BE0A-60F7-4EE4-9FA6-88A2EFB1FBE4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{3B571F71-ACD4-4B5A-9DB1-75CFA55B3D21}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{3620AD47-E894-47F8-84C8-CB1D91B3110C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{7423B0B5-233A-473C-BB3C-A4032B7EA0BE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{1505A911-84EC-4CAE-AE32-E71696A44070}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tropico\Tropico.EXE
FirewallRules: [{E32F9C77-6C08-45FD-A02D-B36226C008B3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tropico\Tropico.EXE
FirewallRules: [{F581802C-2D95-4E59-B72E-6FFD315D8182}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CF63116B-20B3-4892-A712-102390ED402D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4C6692EF-51C0-4623-8C57-40EBA18FDEF4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{49A3271C-BB1D-43DD-9654-075D79195F0E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{DCBC8CE9-D293-4FA1-879B-270196EED1A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
FirewallRules: [{9A9181C1-7313-4E03-936A-64B3E573D028}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
FirewallRules: [{D14185D7-9F38-4C57-965F-43D51E98A39D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{863A7EB5-4496-4987-BF95-C22A2FA2AC22}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{43CF3CA2-59D2-450E-B920-4FC4ABD57704}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\1954 Alcatraz\Alcatraz.exe
FirewallRules: [{2E4E2EBA-A40A-4895-80FD-F0DE745402A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\1954 Alcatraz\Alcatraz.exe
FirewallRules: [{CA846C69-619B-40C8-8594-E8FDF54622DF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{AC494E79-2D9F-423D-847E-3000CCD76907}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{8BFD8407-04E7-4FA9-9E1F-150B376B9783}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F58ADA5A-4C45-4891-9DD3-8254D2E612CF}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{6ACFA7C6-CB3F-4F28-BC50-AAD2F0E06B3F}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{58515D64-FDE2-448A-9448-2FEA27E88E4C}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{876C7FEA-0DEE-4871-BFAB-053A02AED9AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Wolf Among Us\TheWolfAmongUs.exe
FirewallRules: [{BB4BF462-7275-4801-8131-484F5D2EA2C9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Wolf Among Us\TheWolfAmongUs.exe
FirewallRules: [{523A1B31-06BB-4D69-B1DE-10F60E4F3610}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{A153552B-49D1-4361-A137-0D94D18D37B4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{D43680B8-0ACE-4C04-80C7-D8D967C754EA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{B196BF22-7291-48F4-AC03-1DE595A40997}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{4FA950EC-A651-4B05-B178-761195FED113}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B94E9B0F-047D-4BF0-9928-0BE7465C6A86}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization IV\Civilization4.exe
FirewallRules: [{4C463636-3D0B-489D-8D47-B867BB940BCD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization IV\Civilization4.exe
FirewallRules: [TCP Query User{2785A175-2DF4-40EA-91A6-769AEBF450A8}C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [UDP Query User{15F167CC-DEE4-46D4-B376-1BBC8B6631B2}C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [{C648A936-27DA-4F97-9B13-FAF1A85070B9}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSA08E.tmp\SymNRT.exe
FirewallRules: [{330A2776-D04B-4D5E-BA65-F84A7657D6E1}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSA08E.tmp\SymNRT.exe
FirewallRules: [{1C6D9EA5-3BB6-4857-B833-2082CC9F4CDB}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSC64F.tmp\SymNRT.exe
FirewallRules: [{AF593FDA-A8A7-4C9A-ABD1-92EC5903C4AF}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSC64F.tmp\SymNRT.exe
FirewallRules: [{8975AD88-F6EA-4954-9D0A-276E0BE02EB6}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSACAD.tmp\SymNRT.exe
FirewallRules: [{03D5B382-45AA-448A-B5EF-8C2C4A54030F}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSACAD.tmp\SymNRT.exe

==================== Wiederherstellungspunkte =========================

22-02-2016 10:43:20 Geplanter Prüfpunkt

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (02/26/2016 05:40:58 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/26/2016 05:23:25 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/25/2016 08:43:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: backgroundTaskHost.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d8f0
Name des fehlerhaften Moduls: Cortana.BackgroundTask.dll, Version: 0.0.0.0, Zeitstempel: 0x5699d0c9
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000046a65
ID des fehlerhaften Prozesses: 0x1ba8
Startzeit der fehlerhaften Anwendung: 0xbackgroundTaskHost.exe0
Pfad der fehlerhaften Anwendung: backgroundTaskHost.exe1
Pfad des fehlerhaften Moduls: backgroundTaskHost.exe2
Berichtskennung: backgroundTaskHost.exe3
Vollständiger Name des fehlerhaften Pakets: backgroundTaskHost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: backgroundTaskHost.exe5

Error: (02/25/2016 08:41:10 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/25/2016 11:44:23 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (02/25/2016 11:40:52 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/25/2016 11:27:00 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Admin-PC)
Description: Bei der Aktivierung der App „Microsoft.Getstarted_2.6.12.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca“ ist folgender Fehler aufgetreten: -2144927149. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (02/25/2016 11:01:27 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/25/2016 10:42:04 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Name des fehlerhaften Moduls: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Ausnahmecode: 0xe0464645
Fehleroffset: 0x000000000000a6d6
ID des fehlerhaften Prozesses: 0x1680
Startzeit der fehlerhaften Anwendung: 0xNetworkUXBroker.exe0
Pfad der fehlerhaften Anwendung: NetworkUXBroker.exe1
Pfad des fehlerhaften Moduls: NetworkUXBroker.exe2
Berichtskennung: NetworkUXBroker.exe3
Vollständiger Name des fehlerhaften Pakets: NetworkUXBroker.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NetworkUXBroker.exe5

Error: (02/25/2016 10:41:15 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Name des fehlerhaften Moduls: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Ausnahmecode: 0xe0464645
Fehleroffset: 0x000000000000a6d6
ID des fehlerhaften Prozesses: 0x1680
Startzeit der fehlerhaften Anwendung: 0xNetworkUXBroker.exe0
Pfad der fehlerhaften Anwendung: NetworkUXBroker.exe1
Pfad des fehlerhaften Moduls: NetworkUXBroker.exe2
Berichtskennung: NetworkUXBroker.exe3
Vollständiger Name des fehlerhaften Pakets: NetworkUXBroker.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NetworkUXBroker.exe5


Systemfehler:
=============
Error: (02/26/2016 09:33:44 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 09:33:44 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 09:33:44 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 09:33:44 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 05:58:51 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 05:58:51 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 05:58:51 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 05:58:51 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 05:42:16 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/26/2016 05:42:16 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
Prozentuale Nutzung des RAM: 16%
Installierter physikalischer RAM: 16262.64 MB
Verfügbarer physikalischer RAM: 13587.74 MB
Summe virtueller Speicher: 32646.64 MB
Verfügbarer virtueller Speicher: 29495.8 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:1862.48 GB) (Free:1008.25 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 462E0839)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

==================== Ende von Addition.txt ============================


Larusso 27.02.2016 10:50

Hy.

Ich sehe da jetzt keine wirkliche Malware aber paar Dinge möchte ich noch genauer überprüfen.
Norton sollte sich nicht mehr in der Liste von zu deinstallierbarer Software befinden und ist auch nicht mehr in der Windows Verwaltung zu finden. Somit sollte es eigentlich deinstalliert sein, aber es hat halt dezent viele Starteinträge hinterlassen.
Wir nennen es nicht umsonst die gelbe Pest.
Hat der Techniker da 10x das Uninstaller Tool herunter geladen und ausgeführt ? :headbang:

Starte den Rechner bitte in den abgesicherten Modus. Führe dort das Removal Tool erneut aus.
Starte danach in den normalen Modus.

Je nachdem, sag mir ob es gelaufen ist.


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec*.lnk

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.



Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Kanso 27.02.2016 12:11

Hallo,

ich hatte nicht den Eindruck, dass der Miarbeiter von Norton Ahnung hatte von dem was er tut. Er hat es auf jeden Fall ziemlich oft probiert Norten neu zu installieren, ohne großen Erfolg. So ich hab das Uinstall Tool im abgesicherten Modus ausgeführt. Ist auch soweit fehlerfrei durchgelaufen.

Hier der Fixlog:

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:24-02-2016
durchgeführt von Admin (2016-02-27 11:51:12) Run:1
Gestartet von C:\Users\Admin\Desktop
Geladene Profile: Admin (Verfügbare Profile: Admin & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec*.lnk
*****************


=========== "C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec*.lnk" ==========

C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (10).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (2).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (3).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (4).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (5).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (6).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (7).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (8).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (9).lnk => erfolgreich verschoben
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk => erfolgreich verschoben

========= Ende -> "C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec*.lnk" ========


==== Ende von Fixlog 11:51:12 ====

Rootkits wurden Gott sei dank keine gefunden hier der Report:

Code:

11:53:57.0145 0x1b3c  TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12
11:54:01.0410 0x1b3c  ============================================================
11:54:01.0410 0x1b3c  Current date / time: 2016/02/27 11:54:01.0410
11:54:01.0410 0x1b3c  SystemInfo:
11:54:01.0410 0x1b3c 
11:54:01.0411 0x1b3c  OS Version: 10.0.10586 ServicePack: 0.0
11:54:01.0411 0x1b3c  Product type: Workstation
11:54:01.0411 0x1b3c  ComputerName: ADMIN-PC
11:54:01.0411 0x1b3c  UserName: Admin
11:54:01.0411 0x1b3c  Windows directory: C:\WINDOWS
11:54:01.0411 0x1b3c  System windows directory: C:\WINDOWS
11:54:01.0411 0x1b3c  Running under WOW64
11:54:01.0411 0x1b3c  Processor architecture: Intel x64
11:54:01.0411 0x1b3c  Number of processors: 4
11:54:01.0411 0x1b3c  Page size: 0x1000
11:54:01.0411 0x1b3c  Boot type: Normal boot
11:54:01.0411 0x1b3c  ============================================================
11:54:01.0877 0x1b3c  KLMD registered as C:\WINDOWS\system32\drivers\83047933.sys
11:54:02.0633 0x1b3c  System UUID: {FA7F67B2-09A3-7EBB-44B6-5ABA34BB06AF}
11:54:03.0205 0x1b3c  Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:54:03.0543 0x1b3c  ============================================================
11:54:03.0543 0x1b3c  \Device\Harddisk0\DR0:
11:54:03.0565 0x1b3c  MBR partitions:
11:54:03.0565 0x1b3c  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:54:03.0565 0x1b3c  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xE8CF4000
11:54:03.0565 0x1b3c  ============================================================
11:54:03.0637 0x1b3c  C: <-> \Device\Harddisk0\DR0\Partition2
11:54:03.0637 0x1b3c  ============================================================
11:54:03.0637 0x1b3c  Initialize success
11:54:03.0637 0x1b3c  ============================================================
11:55:27.0270 0x09d8  ============================================================
11:55:27.0270 0x09d8  Scan started
11:55:27.0270 0x09d8  Mode: Manual; SigCheck; TDLFS;
11:55:27.0270 0x09d8  ============================================================
11:55:27.0270 0x09d8  KSN ping started
11:55:29.0613 0x09d8  KSN ping finished: true
11:55:31.0348 0x09d8  ================ Scan system memory ========================
11:55:31.0348 0x09d8  System memory - ok
11:55:31.0348 0x09d8  ================ Scan services =============================
11:55:31.0473 0x09d8  1394ohci - ok
11:55:31.0488 0x09d8  3ware - ok
11:55:31.0488 0x09d8  ACPI - ok
11:55:31.0504 0x09d8  acpiex - ok
11:55:31.0504 0x09d8  acpipagr - ok
11:55:31.0520 0x09d8  AcpiPmi - ok
11:55:31.0520 0x09d8  acpitime - ok
11:55:31.0535 0x09d8  ADP80XX - ok
11:55:31.0551 0x09d8  AFD - ok
11:55:31.0551 0x09d8  agp440 - ok
11:55:31.0551 0x09d8  ahcache - ok
11:55:31.0551 0x09d8  AJRouter - ok
11:55:31.0567 0x09d8  ALG - ok
11:55:31.0567 0x09d8  AmdK8 - ok
11:55:31.0567 0x09d8  AmdPPM - ok
11:55:31.0582 0x09d8  amdsata - ok
11:55:31.0582 0x09d8  amdsbs - ok
11:55:31.0582 0x09d8  amdxata - ok
11:55:31.0629 0x09d8  AppHostSvc - ok
11:55:31.0645 0x09d8  AppID - ok
11:55:31.0645 0x09d8  AppIDSvc - ok
11:55:31.0660 0x09d8  Appinfo - ok
11:55:31.0660 0x09d8  AppMgmt - ok
11:55:31.0676 0x09d8  AppReadiness - ok
11:55:31.0676 0x09d8  AppXSvc - ok
11:55:31.0692 0x09d8  arcsas - ok
11:55:31.0738 0x09d8  aspnet_state - ok
11:55:31.0738 0x09d8  AsyncMac - ok
11:55:31.0754 0x09d8  atapi - ok
11:55:31.0770 0x09d8  AudioEndpointBuilder - ok
11:55:31.0770 0x09d8  Audiosrv - ok
11:55:31.0770 0x09d8  AxInstSV - ok
11:55:31.0785 0x09d8  b06bdrv - ok
11:55:31.0801 0x09d8  BasicDisplay - ok
11:55:31.0817 0x09d8  BasicRender - ok
11:55:31.0817 0x09d8  bcmfn - ok
11:55:31.0817 0x09d8  bcmfn2 - ok
11:55:31.0817 0x09d8  BDESVC - ok
11:55:31.0832 0x09d8  Beep - ok
11:55:31.0832 0x09d8  BFE - ok
11:55:31.0879 0x09d8  BITS - ok
11:55:31.0910 0x09d8  bowser - ok
11:55:31.0910 0x09d8  BrokerInfrastructure - ok
11:55:31.0910 0x09d8  Browser - ok
11:55:32.0051 0x09d8  [ 910B5BF2353D5D982D2F6B8F6454A00A, E27A0E9EDF50A935E83F4D5BD86C9B9B297F1B8193AFB7C28313B28B5A4B27A5 ] BstHdAndroidSvc C:\Program Files (x86)\BlueStacks\HD-Service.exe
11:55:32.0129 0x09d8  BstHdAndroidSvc - ok
11:55:32.0145 0x09d8  [ 6A4D927BDEE8D9944FAA0012AF7AD232, F0B8642FB02628899CCE526A59A18E0A89456AA2385E82CD97B25CFC64C0E92E ] BstHdDrv        C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys
11:55:32.0192 0x09d8  BstHdDrv - ok
11:55:32.0223 0x09d8  [ 95B960980034877821E7FB5BFE25136E, 64EA26E9E94767C9EBEEF26FEEAA3176BB7787785F5F20CB8BBB4C75F45AAAA1 ] BstHdLogRotatorSvc C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
11:55:32.0395 0x09d8  BstHdLogRotatorSvc - ok
11:55:32.0457 0x09d8  [ 5EBFF8D302047F4709F3A4F1231236E9, 84010BB25C4C029C03C98853E8AC75F103D1F34922B0643ECD758CE21E7DE4A6 ] BstHdUpdaterSvc C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
11:55:32.0504 0x09d8  BstHdUpdaterSvc - ok
11:55:32.0535 0x09d8  BthAvrcpTg - ok
11:55:32.0551 0x09d8  BthHFEnum - ok
11:55:32.0551 0x09d8  bthhfhid - ok
11:55:32.0567 0x09d8  BthHFSrv - ok
11:55:32.0567 0x09d8  BTHMODEM - ok
11:55:32.0567 0x09d8  bthserv - ok
11:55:32.0582 0x09d8  buttonconverter - ok
11:55:32.0598 0x09d8  CapImg - ok
11:55:32.0598 0x09d8  cdfs - ok
11:55:32.0598 0x09d8  CDPSvc - ok
11:55:32.0613 0x09d8  cdrom - ok
11:55:32.0613 0x09d8  CertPropSvc - ok
11:55:32.0613 0x09d8  circlass - ok
11:55:32.0613 0x09d8  CLFS - ok
11:55:32.0629 0x09d8  ClipSVC - ok
11:55:32.0629 0x09d8  CmBatt - ok
11:55:32.0645 0x09d8  CNG - ok
11:55:32.0645 0x09d8  cnghwassist - ok
11:55:32.0692 0x09d8  CompositeBus - ok
11:55:32.0692 0x09d8  COMSysApp - ok
11:55:32.0692 0x09d8  condrv - ok
11:55:32.0692 0x09d8  CoreMessagingRegistrar - ok
11:55:32.0754 0x09d8  [ 137BC921135ECDA3E9917B56E3550D32, 6585F4FFEAB32583B867A14F7B7C09C563B1EA715AD9C3B850A7965C54A819A0 ] cphs            C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
11:55:32.0988 0x09d8  cphs - ok
11:55:33.0004 0x09d8  CryptSvc - ok
11:55:33.0020 0x09d8  CSC - ok
11:55:33.0020 0x09d8  CscService - ok
11:55:33.0160 0x09d8  [ B4D1D62A09F09CB2DFD55628350CDAFB, 7DD3CE77D88B5AFAC4B6187F4CA6D50B7BD3398207163B2A1E4C76467801FF28 ] cvhsvc          C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
11:55:33.0192 0x09d8  cvhsvc - ok
11:55:33.0192 0x09d8  dam - ok
11:55:33.0192 0x09d8  DcomLaunch - ok
11:55:33.0192 0x09d8  DcpSvc - ok
11:55:33.0207 0x09d8  defragsvc - ok
11:55:33.0207 0x09d8  DeviceAssociationService - ok
11:55:33.0223 0x09d8  DeviceInstall - ok
11:55:33.0223 0x09d8  DevQueryBroker - ok
11:55:33.0238 0x09d8  Dfsc - ok
11:55:33.0238 0x09d8  Dhcp - ok
11:55:33.0301 0x09d8  diagnosticshub.standardcollector.service - ok
11:55:33.0301 0x09d8  DiagTrack - ok
11:55:33.0317 0x09d8  disk - ok
11:55:33.0332 0x09d8  DmEnrollmentSvc - ok
11:55:33.0332 0x09d8  dmvsc - ok
11:55:33.0332 0x09d8  dmwappushservice - ok
11:55:33.0332 0x09d8  Dnscache - ok
11:55:33.0348 0x09d8  dot3svc - ok
11:55:33.0348 0x09d8  DPS - ok
11:55:33.0395 0x09d8  drmkaud - ok
11:55:33.0395 0x09d8  DsmSvc - ok
11:55:33.0410 0x09d8  DsSvc - ok
11:55:33.0442 0x09d8  DXGKrnl - ok
11:55:33.0442 0x09d8  Eaphost - ok
11:55:33.0442 0x09d8  ebdrv - ok
11:55:33.0457 0x09d8  EFS - ok
11:55:33.0457 0x09d8  EhStorClass - ok
11:55:33.0473 0x09d8  EhStorTcgDrv - ok
11:55:33.0488 0x09d8  embeddedmode - ok
11:55:33.0488 0x09d8  EntAppSvc - ok
11:55:33.0488 0x09d8  ErrDev - ok
11:55:33.0520 0x09d8  EventSystem - ok
11:55:33.0520 0x09d8  exfat - ok
11:55:33.0520 0x09d8  fastfat - ok
11:55:33.0520 0x09d8  Fax - ok
11:55:33.0520 0x09d8  fdc - ok
11:55:33.0535 0x09d8  fdPHost - ok
11:55:33.0535 0x09d8  FDResPub - ok
11:55:33.0535 0x09d8  fhsvc - ok
11:55:33.0567 0x09d8  FileCrypt - ok
11:55:33.0567 0x09d8  FileInfo - ok
11:55:33.0567 0x09d8  Filetrace - ok
11:55:33.0567 0x09d8  flpydisk - ok
11:55:33.0582 0x09d8  FltMgr - ok
11:55:33.0598 0x09d8  FontCache - ok
11:55:33.0692 0x09d8  FontCache3.0.0.0 - ok
11:55:33.0707 0x09d8  FsDepends - ok
11:55:33.0707 0x09d8  Fs_Rec - ok
11:55:33.0723 0x09d8  fvevol - ok
11:55:33.0723 0x09d8  gagp30kx - ok
11:55:33.0848 0x09d8  [ 6D18B1088696CF96CBEBD31B8A519BD4, 4B47EECD18C12749FBEFA9C20B466F1A501F238166BBAE5B1793C918305A3348 ] GalaxyClientService C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe
11:55:33.0942 0x09d8  GalaxyClientService - ok
11:55:34.0207 0x09d8  [ C6B53600271EA23A03D5C23316407013, A2B672134EC6415D689F5F1BDF0500B876CB3BA2BA022E4C7FF4C15215AF7BC2 ] GalaxyCommunication C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
11:55:34.0629 0x09d8  GalaxyCommunication - ok
11:55:34.0660 0x09d8  gencounter - ok
11:55:34.0676 0x09d8  genericusbfn - ok
11:55:34.0848 0x09d8  [ 061CC5C12C39899D7398CFEBFD19F69F, 62319596863A74665FA801C305C952A0F20AAA0F1CDC2195F2F69D662790C80B ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
11:55:34.0895 0x09d8  GfExperienceService - ok
11:55:34.0895 0x09d8  GPIOClx0101 - ok
11:55:34.0926 0x09d8  gpsvc - ok
11:55:34.0926 0x09d8  GpuEnergyDrv - ok
11:55:34.0926 0x09d8  HDAudBus - ok
11:55:34.0926 0x09d8  HidBatt - ok
11:55:34.0926 0x09d8  HidBth - ok
11:55:34.0926 0x09d8  hidi2c - ok
11:55:34.0942 0x09d8  hidinterrupt - ok
11:55:34.0942 0x09d8  HidIr - ok
11:55:34.0942 0x09d8  hidserv - ok
11:55:34.0942 0x09d8  HidUsb - ok
11:55:34.0957 0x09d8  HomeGroupListener - ok
11:55:34.0957 0x09d8  HomeGroupProvider - ok
11:55:34.0957 0x09d8  HpSAMD - ok
11:55:34.0988 0x09d8  HTTP - ok
11:55:34.0988 0x09d8  hwpolicy - ok
11:55:34.0988 0x09d8  hyperkbd - ok
11:55:35.0004 0x09d8  i8042prt - ok
11:55:35.0004 0x09d8  iai2c - ok
11:55:35.0004 0x09d8  iaLPSS2i_I2C - ok
11:55:35.0004 0x09d8  iaLPSSi_GPIO - ok
11:55:35.0004 0x09d8  iaLPSSi_I2C - ok
11:55:35.0082 0x09d8  [ FA4C48E36F0B24E7E33D3E7E1844B9C9, F61F448B8E305DEFDDA5D4A6FC4E57C798C11ED4DA0ACB885847DC8A9A7B4E98 ] iaStorA        C:\WINDOWS\system32\drivers\iaStorA.sys
11:55:35.0098 0x09d8  iaStorA - ok
11:55:35.0098 0x09d8  iaStorAV - ok
11:55:35.0160 0x09d8  [ D5854F77CEEAFC5A8405F8ECCBEC09DF, 06D94EAF55787F807FB40E95011E90B0A719AC1A1529C2C110C1EABC5BE02C5B ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
11:55:35.0223 0x09d8  IAStorDataMgrSvc - ok
11:55:35.0223 0x09d8  iaStorV - ok
11:55:35.0223 0x09d8  ibbus - ok
11:55:35.0238 0x09d8  icssvc - ok
11:55:35.0301 0x09d8  [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT        C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
11:55:35.0379 0x09d8  IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
11:55:37.0723 0x09d8  Detect skipped due to KSN trusted
11:55:37.0723 0x09d8  IDriverT - ok
11:55:37.0723 0x09d8  IEEtwCollectorService - ok
11:55:37.0942 0x09d8  [ 34E103A5EFF7EADA5ADE6D61294FAA7F, 29AFF3C2C03D75B55D124EBA35534C1D7E2115748C23EAC79CF0FA6CBC994C1F ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
11:55:38.0270 0x09d8  igfx - ok
11:55:38.0301 0x09d8  [ 078DE1A9D9DB0BB617D4DCF1EF925928, 6E197785DE6F83FAB5E049F24CCC3838BB9B9EB20240BD48A2768103172B6242 ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
11:55:38.0348 0x09d8  igfxCUIService2.0.0.0 - ok
11:55:38.0364 0x09d8  IKEEXT - ok
11:55:38.0504 0x09d8  [ 622868E4BAE8FBCD22CB1A5901A2C824, C1A2264C0984DD16C83B663C9CE43E049E1356E32C5771C3ACE225F285699138 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
11:55:38.0598 0x09d8  IntcAzAudAddService - ok
11:55:38.0613 0x09d8  [ 47577F77C8DD9CF4265B944CAFE1F172, A3F48F01ECFDF8E609D26754E517C06AD6382DA231F42BF64B6746D50F02FC6A ] IntcDAud        C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
11:55:38.0645 0x09d8  IntcDAud - ok
11:55:38.0676 0x09d8  [ DDA8E5AD97231AB50B81FED04C28F64C, 5C9E8F7CC45A9AE7FF12A02641562E271D84894DFA7C50218AC2AAA298251B60 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
11:55:39.0176 0x09d8  Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
11:55:40.0489 0x17c8  Object required for P2P: [ C6B53600271EA23A03D5C23316407013 ] GalaxyCommunication
11:55:41.0520 0x09d8  Detect skipped due to KSN trusted
11:55:41.0520 0x09d8  Intel(R) Capability Licensing Service Interface - ok
11:55:41.0582 0x09d8  [ 86FE509640D77FB0998FC8B1FF5523C6, 13E895DEB9B84379251699D7E52C5E3FD888994425DE01B6C4634F9E959D5584 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
11:55:42.0207 0x09d8  Intel(R) Capability Licensing Service TCP IP Interface - ok
11:55:42.0207 0x09d8  intelide - ok
11:55:42.0223 0x09d8  intelpep - ok
11:55:42.0223 0x09d8  intelppm - ok
11:55:42.0223 0x09d8  IoQos - ok
11:55:42.0239 0x09d8  IpFilterDriver - ok
11:55:42.0239 0x09d8  iphlpsvc - ok
11:55:42.0270 0x09d8  IPMIDRV - ok
11:55:42.0270 0x09d8  IPNAT - ok
11:55:42.0270 0x09d8  IRENUM - ok
11:55:42.0270 0x09d8  isapnp - ok
11:55:42.0270 0x09d8  iScsiPrt - ok
11:55:42.0332 0x09d8  [ BF5D3A2624177C413680DEF19A465AF8, B9909D3E6CB6F9971293116387865AD15CB9D47513C7FAA9C36BE4D2847A41EB ] jhi_service    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
11:55:42.0410 0x09d8  jhi_service - ok
11:55:42.0426 0x09d8  kbdclass - ok
11:55:42.0426 0x09d8  kbdhid - ok
11:55:42.0426 0x09d8  kdnic - ok
11:55:42.0426 0x09d8  KeyIso - ok
11:55:42.0426 0x09d8  KSecDD - ok
11:55:42.0457 0x09d8  KSecPkg - ok
11:55:42.0457 0x09d8  ksthunk - ok
11:55:42.0473 0x09d8  KtmRm - ok
11:55:42.0473 0x09d8  LanmanServer - ok
11:55:42.0489 0x09d8  LanmanWorkstation - ok
11:55:42.0489 0x09d8  lfsvc - ok
11:55:42.0489 0x09d8  LicenseManager - ok
11:55:42.0535 0x09d8  [ 8E4CA9AFD55EF6B509C80A8715ABF8C6, 45698605D17285D346D2052607AEF492EBD89E9625367C31584C7C84757EEFE0 ] lirsgt          C:\WINDOWS\system32\DRIVERS\lirsgt.sys
11:55:42.0754 0x09d8  lirsgt - ok
11:55:42.0754 0x09d8  lltdio - ok
11:55:42.0754 0x09d8  lltdsvc - ok
11:55:42.0770 0x09d8  lmhosts - ok
11:55:42.0817 0x09d8  [ 02A9CBACE666877BBBA4FD66B22F6D4A, 0E783BA7A8F00CEC8F03CFEE03999CA5DB9E4DB7CCE62D9171CFCF36AFBE4BB1 ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:55:42.0832 0x09d8  LMS - ok
11:55:42.0832 0x09d8  LSI_SAS - ok
11:55:42.0864 0x09d8  LSI_SAS2i - ok
11:55:42.0864 0x09d8  LSI_SAS3i - ok
11:55:42.0864 0x09d8  LSI_SSS - ok
11:55:42.0864 0x09d8  LSM - ok
11:55:42.0879 0x09d8  luafv - ok
11:55:42.0895 0x09d8  MapsBroker - ok
11:55:42.0957 0x17c8  Object send P2P result: true
11:55:42.0957 0x09d8  [ A8D28D5B3E2A528D1EF0E338E44F2820, 40D1EFDD253BC0A0D984A5AD8A2721C3E83B15F14D538204714E6D5B00D92CEB ] MBAMProtector  C:\WINDOWS\system32\drivers\mbam.sys
11:55:42.0973 0x09d8  MBAMProtector - ok
11:55:43.0067 0x09d8  [ 301E3FDFCF33640BB8763BA444BC5093, 362B069BB9A313A06B376CE27E6F7F8D569F6CA39A8ABC96D9DF231EE462C604 ] MBAMScheduler  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
11:55:43.0098 0x09d8  MBAMScheduler - ok
11:55:43.0129 0x09d8  [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F606A16768A11DB0C ] MBAMService    C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
11:55:43.0145 0x09d8  MBAMService - ok
11:55:43.0176 0x09d8  [ 85CFE7AB85B43B6B7AC7961AA3983A9F, 4E88B75818FD00C0ABBDF8E02EBFB550A67B46E5E13D3B3DF52611793F7DA0DD ] MBAMWebAccessControl C:\WINDOWS\system32\drivers\mwac.sys
11:55:43.0176 0x09d8  MBAMWebAccessControl - ok
11:55:43.0176 0x09d8  megasas - ok
11:55:43.0176 0x09d8  megasr - ok
11:55:43.0223 0x09d8  [ 2BB3EAE2EA641515D4B205CAB29E1624, D3F18EE393EB1B0F919484281269A3C55A092D023E62C59D74CB63A55612024B ] MEIx64          C:\WINDOWS\System32\drivers\HECIx64.sys
11:55:43.0239 0x09d8  MEIx64 - ok
11:55:43.0270 0x09d8  MessagingService - ok
11:55:43.0332 0x09d8  mlx4_bus - ok
11:55:43.0332 0x09d8  MMCSS - ok
11:55:43.0332 0x09d8  Modem - ok
11:55:43.0348 0x09d8  monitor - ok
11:55:43.0348 0x09d8  mouclass - ok
11:55:43.0348 0x09d8  mouhid - ok
11:55:43.0348 0x09d8  mountmgr - ok
11:55:43.0395 0x09d8  [ 5961C5D8EDD2E2A3B99F1782AE1AC21F, C383A4724A335737C4C7C3211AFCFB82D373267EC634BC47EE078A1C66E1F62A ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:55:43.0489 0x09d8  MozillaMaintenance - ok
11:55:43.0489 0x09d8  mpsdrv - ok
11:55:43.0504 0x09d8  MpsSvc - ok
11:55:43.0520 0x09d8  MQAC - ok
11:55:43.0520 0x09d8  MRxDAV - ok
11:55:43.0520 0x09d8  mrxsmb - ok
11:55:43.0551 0x09d8  mrxsmb10 - ok
11:55:43.0567 0x09d8  mrxsmb20 - ok
11:55:43.0567 0x09d8  MsBridge - ok
11:55:43.0598 0x09d8  MSDTC - ok
11:55:43.0614 0x09d8  Msfs - ok
11:55:43.0629 0x09d8  msgpiowin32 - ok
11:55:43.0629 0x09d8  mshidkmdf - ok
11:55:43.0629 0x09d8  mshidumdf - ok
11:55:43.0645 0x09d8  msisadrv - ok
11:55:43.0660 0x09d8  MSiSCSI - ok
11:55:43.0660 0x09d8  msiserver - ok
11:55:43.0660 0x09d8  MSKSSRV - ok
11:55:43.0660 0x09d8  MsLldp - ok
11:55:43.0676 0x09d8  MSMQ - ok
11:55:43.0676 0x09d8  MSPCLOCK - ok
11:55:43.0676 0x09d8  MSPQM - ok
11:55:43.0676 0x09d8  MsRPC - ok
11:55:43.0676 0x09d8  mssmbios - ok
11:55:43.0676 0x09d8  MSTEE - ok
11:55:43.0692 0x09d8  MTConfig - ok
11:55:43.0692 0x09d8  Mup - ok
11:55:43.0692 0x09d8  mvumis - ok
11:55:43.0692 0x09d8  NativeWifiP - ok
11:55:43.0692 0x09d8  NcaSvc - ok
11:55:43.0707 0x09d8  NcbService - ok
11:55:43.0707 0x09d8  NcdAutoSetup - ok
11:55:43.0707 0x09d8  ndfltr - ok
11:55:43.0707 0x09d8  NDIS - ok
11:55:43.0707 0x09d8  NdisCap - ok
11:55:43.0707 0x09d8  NdisImPlatform - ok
11:55:43.0707 0x09d8  NdisTapi - ok
11:55:43.0707 0x09d8  Ndisuio - ok
11:55:43.0723 0x09d8  NdisVirtualBus - ok
11:55:43.0723 0x09d8  NdisWan - ok
11:55:43.0723 0x09d8  ndiswanlegacy - ok
11:55:43.0723 0x09d8  ndproxy - ok
11:55:43.0723 0x09d8  Ndu - ok
11:55:43.0723 0x09d8  NetBIOS - ok
11:55:43.0723 0x09d8  NetBT - ok
11:55:43.0723 0x09d8  Netlogon - ok
11:55:43.0739 0x09d8  Netman - ok
11:55:43.0754 0x09d8  NetMsmqActivator - ok
11:55:43.0754 0x09d8  NetPipeActivator - ok
11:55:43.0770 0x09d8  netprofm - ok
11:55:43.0817 0x09d8  NetSetupSvc - ok
11:55:43.0817 0x09d8  NetTcpActivator - ok
11:55:43.0817 0x09d8  NetTcpPortSharing - ok
11:55:43.0817 0x09d8  NgcCtnrSvc - ok
11:55:43.0817 0x09d8  NgcSvc - ok
11:55:43.0817 0x09d8  NlaSvc - ok
11:55:43.0817 0x09d8  Npfs - ok
11:55:43.0817 0x09d8  npsvctrig - ok
11:55:43.0832 0x09d8  nsi - ok
11:55:43.0832 0x09d8  nsiproxy - ok
11:55:43.0848 0x09d8  NTFS - ok
11:55:43.0848 0x09d8  Null - ok
11:55:43.0895 0x09d8  [ 786DB821BFD57C0551DBBE4F75384A7D, F956D636F834F2BA5F019E187FDB9CC33940363C75A60E53CD81310A4DB6A6AB ] nusb3hub        C:\WINDOWS\system32\drivers\nusb3hub.sys
11:55:44.0020 0x09d8  nusb3hub - ok
11:55:44.0051 0x09d8  [ DAA8005CAF745042BB427A1ED7433354, 3019002F174783B76D5D8AA47F7A465B7FEC7C14235B70E5C9277FE534839226 ] nusb3xhc        C:\WINDOWS\system32\drivers\nusb3xhc.sys
11:55:44.0098 0x09d8  nusb3xhc - ok
11:55:44.0129 0x09d8  [ D812362E8AF615B521AD4DF19A93BD5A, B1F04122DFE9FCC3FC56BE327D86912D624C89F2EFB9684BE66FC22115D0E19F ] NVHDA          C:\WINDOWS\system32\drivers\nvhda64v.sys
11:55:44.0145 0x09d8  NVHDA - ok
11:55:44.0379 0x09d8  [ 2D766A9EE4FBE2CE60F595EA4ACBE540, 5AF3B1BD24A170D3C70EBAE79CE42FCBB14FF35CB0850DA9B08A9DC646712A5E ] nvlddmkm        C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys
11:55:44.0817 0x09d8  nvlddmkm - ok
11:55:44.0973 0x09d8  [ 1E3277F1C9F62F90488D02869A9522B7, 464870ACE9BDF7A6A9C46701209BEED5C33454CFF44CDABEAF871E06F23FEF17 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
11:55:45.0348 0x09d8  NvNetworkService - ok
11:55:45.0457 0x09d8  nvraid - ok
11:55:45.0473 0x09d8  nvstor - ok
11:55:45.0520 0x09d8  [ 59A8DE923619F3DC0C6C63DC33FB231E, 29D20EA3EB9599DE829A0630F2063D5DFD2263E9222CD4E3559725792D1454A5 ] NvStreamKms    C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
11:55:45.0551 0x09d8  NvStreamKms - ok
11:55:45.0692 0x09d8  [ 9B4B3747C6756F49B986398A46EC1FE0, D0A25F07CBFB39B86DCB148A2EC8F01FDDD9B6D994418C54F49AA2B782CE9811 ] NvStreamNetworkSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
11:55:45.0895 0x09d8  NvStreamNetworkSvc - ok
11:55:46.0020 0x09d8  [ 266512CCC3B2E195CDE3A7A2C98A353A, DCB6C88A32FE3EE11D4FF242DE6E52B3C576C2EA4E4A5A245B4451CDEDCE94B0 ] NvStreamSvc    C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
11:55:46.0160 0x09d8  NvStreamSvc - ok
11:55:46.0270 0x09d8  [ 4F2B65FA16319BBA3A309EC2964920A1, 733D1B203AEC92B523B182438AF61D93388F781682297A48CC7C0FA741C2D21D ] nvsvc          C:\WINDOWS\system32\nvvsvc.exe
11:55:46.0395 0x09d8  nvsvc - ok
11:55:46.0426 0x09d8  [ 64E8275CEAD43D3CA8E3A311B2F4B64A, 99E683890B9AF3243100B387317760B5F91745EF9F7FF2ABA2DC7B6551A6EAB6 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
11:55:46.0457 0x09d8  nvvad_WaveExtensible - ok
11:55:46.0457 0x09d8  nv_agp - ok
11:55:46.0473 0x09d8  OneSyncSvc - ok
11:55:46.0551 0x09d8  [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:55:46.0567 0x09d8  ose - ok
11:55:46.0707 0x09d8  [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:55:46.0817 0x09d8  osppsvc - ok
11:55:46.0817 0x09d8  p2pimsvc - ok
11:55:46.0817 0x09d8  p2psvc - ok
11:55:46.0817 0x09d8  Parport - ok
11:55:46.0817 0x09d8  partmgr - ok
11:55:46.0832 0x09d8  PcaSvc - ok
11:55:46.0848 0x09d8  pci - ok
11:55:46.0848 0x09d8  pciide - ok
11:55:46.0848 0x09d8  pcmcia - ok
11:55:46.0848 0x09d8  pcw - ok
11:55:46.0864 0x09d8  pdc - ok
11:55:46.0864 0x09d8  PEAUTH - ok
11:55:46.0864 0x09d8  PeerDistSvc - ok
11:55:46.0864 0x09d8  percsas2i - ok
11:55:46.0879 0x09d8  percsas3i - ok
11:55:46.0942 0x09d8  PerfHost - ok
11:55:46.0973 0x09d8  PhoneSvc - ok
11:55:46.0989 0x09d8  PimIndexMaintenanceSvc - ok
11:55:47.0020 0x09d8  pla - ok
11:55:47.0036 0x09d8  PlugPlay - ok
11:55:47.0036 0x09d8  PNRPAutoReg - ok
11:55:47.0036 0x09d8  PNRPsvc - ok
11:55:47.0051 0x09d8  PolicyAgent - ok
11:55:47.0051 0x09d8  Power - ok
11:55:47.0051 0x09d8  PptpMiniport - ok
11:55:47.0239 0x09d8  [ 959F94AD1255BC749884EDDD14EC29C4, 2CD6DA9778EA36FA0B4080F6DB1C634712238E014E47546403CD3CDB35A1DCA8 ] PrintNotify    C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
11:55:47.0473 0x09d8  PrintNotify - ok
11:55:47.0473 0x09d8  Processor - ok
11:55:47.0489 0x09d8  ProfSvc - ok
11:55:47.0504 0x09d8  Psched - ok
11:55:47.0520 0x09d8  QWAVE - ok
11:55:47.0520 0x09d8  QWAVEdrv - ok
11:55:47.0536 0x09d8  RasAcd - ok
11:55:47.0536 0x09d8  RasAgileVpn - ok
11:55:47.0551 0x09d8  RasAuto - ok
11:55:47.0551 0x09d8  Rasl2tp - ok
11:55:47.0551 0x09d8  RasMan - ok
11:55:47.0567 0x09d8  RasPppoe - ok
11:55:47.0567 0x09d8  RasSstp - ok
11:55:47.0567 0x09d8  rdbss - ok
11:55:47.0567 0x09d8  rdpbus - ok
11:55:47.0582 0x09d8  RDPDR - ok
11:55:47.0582 0x09d8  RdpVideoMiniport - ok
11:55:47.0582 0x09d8  rdyboost - ok
11:55:47.0582 0x09d8  ReFSv1 - ok
11:55:47.0614 0x09d8  RemoteAccess - ok
11:55:47.0614 0x09d8  RemoteRegistry - ok
11:55:47.0614 0x09d8  RetailDemo - ok
11:55:47.0614 0x09d8  RpcEptMapper - ok
11:55:47.0629 0x09d8  RpcLocator - ok
11:55:47.0629 0x09d8  RpcSs - ok
11:55:47.0629 0x09d8  rspndr - ok
11:55:47.0629 0x09d8  rt640x64 - ok
11:55:47.0770 0x09d8  [ 844CB9DBE08797A2A875DF9E2AF108D7, 53463064C2F34DB9C5E1484FA370AC00C4A3486713EC80E2323B07150A27DD1F ] RtlWlanu        C:\WINDOWS\System32\drivers\rtwlanu.sys
11:55:47.0926 0x09d8  RtlWlanu - ok
11:55:47.0942 0x09d8  s3cap - ok
11:55:47.0957 0x09d8  SamSs - ok
11:55:47.0957 0x09d8  sbp2port - ok
11:55:47.0957 0x09d8  SCardSvr - ok
11:55:47.0957 0x09d8  ScDeviceEnum - ok
11:55:47.0973 0x09d8  scfilter - ok
11:55:47.0973 0x09d8  Schedule - ok
11:55:47.0973 0x09d8  SCPolicySvc - ok
11:55:47.0973 0x09d8  sdbus - ok
11:55:47.0973 0x09d8  SDRSVC - ok
11:55:47.0989 0x09d8  sdstor - ok
11:55:47.0989 0x09d8  seclogon - ok
11:55:47.0989 0x09d8  SENS - ok
11:55:47.0989 0x09d8  SensorDataService - ok
11:55:47.0989 0x09d8  SensorService - ok
11:55:48.0004 0x09d8  SensrSvc - ok
11:55:48.0004 0x09d8  SerCx - ok
11:55:48.0004 0x09d8  SerCx2 - ok
11:55:48.0004 0x09d8  Serenum - ok
11:55:48.0004 0x09d8  Serial - ok
11:55:48.0004 0x09d8  sermouse - ok
11:55:48.0004 0x09d8  SessionEnv - ok
11:55:48.0020 0x09d8  sfloppy - ok
11:55:48.0051 0x09d8  [ 9242988D74674C2819D454F001457BAD, D353A30D224940B0C7750161782CE98D4C47ABC5C4E04B100F8ABB6A3402B5AD ] Sftfs          C:\WINDOWS\system32\DRIVERS\Sftfswin7.sys
11:55:48.0067 0x09d8  Sftfs - ok
11:55:48.0176 0x09d8  [ 4E1BB8A9CCDB4BAF41F7F9A930EB121D, D994B20DACEB187BEB6530309E2185040B58105E4FD5AC1DA435712F9DE027D0 ] sftlist        C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
11:55:48.0192 0x09d8  sftlist - ok
11:55:48.0254 0x09d8  [ 44391FA910901E2B8A2F831340FD707A, 9ACAD655DCCCAF562CEDE9180B187C229FFCAF97BA87D78225253C7868698CB8 ] Sftplay        C:\WINDOWS\system32\DRIVERS\Sftplaywin7.sys
11:55:48.0301 0x09d8  Sftplay - ok
11:55:48.0301 0x09d8  [ 8654DBDC8ED8ED7257618D11B6C590BE, 1A410CCB7CDE99C607662E21054E959D3349647C5BD810CE744DA59EEB9C3FA2 ] Sftredir        C:\WINDOWS\system32\DRIVERS\Sftredirwin7.sys
11:55:48.0317 0x09d8  Sftredir - ok
11:55:48.0332 0x09d8  [ 648F0152A7BAE175905C22E8BD839760, 6E3FC032212FD1F39FEE96D230F47BB25355587E8A73E34776CAEA8C0C1FB58E ] Sftvol          C:\WINDOWS\system32\DRIVERS\Sftvolwin7.sys
11:55:48.0332 0x09d8  Sftvol - ok
11:55:48.0348 0x09d8  [ CECFDE5D3701B2D914862F5E6C3DFE18, E7627F90630C306324A39DC3C652B37D255F90636AC19D3302EE5B85BD504BD5 ] sftvsa          C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
11:55:48.0348 0x09d8  sftvsa - ok
11:55:48.0364 0x09d8  SharedAccess - ok
11:55:48.0395 0x09d8  ShellHWDetection - ok
11:55:48.0395 0x09d8  SiSRaid2 - ok
11:55:48.0411 0x09d8  SiSRaid4 - ok
11:55:48.0411 0x09d8  smphost - ok
11:55:48.0442 0x09d8  SmsRouter - ok
11:55:48.0442 0x09d8  SNMPTRAP - ok
11:55:48.0473 0x09d8  spaceport - ok
11:55:48.0473 0x09d8  SpbCx - ok
11:55:48.0473 0x09d8  Spooler - ok
11:55:48.0473 0x09d8  sppsvc - ok
11:55:48.0473 0x09d8  srv - ok
11:55:48.0489 0x09d8  srv2 - ok
11:55:48.0489 0x09d8  srvnet - ok
11:55:48.0489 0x09d8  SSDPSRV - ok
11:55:48.0489 0x09d8  SstpSvc - ok
11:55:48.0489 0x09d8  StateRepository - ok
11:55:48.0598 0x09d8  [ 591249EA969797C2A24629AF7C71A6F8, 61F28FB495657916514DE2A7FFD4AD833A1B2BBA5591616BE0C9CCD7DAFA40B7 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
11:55:49.0098 0x09d8  Steam Client Service - ok
11:55:49.0192 0x09d8  [ 5311DAD9879DA242A9EA385EE7DD4F0D, AD7180A9176A9243A430ABA45079C7B256E4E05AFBE6215C662B8337B8760E39 ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
11:55:50.0129 0x09d8  Stereo Service - ok
11:55:50.0129 0x09d8  stexstor - ok
11:55:50.0145 0x09d8  stisvc - ok
11:55:50.0145 0x09d8  storahci - ok
11:55:50.0161 0x09d8  storflt - ok
11:55:50.0161 0x09d8  stornvme - ok
11:55:50.0161 0x09d8  storqosflt - ok
11:55:50.0192 0x09d8  StorSvc - ok
11:55:50.0192 0x09d8  storufs - ok
11:55:50.0192 0x09d8  storvsc - ok
11:55:50.0223 0x09d8  svsvc - ok
11:55:50.0223 0x09d8  swenum - ok
11:55:50.0223 0x09d8  swprv - ok
11:55:50.0239 0x09d8  Synth3dVsc - ok
11:55:50.0254 0x09d8  SysMain - ok
11:55:50.0270 0x09d8  SystemEventsBroker - ok
11:55:50.0270 0x09d8  TabletInputService - ok
11:55:50.0286 0x09d8  TapiSrv - ok
11:55:50.0286 0x09d8  Tcpip - ok
11:55:50.0286 0x09d8  Tcpip6 - ok
11:55:50.0286 0x09d8  tcpipreg - ok
11:55:50.0301 0x09d8  tdx - ok
11:55:50.0301 0x09d8  terminpt - ok
11:55:50.0301 0x09d8  TermService - ok
11:55:50.0317 0x09d8  Themes - ok
11:55:50.0317 0x09d8  TieringEngineService - ok
11:55:50.0317 0x09d8  tiledatamodelsvc - ok
11:55:50.0332 0x09d8  TimeBroker - ok
11:55:50.0332 0x09d8  TPM - ok
11:55:50.0332 0x09d8  TrkWks - ok
11:55:50.0379 0x09d8  TrustedInstaller - ok
11:55:50.0395 0x09d8  tsusbflt - ok
11:55:50.0411 0x09d8  TsUsbGD - ok
11:55:50.0411 0x09d8  tunnel - ok
11:55:50.0426 0x09d8  tzautoupdate - ok
11:55:50.0426 0x09d8  uagp35 - ok
11:55:50.0426 0x09d8  UASPStor - ok
11:55:50.0426 0x09d8  UcmCx0101 - ok
11:55:50.0442 0x09d8  UcmUcsi - ok
11:55:50.0442 0x09d8  Ucx01000 - ok
11:55:50.0442 0x09d8  UdeCx - ok
11:55:50.0442 0x09d8  udfs - ok
11:55:50.0442 0x09d8  UEFI - ok
11:55:50.0457 0x09d8  Ufx01000 - ok
11:55:50.0457 0x09d8  UfxChipidea - ok
11:55:50.0457 0x09d8  ufxsynopsys - ok
11:55:50.0473 0x09d8  UI0Detect - ok
11:55:50.0473 0x09d8  uliagpkx - ok
11:55:50.0473 0x09d8  umbus - ok
11:55:50.0473 0x09d8  UmPass - ok
11:55:50.0473 0x09d8  UmRdpService - ok
11:55:50.0489 0x09d8  UnistoreSvc - ok
11:55:50.0489 0x09d8  upnphost - ok
11:55:50.0489 0x09d8  UrsChipidea - ok
11:55:50.0489 0x09d8  UrsCx01000 - ok
11:55:50.0504 0x09d8  UrsSynopsys - ok
11:55:50.0504 0x09d8  usbaudio - ok
11:55:50.0504 0x09d8  usbccgp - ok
11:55:50.0504 0x09d8  usbcir - ok
11:55:50.0504 0x09d8  usbehci - ok
11:55:50.0504 0x09d8  usbhub - ok
11:55:50.0504 0x09d8  USBHUB3 - ok
11:55:50.0520 0x09d8  usbohci - ok
11:55:50.0520 0x09d8  usbprint - ok
11:55:50.0520 0x09d8  usbser - ok
11:55:50.0520 0x09d8  USBSTOR - ok
11:55:50.0536 0x09d8  usbuhci - ok
11:55:50.0551 0x09d8  USBXHCI - ok
11:55:50.0551 0x09d8  UserDataSvc - ok
11:55:50.0567 0x09d8  UserManager - ok
11:55:50.0567 0x09d8  UsoSvc - ok
11:55:50.0567 0x09d8  VaultSvc - ok
11:55:50.0567 0x09d8  vdrvroot - ok
11:55:50.0567 0x09d8  vds - ok
11:55:50.0567 0x09d8  VerifierExt - ok
11:55:50.0567 0x09d8  vhdmp - ok
11:55:50.0567 0x09d8  vhf - ok
11:55:50.0582 0x09d8  vmbus - ok
11:55:50.0582 0x09d8  VMBusHID - ok
11:55:50.0598 0x09d8  vmicguestinterface - ok
11:55:50.0598 0x09d8  vmicheartbeat - ok
11:55:50.0598 0x09d8  vmickvpexchange - ok
11:55:50.0614 0x09d8  vmicrdv - ok
11:55:50.0614 0x09d8  vmicshutdown - ok
11:55:50.0614 0x09d8  vmictimesync - ok
11:55:50.0614 0x09d8  vmicvmsession - ok
11:55:50.0614 0x09d8  vmicvss - ok
11:55:50.0614 0x09d8  volmgr - ok
11:55:50.0614 0x09d8  volmgrx - ok
11:55:50.0614 0x09d8  volsnap - ok
11:55:50.0629 0x09d8  vpci - ok
11:55:50.0629 0x09d8  vsmraid - ok
11:55:50.0629 0x09d8  VSS - ok
11:55:50.0629 0x09d8  VSTXRAID - ok
11:55:50.0629 0x09d8  vwifibus - ok
11:55:50.0629 0x09d8  vwififlt - ok
11:55:50.0629 0x09d8  vwifimp - ok
11:55:50.0645 0x09d8  W32Time - ok
11:55:50.0676 0x09d8  w3logsvc - ok
11:55:50.0692 0x09d8  W3SVC - ok
11:55:50.0692 0x09d8  WacomPen - ok
11:55:50.0707 0x09d8  WalletService - ok
11:55:50.0707 0x09d8  wanarp - ok
11:55:50.0707 0x09d8  wanarpv6 - ok
11:55:50.0707 0x09d8  WAS - ok
11:55:50.0723 0x09d8  wbengine - ok
11:55:50.0723 0x09d8  WbioSrvc - ok
11:55:50.0739 0x09d8  Wcmsvc - ok
11:55:50.0739 0x09d8  wcncsvc - ok
11:55:50.0739 0x09d8  WcsPlugInService - ok
11:55:50.0739 0x09d8  WdBoot - ok
11:55:50.0739 0x09d8  Wdf01000 - ok
11:55:50.0739 0x09d8  WdFilter - ok
11:55:50.0739 0x09d8  WdiServiceHost - ok
11:55:50.0754 0x09d8  WdiSystemHost - ok
11:55:50.0754 0x09d8  wdiwifi - ok
11:55:50.0754 0x09d8  WdNisDrv - ok
11:55:50.0786 0x09d8  WdNisSvc - ok
11:55:50.0786 0x09d8  WebClient - ok
11:55:50.0801 0x09d8  Wecsvc - ok
11:55:50.0801 0x09d8  WEPHOSTSVC - ok
11:55:50.0801 0x09d8  wercplsupport - ok
11:55:50.0801 0x09d8  WerSvc - ok
11:55:50.0801 0x09d8  WFPLWFS - ok
11:55:50.0801 0x09d8  WiaRpc - ok
11:55:50.0817 0x09d8  WIMMount - ok
11:55:50.0817 0x09d8  WinDefend - ok
11:55:50.0832 0x09d8  WindowsTrustedRT - ok
11:55:50.0832 0x09d8  WindowsTrustedRTProxy - ok
11:55:50.0832 0x09d8  WinHttpAutoProxySvc - ok
11:55:50.0848 0x09d8  WinMad - ok
11:55:50.0864 0x09d8  Winmgmt - ok
11:55:50.0895 0x09d8  WinRM - ok
11:55:50.0911 0x09d8  WINUSB - ok
11:55:50.0911 0x09d8  WinVerbs - ok
11:55:50.0911 0x09d8  WlanSvc - ok
11:55:50.0926 0x09d8  wlidsvc - ok
11:55:50.0926 0x09d8  WmiAcpi - ok
11:55:50.0926 0x09d8  wmiApSrv - ok
11:55:50.0957 0x09d8  WMPNetworkSvc - ok
11:55:50.0973 0x09d8  [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof            C:\WINDOWS\system32\drivers\Wof.sys
11:55:51.0004 0x09d8  Wof - ok
11:55:51.0004 0x09d8  workfolderssvc - ok
11:55:51.0004 0x09d8  wpcfltr - ok
11:55:51.0004 0x09d8  WPDBusEnum - ok
11:55:51.0020 0x09d8  WpdUpFltr - ok
11:55:51.0020 0x09d8  WpnService - ok
11:55:51.0020 0x09d8  ws2ifsl - ok
11:55:51.0020 0x09d8  wscsvc - ok
11:55:51.0020 0x09d8  WSearch - ok
11:55:51.0020 0x09d8  WSService - ok
11:55:51.0051 0x09d8  wuauserv - ok
11:55:51.0051 0x09d8  WudfPf - ok
11:55:51.0051 0x09d8  wudfsvc - ok
11:55:51.0051 0x09d8  WUDFWpdFs - ok
11:55:51.0051 0x09d8  WUDFWpdMtp - ok
11:55:51.0067 0x09d8  WwanSvc - ok
11:55:51.0082 0x09d8  XblAuthManager - ok
11:55:51.0082 0x09d8  XblGameSave - ok
11:55:51.0082 0x09d8  xboxgip - ok
11:55:51.0114 0x09d8  XboxNetApiSvc - ok
11:55:51.0114 0x09d8  xinputhid - ok
11:55:51.0114 0x09d8  xusb22 - ok
11:55:51.0114 0x09d8  ================ Scan global ===============================
11:55:51.0176 0x09d8  [ Global ] - ok
11:55:51.0176 0x09d8  ================ Scan MBR ==================================
11:55:51.0192 0x09d8  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:55:51.0504 0x09d8  \Device\Harddisk0\DR0 - ok
11:55:51.0504 0x09d8  ================ Scan VBR ==================================
11:55:51.0504 0x09d8  [ 81ED99DE0B1E4D870D6D05101AD292C3 ] \Device\Harddisk0\DR0\Partition1
11:55:51.0567 0x09d8  \Device\Harddisk0\DR0\Partition1 - ok
11:55:51.0567 0x09d8  [ BD06E1052A646C6802AA8FAA591C618F ] \Device\Harddisk0\DR0\Partition2
11:55:51.0629 0x09d8  \Device\Harddisk0\DR0\Partition2 - ok
11:55:51.0629 0x09d8  ================ Scan generic autorun ======================
11:55:52.0020 0x09d8  [ 65E8545F1297CD83534C354A7BED1848, 19B3F3C17A335837454DC1851C6436D0BB2D8B1595AEB4DC71265FB20868B48F ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
11:55:52.0332 0x09d8  RTHDVCPL - ok
11:55:52.0364 0x09d8  [ 3A19FD28BF891CB67FD89A94BEC88C3F, 6D9F5FA55A4B8A386691E91305C8CA9323B91680FA2DC4585DDDECA69BB80FA0 ] C:\Windows\system32\igfxtray.exe
11:55:52.0379 0x09d8  IgfxTray - ok
11:55:52.0426 0x09d8  [ D94BCD3B86F5220BEFC277B395EEE845, 61D3DE5621CE855F8EA5BF2308D0DFFB3B517BF7187AEE1FEF6785C5880E7D49 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
11:55:52.0520 0x09d8  IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
11:55:54.0832 0x09d8  Detect skipped due to KSN trusted
11:55:54.0832 0x09d8  IAStorIcon - ok
11:55:54.0942 0x09d8  [ E445C0DB7E5E89C657FC89C0C4CCEDE5, ABD7A9B36CFD6740CE06456B152D9EB1856C11CD7FB2A34E06D63BAD0639B2A0 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
11:55:55.0051 0x09d8  NvBackend - ok
11:55:55.0083 0x09d8  ShadowPlay - ok
11:55:55.0145 0x09d8  [ 70BDEE03032BF7CE279838866B25E697, 007C3AC1B4380BC56EC6E14EFC022C03F165D08447AD763854351C530E19D976 ] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
11:55:55.0161 0x09d8  IMSS - ok
11:55:55.0176 0x09d8  [ D2AEADFD998706B4216315B2BD3FA79E, D45634355B7733F9B6754A6FB80B7EC20C0D584A08E2F710DF612B393D96A8F9 ] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
11:55:55.0223 0x09d8  ISUSScheduler - detected UnsignedFile.Multi.Generic ( 1 )
11:55:57.0567 0x09d8  Detect skipped due to KSN trusted
11:55:57.0567 0x09d8  ISUSScheduler - ok
11:55:57.0598 0x09d8  [ EBC0E8C0A4DDA2C32A7D5863462A321A, 2F410138DB66D0219254339F1F098E401CEDAA032596F1F67BC54F394256FC68 ] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
11:55:57.0708 0x09d8  amd_dc_opt - detected UnsignedFile.Multi.Generic ( 1 )
11:56:00.0051 0x09d8  Detect skipped due to KSN trusted
11:56:00.0051 0x09d8  amd_dc_opt - ok
11:56:00.0176 0x09d8  [ D470EB94988531FE20A2A78766BB6858, 59F46FBC2267584422D7C4EC5BCC4071BB8DCF544C3AB44BEEBAE091EDCB9947 ] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
11:56:00.0223 0x09d8  BlueStacks Agent - ok
11:56:00.0286 0x09d8  OneDriveSetup - ok
11:56:00.0286 0x09d8  OneDriveSetup - ok
11:56:00.0301 0x09d8  [ A379B75A6FFE4DFD3184F35F0141CE91, C777B01B4361456D4D829E96723C85CCDC2E3647C4CF25894AC83100552E36AB ] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
11:56:00.0442 0x09d8  ISUSPM Startup - detected UnsignedFile.Multi.Generic ( 1 )
11:56:00.0520 0x156c  Object required for P2P: [ 4F2B65FA16319BBA3A309EC2964920A1 ] nvsvc
11:56:02.0786 0x09d8  Detect skipped due to KSN trusted
11:56:02.0786 0x09d8  ISUSPM Startup - ok
11:56:02.0848 0x09d8  [ 406E7DF08CE79BE3016CC6D15E2ED956, 9DA8D10AE642B9411A3EB253F97918A6F470F1772F0057964267497CE0BDA53A ] C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe
11:56:02.0895 0x09d8  Dxtory Update Checker 2.0 - detected UnsignedFile.Multi.Generic ( 1 )
11:56:02.0942 0x156c  Object send P2P result: true
11:56:05.0239 0x09d8  Detect skipped due to KSN trusted
11:56:05.0239 0x09d8  Dxtory Update Checker 2.0 - ok
11:56:05.0411 0x09d8  [ 91DD4AD85BB341CC8CF5187EA06FD171, 68330A5EBDA7E4A51926EC2085D71C11BD2857A6EB1D4749DEE7A6D1D5679B98 ] C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
11:56:05.0426 0x09d8  OneDrive - ok
11:56:05.0426 0x09d8  OneDriveSetup - ok
11:56:05.0458 0x09d8  WAB Migrate - ok
11:56:05.0458 0x09d8  Waiting for KSN requests completion. In queue: 2
11:56:06.0473 0x09d8  Waiting for KSN requests completion. In queue: 2
11:56:07.0489 0x09d8  Waiting for KSN requests completion. In queue: 1
11:56:08.0520 0x09d8  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.0 ), 0x61100 ( enabled : updated )
11:56:08.0536 0x09d8  Win FW state via NFP2: enabled ( trusted )
11:56:10.0926 0x09d8  ============================================================
11:56:10.0926 0x09d8  Scan finished
11:56:10.0926 0x09d8  ============================================================
11:56:10.0942 0x030c  Detected object count: 0
11:56:10.0942 0x030c  Actual detected object count: 0


Kanso 27.02.2016 12:12

FRST.txt:

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:24-02-2016
durchgeführt von Admin (Administrator) auf ADMIN-PC (27-02-2016 12:06:26)
Gestartet von C:\Users\Admin\Desktop
Geladene Profile: Admin (Verfügbare Profile: Admin & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Kaspersky Lab ZAO) C:\Users\Admin\Desktop\tdsskiller.exe
(Kaspersky Lab ZAO) C:\Users\Admin\AppData\Local\Temp\{F961F371-BEAD-4706-A050-0AEF9D9A4216}\{9CC410C8-AFCD-40DD-9A05-0AF1C39898D7}.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [402344 2015-12-19] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-01-31] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-03-12] (Intel Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [896632 2015-07-22] (BlueStack Systems, Inc.)
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-16] (InstallShield Software Corporation)
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [175368 2016-02-09] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK-Konfigurationstool.lnk [2014-02-28]
ShortcutTarget: TP-LINK-Konfigurationstool.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK-Konfigurationstool\TWCU.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{38fa8d64-1429-4eb3-94d0-479866b2cb77}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-988284940-210793992-766847566-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-988284940-210793992-766847566-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-988284940-210793992-766847566-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.de/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll => Keine Datei
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll => Keine Datei

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-15] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2011-04-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2015-06-19] (Pando Networks)
FF Plugin HKU\S-1-5-21-988284940-210793992-766847566-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-988284940-210793992-766847566-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-09-10] ()
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\searchplugins\safesearch.xml [2015-06-25]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\adblockpopups@jessehakanen.net.xpi [2015-05-29]
FF Extension: NoScript - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-02-12]
FF Extension: WOT - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-12-09]
FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433784 2015-06-16] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413304 2015-06-16] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [831096 2015-07-21] (BlueStack Systems, Inc.)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-31] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7220792 2016-01-30] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-12] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373160 2015-12-19] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-12] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-12] (NVIDIA Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [145528 2015-06-16] (BlueStack Systems)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2014-06-19] ()
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [3870464 2015-10-01] (Realtek Semiconductor Corporation                          )
R3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation)
R3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation)
R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation)
R3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 condrv; System32\drivers\condrv.sys [X]
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-02-27 12:06 - 2016-02-27 12:07 - 00015268 _____ C:\Users\Admin\Desktop\FRST.txt
2016-02-27 12:05 - 2016-02-27 12:06 - 02371072 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2016-02-27 11:54 - 2016-02-27 11:54 - 00246848 ____N (Kaspersky Lab, Yury Parshin) C:\WINDOWS\system32\Drivers\83047933.sys
2016-02-27 11:53 - 2016-02-27 11:56 - 00078164 _____ C:\TDSSKiller.3.1.0.9_27.02.2016_11.53.57_log.txt
2016-02-27 11:52 - 2016-02-27 11:53 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\Admin\Desktop\tdsskiller.exe
2016-02-27 11:51 - 2016-02-27 11:51 - 00001845 _____ C:\Users\Admin\Desktop\Fixlog.txt
2016-02-26 09:35 - 2016-02-27 12:06 - 00000000 ____D C:\FRST
2016-02-26 05:36 - 2016-02-26 05:36 - 00001364 _____ C:\Users\Admin\Desktop\Norton-Installationsdateien.lnk
2016-02-26 05:36 - 2016-02-26 05:36 - 00000000 ____D C:\WINDOWS\system32\Drivers\NSx64
2016-02-26 05:35 - 2016-02-26 05:36 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader(2).exe
2016-02-26 05:30 - 2016-02-26 19:27 - 00364004 _____ C:\WINDOWS\ntbtlog.txt
2016-02-26 05:28 - 2016-02-26 05:28 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (2).exe
2016-02-26 05:12 - 2016-02-26 05:14 - 00412020 _____ C:\WINDOWS\Minidump\022616-17640-01.dmp
2016-02-25 11:37 - 2016-02-25 11:37 - 00000432 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp.bat
2016-02-25 11:37 - 2016-02-25 11:37 - 00000357 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp_r.bat
2016-02-25 11:33 - 2016-02-25 11:36 - 00000000 ____D C:\Program Files (x86)\LogMeIn Rescue RC - 0bfdcd33-f52c-4b3b-a4a7-71770fabb626
2016-02-25 11:28 - 2016-02-27 11:45 - 00000000 ____D C:\ProgramData\Norton
2016-02-25 11:28 - 2016-02-26 19:28 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-02-25 11:28 - 2016-02-26 05:38 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-02-25 11:15 - 2016-02-25 11:15 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (1).exe
2016-02-25 11:13 - 2016-02-25 11:13 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool(1).exe
2016-02-25 10:48 - 2016-02-25 10:48 - 00000000 __SHD C:\found.000
2016-02-25 10:29 - 2016-02-27 11:44 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-25 10:28 - 2016-02-25 10:28 - 00000000 ____D C:\WINDOWS\pss
2016-02-25 10:07 - 2016-02-26 05:31 - 00000000 ____D C:\NPE
2016-02-25 10:05 - 2016-02-26 05:33 - 00000000 ____D C:\Users\Admin\AppData\Local\NPE
2016-02-25 10:05 - 2016-02-25 10:05 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE.exe
2016-02-25 10:02 - 2016-02-25 10:02 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader (1).exe
2016-02-25 09:58 - 2016-02-27 07:56 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3CF3C132-6859-4994-8DAC-3B31CD8D194C}
2016-02-25 09:54 - 2016-02-25 09:55 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool.exe
2016-02-25 09:48 - 2016-02-25 09:48 - 00000248 _____ C:\rescue.info
2016-02-25 09:46 - 2016-02-25 09:46 - 01857576 _____ (LogMeIn, Inc.) C:\Users\Admin\Downloads\Support-LogMeInRescue.exe
2016-02-25 09:46 - 2016-02-25 09:46 - 00000000 ____D C:\Users\Admin\AppData\Local\LogMeIn Rescue Applet
2016-02-24 21:57 - 2016-02-24 21:57 - 00000000 ____D C:\Users\Admin\AppData\LocalLow\HuniePot
2016-02-24 21:55 - 2016-02-24 21:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HuniePop [GOG.com]
2016-02-16 00:11 - 2016-02-16 00:11 - 00002202 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2016-02-16 00:10 - 2016-02-16 00:10 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-02-16 00:10 - 2016-02-09 06:04 - 00111672 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-02-16 00:09 - 2016-02-09 09:25 - 42983480 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 37616184 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 31119296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 24944064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 21201784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 20741880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17631304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17224664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17175248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17116936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02541504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02187712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00950328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00882232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00745408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00689600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00541000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00445728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00383424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00379448 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00378968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00348216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00317144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00153392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-02-14 10:24 - 2016-02-14 10:26 - 00353028 _____ C:\WINDOWS\Minidump\021416-29546-01.dmp
2016-02-12 06:29 - 2016-02-24 09:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-09 19:52 - 2016-01-29 07:57 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-09 19:52 - 2016-01-29 07:33 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-02-09 19:52 - 2016-01-27 07:15 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-02-09 19:52 - 2016-01-27 07:15 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-02-09 19:52 - 2016-01-27 07:01 - 07476064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-02-09 19:52 - 2016-01-27 07:01 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-02-09 19:52 - 2016-01-27 07:01 - 01819720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-02-09 19:52 - 2016-01-27 06:59 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-09 19:52 - 2016-01-27 06:57 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-02-09 19:52 - 2016-01-27 06:57 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-09 19:52 - 2016-01-27 06:57 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-09 19:52 - 2016-01-27 06:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-02-09 19:52 - 2016-01-27 06:55 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-02-09 19:52 - 2016-01-27 06:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-02-09 19:52 - 2016-01-27 06:54 - 00295264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-02-09 19:52 - 2016-01-27 06:46 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-09 19:52 - 2016-01-27 06:46 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-09 19:52 - 2016-01-27 06:45 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-02-09 19:52 - 2016-01-27 06:45 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-02-09 19:52 - 2016-01-27 06:44 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-09 19:52 - 2016-01-27 06:44 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-09 19:52 - 2016-01-27 06:43 - 00359776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-02-09 19:52 - 2016-01-27 06:37 - 01998176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-02-09 19:52 - 2016-01-27 06:37 - 00576352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-02-09 19:52 - 2016-01-27 06:21 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-09 19:52 - 2016-01-27 06:15 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-02-09 19:52 - 2016-01-27 06:13 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-02-09 19:52 - 2016-01-27 06:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-02-09 19:52 - 2016-01-27 06:11 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-09 19:52 - 2016-01-27 06:10 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-02-09 19:52 - 2016-01-27 06:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-09 19:52 - 2016-01-27 06:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-09 19:52 - 2016-01-27 06:08 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-09 19:52 - 2016-01-27 06:07 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-02-09 19:52 - 2016-01-27 06:04 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-02-09 19:52 - 2016-01-27 06:04 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-09 19:52 - 2016-01-27 06:03 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-02-09 19:52 - 2016-01-27 06:02 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-09 19:52 - 2016-01-27 06:01 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-09 19:52 - 2016-01-27 05:59 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-09 19:52 - 2016-01-27 05:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-02-09 19:52 - 2016-01-27 05:57 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-02-09 19:52 - 2016-01-27 05:55 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-02-09 19:52 - 2016-01-27 05:55 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-02-09 19:52 - 2016-01-27 05:54 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-02-09 19:52 - 2016-01-27 05:52 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 02230784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 01504768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-09 19:52 - 2016-01-27 05:49 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-02-09 19:52 - 2016-01-27 05:48 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-02-09 19:52 - 2016-01-27 05:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-09 19:52 - 2016-01-27 05:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-09 19:52 - 2016-01-27 05:41 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-02-09 19:52 - 2016-01-27 05:39 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-02-09 19:52 - 2016-01-27 05:38 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-02-09 19:52 - 2016-01-27 05:38 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-02-09 19:52 - 2016-01-27 05:37 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-02-09 19:52 - 2016-01-27 05:36 - 02757120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-02-09 19:52 - 2016-01-27 05:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-09 19:52 - 2016-01-27 05:31 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-03 19:18 - 2016-02-03 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher® 3 - Wild Hunt [GOG.com]
2016-02-02 19:33 - 2016-02-02 19:35 - 10026464 _____ C:\Users\Admin\Downloads\Worlds Apart (Sami Zayn)_Megalouis100v4.m4a
2016-01-31 12:53 - 2016-02-08 00:23 - 00000000 ____D C:\Users\Admin\Documents\Broken Sword - Director's Cut
2016-01-31 12:19 - 2016-01-31 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broken Sword - Director's Cut [GOG.com]
2016-01-31 01:02 - 2016-01-23 04:31 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436175.dll
2016-01-31 01:02 - 2016-01-23 04:31 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436175.dll
2016-01-29 19:10 - 2016-01-29 19:10 - 00000000 ____D C:\Users\Admin\Documents\League of Legends
2016-01-29 19:03 - 2016-02-25 09:55 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-01-29 18:55 - 2016-01-29 18:55 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader(1).exe
2016-01-29 17:44 - 2016-01-29 17:44 - 00102616 _____ (Symantec Corporation) C:\WINDOWS\SMSS-PFRO5d7c.tmp

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-02-27 11:51 - 2015-12-03 04:01 - 02091230 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-27 11:51 - 2015-10-30 19:35 - 00889534 _____ C:\WINDOWS\system32\perfh007.dat
2016-02-27 11:51 - 2015-10-30 19:35 - 00197858 _____ C:\WINDOWS\system32\perfc007.dat
2016-02-27 11:51 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-02-27 11:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-27 11:47 - 2015-12-03 04:17 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-27 11:47 - 2015-12-03 03:58 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-27 11:47 - 2015-12-03 03:57 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-02-27 11:46 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-02-26 19:34 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-26 19:34 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-26 05:30 - 2015-10-30 08:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-02-26 05:12 - 2015-12-04 19:37 - 00000000 ____D C:\WINDOWS\Minidump
2016-02-26 05:12 - 2014-03-07 16:29 - 890432205 _____ C:\WINDOWS\MEMORY.DMP
2016-02-25 20:43 - 2014-10-15 18:28 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2016-02-25 20:39 - 2015-03-05 20:41 - 00000000 ____D C:\GOG Games
2016-02-25 20:39 - 2015-03-05 20:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-02-25 20:39 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieUserList
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieSiteList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieUserList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieSiteList
2016-02-25 09:03 - 2015-12-03 04:01 - 00000000 ____D C:\Users\Admin
2016-02-25 08:44 - 2015-08-06 20:56 - 00000000 __SHD C:\Users\Admin\IntelGraphicsProfiles
2016-02-24 18:56 - 2015-06-01 19:35 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2016-02-22 01:16 - 2015-10-30 07:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-02-21 23:27 - 2015-01-27 10:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-21 00:02 - 2014-02-10 11:42 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SoftGrid Client
2016-02-20 22:15 - 2014-08-10 22:06 - 00000000 ____D C:\Program Files (x86)\Steam
2016-02-16 00:11 - 2015-12-03 03:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-16 00:11 - 2014-02-26 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-02-14 10:24 - 2015-01-26 02:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-13 20:35 - 2014-02-10 12:11 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-13 20:32 - 2014-02-10 12:11 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-12 02:22 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2016-02-10 19:34 - 2015-08-06 20:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-10 10:37 - 2015-10-30 19:47 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-10 07:27 - 2015-09-22 23:03 - 12478528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-02-09 22:20 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-02-09 09:25 - 2015-09-22 23:03 - 19779648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 14115136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 03649576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 03231544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 00035832 _____ C:\WINDOWS\system32\nvinfo.pb
2016-02-09 06:29 - 2015-12-03 03:57 - 06368824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 02992064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 02561472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 01263040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-02-09 06:29 - 2015-12-03 03:57 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-02-09 06:29 - 2014-11-24 17:02 - 00530368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-02-09 06:29 - 2014-11-24 17:02 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-02-07 23:20 - 2015-05-20 16:56 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
2016-02-07 20:41 - 2014-04-12 17:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2016-02-06 15:58 - 2015-12-03 03:57 - 06154909 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-02-03 20:01 - 2015-10-30 08:26 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-02-03 20:01 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-31 12:19 - 2014-08-31 18:56 - 00466456 _____ (Creative Labs) C:\WINDOWS\system32\wrap_oal.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00444952 _____ (Creative Labs) C:\WINDOWS\SysWOW64\wrap_oal.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\system32\OpenAL32.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\SysWOW64\OpenAL32.dll
2016-01-31 01:02 - 2015-12-03 03:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-01-29 18:55 - 2015-07-25 17:47 - 00000000 ____D C:\Users\Public\Downloads\Norton
2016-01-29 17:37 - 2015-12-03 03:57 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-01-28 22:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2016-02-25 11:37 - 2016-02-25 11:37 - 0000432 _____ () C:\Users\Admin\AppData\Local\LMIR0001.tmp.bat
2016-02-25 11:37 - 2016-02-25 11:37 - 0000357 _____ () C:\Users\Admin\AppData\Local\LMIR0001.tmp_r.bat
2015-12-03 03:57 - 2015-12-03 03:57 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


ACHTUNG: ==> Auf den BCD konnte nicht zugegriffen werden.


LastRegBack: 2016-02-27 10:03

==================== Ende von FRST.txt ============================


Addition.txt:

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:24-02-2016
durchgeführt von Admin (2016-02-27 12:07:32)
Gestartet von C:\Users\Admin\Desktop
Windows 10 Pro Version 1511 (X64) (2015-12-03 03:22:42)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Admin (S-1-5-21-988284940-210793992-766847566-1000 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-988284940-210793992-766847566-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-988284940-210793992-766847566-503 - Limited - Disabled)
Gast (S-1-5-21-988284940-210793992-766847566-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-988284940-210793992-766847566-1003 - Limited - Enabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

1954 Alcatraz (HKLM-x32\...\Steam App 255280) (Version:  - Daedalic Entertainment)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassins Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.03 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.03 - Ubisoft)
Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Baldur's Gate -  The Original Saga (German) (HKLM-x32\...\GOGPACKBALDURSGATE1_is1) (Version: 2.0.0.20 - GOG.com)
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BioShock (HKLM-x32\...\Steam App 7670) (Version:  - 2K Boston)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
Broken Sword - Director's Cut (HKLM-x32\...\1207658900_is1) (Version: 2.1.0.16 - GOG.com)
Dark Souls: Prepare to Die Edition (HKLM-x32\...\Steam App 211420) (Version:  - FromSoftware)
DARK SOULS™ II (HKLM-x32\...\Steam App 236430) (Version:  - FromSoftware, Inc)
Darksiders (HKLM-x32\...\Steam App 50620) (Version:  - Vigil Games)
DarksidersInstaller (HKLM-x32\...\{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}) (Version: 1.00.1000 - Ihr Firmenname)
Deus Ex: Human Revolution - Director's Cut (HKLM-x32\...\Steam App 238010) (Version:  - Eidos Montreal)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
DVD Architect Studio 5.0 (HKLM-x32\...\{E42939AE-9660-11E2-9A0D-F04DA23A5C58}) (Version: 5.0.178 - Sony)
Dxtory version 2.0.130 (HKLM-x32\...\Dxtory2.0_is1) (Version: 2.0.130 - ExKode Co. Ltd.)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version:  - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
FINAL FANTASY XIV: A Realm Reborn (HKLM-x32\...\Steam App 39210) (Version:  - SQUARE ENIX)
Geheimakte Tunguska (HKLM-x32\...\{3B416FDA-CB3E-4514-9616-763E5B0D1140}) (Version: 1.03.02 - Deep Silver)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
GOG.com Downloader version 3.6.0 (HKLM-x32\...\{456A5815-604D-4D72-94DF-346D2B978A59}_is1) (Version: 3.6.0 - GOG.com)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
How to Survive (HKLM-x32\...\Steam App 250400) (Version:  - )
HuniePop (HKLM-x32\...\1443428641_is1) (Version: 2.0.0.1 - GOG.com)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4331 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.0.1083 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.63463 - Intel Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Leisure Suit Larry - Reloaded (HKLM-x32\...\1207659243_is1) (Version: 2.1.0.11 - GOG.com)
Magic Bullet QuickLooks for Movie Studio 64 bit (HKLM-x32\...\InstallShield_{03B2F2B1-247A-4216-997F-2BE0372FFEC9}) (Version: 1.4.3 - Ihr Firmenname)
Magic Bullet QuickLooks for Movie Studio 64 bit (Version: 1.4.3 - Ihr Firmenname) Hidden
MagicYUV Lossless Video Codec version 1.0 (HKLM-x32\...\{90410593-E0EB-4F9B-B984-65BEA8F07B91}_is1) (Version: 1.0 - INNOMAGIC, Ltd.)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Metro 2033 (HKLM-x32\...\Steam App 43110) (Version:  - 4A Games)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.6122.5000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.6129.5001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MKVToolNix 7.5.0 (64bit) (HKLM-x32\...\MKVToolNix) (Version: 7.5.0 - Moritz Bunkus)
Movie Studio Platinum 12.0 (64-bit) (HKLM\...\{6C3C3A70-958D-11E2-B0E5-F04DA23A5C58}) (Version: 12.0.896 - Sony)
Mozilla Firefox 44.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 de)) (Version: 44.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 44.0.2.5884 - Mozilla)
MSI Afterburner 4.1.0 (HKLM-x32\...\Afterburner) (Version: 4.1.0 - MSI Co., LTD)
NewBlue VideoFX for Sony Vegas MSPPS (HKLM\...\NewBlue VideoFX for Sony Vegas MSPPS) (Version: 2.0 - NewBlue)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.53.2 - Black Tree Gaming)
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.91 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.9.1.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.9.1.22 - NVIDIA Corporation)
NVIDIA Grafiktreiber 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.91 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA PhysX (Legacy) (HKLM-x32\...\{6F9D5A0B-202C-4161-BC7F-0664EA39E7E7}) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
ON_OFF Charge 2 B13.0403.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE)
ON_OFF Charge 2 B13.0403.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Papers, Please (HKLM-x32\...\1207659209_is1) (Version: 2.5.0.11 - GOG.com)
PhotoFiltre 7 (HKU\S-1-5-21-988284940-210793992-766847566-1000\...\PhotoFiltre 7) (Version:  - )
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.)
Rayman Origins (HKLM-x32\...\Steam App 207490) (Version:  - UBIart Montpellier)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 6.3.0 (HKLM-x32\...\RTSS) (Version: 6.3.0 - Unwinder)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\...\Steam App 2700) (Version:  - Frontier)
Sacred 2 Gold (HKLM-x32\...\Steam App 225640) (Version:  - Ascaron)
SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.9.1.22 - NVIDIA Corporation) Hidden
Sid Meier's Civilization IV (HKLM-x32\...\Steam App 3900) (Version:  - Firaxis Games)
Sony Vocal Eraser (HKLM-x32\...\Sony Vocal Eraser_is1) (Version: 1.00 - iZotope, Inc.)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{BC7B099E-4643-11E3-9A41-F04DA23A5C58}) (Version: 10.0.252 - Sony)
South Park™: The Stick of Truth™ (HKLM-x32\...\Steam App 213670) (Version:  - Obsidian Entertainment)
Spelunky (HKLM-x32\...\Steam App 239350) (Version:  - )
State of Decay (HKLM-x32\...\Steam App 241540) (Version:  - Undead Labs)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
TeamSpeak 3 Client (HKU\S-1-5-21-988284940-210793992-766847566-1000\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)
The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version:  - Edmund McMillen and Florian Himsl)
The Binding of Isaac: Rebirth (HKLM-x32\...\Steam App 250900) (Version:  - Nicalis, Inc.)
The Last Remnant (HKLM-x32\...\Steam App 23310) (Version:  - SQUARE ENIX)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.12.1.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.12.1.0 - GOG.com)
The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\...\Hearts of Stone_is1) (Version: 1.12.1.0 - GOG.com)
The Wolf Among Us (HKLM-x32\...\Steam App 250320) (Version:  - Telltale Games)
Torchlight (HKLM-x32\...\Steam App 41500) (Version:  - Runic Games)
TP-LINK 300Mbps Wireless USB Adapter Treiber (HKLM-x32\...\{852E893E-E4FD-45BB-8B17-72ADDF686974}) (Version: 1.3.1 - TP-LINK)
TP-LINK-Konfigurationstool (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Tropico (HKLM-x32\...\Steam App 33520) (Version:  - PopTop Software)
Two Worlds: Epic Edition (HKLM-x32\...\Steam App 1930) (Version:  - Reality Pump Studios)
Unity Web Player (HKU\S-1-5-21-988284940-210793992-766847566-1000\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR 5.10 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.1 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {02A600D9-1622-4911-9725-509354AEEC6E} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {0D117D4E-EE80-429D-9B8F-D88A92248012} - System32\Tasks\{A7EDC86C-AC88-4B0D-8EBF-801BB3377055} => pcalua.exe -a "C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Prerequisites\vcredist_x64.exe" -d "C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Prerequisites"
Task: {0E38147A-4851-42DC-9070-354ABDEA17FC} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {17C1BB3F-9616-44CB-922F-FF23AE97B1C0} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {1AC1141E-5152-4088-903E-CA244D117CC3} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {1F12A9F8-7D8D-4065-B944-4AEA70A1E4D3} - System32\Tasks\{F1F9B1E2-1649-459F-8D19-CE3F57076C12} => pcalua.exe -a "C:\Users\Admin\Downloads\chromeinstall-8u31 (1).exe" -d C:\Users\Admin\Downloads
Task: {27010340-37CF-488A-BE23-11555D46A73B} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {2DB268B3-0211-4F20-A876-262F2EEAD600} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {2F4F6831-28EB-427C-968C-08B0E3E853D5} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {40F43CEE-3685-41BD-BD05-D3E30DDF1876} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {4184E456-B813-43F0-9B55-96D23C9CD64C} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {41C95DAF-DDF2-405F-A8C4-7C2A140FA0E7} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {4EBCE7C4-AC84-4EAF-B36A-56BD4FF4205A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {5A65B13D-C7DD-442B-BC9F-E849177D96B1} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {5B136352-F75E-4BE9-8434-23C71C470FAC} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {5DC6463A-620C-498C-B8CC-3F26CD93C061} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {6D44F053-69EA-461A-ABFA-2E9FC7A0C0A4} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {6E01809B-A6A1-48BD-B4CA-115117903BF4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {6FC1A9A9-FC4E-40C5-A882-8E0B53ECC4D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {734D0CE1-F91D-46C2-AEF6-86D2515E6550} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {73907E84-CF68-44D4-BC7D-C426518C8A13} - System32\Tasks\{459661D1-D2F6-419D-ADE9-E7E05FD0DA52} => pcalua.exe -a C:\ProgramData\HealthAlert\uninstall.exe -c /kb=y /ic=1
Task: {75DDAAA5-05CE-48D1-917F-D076DB6B8997} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {7CD1B924-1215-4D6F-B79B-0807B81C65DD} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {927B26A2-EDC4-4E89-A784-2709B910E102} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {975DC5FC-0BF4-4734-A115-4331365C7EC0} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {9B842312-0CD7-412B-9771-E75313F50259} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {A3A38E1E-FA91-4361-A90B-CB608B7FE192} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {ABF95328-BD1A-4C58-AA4C-7D9E44654241} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {AD6C2470-2782-4D1D-94D2-D509E96F0AEB} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-02-13] (Microsoft Corporation)
Task: {ADAA0D57-05AF-4D42-97A2-CA60B486A4FD} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {B0297718-FC73-4D55-A112-237A0A2FA275} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {BCF1AC20-C954-415B-90EB-09B341F654CA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {DA3C86F9-5E29-40D8-8035-3E189AC2D6E3} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DEADD6EE-4754-42BF-96F9-AF94B6F06D4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E04234EA-61B8-4CE5-B5DF-08E264BCF2FC} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {E5FA8F18-29CC-41E7-BDEC-EC7888343D95} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {EDACD965-B245-4FD8-8F97-275FB23FECAB} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {F1A14AE5-8D99-4F21-9EEF-F5C2007E7C6B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {F855E92F-2699-4DE3-AF41-951E76CED339} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-03 03:57 - 2016-02-09 06:29 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-12-03 19:37 - 2015-11-22 11:47 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 19:37 - 2015-11-22 11:47 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-01-21 20:31 - 2016-01-21 20:32 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-17 20:43 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-12-17 20:43 - 2015-12-07 05:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-12 20:52 - 2016-01-05 02:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-12 20:52 - 2016-01-05 02:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-27 19:53 - 2016-01-16 06:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-27 19:53 - 2016-01-16 06:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-01-21 20:31 - 2016-01-21 20:32 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 20:31 - 2016-01-21 20:32 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-03-30 22:38 - 2016-01-12 05:43 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\ProgramData\TEMP:8CE646EE

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2015-01-26 20:44 - 00000027 ____N C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1      localhost

==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-988284940-210793992-766847566-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\Pictures\Wallpaper\the_witcher_3_wild_hunt_wallpaper_3-1920x1200.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
HKLM\...\StartupApproved\StartupFolder: => "TP-LINK-Konfigurationstool.lnk"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\StartupApproved\Run: => "Dxtory Update Checker 2.0"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{6E420D0A-379E-4325-997B-5705899CAC39}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe
FirewallRules: [{B96ABC35-9B8B-4784-A9DB-0C1EA97B9030}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe
FirewallRules: [{0F6FC0BD-FCD4-42C7-B4AA-5BC87EE1A220}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
FirewallRules: [{B314AF56-BBF0-45AF-8C29-039C4BD429B8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
FirewallRules: [{256921F5-44A9-4B3A-BD2B-2A570C22DE55}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{57D125E4-42FB-44D2-A0EE-0F02B56DFC57}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F971CB50-BA99-4142-B8DF-8B89A8E07B33}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{E7D8D473-00F7-4EE1-9530-60C4A0F4C150}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{4925243F-FBE6-44B7-A975-BCCB0C180AF7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{30FDAB68-6C8E-4A7B-AA22-CCEA454D4F1A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{506017D7-8AC0-4E6C-A834-C122FCF909C4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds_RADEON.exe
FirewallRules: [{795906C9-BC9B-49FA-8325-C7C8870C2EF3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds_RADEON.exe
FirewallRules: [{E9A061A9-73B5-482C-997D-862ACF115145}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds.exe
FirewallRules: [{F4EBEA40-A7D8-43C7-AE9D-778C4CA5D7CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Two Worlds - Epic Edition\TwoWorlds.exe
FirewallRules: [{65C91C97-F856-4271-9C73-C98B7567A801}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{360AEBC8-A0BE-4E94-8A33-AE6EAEC656E8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{315E15EB-B4F1-43E8-A4E6-402275B529A5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FF509E52-645D-4365-84AD-FB0C261C9868}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C5998C02-632D-43E9-90CA-60097EF8E86A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{991121E2-9026-4743-B7E5-7A8E55384142}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{86DF2C1A-1739-488B-875A-1AC9DB9C5060}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{6064EF51-4B50-4444-B1A4-EFA61BFF49F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{1B15FC00-36FB-4A93-AE32-9647175F8F76}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{DC722C51-C46D-40EC-8668-E362EAE276B6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\HowToSurvive.exe
FirewallRules: [{C3A04E99-322D-46E9-B9BD-703483A7B189}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\HowToSurvive.exe
FirewallRules: [{0F98958F-E861-40DD-BDC6-995B42040165}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\Detect.exe
FirewallRules: [{36EB300B-5DA7-4BF0-90A6-F1DE17CD6573}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\How to Survive\Detect.exe
FirewallRules: [{49455361-4214-40EC-B265-FC6266F267D5}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe
FirewallRules: [{3956483D-656F-4265-BDA2-02173B16C080}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe
FirewallRules: [{D307758E-88ED-41D1-BA4D-784FC8711CA3}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe
FirewallRules: [{83F8AF97-7FB9-454C-A591-89EB18A99069}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe
FirewallRules: [{711528E3-97F2-4F8A-9EA5-082E57617A17}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\UPlayBrowser.exe
FirewallRules: [{C5046C9C-B48A-4D3C-AE86-93A41B7D5923}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed II\UPlayBrowser.exe
FirewallRules: [{7DB14810-4D82-4530-8D15-AC1FCBB8292F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{D2A93941-11DF-48F6-860B-F94D40812543}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{43838B64-8209-499B-ADF7-50A08698FC1C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{04679FA5-74EB-4F69-9CF8-D680702FF885}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [TCP Query User{AA756576-BAC1-4E66-88B8-E0048499E0E2}C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [UDP Query User{D89FE854-8AF1-4764-9460-3B065BD66B94}C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [{3248C1A6-D190-4F12-8664-CE8FC448256F}] => (Block) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [{3C04B63A-6BE8-44F6-9601-3F5512BD4BD5}] => (Block) C:\program files (x86)\steam\steamapps\common\sacred 2 gold\system\s2gs.exe
FirewallRules: [{C5EB114E-20B2-4E5A-A3C0-42DB2A0E0E3B}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe
FirewallRules: [{B3BEF09D-7E43-474E-B668-25C680E2C25F}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe
FirewallRules: [{E739C62B-55ED-493C-8218-9EA012051BBD}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{1DDA49CF-21C4-4183-902F-D13104F301A1}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2C3D6D71-6A44-4A80-B2A7-219C1420825F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{D560325B-8725-48E5-8ABC-2E1FF99FCE98}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{E48773F8-4DF5-4A58-A166-1B312C9269EF}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe
FirewallRules: [{412CA1BF-B6E1-4713-B8FB-7EBC424876D0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRSP.exe
FirewallRules: [{2D959B1C-9A0A-4CAC-A4FC-75936D9D49F2}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRMP.exe
FirewallRules: [{C0F791F9-DF54-4563-8410-219F17F6D25F}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\ACRMP.exe
FirewallRules: [{6CE64287-2232-4D23-AE8C-292D1C5D4F93}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe
FirewallRules: [{4E8BD3CA-B72A-4C48-A323-F5A3B2EBF83E}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe
FirewallRules: [{00AB475C-77DB-4C57-B574-1D524BA5CA20}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Binding Of Isaac\Isaac.exe
FirewallRules: [{9AAD1A10-DA90-478C-9C63-08C7D8B02EC8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Binding Of Isaac\Isaac.exe
FirewallRules: [{090A43EF-2DD9-4261-990A-CAFE332D8E92}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\SinglePlayer\Binaries\Win32\BatmanOrigins.exe
FirewallRules: [{2102550E-749E-41E2-8FEE-B7EBBD08C1CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\SinglePlayer\Binaries\Win32\BatmanOrigins.exe
FirewallRules: [{4BCFAB4F-2B9D-45DE-B077-F08168D5D67C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\Online\Binaries\Win32\BatmanOriginsOnline.exe
FirewallRules: [{E42C92D2-79D8-4882-87F6-3B1B1594FDE7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman Arkham Origins\Online\Binaries\Win32\BatmanOriginsOnline.exe
FirewallRules: [TCP Query User{C1109CDB-71AE-439E-B1C2-50213C8C7A5B}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [UDP Query User{83D4C6C7-813C-44E2-B75B-C4BE83A4CB62}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [{36973D42-9A1C-4CFE-BF4D-E518212F5373}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ValveTestApp207490\Rayman Origins.exe
FirewallRules: [{7D9C5840-7C9D-46DF-B0A2-BC21610BF4A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ValveTestApp207490\Rayman Origins.exe
FirewallRules: [{C879E974-3CD9-40F1-9C30-303E9B43905F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{C7E055CB-D40D-4E27-B447-69B9B33F8345}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{12825260-A3BB-45E7-9C28-A1420FF60F33}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{997E46D0-78E6-4A77-8D4F-3A92C07FE6B0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{CFB6F006-D750-49A3-BAE0-6BDFB7E2AC9C}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{6B5F1130-E279-488D-AE55-A2DAE030F088}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{CEED23D0-3A11-4786-864D-3081A7F322BE}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{DE762189-4EF7-4EC1-A60F-21B017CB8085}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{6D55673B-0FF9-4D59-A9A2-9F7BDF50B34C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
FirewallRules: [{A2B93ADD-9986-4733-9E48-06254363C283}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
FirewallRules: [{9E681173-7A4C-46C3-86A6-A36B1C2B5BA3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{05AA5451-BEE9-4D9E-94C0-0B0EC6026DC5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{7D4D3518-150E-4447-B19A-4B0748E50D4B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Spelunky\Spelunky.exe
FirewallRules: [{AF8D2895-5885-495F-9C5B-E3B660A1F778}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Spelunky\Spelunky.exe
FirewallRules: [TCP Query User{A544BD62-14C2-4259-AAEF-022952556857}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [UDP Query User{3909E355-B5FB-4A27-9199-194854704AAD}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [{545D9B8D-9953-4CB7-8C25-D73B6336E07A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{29E901E5-DBD7-43C3-A1BC-B594CC13EA25}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{3259E222-4518-4F5A-8904-4EE437F4BBFB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{0F2CF57D-DE06-430D-82E2-7174208088DC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{1F3813EE-F4C8-49CB-8E88-BD546DB1DA23}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{6E7F3C96-0F1D-4656-9A5C-740C8216C7D9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{C9ACFBFE-A603-4442-A109-BCD1CC90A1DD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{05C428E6-A1B0-451B-B550-113694555C8E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{460DC9FE-CE1D-4C6B-B70E-1703B62E80E1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{4E52E920-FB9E-4B2F-85DE-B8FBBB13529B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{286BEAE6-98AE-4193-BA0D-534FE8742A51}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{C22367D4-EBB9-418D-B4E8-5F73846A2869}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{BC8E747A-F61E-4EB5-84D4-E88C3716963C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{7DC3F700-62CA-4230-B7C6-F13844A6B5B2}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{BFCBE96B-6F69-480B-8884-A8212FEEAC8A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{9FFD4D7B-09F4-4441-ACF9-B3D8D37FE1B2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{871626AC-BD7C-4745-A16B-45EE7A67EB03}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{42F54F3E-40B8-4B0B-823A-B3B14CEFC3BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{E97DDFC4-E97B-4704-B17D-FD5020048649}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Torchlight\Torchlight.exe
FirewallRules: [{52B0886E-3621-49AD-964F-D4A2E707BE12}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Torchlight\Torchlight.exe
FirewallRules: [{F41E3239-CD33-4579-B34B-0AAF256F6C55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{D430042B-5DF0-418A-880D-9230DBE275EF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{2B96A400-FD44-4DFD-9CFC-D29F6FB58F7D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metro 2033\metro2033.exe
FirewallRules: [{D793FCDF-0842-4FBC-90D7-B0973680D2EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metro 2033\metro2033.exe
FirewallRules: [TCP Query User{4BCF5F21-C99A-478A-95FD-4A0869F00131}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [UDP Query User{9E1EF25B-113D-422A-A4F8-11CBCA584F82}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [{3F675CC0-3184-4393-894F-B4B33B351994}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{129A599D-446F-40B7-A918-9B2D3D6375EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{20ECE902-9A57-4F70-8E04-4C88E2419E05}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Last Remnant\Binaries\TLR.exe
FirewallRules: [{2D848495-1A91-4179-8CBB-3866ED0E0C34}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Last Remnant\Binaries\TLR.exe
FirewallRules: [{BA367573-7B8F-4777-8AB5-864A549D3CFB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{CF00F149-60EB-48EB-92C5-AF5CB3E8B370}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{02A409DB-0A4D-415A-B68D-E2C8AD421B30}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{7A43CD6B-4116-4279-9B1A-29C245724E88}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{B063BE0A-60F7-4EE4-9FA6-88A2EFB1FBE4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{3B571F71-ACD4-4B5A-9DB1-75CFA55B3D21}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{3620AD47-E894-47F8-84C8-CB1D91B3110C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{7423B0B5-233A-473C-BB3C-A4032B7EA0BE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{1505A911-84EC-4CAE-AE32-E71696A44070}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tropico\Tropico.EXE
FirewallRules: [{E32F9C77-6C08-45FD-A02D-B36226C008B3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tropico\Tropico.EXE
FirewallRules: [{F581802C-2D95-4E59-B72E-6FFD315D8182}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CF63116B-20B3-4892-A712-102390ED402D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4C6692EF-51C0-4623-8C57-40EBA18FDEF4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{49A3271C-BB1D-43DD-9654-075D79195F0E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sacred 2 Gold\system\sacred2.exe
FirewallRules: [{DCBC8CE9-D293-4FA1-879B-270196EED1A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
FirewallRules: [{9A9181C1-7313-4E03-936A-64B3E573D028}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
FirewallRules: [{D14185D7-9F38-4C57-965F-43D51E98A39D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{863A7EB5-4496-4987-BF95-C22A2FA2AC22}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{43CF3CA2-59D2-450E-B920-4FC4ABD57704}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\1954 Alcatraz\Alcatraz.exe
FirewallRules: [{2E4E2EBA-A40A-4895-80FD-F0DE745402A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\1954 Alcatraz\Alcatraz.exe
FirewallRules: [{CA846C69-619B-40C8-8594-E8FDF54622DF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{AC494E79-2D9F-423D-847E-3000CCD76907}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{8BFD8407-04E7-4FA9-9E1F-150B376B9783}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F58ADA5A-4C45-4891-9DD3-8254D2E612CF}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{6ACFA7C6-CB3F-4F28-BC50-AAD2F0E06B3F}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{58515D64-FDE2-448A-9448-2FEA27E88E4C}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{876C7FEA-0DEE-4871-BFAB-053A02AED9AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Wolf Among Us\TheWolfAmongUs.exe
FirewallRules: [{BB4BF462-7275-4801-8131-484F5D2EA2C9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Wolf Among Us\TheWolfAmongUs.exe
FirewallRules: [{523A1B31-06BB-4D69-B1DE-10F60E4F3610}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{A153552B-49D1-4361-A137-0D94D18D37B4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{D43680B8-0ACE-4C04-80C7-D8D967C754EA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{B196BF22-7291-48F4-AC03-1DE595A40997}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{4FA950EC-A651-4B05-B178-761195FED113}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B94E9B0F-047D-4BF0-9928-0BE7465C6A86}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization IV\Civilization4.exe
FirewallRules: [{4C463636-3D0B-489D-8D47-B867BB940BCD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization IV\Civilization4.exe
FirewallRules: [TCP Query User{2785A175-2DF4-40EA-91A6-769AEBF450A8}C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [UDP Query User{15F167CC-DEE4-46D4-B376-1BBC8B6631B2}C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\admin\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [{C648A936-27DA-4F97-9B13-FAF1A85070B9}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSA08E.tmp\SymNRT.exe
FirewallRules: [{330A2776-D04B-4D5E-BA65-F84A7657D6E1}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSA08E.tmp\SymNRT.exe
FirewallRules: [{1C6D9EA5-3BB6-4857-B833-2082CC9F4CDB}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSC64F.tmp\SymNRT.exe
FirewallRules: [{AF593FDA-A8A7-4C9A-ABD1-92EC5903C4AF}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSC64F.tmp\SymNRT.exe
FirewallRules: [{8975AD88-F6EA-4954-9D0A-276E0BE02EB6}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSACAD.tmp\SymNRT.exe
FirewallRules: [{03D5B382-45AA-448A-B5EF-8C2C4A54030F}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zSACAD.tmp\SymNRT.exe

==================== Wiederherstellungspunkte =========================

22-02-2016 10:43:20 Geplanter Prüfpunkt

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (02/27/2016 11:57:27 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/27/2016 11:44:54 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Admin-PC)
Description: Bei der Aktivierung der App „Microsoft.Getstarted_2.6.12.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca“ ist folgender Fehler aufgetreten: -2144927149. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (02/26/2016 09:55:46 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.SystemException: Helper process exited prematurely
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (02/26/2016 07:39:30 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/26/2016 05:40:58 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/26/2016 05:23:25 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/25/2016 08:43:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: backgroundTaskHost.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d8f0
Name des fehlerhaften Moduls: Cortana.BackgroundTask.dll, Version: 0.0.0.0, Zeitstempel: 0x5699d0c9
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000046a65
ID des fehlerhaften Prozesses: 0x1ba8
Startzeit der fehlerhaften Anwendung: 0xbackgroundTaskHost.exe0
Pfad der fehlerhaften Anwendung: backgroundTaskHost.exe1
Pfad des fehlerhaften Moduls: backgroundTaskHost.exe2
Berichtskennung: backgroundTaskHost.exe3
Vollständiger Name des fehlerhaften Pakets: backgroundTaskHost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: backgroundTaskHost.exe5

Error: (02/25/2016 08:41:10 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.

Error: (02/25/2016 11:44:23 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (02/25/2016 11:40:52 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: HTTP-Status 403: Der Client verfügt nicht über genügend Zugriffsrechte auf das angeforderte Serverobjekt.


Systemfehler:
=============
Error: (02/27/2016 11:51:17 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/27/2016 11:51:17 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/27/2016 11:51:14 AM) (Source: DCOM) (EventID: 10016) (User: Admin-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-988284940-210793992-766847566-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (02/27/2016 11:48:11 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Defender-Dienst" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577

Error: (02/27/2016 11:47:29 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll
Fehlercode: 21

Error: (02/27/2016 11:47:13 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (02/27/2016 11:46:24 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (02/27/2016 11:46:06 AM) (Source: DCOM) (EventID: 10005) (User: Admin-PC)
Description: 1084ShellHWDetectionNicht verfügbar{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (02/27/2016 11:45:49 AM) (Source: DCOM) (EventID: 10005) (User: Admin-PC)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/27/2016 11:45:49 AM) (Source: DCOM) (EventID: 10005) (User: Admin-PC)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
Prozentuale Nutzung des RAM: 13%
Installierter physikalischer RAM: 16262.64 MB
Verfügbarer physikalischer RAM: 14072.23 MB
Summe virtueller Speicher: 32646.64 MB
Verfügbarer virtueller Speicher: 30255.83 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:1862.48 GB) (Free:1008.55 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 462E0839)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

==================== Ende von Addition.txt ============================

Gruß Kanso

Larusso 28.02.2016 11:11

Hy

Sorry, war gestern den ganzen Tag unterwegs.

Das die Leute vom Support manchmal nur auf ihre Tools beschränkt sind, ist leider trauriger Alltag.

Der Uninstaller hat zumindest die aktiven Komponenten entfernt, dennoch sind noch Ordner vorhanden, die eigentlich nicht mehr stören dürften.
Da du dafür bezahlt hast, gehe ich mal davon aus, dass du es wieder installieren willst oder ?
( Ich persönlich würde diese Lizenz aber nicht mehr verlängern )

Checken wir das System noch etwas durch, bevor wir uns an die Neuinstallation machen.



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Da du dafür ja bezahlt hast,

Kanso 28.02.2016 13:24

Hallo Daniel,

kein Problem. Ja ich möchte Norton nochmal installieren (Meine Lizenz läuft leider noch bis 2017). Was würdest du mir danach für ein Programm empfehlen? Nach diesem Vorfall werde ich in Zunkunft auf Norton verzichten. Konnte jetzt aber mittlerweile ein Windows Update ausführen, das vorher nicht funktioniert hat. Wenn ich das dir zu verdanken habe, dann vielen Dank :lach:

Der ESET Online Scanner lässt sich nicht ausführen. Bei der Initialisierung erscheint die Fehlermeldung "Unerwarteter Fehler 101". (Habe die richtigen Einstellungen verwendet).

Gruß Kanso

Larusso 28.02.2016 14:16

Für die Zukunft ?
http://www.trojaner-board.de/166031-...-produkte.html

Hm, den Fehler kenn ich nur, wenn die Uhrzeit nicht stimmt.

Stimmt Datum und Jahr in der Taskleiste ?

Kanso 28.02.2016 14:18

Ja Datum und Uhrzeit stimmen soweit.

Gruß Kanso

Larusso 28.02.2016 14:49

Gerade bei mir versucht und läuft.

Downloade dir mal bitte Windows All In One Repair von hier herunter
http://filepony.de/download-windows_repair_aio/

Entpacke das Archiv.
Starte den Rechner in den abgesicherten Modus !!!

Im erstellten Ordner starte die Repair_Windows.exe.
Ignoriere das verfügbare Update.

Führe Step 3 - 5 vollständig aus ( Ich empfehle dringends die Backup Funktionen zu nutzen )


Wenn erledigt, öffne den Repairs Tab und belasse alles wie es ist.
Rechts kannst du unter "Restart/Shutdown" den automatischen Neustart auswählen ( wenn du willst )

Klicke auf "Start Repairs".


Nach dem Neustart, versuche bitte ESET erneut.

Kanso 28.02.2016 17:00

Hallo,

hat leider nicht funktioniert, ich bekomme ständig die Fehlermeldung: "cmd.exe Anwendungsfehler" Die Anwendung konnte nicht gestartet werden (0xc0000142)
Also bei Step 3 hat sich garnix getan, hat ungefähr ne Stunde lang geladen aber nix ist passiert und bei step 4 kam eben diese Fehlermeldung.

Gruß Kanso

Larusso 28.02.2016 18:52

Drücke bitte die Windows Taste und gib CMD ein.
Starte die Eingabeaufforderung mit Rechtsklick "Als Admin ausführen "
Gib ein : sfc /scannow

Dies prüft das System auf fehlerhafte Dateien.
Wenn dies beendet ist, versuche Windows Repair erneut.

Kanso 28.02.2016 19:05

Hallo,

kann ich leider nicht öffnen, es erscheint die Fehlermeldung "Die Anwendung konnte nicht korrekt gestartet werden (0xc0000142)". :confused:

Gruß Kanso

Larusso 29.02.2016 08:48

Okay, dann gehen wir mal auf Problemsuche. Macht der Rechner sonst noch Probleme ?

Note
Mit Windows 10 kommst du so in die RC

1. Neustart des PC bei gedrückter SHIFT-Taste
2. "Problembehandlung" auswählen
3. Aufruf der "Erweiterten Optionen"
4. "Eingabeaufforderung" auswählen
5. Benutzerkonto auswählen
6. Falls gesetzt: "Kennwort-Eingabe"
7. "Eingabeaufforderung" wird geöffnet.

Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST Download FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Ja und klicke Untersuchen
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).


Kanso 29.02.2016 20:59

Hallo,

sonst habe ich keine Probleme festgestellt. Bin grade in der Arbeit. Werde mir das heute Abend mal angucken und mich dann nochmal melden.



Tut mir Leid hat ein wenig länger gedauert.

FRST.txt:

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:27-02-2016
durchgeführt von SYSTEM auf MININT-9ERL7K0 (29-02-2016 20:41:12)
Gestartet von d:\
Platform: Windows 10 Pro (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11
Start-Modus: Recovery
Standard: ControlSet001
ACHTUNG!:=====> Wenn das System startfähig ist sollte FRST im normalen oder abgesicherten Modus ausgeführt werden, um ein vollständiges Ergebnis zu erhalten.

Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [402344 2015-12-19] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-01-31] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-03-12] (Intel Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKU\Admin\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-16] (InstallShield Software Corporation)
HKU\Admin\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
HKU\DefaultAppPool\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [175368 2016-02-09] (NVIDIA Corporation)

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-31] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7220792 2016-01-30] (GOG.com)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-12] (NVIDIA Corporation)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
S2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373160 2015-12-19] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-12] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-12] (NVIDIA Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S3 BstHdAndroidSvc; "C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android [X]
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [X]
S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2014-06-19] ()
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-12] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
S3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [3870464 2015-10-01] (Realtek Semiconductor Corporation                          )
S3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation)
S3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation)
S3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation)
S3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X]
S3 condrv; System32\drivers\condrv.sys [X]
S3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-02-29 20:38 - 2016-02-29 20:38 - 00000000 ____D C:\Users\Admin\Desktop\2011-04-21
2016-02-28 16:42 - 2016-02-28 16:42 - 00000207 _____ C:\Windows\tweaking.com-regbackup-ADMIN-PC-Windows-10-Pro-(64-bit).dat
2016-02-28 16:42 - 2016-02-28 16:42 - 00000000 ____D C:\RegBackup
2016-02-28 15:18 - 2016-02-28 15:22 - 00000000 ____D C:\Users\Admin\Desktop\Tweaking.com - Windows Repair
2016-02-28 13:17 - 2016-02-28 13:17 - 02870984 _____ (ESET) C:\Users\Admin\Desktop\esetsmartinstaller_deu.exe
2016-02-28 13:17 - 2016-02-28 13:17 - 00000000 ____D C:\Program Files (x86)\ESET
2016-02-27 12:07 - 2016-02-27 12:08 - 00056144 _____ C:\Users\Admin\Desktop\Addition.txt
2016-02-27 12:06 - 2016-02-27 12:08 - 00039830 _____ C:\Users\Admin\Desktop\FRST.txt
2016-02-27 12:05 - 2016-02-27 12:06 - 02371072 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2016-02-27 11:53 - 2016-02-27 14:36 - 00078252 _____ C:\TDSSKiller.3.1.0.9_27.02.2016_11.53.57_log.txt
2016-02-27 11:52 - 2016-02-27 11:53 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\Admin\Desktop\tdsskiller.exe
2016-02-27 11:51 - 2016-02-27 11:51 - 00001845 _____ C:\Users\Admin\Desktop\Fixlog.txt
2016-02-26 09:35 - 2016-02-27 12:08 - 00000000 ____D C:\FRST
2016-02-26 05:36 - 2016-02-26 05:36 - 00001364 _____ C:\Users\Admin\Desktop\Norton-Installationsdateien.lnk
2016-02-26 05:36 - 2016-02-26 05:36 - 00000000 ____D C:\Windows\System32\Drivers\NSx64
2016-02-26 05:35 - 2016-02-26 05:36 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader(2).exe
2016-02-26 05:30 - 2016-02-26 19:27 - 00364004 _____ C:\Windows\ntbtlog.txt
2016-02-26 05:28 - 2016-02-26 05:28 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (2).exe
2016-02-26 05:12 - 2016-02-26 05:14 - 00412020 _____ C:\Windows\Minidump\022616-17640-01.dmp
2016-02-25 11:37 - 2016-02-25 11:37 - 00000432 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp.bat
2016-02-25 11:37 - 2016-02-25 11:37 - 00000357 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp_r.bat
2016-02-25 11:33 - 2016-02-25 11:36 - 00000000 ____D C:\Program Files (x86)\LogMeIn Rescue RC - 0bfdcd33-f52c-4b3b-a4a7-71770fabb626
2016-02-25 11:28 - 2016-02-27 11:45 - 00000000 ____D C:\ProgramData\Norton
2016-02-25 11:28 - 2016-02-26 19:28 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-02-25 11:28 - 2016-02-26 05:38 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-02-25 11:15 - 2016-02-25 11:15 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (1).exe
2016-02-25 11:13 - 2016-02-25 11:13 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool(1).exe
2016-02-25 10:48 - 2016-02-25 10:48 - 00000000 __SHD C:\found.000
2016-02-25 10:29 - 2016-02-28 16:53 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-25 10:28 - 2016-02-25 10:28 - 00000000 ____D C:\Windows\pss
2016-02-25 10:07 - 2016-02-26 05:31 - 00000000 ____D C:\NPE
2016-02-25 10:05 - 2016-02-26 05:33 - 00000000 ____D C:\Users\Admin\AppData\Local\NPE
2016-02-25 10:05 - 2016-02-25 10:05 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE.exe
2016-02-25 10:02 - 2016-02-25 10:02 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader (1).exe
2016-02-25 09:58 - 2016-02-28 20:54 - 00004152 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3CF3C132-6859-4994-8DAC-3B31CD8D194C}
2016-02-25 09:54 - 2016-02-25 09:55 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool.exe
2016-02-25 09:48 - 2016-02-25 09:48 - 00000248 _____ C:\rescue.info
2016-02-25 09:46 - 2016-02-25 09:46 - 01857576 _____ (LogMeIn, Inc.) C:\Users\Admin\Downloads\Support-LogMeInRescue.exe
2016-02-25 09:46 - 2016-02-25 09:46 - 00000000 ____D C:\Users\Admin\AppData\Local\LogMeIn Rescue Applet
2016-02-24 21:57 - 2016-02-24 21:57 - 00000000 ____D C:\Users\Admin\AppData\LocalLow\HuniePot
2016-02-16 00:11 - 2016-02-16 00:11 - 00002202 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2016-02-16 00:10 - 2016-02-16 00:10 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-02-16 00:10 - 2016-02-09 06:04 - 00111672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-02-16 00:09 - 2016-02-09 09:25 - 42983480 _____ C:\Windows\System32\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 37616184 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 31119296 _____ (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 24944064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 21201784 _____ (NVIDIA Corporation) C:\Windows\System32\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 20741880 _____ (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17631304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17224664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17175248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17116936 _____ (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02541504 _____ (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02187712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01924152 _____ (NVIDIA Corporation) C:\Windows\System32\nvdispco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01573432 _____ (NVIDIA Corporation) C:\Windows\System32\nvdispgenco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00950328 _____ (NVIDIA Corporation) C:\Windows\System32\NvFBC64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00882232 _____ (NVIDIA Corporation) C:\Windows\System32\NvIFR64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00786688 _____ (NVIDIA Corporation) C:\Windows\System32\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00745408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00689600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00632336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00541000 _____ (NVIDIA Corporation) C:\Windows\System32\nvumdshimx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00445728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00423360 _____ (NVIDIA Corporation) C:\Windows\System32\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00383424 _____ (NVIDIA Corporation) C:\Windows\System32\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00379448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00378968 _____ (NVIDIA Corporation) C:\Windows\System32\nvEncodeAPI64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00348216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00317144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00175368 _____ (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00151368 _____ (NVIDIA Corporation) C:\Windows\System32\nvoglshim64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-02-14 10:24 - 2016-02-14 10:26 - 00353028 _____ C:\Windows\Minidump\021416-29546-01.dmp
2016-02-12 06:29 - 2016-02-24 09:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-09 19:52 - 2016-01-29 07:57 - 04502352 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-02-09 19:52 - 2016-01-29 07:33 - 04064320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-02-09 19:52 - 2016-01-27 07:15 - 01557776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-02-09 19:52 - 2016-01-27 07:15 - 01542816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-02-09 19:52 - 2016-01-27 07:01 - 07476064 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2016-02-09 19:52 - 2016-01-27 07:01 - 01997328 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2016-02-09 19:52 - 2016-01-27 07:01 - 01819720 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2016-02-09 19:52 - 2016-01-27 06:59 - 00304752 _____ (Microsoft Corporation) C:\Windows\System32\systemreset.exe
2016-02-09 19:52 - 2016-01-27 06:57 - 02919320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-02-09 19:52 - 2016-01-27 06:57 - 01824264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2016-02-09 19:52 - 2016-01-27 06:57 - 00820704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2016-02-09 19:52 - 2016-01-27 06:56 - 21124344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-02-09 19:52 - 2016-01-27 06:55 - 05242496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2016-02-09 19:52 - 2016-01-27 06:55 - 00081112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpenWith.exe
2016-02-09 19:52 - 2016-01-27 06:54 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-02-09 19:52 - 2016-01-27 06:46 - 02606824 _____ (Microsoft Corporation) C:\Windows\System32\combase.dll
2016-02-09 19:52 - 2016-01-27 06:46 - 01270072 _____ (Microsoft Corporation) C:\Windows\System32\WinTypes.dll
2016-02-09 19:52 - 2016-01-27 06:45 - 22564328 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2016-02-09 19:52 - 2016-01-27 06:45 - 06605544 _____ (Microsoft Corporation) C:\Windows\System32\windows.storage.dll
2016-02-09 19:52 - 2016-01-27 06:44 - 00604928 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2016-02-09 19:52 - 2016-01-27 06:44 - 00085320 _____ (Microsoft Corporation) C:\Windows\System32\OpenWith.exe
2016-02-09 19:52 - 2016-01-27 06:43 - 00359776 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2016-02-09 19:52 - 2016-01-27 06:37 - 01998176 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2016-02-09 19:52 - 2016-01-27 06:37 - 00576352 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms2.sys
2016-02-09 19:52 - 2016-01-27 06:21 - 00162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-02-09 19:52 - 2016-01-27 06:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ztrace_maps.dll
2016-02-09 19:52 - 2016-01-27 06:13 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininetlui.dll
2016-02-09 19:52 - 2016-01-27 06:12 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-02-09 19:52 - 2016-01-27 06:11 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-02-09 19:52 - 2016-01-27 06:10 - 22394368 _____ (Microsoft Corporation) C:\Windows\System32\edgehtml.dll
2016-02-09 19:52 - 2016-01-27 06:10 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2016-02-09 19:52 - 2016-01-27 06:08 - 00299008 _____ (Microsoft Corporation) C:\Windows\System32\microsoft-windows-system-events.dll
2016-02-09 19:52 - 2016-01-27 06:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\ztrace_maps.dll
2016-02-09 19:52 - 2016-01-27 06:07 - 00203264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iassam.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 19339776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 18678272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\wininetlui.dll
2016-02-09 19:52 - 2016-01-27 06:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2016-02-09 19:52 - 2016-01-27 06:04 - 09918976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2016-02-09 19:52 - 2016-01-27 06:04 - 00147456 _____ (Microsoft Corporation) C:\Windows\System32\mtxoci.dll
2016-02-09 19:52 - 2016-01-27 06:03 - 00099328 _____ (Microsoft Corporation) C:\Windows\System32\ngckeyenum.dll
2016-02-09 19:52 - 2016-01-27 06:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\System32\hlink.dll
2016-02-09 19:52 - 2016-01-27 06:01 - 00792064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-02-09 19:52 - 2016-01-27 05:59 - 00258048 _____ (Microsoft Corporation) C:\Windows\System32\iassam.dll
2016-02-09 19:52 - 2016-01-27 05:58 - 11545088 _____ (Microsoft Corporation) C:\Windows\System32\twinui.dll
2016-02-09 19:52 - 2016-01-27 05:57 - 00764928 _____ (Microsoft Corporation) C:\Windows\System32\Chakradiag.dll
2016-02-09 19:52 - 2016-01-27 05:55 - 12125696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-02-09 19:52 - 2016-01-27 05:55 - 03666432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-02-09 19:52 - 2016-01-27 05:54 - 24603136 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2016-02-09 19:52 - 2016-01-27 05:52 - 00970752 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 02230784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 01504768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-02-09 19:52 - 2016-01-27 05:50 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2016-02-09 19:52 - 2016-01-27 05:49 - 05662208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-02-09 19:52 - 2016-01-27 05:48 - 13382656 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2016-02-09 19:52 - 2016-01-27 05:44 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgbkend.dll
2016-02-09 19:52 - 2016-01-27 05:42 - 01387520 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2016-02-09 19:52 - 2016-01-27 05:41 - 03592704 _____ (Microsoft Corporation) C:\Windows\System32\win32kfull.sys
2016-02-09 19:52 - 2016-01-27 05:39 - 02275328 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2016-02-09 19:52 - 2016-01-27 05:38 - 07835648 _____ (Microsoft Corporation) C:\Windows\System32\Chakra.dll
2016-02-09 19:52 - 2016-01-27 05:38 - 01734656 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2016-02-09 19:52 - 2016-01-27 05:37 - 04894720 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2016-02-09 19:52 - 2016-01-27 05:36 - 02757120 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2016-02-09 19:52 - 2016-01-27 05:32 - 01087488 _____ (Microsoft Corporation) C:\Windows\System32\reseteng.dll
2016-02-09 19:52 - 2016-01-27 05:31 - 00079360 _____ (Microsoft Corporation) C:\Windows\System32\cfgbkend.dll
2016-02-02 19:33 - 2016-02-02 19:35 - 10026464 _____ C:\Users\Admin\Downloads\Worlds Apart (Sami Zayn)_Megalouis100v4.m4a
2016-01-31 12:53 - 2016-02-08 00:23 - 00000000 ____D C:\Users\Admin\Documents\Broken Sword - Director's Cut
2016-01-31 01:02 - 2016-01-23 04:31 - 01924152 _____ (NVIDIA Corporation) C:\Windows\System32\nvdispco6436175.dll
2016-01-31 01:02 - 2016-01-23 04:31 - 01571776 _____ (NVIDIA Corporation) C:\Windows\System32\nvdispgenco6436175.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-02-29 20:39 - 2015-12-03 04:17 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-29 20:39 - 2015-12-03 04:01 - 02091230 _____ C:\Windows\System32\PerfStringBackup.INI
2016-02-29 20:39 - 2015-10-30 19:35 - 00889534 _____ C:\Windows\System32\perfh007.dat
2016-02-29 20:39 - 2015-10-30 19:35 - 00197858 _____ C:\Windows\System32\perfc007.dat
2016-02-29 20:39 - 2015-10-30 07:28 - 00524288 ___SH C:\Windows\System32\config\BBI
2016-02-29 20:33 - 2015-12-03 03:58 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-29 20:33 - 2015-12-03 03:57 - 00000180 _____ C:\Windows\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-02-29 20:19 - 2015-12-03 04:01 - 00000000 ____D C:\users\Admin
2016-02-29 20:17 - 2015-10-30 08:21 - 00000000 ____D C:\Windows\INF
2016-02-29 09:58 - 2014-08-10 22:06 - 00000000 ____D C:\Program Files (x86)\Steam
2016-02-28 23:10 - 2014-10-15 18:28 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2016-02-28 15:19 - 2014-02-10 11:42 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SoftGrid Client
2016-02-28 10:43 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\AppReadiness
2016-02-27 14:45 - 2015-10-30 08:24 - 00000000 __RHD C:\Users\Public\Libraries
2016-02-27 11:48 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\System32\NDF
2016-02-26 19:34 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-26 05:30 - 2015-10-30 08:24 - 00000000 ___HD C:\Windows\ELAMBKUP
2016-02-26 05:12 - 2015-12-04 19:37 - 00000000 ____D C:\Windows\Minidump
2016-02-26 05:12 - 2014-03-07 16:29 - 890432205 _____ C:\Windows\MEMORY.DMP
2016-02-25 20:39 - 2015-03-05 20:41 - 00000000 ____D C:\GOG Games
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieUserList
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieSiteList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieUserList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieSiteList
2016-02-25 09:55 - 2016-01-29 19:03 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-02-25 08:44 - 2015-08-06 20:56 - 00000000 __SHD C:\Users\Admin\IntelGraphicsProfiles
2016-02-22 01:16 - 2015-10-30 07:28 - 00032768 ___SH C:\Windows\System32\config\ELAM
2016-02-21 23:27 - 2015-01-27 10:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-16 00:11 - 2015-12-03 03:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-14 10:24 - 2015-01-26 02:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-13 20:35 - 2014-02-10 12:11 - 00000000 ____D C:\Windows\System32\MRT
2016-02-13 20:32 - 2014-02-10 12:11 - 146614896 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2016-02-12 02:22 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\rescache
2016-02-10 19:34 - 2015-08-06 20:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-10 10:37 - 2015-10-30 19:47 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-10 07:27 - 2015-09-22 23:03 - 12478528 _____ (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2016-02-09 22:20 - 2015-10-30 08:11 - 00000000 ____D C:\Windows\CbsTemp
2016-02-09 09:25 - 2015-09-22 23:03 - 19779648 _____ (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 14115136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 03649576 _____ (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 03231544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2016-02-09 09:25 - 2015-09-22 23:03 - 00035832 _____ C:\Windows\System32\nvinfo.pb
2016-02-09 06:29 - 2015-12-03 03:57 - 06368824 _____ (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 02992064 _____ (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 02561472 _____ (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 01263040 _____ (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2016-02-09 06:29 - 2015-12-03 03:57 - 00392128 _____ (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2016-02-09 06:29 - 2015-12-03 03:57 - 00071224 _____ (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2016-02-09 06:29 - 2014-11-24 17:02 - 00530368 _____ (NVIDIA Corporation) C:\Windows\System32\nv3dappshext.dll
2016-02-09 06:29 - 2014-11-24 17:02 - 00083512 _____ (NVIDIA Corporation) C:\Windows\System32\nv3dappshextr.dll
2016-02-07 23:20 - 2015-05-20 16:56 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
2016-02-07 20:41 - 2014-04-12 17:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2016-02-06 15:58 - 2015-12-03 03:57 - 06154909 _____ C:\Windows\System32\nvcoproc.bin
2016-02-03 20:01 - 2015-10-30 08:26 - 00828920 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-02-03 20:01 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-31 12:19 - 2014-08-31 18:56 - 00466456 _____ (Creative Labs) C:\Windows\System32\wrap_oal.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2016-01-31 12:19 - 2014-08-31 18:56 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2016-01-31 01:02 - 2015-12-03 03:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation

==================== Known DLLs (Nicht auf der Ausnahmeliste) =========================

[2015-10-30 08:17] - [2015-10-30 08:17] - 0442720 ____A (Microsoft Corporation) C:\Windows\System32\coml2.dll
[2015-10-30 08:18] - [2015-10-30 08:18] - 0358240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\coml2.dll

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\System32\winlogon.exe
[2016-01-12 20:52] - [2016-01-05 02:43] - 0584704 ____A (Microsoft Corporation) 7B24B823404D53DA4748F21AD2BF04C9

C:\Windows\System32\wininit.exe
[2015-10-30 08:17] - [2015-10-30 08:17] - 0290856 ____A (Microsoft Corporation) CAD491DD9EC00BB841EA407D9C498C4A

C:\Windows\explorer.exe
[2016-02-09 19:52] - [2016-01-29 07:57] - 4502352 ____A (Microsoft Corporation) 95D730526EF81792CD6848D8D10FAA1C

C:\Windows\SysWOW64\explorer.exe
[2016-02-09 19:52] - [2016-01-29 07:33] - 4064320 ____A (Microsoft Corporation) FCBCED2A237DCD7EF86CED551B731742

C:\Windows\System32\svchost.exe
[2015-10-30 08:17] - [2015-10-30 08:17] - 0043944 ____A (Microsoft Corporation) 8497852ED44AFF902D502015792D315D

C:\Windows\SysWOW64\svchost.exe
[2015-10-30 08:18] - [2015-10-30 08:18] - 0037256 ____A (Microsoft Corporation) 6A1212077C0559029CDFB9C39580C835

C:\Windows\System32\services.exe
[2016-01-27 19:53] - [2016-01-16 07:08] - 0440152 ____A (Microsoft Corporation) 6FF8248F3A9D69A095C7F3F42BC29CB2

C:\Windows\System32\User32.dll
[2015-12-11 19:17] - [2015-11-24 11:26] - 1399224 ____A (Microsoft Corporation) DD97EF0AE9224B8C1161736E033C03F1

C:\Windows\SysWOW64\User32.dll
[2015-12-11 19:17] - [2015-11-24 10:26] - 1337240 ____A (Microsoft Corporation) B8C4EFAA6AAED98E6B5AB57CAFA489B9

C:\Windows\System32\userinit.exe
[2015-10-30 08:17] - [2015-10-30 08:17] - 0030720 ____A (Microsoft Corporation) 8F3ECCB5DC878FA14887B43CD148CBA9

C:\Windows\SysWOW64\userinit.exe
[2015-10-30 08:18] - [2015-10-30 08:18] - 0026112 ____A (Microsoft Corporation) A878CF325C93723B5017642E6FDB80E8

C:\Windows\System32\rpcss.dll
[2015-10-30 08:17] - [2015-10-30 08:17] - 0904704 ____A (Microsoft Corporation) B339861C6A2A86FBCA67C2006B461473

C:\Windows\System32\dnsapi.dll
[2015-10-30 08:18] - [2015-10-30 08:18] - 0686984 ____A (Microsoft Corporation) E7B524818100B0FDE2B057C74B0C0DCD

C:\Windows\SysWOW64\dnsapi.dll
[2015-10-30 08:18] - [2015-10-30 08:18] - 0535088 ____A (Microsoft Corporation) 2796C0957F6F05A528DD64B8591371B6

C:\Windows\System32\Drivers\volsnap.sys
[2015-10-30 08:17] - [2015-10-30 08:17] - 0414560 ____A (Microsoft Corporation) E1F91A727A04C9F8199D04FF3BBBF63C


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============


==================== Wiederherstellungspunkte =========================

Wiederherstellungspunkt Datum: 2016-02-25 10:46
Wiederherstellungspunkt Datum: 2016-02-27 14:40
Wiederherstellungspunkt Datum: 2016-02-29 09:57

==================== Speicherinformationen ===========================

Prozentuale Nutzung des RAM: 5%
Installierter physikalischer RAM: 16259.55 MB
Verfügbarer physikalischer RAM: 15289.33 MB
Summe virtueller Speicher: 16259.55 MB
Verfügbarer virtueller Speicher: 15334.24 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:1862.48 GB) (Free:1012.98 GB) NTFS
Drive d: (STORE N GO) (Removable) (Total:3.72 GB) (Free:3.05 GB) FAT32
Drive f: () (Fixed) (Total:0.44 GB) (Free:0.11 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.49 GB) NTFS
Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 462E0839)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000)

Partition: GPT.


LastRegBack: 2016-02-27 10:03

==================== Ende von FRST.txt ============================

Schönen Abend noch.

Gruß Kanso

Larusso 02.03.2016 09:47

Hy. Hab wohl vergessen, auf antworten zu klicken.

Das Problem bei dieser Meldung ist, dass es sehr viele Ursachen haben kann aber Malware sehe ich keine.

Da die Eingabeaufforderung aber im Recovery Modus problemlos läuft, schieb ich den Fehler mal auf Norton :D

[Edit]
Kannst du in der Befehlszeile ( Windows + R Taste ) regedit eingeben -> Enter. Kommt da die selbe Meldung ?
[/Edit ]

Versuche bitte einmal es neu zu installieren.

Kanso 02.03.2016 19:40

Hallo,

also "regedit" klappt ohne Probleme. Ich muss jetzt in die Arbeit, aber ich versuch Norton heute Abend nochmal zu installieren und geb dir dann Bescheid ob es funktioniert hat

Gruß Kanso

Hallo,

so hab grade nochmal die Norton-Installation versucht. Leider immer noch kein Erfolg. Das Problem besteht weiterhin. Noch irgendwelche Ideen was man tun könnte?

Gruß Kanso

Larusso 03.03.2016 09:33

-,-
2 Ideen habe ich noch.

Kannst du bitte Option 1 von hier ausführen ( Bis Schritt 6 )
SFC Command - Run in Windows 10 - Windows 10 Forums

Du musst dazu in den Recovery Mode booten ( wie beim letzten fest scan )

Kanso 04.03.2016 19:51

Hallo Daniel,

sorry hatte gestern keine Zeit. So ich hab das ganze 2 mal durchlaufen lassen und es wurden beide Male Dateien gefunden, die nicht repariert werden konnten. Brauchst du die CBS.log oder soll ich jetzt "Inbox Corruption Repair" probieren wie in deinem Link beschrieben?

Gruß Kanso

Larusso 05.03.2016 08:07

Das System scheint echt was abbekommen zu haben.
Kannst du die CMD.exe jz wieder ausführen ?
Wenn nein, dann folgendes:

Häng mir die CBS Log mal an und führe bitte option 2 von hier aus
DISM - Repair Windows 10 Image - Windows 10 Forums

( Sorry für die Links aber mit Handy solche Anleitungen schreiben ist nicht cool :D )
Hast du ne Windows 10 DVD oder nen USB Stick zur Hand ?

Kanso 05.03.2016 12:42

Hallo Daniel,

das hört sich ja nicht so gut an. Hoffe das lässt sich beheben. CMD.exe kann ich nach wie vor nicht ausführen. Es kommt immer noch die Fehlermeldung.

Hier ist mal das CBS.log:
Code:

2016-03-04 19:13:18, Info                  CBS    TI: --- Initializing Trusted Installer ---
2016-03-04 19:13:19, Info                  CBS    TI: Last boot time: 2016-03-04 19:12:42.495
2016-03-04 19:13:19, Info                  CBS    Starting TrustedInstaller initialization.
2016-03-04 19:13:19, Info                  CBS    Ending TrustedInstaller initialization.
2016-03-04 19:13:19, Info                  CBS    Starting the TrustedInstaller main loop.
2016-03-04 19:13:19, Info                  CBS    TrustedInstaller service starts successfully.
2016-03-04 19:13:19, Info                  CBS    No startup processing required, TrustedInstaller service was not set as autostart
2016-03-04 19:13:19, Info                  CBS    Startup processing thread terminated normally
2016-03-04 19:13:22, Info                  CBS    Starting TiWorker initialization.
2016-03-04 19:13:22, Info                  CBS    Ending TiWorker initialization.
2016-03-04 19:13:22, Info                  CBS    Starting the TiWorker main loop.
2016-03-04 19:13:22, Info                  CBS    TiWorker starts successfully.
2016-03-04 19:13:22, Info                  CBS    Universal Time is: 2016-03-04 18:13:22.176
2016-03-04 19:13:22, Info                  CBS    Loaded Servicing Stack v10.0.10586.0 with Core: C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\cbscore.dll
2016-03-04 19:13:24, Info                  CSI    00000001@2016/3/4:18:13:24.551 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7ffbb22f4699 @0x7ffbb27f1248 @0x7ffbb280150b @0x7ff6d67e2ee0 @0x7ff6d67e38e1 @0x7ffbc2fed533)
2016-03-04 19:13:25, Info                  CBS    NonStart: Set pending store consistency check.
2016-03-04 19:13:25, Info                  CBS    Session: 30504513_2341202592 initialized by client lpksetup, external staging directory: (null)
2016-03-04 19:13:27, Info                  CBS    TI: CBS has queried the current reboot required state: 0
2016-03-04 19:13:27, Info                  CBS    Session: 30504513_2341202592 finalized. Reboot required: no [HRESULT = 0x00000000 - S_OK]
2016-03-04 19:15:21, Info                  CBS    Trusted Installer signaled for shutdown, going to exit.
2016-03-04 19:15:21, Info                  CBS    Trusted Installer is shutting down because: SHUTDOWN_REASON_NOTIFICATION:PRESHUTDOWN
2016-03-04 19:15:21, Info                  CBS    TiWorker signaled for shutdown, going to exit.
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-04 19:15:21, Info                  CBS    Ending the TiWorker main loop.
2016-03-04 19:15:21, Info                  CBS    Starting TiWorker finalization.
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: ManifestCacheFinalize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: ComponentAnalyzerFinalize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: PackageTrackerFinalize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: CoreResourcesUnload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: SessionManagerFinalize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: CapabilityManagerFinalize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: PublicObjectMonitorFinalize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: Enter vCoreInitializeLock
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: WcpUnload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: DrupUnload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: CfgMgr32Unload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: DpxUnload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: SrUnload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: CbsEsdUnload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: CbsTraceInfoUninitialize
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: CbsEventUnregister
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: AppContainerUnload
2016-03-04 19:15:21, Info                  CBS    CbsCoreFinalize: WdsUnload, logging from cbscore will end.
2016-03-04 19:15:21, Info                  CBS    Ending TiWorker finalization.
2016-03-04 19:15:21, Info                  CBS    Ending the TrustedInstaller main loop.
2016-03-04 19:15:21, Info                  CBS    Starting TrustedInstaller finalization.
2016-03-04 19:15:21, Info                  CBS    Ending TrustedInstaller finalization.
2016-03-04 19:42:07, Info                  CBS    TI: --- Initializing Trusted Installer ---
2016-03-04 19:42:07, Info                  CBS    TI: Last boot time: 2016-03-04 19:41:37.494
2016-03-04 19:42:07, Info                  CBS    Starting TrustedInstaller initialization.
2016-03-04 19:42:07, Info                  CBS    Ending TrustedInstaller initialization.
2016-03-04 19:42:07, Info                  CBS    Starting the TrustedInstaller main loop.
2016-03-04 19:42:07, Info                  CBS    TrustedInstaller service starts successfully.
2016-03-04 19:42:07, Info                  CBS    No startup processing required, TrustedInstaller service was not set as autostart
2016-03-04 19:42:07, Info                  CBS    Startup processing thread terminated normally
2016-03-04 19:42:09, Info                  CBS    Starting TiWorker initialization.
2016-03-04 19:42:09, Info                  CBS    Ending TiWorker initialization.
2016-03-04 19:42:09, Info                  CBS    Starting the TiWorker main loop.
2016-03-04 19:42:09, Info                  CBS    TiWorker starts successfully.
2016-03-04 19:42:09, Info                  CBS    Universal Time is: 2016-03-04 18:42:09.578
2016-03-04 19:42:09, Info                  CBS    Loaded Servicing Stack v10.0.10586.0 with Core: C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\cbscore.dll
2016-03-04 19:42:11, Info                  CSI    00000001@2016/3/4:18:42:11.062 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fffe9e64699 @0x7fffea511248 @0x7fffea52150b @0x7ff6a53f2ee0 @0x7ff6a53f38e1 @0x7ffff97ad533)
2016-03-04 19:42:11, Info                  CBS    NonStart: Set pending store consistency check.
2016-03-04 19:42:11, Info                  CBS    Session: 30504517_2421756454 initialized by client lpksetup, external staging directory: (null)
2016-03-04 19:42:12, Info                  CBS    TI: CBS has queried the current reboot required state: 0
2016-03-04 19:42:13, Info                  CBS    Session: 30504517_2421756454 finalized. Reboot required: no [HRESULT = 0x00000000 - S_OK]
2016-03-04 19:44:13, Info                  CBS    Trusted Installer is shutting down because: SHUTDOWN_REASON_AUTOSTOP
2016-03-04 19:44:13, Info                  CBS    TiWorker signaled for shutdown, going to exit.
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-04 19:44:13, Info                  CBS    Ending the TiWorker main loop.
2016-03-04 19:44:13, Info                  CBS    Starting TiWorker finalization.
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: ManifestCacheFinalize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: ComponentAnalyzerFinalize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: PackageTrackerFinalize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: CoreResourcesUnload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: SessionManagerFinalize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: CapabilityManagerFinalize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: PublicObjectMonitorFinalize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: Enter vCoreInitializeLock
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: WcpUnload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: DrupUnload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: CfgMgr32Unload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: DpxUnload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: SrUnload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: CbsEsdUnload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: CbsTraceInfoUninitialize
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: CbsEventUnregister
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: AppContainerUnload
2016-03-04 19:44:13, Info                  CBS    CbsCoreFinalize: WdsUnload, logging from cbscore will end.
2016-03-04 19:44:13, Info                  CBS    Ending TiWorker finalization.
2016-03-04 19:44:13, Info                  CBS    Ending the TrustedInstaller main loop.
2016-03-04 19:44:13, Info                  CBS    Starting TrustedInstaller finalization.
2016-03-04 19:44:13, Info                  CBS    Ending TrustedInstaller finalization.
2016-03-05 11:31:21, Info                  CBS    TI: --- Initializing Trusted Installer ---
2016-03-05 11:31:21, Info                  CBS    TI: Last boot time: 2016-03-05 11:29:14.495
2016-03-05 11:31:21, Info                  CBS    Starting TrustedInstaller initialization.
2016-03-05 11:31:21, Info                  CBS    Ending TrustedInstaller initialization.
2016-03-05 11:31:21, Info                  CBS    Starting the TrustedInstaller main loop.
2016-03-05 11:31:21, Info                  CBS    TrustedInstaller service starts successfully.
2016-03-05 11:31:21, Info                  CBS    No startup processing required, TrustedInstaller service was not set as autostart
2016-03-05 11:31:21, Info                  CBS    Startup processing thread terminated normally
2016-03-05 11:31:22, Info                  CBS    Starting TiWorker initialization.
2016-03-05 11:31:22, Info                  CBS    Ending TiWorker initialization.
2016-03-05 11:31:22, Info                  CBS    Starting the TiWorker main loop.
2016-03-05 11:31:22, Info                  CBS    TiWorker starts successfully.
2016-03-05 11:31:22, Info                  CBS    Universal Time is: 2016-03-05 10:31:22.663
2016-03-05 11:31:22, Info                  CBS    Loaded Servicing Stack v10.0.10586.0 with Core: C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\cbscore.dll
2016-03-05 11:31:22, Info                  CSI    00000001@2016/3/5:10:31:22.679 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7ffcdf334699 @0x7ffcdf651248 @0x7ffcdf66150b @0x7ff6a5302ee0 @0x7ff6a53038e1 @0x7ffd04fdd533)
2016-03-05 11:31:22, Info                  CBS    NonStart: Set pending store consistency check.
2016-03-05 11:31:22, Info                  CBS    Session: 30504650_700869509 initialized by client lpksetup, external staging directory: (null)
2016-03-05 11:31:22, Info                  CBS    TI: CBS has queried the current reboot required state: 0
2016-03-05 11:31:22, Info                  CBS    Session: 30504650_700869509 finalized. Reboot required: no [HRESULT = 0x00000000 - S_OK]
2016-03-05 11:33:22, Info                  CBS    Trusted Installer is shutting down because: SHUTDOWN_REASON_AUTOSTOP
2016-03-05 11:33:22, Info                  CBS    TiWorker signaled for shutdown, going to exit.
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-05 11:33:22, Info                  CBS    Ending the TiWorker main loop.
2016-03-05 11:33:22, Info                  CBS    Starting TiWorker finalization.
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: ManifestCacheFinalize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: ComponentAnalyzerFinalize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: PackageTrackerFinalize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: CoreResourcesUnload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: SessionManagerFinalize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: CapabilityManagerFinalize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: PublicObjectMonitorFinalize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: Enter vCoreInitializeLock
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: WcpUnload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: DrupUnload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: CfgMgr32Unload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: DpxUnload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: SrUnload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: CbsEsdUnload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: CbsTraceInfoUninitialize
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: CbsEventUnregister
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: AppContainerUnload
2016-03-05 11:33:22, Info                  CBS    CbsCoreFinalize: WdsUnload, logging from cbscore will end.
2016-03-05 11:33:22, Info                  CBS    Ending TiWorker finalization.
2016-03-05 11:33:22, Info                  CBS    Ending the TrustedInstaller main loop.
2016-03-05 11:33:22, Info                  CBS    Starting TrustedInstaller finalization.
2016-03-05 11:33:22, Info                  CBS    Ending TrustedInstaller finalization.
2016-03-05 11:40:58, Info                  CBS    TI: --- Initializing Trusted Installer ---
2016-03-05 11:40:58, Info                  CBS    TI: Last boot time: 2016-03-05 11:29:14.495
2016-03-05 11:40:58, Info                  CBS    Starting TrustedInstaller initialization.
2016-03-05 11:40:58, Info                  CBS    Ending TrustedInstaller initialization.
2016-03-05 11:40:58, Info                  CBS    Starting the TrustedInstaller main loop.
2016-03-05 11:40:58, Info                  CBS    TrustedInstaller service starts successfully.
2016-03-05 11:40:58, Info                  CBS    No startup processing required, TrustedInstaller service was not set as autostart
2016-03-05 11:40:58, Info                  CBS    Startup processing thread terminated normally
2016-03-05 11:41:02, Info                  CBS    Starting TiWorker initialization.
2016-03-05 11:41:02, Info                  CBS    Ending TiWorker initialization.
2016-03-05 11:41:02, Info                  CBS    Starting the TiWorker main loop.
2016-03-05 11:41:02, Info                  CBS    TiWorker starts successfully.
2016-03-05 11:41:02, Info                  CBS    Universal Time is: 2016-03-05 10:41:02.307
2016-03-05 11:41:02, Info                  CBS    Loaded Servicing Stack v10.0.10586.0 with Core: C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\cbscore.dll
2016-03-05 11:41:02, Info                  CSI    00000001@2016/3/5:10:41:02.307 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7ffcda574699 @0x7ffcda921248 @0x7ffcda93150b @0x7ff6a5302ee0 @0x7ff6a53038e1 @0x7ffd04fdd533)
2016-03-05 11:41:02, Info                  CBS    NonStart: Set pending store consistency check.
2016-03-05 11:41:02, Info                  CBS    Session: 30504651_2202182295 initialized by client DISM Package Manager Provider, external staging directory: (null)
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Microsoft-Windows-Client-LanguagePack-Package~31bf3856ad364e35~amd64~de-DE~10.0.10586.0, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-Client-LanguagePack-Package~31bf3856ad364e35~amd64~de-DE~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-Client-LanguagePack-Package~31bf3856ad364e35~amd64~de-DE~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-DiagTrack-Internal-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-DiagTrack-Internal-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-LanguageFeatures-Basic-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-LanguageFeatures-Basic-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-LanguageFeatures-Basic-en-us-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-LanguageFeatures-Basic-en-us-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-LanguageFeatures-Handwriting-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-LanguageFeatures-Handwriting-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-LanguageFeatures-OCR-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-LanguageFeatures-OCR-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-LanguageFeatures-Speech-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-LanguageFeatures-Speech-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-LanguageFeatures-TextToSpeech-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-LanguageFeatures-TextToSpeech-de-de-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Microsoft-Windows-NetFx3-OnDemand-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.0.0, Disposition = Detect, VersionComp: EQ, BuildComp: GE, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent: parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.10586.0, state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-NetFx3-OnDemand-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-NetFx3-OnDemand-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Microsoft-Windows-Prerelease-Client-Package~31bf3856ad364e35~amd64~de-DE~10.0.10586.0, Parent: Microsoft-Windows-Prerelease-Client-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-Prerelease-Client-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-Prerelease-Client-Package~31bf3856ad364e35~amd64~de-DE~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-Prerelease-Client-Package~31bf3856ad364e35~amd64~de-DE~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-Prerelease-Client-Package~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-Prerelease-Client-Package~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3116900~31bf3856ad364e35~amd64~~10.0.1.2, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3116908~31bf3856ad364e35~amd64~~10.0.1.1, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3120677~31bf3856ad364e35~amd64~~10.0.1.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3124200~31bf3856ad364e35~amd64~~10.0.1.3, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-OEM-Drivers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-OEM-Drivers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-Storage-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Storage-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3124262~31bf3856ad364e35~amd64~~10.0.1.5, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-NanoServer-Storage-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Storage-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3124263~31bf3856ad364e35~amd64~~10.0.1.5, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Compute-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Containers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-DNS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-FailoverCluster-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-NPDS-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-OEM-Drivers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-OEM-Drivers-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-NanoServer-Storage-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-NanoServer-Storage-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreCountrySpecificEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSingleLanguageEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-CoreSystemServerEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EducationNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Staged
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-EnterpriseNEvalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-PPIProEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Absent
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Microsoft-Windows-ProfessionalEdition~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3135173~31bf3856ad364e35~amd64~~10.0.1.2, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:41:02, Info                  CBS    Appl: detect Parent, Package: Package_for_KB3135782~31bf3856ad364e35~amd64~~10.0.1.0, Parent: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~10.0.10586.0, Disposition = Detect, VersionComp: EQ, BuildComp: EQ, RevisionComp: EQ, Exist: present
2016-03-05 11:41:02, Info                  CBS    Appl: detectParent (exact match): Parent: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~10.0.10586.0, parent state: Installed
2016-03-05 11:41:02, Info                  CBS    Appl: Evaluating package applicability for package Package_for_KB3135782~31bf3856ad364e35~amd64~~10.0.1.0, applicable state: Installed
2016-03-05 11:41:02, Info                  CBS    External EvaluateApplicability, package: Package_for_KB3135782~31bf3856ad364e35~amd64~~10.0.1.0, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed
2016-03-05 11:55:00, Info                  CBS    Trusted Installer is shutting down because: SHUTDOWN_REASON_AUTOSTOP
2016-03-05 11:55:00, Info                  CBS    TiWorker signaled for shutdown, going to exit.
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-05 11:55:00, Info                  CBS    Ending the TiWorker main loop.
2016-03-05 11:55:00, Info                  CBS    Starting TiWorker finalization.
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: ManifestCacheFinalize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: ExecutionEngineFinalize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: ComponentAnalyzerFinalize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: PackageTrackerFinalize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: CoreResourcesUnload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: SessionManagerFinalize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: CapabilityManagerFinalize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: PublicObjectMonitorFinalize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: Enter vCoreInitializeLock
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: WcpUnload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: DrupUnload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: CfgMgr32Unload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: DpxUnload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: SrUnload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: CbsEsdUnload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: CbsTraceInfoUninitialize
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: CbsEventUnregister
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: AppContainerUnload
2016-03-05 11:55:00, Info                  CBS    CbsCoreFinalize: WdsUnload, logging from cbscore will end.
2016-03-05 11:55:00, Info                  CBS    Ending TiWorker finalization.
2016-03-05 11:55:00, Info                  CBS    Ending the TrustedInstaller main loop.
2016-03-05 11:55:00, Info                  CBS    Starting TrustedInstaller finalization.
2016-03-05 11:55:00, Info                  CBS    Ending TrustedInstaller finalization.

Ne Windows 10 CD hab ich keine. Habe das Upgrade von Windows 7 auf Windows 10 gemacht und das ging ohne CD. Einen USB-Stick habe ich. Hab kein Problem damit, dass du mir Links schickst. Muss man sich halt genau durchlesen. Ich werde das heute Abend mal versuchen. Bin ja schon froh, dass mir jemand hilft der Ahnung hat und ich meinen PC nicht in die Obhut eines Norton-Technikers geben muss der wahrscheinlich mehr kaputt macht als er rettet.

Gruß Kanso

Hallo,

habs doch grade ausprobiert weil ich noch etwas Zeit hatte. Ich kann Windows Powershell nicht ausführen. Es erscheint die gleiche Fehlermeldung wie bei CMD.exe. Soll ich Option 1 mal probieren?

Gruß Kanso

Larusso 05.03.2016 13:12

Hy.

Ich sehe, dass du einen Wiederherstellungspunkt vom 22.2 hast. Wann hat denn der Norton Pfuscher an deinem Rechner gearbeitet ?

Kanso 05.03.2016 13:34

Hallo Daniel,

das war auf jeden Fall nach dem 22.02. aber als er an meinem PC rumprobiert hat, ging die CMB.exe auch schon nicht. Hat er glaub ich mehrmal ausprobiert. Ich kann zwar versuchen das System wiederherzustellen, glaube aber nicht, dass es was bringen wird.

Gruß Kanso

Larusso 05.03.2016 13:38

Ne ist gut. Versuchen wir mal was anderes.

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:

cmd: sfc /scannow
cmd: Dism /Online /Cleanup-Image /RestoreHealth


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Note, das kann ne Weile dauern.

Kanso 05.03.2016 13:48

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016
durchgeführt von Admin (2016-03-05 13:46:26) Run:2
Gestartet von C:\Users\Admin\Desktop
Geladene Profile: Admin (Verfügbare Profile: Admin & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
cmd: sfc /scannow
cmd: Dism /Online /Cleanup-Image /RestoreHealth
*****************


=========  sfc /scannow =========


========= Ende von CMD: =========


=========  Dism /Online /Cleanup-Image /RestoreHealth =========


========= Ende von CMD: =========


==== Ende von Fixlog 13:46:32 ====

Gruß Kanso

Larusso 05.03.2016 13:54

Ich bekomm bald nen Anfall :D

Starte bitte FRST und gib folgendes in die Suchleiste ein

cmd.*

und klicke auf Dateisuche. Poste die Logfile bitte hier.

Kanso 05.03.2016 14:03

Kann ich verstehen :rolleyes:

Code:

Farbar Recovery Scan Tool (x64) Version:05-03-2016
durchgeführt von Admin (2016-03-05 13:57:29)
Gestartet von C:\Users\Admin\Desktop
Start-Modus: Normal

================== Datei-Suche: "cmd.*" =============

C:\Windows\WinSxS\wow64_microsoft-windows-commandprompt_31bf3856ad364e35_10.0.10586.0_none_21e70967f9147e9b\cmd.exe
[2015-10-30 08:18][2015-10-30 08:18] 0202240 ____A (Microsoft Corporation) 7DB6A5CEEAC1CB15CF78552794B3DB31 [Datei ist digital signiert]

C:\Windows\WinSxS\wow64_microsoft-windows-c..andprompt.resources_31bf3856ad364e35_10.0.10586.0_de-de_6d6b4aea81c41c73\cmd.exe.mui
[2015-10-30 19:34][2015-10-30 19:34] 0148992 ____A (Microsoft Corporation) 3CDBFF7D12523CD4A07C6A13F1A04929 [Datei ist digital signiert]

C:\Windows\WinSxS\amd64_microsoft-windows-commandprompt_31bf3856ad364e35_10.0.10586.0_none_17925f15c4b3bca0\cmd.exe
[2015-10-30 08:17][2015-10-30 08:17] 0233984 ____A (Microsoft Corporation) 41E25E514D90E9C8BC570484DBAFF62B [Datei ist digital signiert]

C:\Windows\WinSxS\amd64_microsoft-windows-c..andprompt.resources_31bf3856ad364e35_10.0.10586.0_de-de_6316a0984d635a78\cmd.exe.mui
[2015-10-30 19:33][2015-10-30 19:33] 0148992 ____A (Microsoft Corporation) 8534F98A2AF27705FAA6B6F44B13E0FD [Datei ist digital signiert]

C:\Windows\SysWOW64\cmd.exe
[2015-10-30 08:18][2015-10-30 08:18] 0202240 ____A (Microsoft Corporation) 7DB6A5CEEAC1CB15CF78552794B3DB31 [Datei ist digital signiert]

C:\Windows\SysWOW64\de-DE\cmd.exe.mui
[2015-10-30 19:34][2015-10-30 19:34] 0148992 ____A (Microsoft Corporation) 3CDBFF7D12523CD4A07C6A13F1A04929 [Datei ist digital signiert]

C:\Windows\System32\cmd.exe
[2015-10-30 08:17][2015-10-30 08:17] 0233984 ____A (Microsoft Corporation) 41E25E514D90E9C8BC570484DBAFF62B [Datei ist digital signiert]

C:\Windows\System32\de-DE\cmd.exe.mui
[2015-10-30 19:33][2015-10-30 19:33] 0148992 ____A (Microsoft Corporation) 8534F98A2AF27705FAA6B6F44B13E0FD [Datei ist digital signiert]

C:\Windows\Prefetch\CMD.EXE-4A81B364.pf
[2016-03-03 19:34][2016-03-05 13:46] 0001202 ____A () C36A9E7D73CD01174040EB2A4BE9BB39 [Datei ist nicht signiert]

C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization IV\Assets\Python\System\cmd.pyc
[2015-12-26 03:54][2015-12-26 03:54] 0013847 ____A () 83D03A070CE0B7BA25FE935F96ABEF1F [Datei ist nicht signiert]

C:\$RECYCLE.BIN\S-1-5-21-988284940-210793992-766847566-1000\$RBZBLLG\files\regfiles\file_associations\xp\cmd.reg
[2016-02-28 15:18][2012-11-13 21:47] 0002094 ____A () 8420F169D31F352EBB6B99121A0C45DA [Datei ist nicht signiert]

C:\$RECYCLE.BIN\S-1-5-21-988284940-210793992-766847566-1000\$RBZBLLG\files\regfiles\file_associations\vista\cmd.reg
[2016-02-28 15:18][2012-11-13 21:47] 0002742 ____A () A69E3FD4F0DC75035EC4103A961EFFC8 [Datei ist nicht signiert]

C:\$RECYCLE.BIN\S-1-5-21-988284940-210793992-766847566-1000\$RBZBLLG\files\regfiles\file_associations\8.1\cmd.reg
[2016-02-28 15:18][2012-11-13 21:33] 0003203 ____A () 32979EBBBFBCF35A3F06340BBC1F315A [Datei ist nicht signiert]

C:\$RECYCLE.BIN\S-1-5-21-988284940-210793992-766847566-1000\$RBZBLLG\files\regfiles\file_associations\8\cmd.reg
[2016-02-28 15:18][2012-11-13 21:33] 0003203 ____A () 32979EBBBFBCF35A3F06340BBC1F315A [Datei ist nicht signiert]

C:\$RECYCLE.BIN\S-1-5-21-988284940-210793992-766847566-1000\$RBZBLLG\files\regfiles\file_associations\7\cmd.reg
[2016-02-28 15:18][2012-11-13 21:33] 0003203 ____A () 32979EBBBFBCF35A3F06340BBC1F315A [Datei ist nicht signiert]

C:\$RECYCLE.BIN\S-1-5-21-988284940-210793992-766847566-1000\$RBZBLLG\files\regfiles\file_associations\10\cmd.reg
[2016-02-28 15:18][2015-07-28 14:11] 0006466 ____A () 462B404ED301956F99E60BA831876481 [Datei ist nicht signiert]

====== Ende von Suche ======

Gruß Kanso

Larusso 05.03.2016 14:38

Drücke mal die Windows + R Taste und kopiere folgende Zeile und drücke Enter
Code:

C:\Windows\WinSxS\amd64_microsoft-windows-commandprompt_31bf3856ad364e35_10.0.10586.0_none_17925f15c4b3bca0\cmd.exe
Startet diese Datei ?

Kanso 05.03.2016 14:44

Nein startet leider nicht. :lmaa:

Gruß Kanso

Larusso 05.03.2016 15:06

Okay, dann eben den Vorschlaghammer => Inplace Upgrade.

Repair Install Windows 10 with an In-place Upgrade - Windows 10 Forums

Lies dir die Anleitung bitte erst vollständig durch. Wenn was unklar ist, frage vorher nach.

Kanso 07.03.2016 13:09

Hey Daniel,

ok wenn ich das richtig verstehe ging damals was bei dem Upgrade auf Windows 10 schief. Mittlerweile hab ich das gefühl, dass immer weniger funktioniert. Kann nicht mal mehr meinen Grafiktreiber aktualisieren. Ich hatte die letzten Tage leider keine Zeit und werde das mal heute Abend versuchen. Wird schon schief gehen. Welchen Step ich nehme (Step 4-7) ist im Prinzip egal oder?

Gruß Kanso

Larusso 07.03.2016 18:18

Hy
Ich würde nen USB Stick erstellen aber grundsätzlich egal. Mit nem Media Creation Tool hab ich das noch nie gemacht, rate daher davon ab.

Kanso 07.03.2016 20:29

Hallo,

habe es gerade durchlaufen lassen und ist auch alles soweit durchgelaufen. Muss nur noch die Datenträgerbereinigung durchführen. Was ist jetzt der nächste Schritt? Soll ich nochmal versuchen Norton zu installieren?

Also hab noch ein paar Dinge probiert und die Eingabeaufforderung funktioniert jetzt zumindest wieder und es erscheint keine Fehlermeldung mehr.

Gruß Kanso

Larusso 07.03.2016 21:48

:daumenhoc

Lass bitte Windows Repair nochmal im abgesicherten Modus laufen und poste danach eine neue Frst logfile :)

Kanso 07.03.2016 22:16

Beziehst du dich mit "Windows Repair" auf Post #11 oder #21 von dir? Ich frag zu Sicherheit nochmal nach, bevor ich was falsch mach.

Larusso 08.03.2016 07:48

Fragen ist nie falsch :)

Ich meine natürlich das Tool aus post 11. sorry

Kanso 11.03.2016 21:18

Hallo Daniel,

sorry hat ein wenig länger gedauert. Hatte viel um die Ohren die letzten Tage. Also ich hab Windows Repair komplett durchlaufen lassen und hier ist die neuste FRST Logfile:

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016
durchgeführt von Admin (Administrator) auf ADMIN-PC (11-03-2016 21:06:18)
Gestartet von C:\Users\Admin\Desktop
Geladene Profile: Admin (Verfügbare Profile: Admin & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Users\Admin\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [402344 2015-12-19] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-01-31] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-03-12] (Intel Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-16] (InstallShield Software Corporation)
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
HKU\S-1-5-21-988284940-210793992-766847566-1000\...\Run: [Norton Download Manager{N3602250124-SHPD-ESD-FSD51083}] => C:\Users\Public\Downloads\Norton\{N3602250124-SHPD-ESD-FSD51083}\FSDUI_Custom.exe /m /SHOWONECLICK /WIN10_UPGRADE "C:\Users\Admin\AppData\Local\Temp\{00630E4B-1451-412F-B611-CE163CC1A321}\Upgrade.exe" <===== ACHTUNG
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK-Konfigurationstool.lnk [2014-02-28]
ShortcutTarget: TP-LINK-Konfigurationstool.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK-Konfigurationstool\TWCU.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{38fa8d64-1429-4eb3-94d0-479866b2cb77}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{963c500a-6b9d-4d7e-bd5c-92f4985dcea0}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\S-1-5-21-988284940-210793992-766847566-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-988284940-210793992-766847566-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-988284940-210793992-766847566-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.de/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll => Keine Datei
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll => Keine Datei

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-15] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2011-04-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2015-06-19] (Pando Networks)
FF Plugin HKU\S-1-5-21-988284940-210793992-766847566-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-988284940-210793992-766847566-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-09-10] ()
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\searchplugins\safesearch.xml [2015-06-25]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\adblockpopups@jessehakanen.net.xpi [2015-05-29]
FF Extension: NoScript - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-02-12]
FF Extension: WOT - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-12-09]
FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\sxq420uz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-31] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6435896 2016-03-06] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373160 2015-12-19] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2014-06-19] ()
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [3870464 2015-10-01] (Realtek Semiconductor Corporation                          )
R3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation)
R3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation)
R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation)
R3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-03-11 21:06 - 2016-03-11 21:06 - 00015256 _____ C:\Users\Admin\Desktop\FRST.txt
2016-03-11 08:38 - 2016-03-11 08:39 - 00412060 _____ C:\WINDOWS\Minidump\031116-55562-01.dmp
2016-03-10 10:54 - 2016-03-10 10:54 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-03-09 08:54 - 2016-03-09 08:54 - 00412036 _____ C:\WINDOWS\Minidump\030916-36046-01.dmp
2016-03-08 20:47 - 2016-02-24 10:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-03-08 20:47 - 2016-02-24 06:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-08 20:47 - 2016-02-24 06:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-08 20:47 - 2016-02-24 06:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-08 20:47 - 2016-02-24 06:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-08 20:47 - 2016-02-24 06:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-08 20:46 - 2016-03-01 06:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-03-08 20:46 - 2016-03-01 06:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-03-08 20:46 - 2016-02-24 10:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-03-08 20:46 - 2016-02-24 10:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-08 20:46 - 2016-02-24 10:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-03-08 20:46 - 2016-02-24 10:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-08 20:46 - 2016-02-24 10:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-03-08 20:46 - 2016-02-24 10:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-08 20:46 - 2016-02-24 10:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-03-08 20:46 - 2016-02-24 09:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-08 20:46 - 2016-02-24 09:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2016-03-08 20:46 - 2016-02-24 09:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-08 20:46 - 2016-02-24 09:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-03-08 20:46 - 2016-02-24 09:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-03-08 20:46 - 2016-02-24 09:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-03-08 20:46 - 2016-02-24 09:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-03-08 20:46 - 2016-02-24 09:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2016-03-08 20:46 - 2016-02-24 09:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-08 20:46 - 2016-02-24 09:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-08 20:46 - 2016-02-24 09:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-03-08 20:46 - 2016-02-24 09:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-08 20:46 - 2016-02-24 09:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-03-08 20:46 - 2016-02-24 09:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-03-08 20:46 - 2016-02-24 09:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-03-08 20:46 - 2016-02-24 09:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-08 20:46 - 2016-02-24 09:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-08 20:46 - 2016-02-24 09:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-03-08 20:46 - 2016-02-24 09:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-08 20:46 - 2016-02-24 09:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-08 20:46 - 2016-02-24 09:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-03-08 20:46 - 2016-02-24 08:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-03-08 20:46 - 2016-02-24 08:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-08 20:46 - 2016-02-24 08:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-08 20:46 - 2016-02-24 08:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-03-08 20:46 - 2016-02-24 08:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-08 20:46 - 2016-02-24 08:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-08 20:46 - 2016-02-24 08:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-08 20:46 - 2016-02-24 08:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-08 20:46 - 2016-02-24 08:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-03-08 20:46 - 2016-02-24 08:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-08 20:46 - 2016-02-24 08:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-08 20:46 - 2016-02-24 08:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-08 20:46 - 2016-02-24 08:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-08 20:46 - 2016-02-24 08:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-03-08 20:46 - 2016-02-24 08:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2016-03-08 20:46 - 2016-02-24 08:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-03-08 20:46 - 2016-02-24 08:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-08 20:46 - 2016-02-24 08:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-08 20:46 - 2016-02-24 08:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-08 20:46 - 2016-02-24 08:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-03-08 20:46 - 2016-02-24 08:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-03-08 20:46 - 2016-02-24 08:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-08 20:46 - 2016-02-24 08:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2016-03-08 20:46 - 2016-02-24 08:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-08 20:46 - 2016-02-24 08:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-08 20:46 - 2016-02-24 08:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-03-08 20:46 - 2016-02-24 08:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-08 20:46 - 2016-02-24 08:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2016-03-08 20:46 - 2016-02-24 08:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-08 20:46 - 2016-02-24 08:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-03-08 20:46 - 2016-02-24 08:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-08 20:46 - 2016-02-24 08:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2016-03-08 20:46 - 2016-02-24 08:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-08 20:46 - 2016-02-24 08:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-03-08 20:46 - 2016-02-24 08:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-08 20:46 - 2016-02-24 08:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-08 20:46 - 2016-02-24 08:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-08 20:46 - 2016-02-24 08:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-03-08 20:46 - 2016-02-24 08:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2016-03-08 20:46 - 2016-02-24 08:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-08 20:46 - 2016-02-24 07:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-08 20:46 - 2016-02-24 07:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2016-03-08 20:46 - 2016-02-24 07:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-03-08 20:46 - 2016-02-24 07:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-08 20:46 - 2016-02-24 07:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-03-08 20:46 - 2016-02-24 07:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-08 20:46 - 2016-02-24 07:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-03-08 20:46 - 2016-02-24 07:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2016-03-08 20:46 - 2016-02-24 07:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2016-03-08 20:46 - 2016-02-24 07:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-08 20:46 - 2016-02-24 07:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-08 20:46 - 2016-02-24 07:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-03-08 20:46 - 2016-02-24 07:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-03-08 20:46 - 2016-02-24 07:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-08 20:46 - 2016-02-24 07:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-08 20:46 - 2016-02-24 07:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-08 20:46 - 2016-02-24 07:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-03-08 20:46 - 2016-02-24 07:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-03-08 20:46 - 2016-02-24 07:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2016-03-08 20:46 - 2016-02-24 07:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-03-08 20:46 - 2016-02-24 07:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-08 20:46 - 2016-02-24 07:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-03-08 20:46 - 2016-02-24 07:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-03-08 20:46 - 2016-02-24 07:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-03-08 20:46 - 2016-02-24 07:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-03-08 20:46 - 2016-02-24 07:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-03-08 20:46 - 2016-02-24 07:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-08 20:46 - 2016-02-24 07:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2016-03-08 20:46 - 2016-02-24 07:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-08 20:46 - 2016-02-24 07:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-08 20:46 - 2016-02-24 07:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-03-08 20:46 - 2016-02-24 07:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2016-03-08 20:46 - 2016-02-24 07:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-03-08 20:46 - 2016-02-24 07:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-08 20:46 - 2016-02-24 07:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-03-08 20:46 - 2016-02-24 07:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-08 20:46 - 2016-02-24 07:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-03-08 20:46 - 2016-02-24 07:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-03-08 20:46 - 2016-02-24 07:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2016-03-08 20:46 - 2016-02-24 07:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2016-03-08 20:46 - 2016-02-24 07:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-03-08 20:46 - 2016-02-24 07:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-03-08 20:46 - 2016-02-24 07:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2016-03-08 20:46 - 2016-02-24 07:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-08 20:46 - 2016-02-24 07:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2016-03-08 20:46 - 2016-02-24 07:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2016-03-08 20:46 - 2016-02-24 07:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-08 20:46 - 2016-02-24 07:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-03-08 20:46 - 2016-02-24 07:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-03-08 20:46 - 2016-02-24 07:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-03-08 20:46 - 2016-02-24 07:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2016-03-08 20:46 - 2016-02-24 07:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2016-03-08 20:46 - 2016-02-24 07:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-08 20:46 - 2016-02-24 07:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-03-08 20:46 - 2016-02-24 07:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-08 20:46 - 2016-02-24 07:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-03-08 20:46 - 2016-02-24 07:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-03-08 20:46 - 2016-02-24 07:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-03-08 20:46 - 2016-02-24 07:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2016-03-08 20:46 - 2016-02-24 07:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2016-03-08 20:46 - 2016-02-24 07:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-03-08 20:46 - 2016-02-24 07:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-03-08 20:46 - 2016-02-24 07:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-08 20:46 - 2016-02-24 07:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-03-08 20:46 - 2016-02-24 07:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-08 20:46 - 2016-02-24 07:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-08 20:46 - 2016-02-24 07:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-03-08 20:46 - 2016-02-24 06:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-08 20:46 - 2016-02-24 06:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-08 20:46 - 2016-02-24 06:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2016-03-08 20:46 - 2016-02-24 06:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-03-08 20:46 - 2016-02-24 06:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2016-03-08 20:46 - 2016-02-24 06:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-08 20:46 - 2016-02-24 06:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-08 20:46 - 2016-02-24 06:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-08 20:46 - 2016-02-24 05:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-08 20:46 - 2016-02-24 05:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-08 08:13 - 2016-03-11 08:38 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-08 08:13 - 2016-03-08 08:13 - 00370124 _____ C:\WINDOWS\Minidump\030816-29859-01.dmp
2016-03-07 19:27 - 2016-03-07 19:27 - 00000020 ___SH C:\Users\Admin\ntuser.ini
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Vorlagen
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Startmenü
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2016-03-07 19:27 - 2016-03-07 19:27 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2016-03-07 19:22 - 2016-03-11 21:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-07 19:15 - 2016-03-07 19:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-03-07 19:15 - 2016-03-07 19:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-03-07 19:13 - 2016-03-07 19:13 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2016-03-07 19:12 - 2016-03-07 19:15 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-03-07 19:10 - 2016-03-07 19:27 - 00000000 ____D C:\Users\Admin
2016-03-07 19:10 - 2016-03-07 19:19 - 00000000 ____D C:\Users\DefaultAppPool
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Vorlagen
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Startmenü
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Netzwerkumgebung
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Lokale Einstellungen
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Eigene Dateien
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Druckumgebung
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Documents\Eigene Videos
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Documents\Eigene Musik
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Documents\Eigene Bilder
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\AppData\Local\Verlauf
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\AppData\Local\Anwendungsdaten
2016-03-07 19:10 - 2016-03-07 19:10 - 00000000 _SHDL C:\Users\Admin\Anwendungsdaten
2016-03-07 19:09 - 2016-03-11 21:06 - 01860414 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-07 19:09 - 2016-03-07 19:21 - 02111952 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-03-07 19:06 - 2016-03-11 21:01 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-07 19:06 - 2016-03-07 19:13 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-07 19:06 - 2016-03-07 19:13 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-07 19:06 - 2016-03-07 19:13 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-07 19:06 - 2016-02-09 06:29 - 06368824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-03-07 19:06 - 2016-02-09 06:29 - 02992064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-03-07 19:06 - 2016-02-09 06:29 - 02561472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-03-07 19:06 - 2016-02-09 06:29 - 01263040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-03-07 19:06 - 2016-02-09 06:29 - 00530368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-03-07 19:06 - 2016-02-09 06:29 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-03-07 19:06 - 2016-02-09 06:29 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-07 19:06 - 2016-02-09 06:29 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-03-07 19:06 - 2016-02-06 15:58 - 06154909 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-03-07 19:05 - 2016-03-11 21:02 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-03-07 19:05 - 2016-03-07 19:13 - 00000000 ____D C:\Program Files\Intel
2016-03-07 19:05 - 2016-03-07 19:05 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-03-07 19:05 - 2016-03-07 19:05 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-03-07 19:05 - 2016-03-07 19:05 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-03-07 19:05 - 2016-03-07 19:05 - 00000000 ____D C:\Program Files\Realtek
2016-03-07 19:05 - 2015-12-19 01:08 - 00099848 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2016-03-07 19:03 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-03-07 19:00 - 2016-03-11 20:57 - 00202776 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-07 18:59 - 2016-03-08 00:00 - 00000000 ___DC C:\WINDOWS\Panther
2016-03-07 18:57 - 2016-03-07 20:03 - 00000000 ____D C:\Windows.old
2016-03-07 18:56 - 2016-03-07 18:56 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-03-07 18:56 - 2016-03-07 18:56 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-03-07 18:56 - 2016-03-07 18:56 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-03-07 18:56 - 2016-03-07 18:56 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-03-07 18:56 - 2016-03-07 18:56 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-07 18:56 - 2016-03-07 18:56 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-03-07 18:56 - 2016-03-07 18:56 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-03-07 18:56 - 2016-03-07 18:56 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2016-03-07 18:56 - 2016-03-07 18:56 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2016-03-07 18:56 - 2016-03-07 18:56 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll


Kanso 11.03.2016 21:19

Code:

2016-03-07 18:56 - 2016-03-07 18:56 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2016-03-07 18:56 - 2016-03-07 18:56 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2016-03-07 18:56 - 2016-03-07 18:56 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2016-03-07 18:56 - 2016-03-07 18:56 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2016-03-07 18:56 - 2016-03-07 18:56 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2016-03-07 18:56 - 2016-03-07 18:56 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
2016-03-07 18:56 - 2016-03-07 18:56 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-03-07 18:56 - 2016-03-07 18:56 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-03-07 18:56 - 2016-03-07 18:56 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-03-07 18:56 - 2016-03-07 18:56 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2016-03-07 18:53 - 2015-10-29 19:43 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2016-03-07 18:53 - 2015-10-29 19:43 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2016-03-07 18:53 - 2015-10-29 19:41 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2016-03-07 18:53 - 2015-10-29 19:25 - 06359040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2016-03-07 18:53 - 2015-10-29 19:24 - 04847616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2016-03-07 18:52 - 2016-03-07 18:52 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\WINDOWS\system32\msmq
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\Program Files\MSBuild
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-03-07 18:50 - 2016-03-07 18:50 - 00000000 ____D C:\inetpub
2016-03-07 18:50 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-03-07 18:50 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-03-07 18:50 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-03-07 18:49 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-03-07 18:49 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-03-07 18:49 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-03-07 18:19 - 2016-03-07 18:19 - 00000000 ____D C:\ESD
2016-03-07 18:09 - 2016-03-07 18:09 - 00000000 ___HD C:\$Windows.~WS
2016-03-02 19:29 - 2016-03-02 19:35 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-02-29 20:38 - 2016-02-29 20:38 - 00000000 ____D C:\Users\Admin\Desktop\2011-04-21
2016-02-28 16:42 - 2016-02-28 16:42 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-ADMIN-PC-Windows-10-Pro-(64-bit).dat
2016-02-28 16:42 - 2016-02-28 16:42 - 00000000 ____D C:\RegBackup
2016-02-28 13:17 - 2016-02-28 13:17 - 02870984 _____ (ESET) C:\Users\Admin\Desktop\esetsmartinstaller_deu.exe
2016-02-28 13:17 - 2016-02-28 13:17 - 00000000 ____D C:\Program Files (x86)\ESET
2016-02-27 12:05 - 2016-03-05 13:46 - 02374144 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2016-02-27 11:53 - 2016-02-27 14:36 - 00078252 _____ C:\TDSSKiller.3.1.0.9_27.02.2016_11.53.57_log.txt
2016-02-27 11:52 - 2016-02-27 11:53 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\Admin\Desktop\tdsskiller.exe
2016-02-26 09:35 - 2016-03-11 21:06 - 00000000 ____D C:\FRST
2016-02-26 05:36 - 2016-03-11 21:03 - 00001394 _____ C:\Users\Admin\Desktop\Norton-Installationsdateien.lnk
2016-02-26 05:35 - 2016-02-26 05:36 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader(2).exe
2016-02-26 05:30 - 2016-02-26 19:27 - 00364004 _____ C:\WINDOWS\ntbtlog.txt
2016-02-26 05:28 - 2016-02-26 05:28 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (2).exe
2016-02-25 11:37 - 2016-02-25 11:37 - 00000432 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp.bat
2016-02-25 11:37 - 2016-02-25 11:37 - 00000357 _____ C:\Users\Admin\AppData\Local\LMIR0001.tmp_r.bat
2016-02-25 11:33 - 2016-02-25 11:36 - 00000000 ____D C:\Program Files (x86)\LogMeIn Rescue RC - 0bfdcd33-f52c-4b3b-a4a7-71770fabb626
2016-02-25 11:28 - 2016-03-11 21:04 - 00000000 ____D C:\ProgramData\Norton
2016-02-25 11:28 - 2016-03-02 19:32 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-02-25 11:15 - 2016-02-25 11:15 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE (1).exe
2016-02-25 11:13 - 2016-02-25 11:13 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool(1).exe
2016-02-25 10:48 - 2016-02-25 10:48 - 00000000 __SHD C:\found.000
2016-02-25 10:29 - 2016-03-11 20:59 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-25 10:28 - 2016-02-25 10:28 - 00000000 ____D C:\WINDOWS\pss
2016-02-25 10:07 - 2016-02-26 05:31 - 00000000 ____D C:\NPE
2016-02-25 10:05 - 2016-02-26 05:33 - 00000000 ____D C:\Users\Admin\AppData\Local\NPE
2016-02-25 10:05 - 2016-02-25 10:05 - 10079720 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NPE.exe
2016-02-25 10:02 - 2016-02-25 10:02 - 01110464 _____ (Symantec Corporation) C:\Users\Admin\Downloads\NSDownloader (1).exe
2016-02-25 09:58 - 2016-03-11 19:55 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3CF3C132-6859-4994-8DAC-3B31CD8D194C}
2016-02-25 09:54 - 2016-02-25 09:55 - 00895080 _____ C:\Users\Admin\Downloads\Norton_Removal_Tool.exe
2016-02-25 09:48 - 2016-02-25 09:48 - 00000248 _____ C:\rescue.info
2016-02-25 09:46 - 2016-02-25 09:46 - 01857576 _____ (LogMeIn, Inc.) C:\Users\Admin\Downloads\Support-LogMeInRescue.exe
2016-02-25 09:46 - 2016-02-25 09:46 - 00000000 ____D C:\Users\Admin\AppData\Local\LogMeIn Rescue Applet
2016-02-24 21:57 - 2016-02-24 21:57 - 00000000 ____D C:\Users\Admin\AppData\LocalLow\HuniePot
2016-02-24 21:55 - 2016-03-07 19:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HuniePop [GOG.com]
2016-02-16 00:11 - 2016-02-16 00:11 - 00002202 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2016-02-16 00:10 - 2016-02-09 06:04 - 00111672 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-02-16 00:09 - 2016-02-11 18:27 - 01572496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2016-02-16 00:09 - 2016-02-11 18:27 - 00205456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2016-02-16 00:09 - 2016-02-11 18:27 - 00039240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2016-02-16 00:09 - 2016-02-10 07:27 - 12478528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-02-16 00:09 - 2016-02-09 09:25 - 42983480 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 37616184 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 31119296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 24944064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 21201784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 20741880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 19779648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17631304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17224664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17175248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 17116936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 14115136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 03649576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 03231544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02541504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 02187712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00950328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00882232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00745408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00689600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00541000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00445728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00383424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00379448 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00378968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00348216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00317144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00153392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-02-16 00:09 - 2016-02-09 09:25 - 00035832 _____ C:\WINDOWS\system32\nvinfo.pb
2016-02-12 06:29 - 2016-02-24 09:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-03-11 21:06 - 2015-10-30 19:35 - 00788142 _____ C:\WINDOWS\system32\perfh007.dat
2016-03-11 21:06 - 2015-10-30 19:35 - 00158968 _____ C:\WINDOWS\system32\perfc007.dat
2016-03-11 21:06 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-03-11 21:02 - 2015-08-06 20:56 - 00000000 __SHD C:\Users\Admin\IntelGraphicsProfiles
2016-03-11 21:01 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-11 21:01 - 2010-11-21 08:17 - 00000000 ____D C:\WINDOWS\CSC
2016-03-11 20:56 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-11 19:58 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-11 08:37 - 2014-03-07 16:29 - 794877069 _____ C:\WINDOWS\MEMORY.DMP
2016-03-10 01:19 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 01:19 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 01:19 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 01:19 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 00:28 - 2014-08-10 22:06 - 00000000 ____D C:\Program Files (x86)\Steam
2016-03-09 23:17 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-09 20:18 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-03-09 20:04 - 2014-02-10 12:11 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-09 20:00 - 2014-02-10 12:11 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-08 08:21 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\appcompat
2016-03-08 08:12 - 2015-10-30 08:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 08:12 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-07 19:49 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-03-07 19:32 - 2015-08-06 21:00 - 00002388 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-07 19:32 - 2015-08-06 21:00 - 00000000 ___RD C:\Users\Admin\OneDrive
2016-03-07 19:29 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-03-07 19:29 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-03-07 19:28 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-03-07 19:28 - 2015-10-30 07:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-03-07 19:28 - 2015-08-06 20:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-07 19:27 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2016-03-07 19:27 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows NT
2016-03-07 19:26 - 2015-08-06 19:18 - 00013338 _____ C:\WINDOWS\diagwrn.xml
2016-03-07 19:26 - 2015-08-06 19:18 - 00013338 _____ C:\WINDOWS\diagerr.xml
2016-03-07 19:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-03-07 19:22 - 2015-10-30 08:24 - 00000000 __RSD C:\WINDOWS\Media
2016-03-07 19:22 - 2015-01-25 04:50 - 00002248 _____ C:\WINDOWS\System32\Tasks\{459661D1-D2F6-419D-ADE9-E7E05FD0DA52}
2016-03-07 19:22 - 2015-01-25 03:45 - 00002300 _____ C:\WINDOWS\System32\Tasks\{F1F9B1E2-1649-459F-8D19-CE3F57076C12}
2016-03-07 19:22 - 2014-07-02 12:09 - 00002472 _____ C:\WINDOWS\System32\Tasks\{A7EDC86C-AC88-4B0D-8EBF-801BB3377055}
2016-03-07 19:22 - 2014-02-10 13:23 - 00002532 _____ C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask
2016-03-07 19:21 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration
2016-03-07 19:20 - 2015-10-30 08:24 - 00000000 __RHD C:\Users\Public\Libraries
2016-03-07 19:15 - 2016-02-03 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher® 3 - Wild Hunt [GOG.com]
2016-03-07 19:15 - 2016-01-31 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broken Sword - Director's Cut [GOG.com]
2016-03-07 19:15 - 2015-10-30 07:28 - 00000000 ____D C:\Users\Default.migrated
2016-03-07 19:15 - 2015-09-16 11:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Leisure Suit Larry - Reloaded [GOG.com]
2016-03-07 19:15 - 2015-07-24 21:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2016-03-07 19:15 - 2015-07-24 21:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2016-03-07 19:15 - 2015-07-12 22:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7
2016-03-07 19:15 - 2015-03-05 20:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-03-07 19:15 - 2015-02-12 00:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
2016-03-07 19:15 - 2015-01-25 05:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-07 19:15 - 2015-01-25 04:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix
2016-03-07 19:15 - 2015-01-25 04:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicYUV
2016-03-07 19:15 - 2015-01-25 00:05 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2016-03-07 19:15 - 2015-01-24 23:44 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2016-03-07 19:15 - 2014-12-13 11:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-03-07 19:15 - 2014-11-01 19:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2016-03-07 19:15 - 2014-08-14 18:56 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-03-07 19:15 - 2014-08-10 22:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-03-07 19:15 - 2014-04-12 17:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2016-03-07 19:15 - 2014-03-30 21:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
2016-03-07 19:15 - 2014-02-28 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
2016-03-07 19:15 - 2014-02-26 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-07 19:15 - 2014-02-10 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Deutsch)
2016-03-07 19:15 - 2014-02-10 08:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-03-07 19:15 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-03-07 19:14 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2016-03-07 19:14 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2016-03-07 19:14 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spool
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-03-07 19:14 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\IME
2016-03-07 19:14 - 2015-06-19 23:22 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2016-03-07 19:14 - 2014-03-30 21:14 - 00000000 ____D C:\WINDOWS\SysWOW64\xlive
2016-03-07 19:13 - 2015-10-30 19:36 - 00000000 ____D C:\WINDOWS\OCR
2016-03-07 19:13 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files\Windows Sidebar
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\schemas
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InputMethod
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\IME
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Help
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\USOPrivate
2016-03-07 19:13 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-03-07 19:13 - 2015-02-05 18:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue
2016-03-07 19:13 - 2015-02-05 18:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2016-03-07 19:13 - 2014-09-06 17:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
2016-03-07 19:13 - 2014-07-02 12:17 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2016-03-07 19:13 - 2014-06-19 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deep Silver
2016-03-07 19:11 - 2015-08-06 20:56 - 00000000 ____D C:\Users\Admin\AppData\Local\Packages
2016-03-07 19:11 - 2014-02-27 03:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2016-03-07 19:08 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-03-07 19:00 - 2015-10-30 19:58 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-03-07 18:59 - 2015-10-30 08:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-03-07 18:57 - 2015-10-30 19:47 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-07 18:57 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-03-07 18:57 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-03-07 18:57 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-03-07 18:57 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Provisioning
2016-03-07 18:57 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-03-07 18:57 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-03-07 18:57 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-03-07 18:50 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-03-07 18:50 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-03-07 18:50 - 2015-10-30 08:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2016-03-07 18:50 - 2015-10-30 08:19 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2016-03-07 18:50 - 2015-10-30 08:19 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2016-03-07 18:50 - 2015-10-30 08:19 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2016-03-07 18:50 - 2015-10-30 08:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2016-03-07 18:50 - 2015-10-30 08:19 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2016-03-07 18:50 - 2015-10-30 08:19 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2016-03-07 18:50 - 2015-10-30 08:18 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2016-03-07 18:50 - 2015-10-30 08:18 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2016-03-07 18:50 - 2015-10-30 08:18 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2016-03-07 18:50 - 2015-10-30 08:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2016-03-07 18:50 - 2015-10-30 08:18 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2016-03-07 18:50 - 2015-10-30 08:18 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2016-03-07 18:50 - 2015-10-30 08:18 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2016-03-07 18:50 - 2015-10-30 08:18 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2016-03-07 18:50 - 2015-10-30 08:18 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2016-03-07 18:50 - 2015-10-30 08:18 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2016-03-06 00:27 - 2014-02-26 22:03 - 00000000 ____D C:\Users\Admin\AppData\Local\NVIDIA
2016-03-06 00:26 - 2014-02-26 21:02 - 00000000 ____D C:\Users\Admin\AppData\Local\NVIDIA Corporation
2016-03-05 14:06 - 2014-02-10 11:42 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SoftGrid Client
2016-03-05 13:56 - 2014-10-15 18:28 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2016-02-25 20:39 - 2015-03-05 20:41 - 00000000 ____D C:\GOG Games
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieUserList
2016-02-25 09:59 - 2014-11-29 21:19 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieSiteList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieUserList
2016-02-25 09:58 - 2015-02-05 18:42 - 00000000 __SHD C:\Users\Admin\AppData\LocalLow\EmieSiteList
2016-02-25 09:55 - 2016-01-29 19:03 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-02-21 23:27 - 2015-01-27 10:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-17 07:40 - 2016-01-10 22:44 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-02-17 07:40 - 2014-10-23 15:15 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-02-17 07:40 - 2014-10-23 15:15 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-02-17 07:40 - 2014-02-26 20:57 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-02-17 07:40 - 2014-02-26 20:57 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-02-14 10:24 - 2015-01-26 02:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2016-02-25 11:37 - 2016-02-25 11:37 - 0000432 _____ () C:\Users\Admin\AppData\Local\LMIR0001.tmp.bat
2016-02-25 11:37 - 2016-02-25 11:37 - 0000357 _____ () C:\Users\Admin\AppData\Local\LMIR0001.tmp_r.bat
2016-03-07 19:05 - 2016-03-07 19:05 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-03-07 19:00

==================== Ende von FRST.txt ============================

Gruß Kanso

Larusso 12.03.2016 09:29

Ich hab heute den ganzen Tag Unterricht. Melde mich also spätestens morgen wieder.

Dennoch, macht der Rechner noch irgendwelche Macken ?

Kanso 12.03.2016 11:32

Hallo Daniel,

du kein Problem. Hab bis jetzt keine weiteren Macken mehr festgestellt. Mittlerweile konnte ich auch meinen Grafiktreiber wieder aktualisieren. Also alles ok soweit.

Gruß Kanso

Larusso 13.03.2016 10:04

Morgen

Erstelle bitte einen Systemwiederherstellungspunkt und versuche nun erneut Norton zu installieren ;)

Kanso 13.03.2016 10:57

Hallo Daniel,

puh das war ne schwere Geburt. Es hat nun endlich funktioniert und Norton läuft wieder einwandfrei. :daumenhoc Vielen Dank für deine Hilfe. Bin froh, dass es dieses Board hier gibt.

Gruß Kanso

Larusso 13.03.2016 11:57

Super :daumenhoc

Kannst du jz nochmal den ESET Online Scan versuchen ? :)

Kanso 13.03.2016 15:30

Hallo,

log.txt:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=8ec3d38b7f533c4b9ac3a5bc568f541d
# end=init
# utc_time=2016-02-28 12:17:34
# local_time=2016-02-28 01:17:34 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
DLL:pipe not connected. attempts=120
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=8ec3d38b7f533c4b9ac3a5bc568f541d
# end=init
# utc_time=2016-02-28 03:57:24
# local_time=2016-02-28 04:57:24 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
DLL:pipe not connected. attempts=120
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=8ec3d38b7f533c4b9ac3a5bc568f541d
# end=init
# utc_time=2016-03-13 11:50:17
# local_time=2016-03-13 12:50:17 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 28554
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=8ec3d38b7f533c4b9ac3a5bc568f541d
# end=updated
# utc_time=2016-03-13 11:52:41
# local_time=2016-03-13 12:52:41 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=8ec3d38b7f533c4b9ac3a5bc568f541d
# engine=28554
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-03-13 02:20:37
# local_time=2016-03-13 03:20:37 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Norton Security'
# compatibility_mode=3604 16777213 100 97 19546 50581363 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 70573 11692980 0 0
# scanned=294706
# found=1
# cleaned=0
# scan_time=8876
sh=1ECFC21820718B28EF8D02235CF47C9A2B4769C7 ft=1 fh=d64bdcab81966442 vn="Win32/InstallMonetizer.AU evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Admin\Downloads\audioextractor_CB-DL-Manager [1].exe"


Larusso 13.03.2016 17:47

Ich sehr nichts, ESET nichts, Norton läuft.
Ich würde sagen, dass Thema ist erledigt :)

Kanso 14.03.2016 16:16

Hallo Daniel,

sehr schön. Wie gesagt vielen Dank für deine Hilfe. Jetzt hab ich zwar noch Norton bis 2017 an der Backe. Aber die Ursache, die zu diesem Problem geführt hat, lag ja anscheinend bei Windows und nicht an Norton. Dann sind wir soweit fertig oder?

Gruß Kanso

Larusso 14.03.2016 16:44

Jup, sind wir :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 19:55 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131