Additon.txt Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 03-08-2016
durchgeführt von Felix (2016-08-08 20:12:23)
Gestartet von C:\Users\Felix\Desktop
Windows 10 Home Version 1607 (X64) (2016-08-04 19:28:37)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-1449009979-2283773056-3025972245-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1449009979-2283773056-3025972245-503 - Limited - Disabled)
Felix (S-1-5-21-1449009979-2283773056-3025972245-1001 - Administrator - Enabled) => C:\Users\Felix
Gast (S-1-5-21-1449009979-2283773056-3025972245-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1449009979-2283773056-3025972245-1002 - Limited - Enabled)
Manager Jodle (S-1-5-21-1449009979-2283773056-3025972245-1003 - Limited - Enabled) => C:\Users\Manager Jodle
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Kaspersky Internet Security (Enabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.17) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.17 - Adobe Systems Incorporated)
Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
Anno 1404 (HKLM-x32\...\Steam App 33250) (Version: - Blue Byte)
Apple Application Support (32-Bit) (HKLM-x32\...\{26356515-5821-40FA-9C3D-9785052A1062}) (Version: 4.3.1 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{C2651553-6CA3-4822-B2E6-BC4ACA6E0EA2}) (Version: 4.3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
ATI Catalyst Install Manager (HKLM\...\{5BC83141-83DD-07BE-C940-04B385540F04}) (Version: 3.0.769.0 - ATI Technologies, Inc.)
AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version: - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version: - AVM Berlin)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Caesar III (HKLM-x32\...\Caesar III) (Version: - )
Canon MP Navigator EX 3.0 (HKLM-x32\...\MP Navigator EX 3.0) (Version: - )
Canon MP270 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP270_series) (Version: - )
ccc-core-static (x32 Version: 2010.0920.2143.37117 - Ihr Firmenname) Hidden
Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.3.0.0156 - Disc Soft Ltd)
Dota 2 (HKLM\...\Steam App 570) (Version: - Valve)
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.)
FUSSBALL MANAGER 13 (HKLM-x32\...\{80AF0300-866F-400F-A350-D53E3C3E34E0}) (Version: 1.0.3.0 - Electronic Arts)
FUSSBALL MANAGER 2005 (HKLM-x32\...\{6E5BC38E-F22B-4197-00A2-CD8E58EF139D}) (Version: - )
iCloud (HKLM\...\{ADFDB647-35C0-4254-9EE6-2D9C3B7104BD}) (Version: 5.2.1.69 - Apple Inc.)
iTunes (HKLM\...\{9F4BF859-C3A4-4AB6-BDD1-9C5D58188598}) (Version: 12.4.1.6 - Apple Inc.)
Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{77E7AE5C-181C-4CAF-ADBF-946F11C1CE26}) (Version: 16.0.0.614 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 16.0.0.614 - Kaspersky Lab) Hidden
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0407-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 16.0.7070.2033 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 47.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 de)) (Version: 47.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.1.6018 - Mozilla)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.1.13.85 - Electronic Arts, Inc.)
QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
RICOH Media Driver v2.15.17.02 (HKLM-x32\...\{FE041B02-234C-4AAA-9511-80DF6482A458}) (Version: 2.15.17.02 - RICOH)
RollerCoaster Tycoon 3: Platinum! (HKLM\...\Steam App 2700) (Version: - Frontier)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Sid Meier's Civilization V (HKLM-x32\...\steam app 8930) (Version: - 2K Games, Inc.)
SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
WestwoodOnline (HKLM-x32\...\{BBCD6D56-8A26-4DDE-9482-DBC9C7B7341D}) (Version: 1.0.0.0 - WestwoodOnline)
Windows 10-Upgrade-Assistent (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17346 - Microsoft Corporation)
WinRAR 5.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
Wondershare MobileTrans ( Version 7.4.5 ) (HKLM-x32\...\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 7.4.5 - Wondershare)
Yahoo Search Set (HKLM-x32\...\Yahoo! SearchSet) (Version: - Yahoo Inc.)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-1449009979-2283773056-3025972245-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Felix\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileCoAuth.exe (Microsoft Corporation)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {03896D04-23AB-4F74-A27D-B1B71EE41E2C} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask => C:\Windows\system32\MDMAgent.exe [2016-07-16] (Microsoft Corporation)
Task: {0C662E33-6028-42EB-8E0D-20826CBE2A7E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {0DE31D82-BFE8-464F-AFFF-C9FA527ABF89} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {16DEA092-FB0C-40D0-AE20-0536BECC21D9} - System32\Tasks\Microsoft\Windows\EDP\EDP App Launch Task
Task: {184784E2-6ACB-4154-BD0F-A955BE13F177} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange
Task: {1962257A-1F23-48D4-ACF2-7B1C2F13CC78} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {1B65DD58-D16B-45E8-BEB4-94D7E4D64DF7} - System32\Tasks\Microsoft\Windows\EDP\EDP Auth Task
Task: {1EBAD352-8C27-4FCA-9C29-B568C3F8F404} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {20555343-DF53-44B9-ADE1-C5AC642A1CE9} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {2A3C4601-21B4-40B2-B8D3-6C12F2067DA0} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {3165D2C6-FA3F-44D0-AF0D-F0EB61B3C6C0} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {3FD4029F-733C-4CF4-B07E-AB898E0EB37F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {44772016-0DFB-41FA-8A85-16CAC6CE486B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {44BECCE8-B7DC-4066-9D44-821067D3B36D} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {4721E700-4063-48B0-BECC-5525900CC05D} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {488AB12B-9A59-42DF-ADFE-9D9C0A3C7FE1} - System32\Tasks\{6A82991B-E19E-44C0-BC5A-FE244B49FD7C} => pcalua.exe -a C:\Users\Felix\Downloads\RIDMSC-00203446-764(1).EXE -d C:\Users\Felix\Downloads
Task: {518B0AD7-ED2A-4DAE-BBA2-98BAD3DE7DF3} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {5BE91AA6-4313-4E4B-9C09-33DBE53D8152} - System32\Tasks\Microsoft\XblGameSave\XblGameSaveTask => C:\Windows\System32\XblGameSaveTask.exe [2016-07-16] (Microsoft Corporation)
Task: {5F36E9C7-0917-4E87-B62B-33AF929D4C5E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-08-06] (Microsoft Corporation)
Task: {6232090F-3BD0-4E1F-960B-78CBA797F685} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand
Task: {62619896-9682-4E97-B716-0283128B7136} - System32\Tasks\{AC6DAF48-D7F9-465C-9951-CF09EB231830} => pcalua.exe -a "C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE" -d "C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005"
Task: {6B1AE720-1359-4B9E-9C0F-60167361EF01} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefreshTask
Task: {6E8AE752-C5D2-4B34-B351-338B4370A342} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleCommand
Task: {7864854A-EA4A-4A90-9D40-37CD37AB392A} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {7AC5E1E2-2FD3-40CD-8842-88CE53A3609C} - System32\Tasks\Microsoft\Windows\DiskFootprint\StorageSense
Task: {7CC8C833-BEBF-43F3-AEEC-C5AE394DC20E} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {7CF9508C-FE2D-45E4-8522-17EC5EC6B8CA} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {8115F1DE-F0C4-4F8A-932D-A96F001749E5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {81D7AC79-111A-4211-8AAF-4EDD958E21EE} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {8574FEAB-6F02-439B-B4A6-DE5FD0CE3195} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {8D546DAB-4158-42E2-BEAB-021545E26A1B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {8E8782F0-2FAF-470C-BD0F-264F8E4C727A} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {94F15D37-1F03-4342-A8F9-D503FE912BA4} - \CCleanerSkipUAC -> Keine Datei <==== ACHTUNG
Task: {9851188E-AC07-4F36-BA28-6D00BB2C9C46} - System32\Tasks\Microsoft\Windows\Device Information\Device => C:\Windows\system32\devicecensus.exe [2016-07-16] (Microsoft Corporation)
Task: {9A4A8135-E830-4B38-899F-2376623DC328} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {A5DB66E0-0C00-4C9D-9BC9-BAF149B27E0A} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation)
Task: {AC7F23C4-DAE8-4C3E-8076-BC63085D091F} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {B11BACBA-93B8-4750-BC33-F64A53DDBAC1} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {B5B4B8F1-8E83-427A-9404-BA79CD59F7FF} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {B6EE76B2-4F82-4E15-9345-C867A29CBAD0} - System32\Tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask => C:\Windows\system32\speech_onecore\common\SpeechModelDownload.exe [2016-07-16] (Microsoft Corporation)
Task: {BED917BF-D4E9-45C0-AC34-4A2C0E8BAD6E} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {C1483001-C044-446F-BC50-BA0391AB7960} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {C184BAF6-440C-4C87-BF3D-23F42EBCE79C} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {C1F2D29D-949A-4760-81D5-CA231E304C4C} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {C6E86CA0-3706-4413-8D9C-37EBF1D8EC73} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {C723E501-7EE8-4C6C-8ED2-CEDBA179101C} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {CBBFEF9A-F31D-419C-8DE2-043D9505F646} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {CC636E49-0109-402B-A40B-A37C29069A95} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession
Task: {CD19BC8A-E9FE-49ED-92A5-0E1194F69F00} - System32\Tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon => C:\Windows\System32\XblGameSaveTask.exe [2016-07-16] (Microsoft Corporation)
Task: {D394BE25-2E16-45D4-AAB2-3E8861A09351} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitorToastTask
Task: {D3C4106A-D511-42C6-9716-465644534C87} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierinstall => C:\Windows\system32\AppHostRegistrationVerifier.exe [2016-07-16] (Microsoft Corporation)
Task: {D941F53F-7907-4FBE-B1E7-69EBD5B3A5D8} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange
Task: {E3072F2C-0AFF-4C4E-9CE4-0ED470A1DF24} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation)
Task: {E3A36466-90D4-42E4-BA4C-8E9C9B403885} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Keine Datei <==== ACHTUNG
Task: {E3C898F6-B652-45D8-AD07-1F3AC86720E4} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {E690FD1B-7CBF-4C66-BB9B-205148DAE65C} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {E6C59E24-43F2-46C0-B440-6E7B853D265D} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {E84CD7A7-BA61-42E1-9146-EA4F85E339E3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-08-06] (Microsoft Corporation)
Task: {EA9BAA00-6604-4A27-8A73-AFA65F0EE1B3} - System32\Tasks\Microsoft\Windows\SharedPC\Account Cleanup => Rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
Task: {ECEDC57D-8965-4EB1-BD6F-84791D928E23} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierdaily => C:\Windows\system32\AppHostRegistrationVerifier.exe [2016-07-16] (Microsoft Corporation)
Task: {F84D122D-9316-4208-BFA0-0449EC4F4881} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {FA376619-048C-43E9-B918-CD3E57BA5B13} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-29] (Adobe Systems Incorporated)
Task: {FE8B5F3F-885D-4367-97E4-7275749C441C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-04-22 01:07 - 2016-04-22 01:07 - 01337144 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-08-04 21:57 - 2016-08-04 21:57 - 00959168 _____ () C:\Users\Felix\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00130048 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-07-16 13:43 - 2016-07-16 13:43 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-07-16 13:43 - 2016-07-16 13:43 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 09761280 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 01033728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 02438144 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00236488 _____ () c:\windows\system32\WerEtw.dll
2015-07-08 23:18 - 2015-07-08 23:18 - 00794920 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\kpcengine.2.3.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2009-07-14 04:34 - 2015-07-18 12:51 - 00000854 ____A C:\WINDOWS\system32\Drivers\etc\hosts
0.0.0.1 mssplus.mcafee.com
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Felix\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-1449009979-2283773056-3025972245-1003\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BCSSync"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\...\StartupApproved\Run: => "ApplePhotoStreams"
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\...\StartupApproved\Run: => "iCloudServices"
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\...\StartupApproved\Run: => "OneDrive"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [WirelessDisplay-Infra-In-TCP] => (Allow) %systemroot%\system32\CastSrv.exe
FirewallRules: [{08DA4542-0EAE-453C-AA9D-D3667F7488C4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{65371616-6032-498A-A43D-B40A1A6D6437}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{18023139-7745-4F73-A43E-8C0D039BBAFD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{1904FDFD-F5FD-443B-8204-83030B626666}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{676259C2-6D52-46D0-8F6D-AFF077960856}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{BC5AD5A9-7BF8-4478-BDCB-97956F3F7FD8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{E7F85166-B013-4F17-B370-719C20AE33ED}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{D08E3BB2-03B7-4663-A322-BEB637442AE5}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{260261AB-1122-4B3C-B8D3-2AC57A415B5C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{662D9A8C-FFAF-433E-AC42-782CDE725425}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{FA40576E-C69E-46E1-A489-ED1376F56AAC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{078D826B-E7A9-463D-B335-4BD8DBF9B0EA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{772B08E3-B2F6-4B94-9185-A436292959CA}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert II\RA2Launcher.exe
FirewallRules: [{9145900B-2607-42D4-B4CF-44D3000118DA}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert II\RA2Launcher.exe
FirewallRules: [{78EF3B20-6067-4F69-BD10-F9D564D7FDDB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B114E272-6242-40C3-8C4C-75B1B44E6394}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AECA05C5-2234-4B65-ABEC-D9D057192B88}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{58025253-16C5-466C-A5FF-481FBA9C3E39}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{52274820-F5A9-43A4-87AF-6F8A5AD6DE3E}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA Manager 13\Manager13.exe
FirewallRules: [{0E59936F-A992-40F3-BB91-A64C30DF5430}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA Manager 13\Manager13.exe
FirewallRules: [{CAF159A1-E224-4B4C-AE01-D9D132154F0C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{AD6FCB36-633D-4B86-9739-40C1C10D2505}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A88189AB-3961-44D7-9626-24B7EA7F2FEA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{33BF0DC8-E28C-49F0-B2B1-A61CA75DB2BD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{9F854867-E0CC-4219-9507-DD6F00DA9A77}] => (Allow) D:\fsetup.exe
FirewallRules: [{43C2231D-31DB-4E8D-ABF4-B5A590DCAE0F}] => (Allow) D:\fsetup.exe
FirewallRules: [{8F30B3A7-CC76-47E3-BC8B-624DC5EC36CE}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{D0167F14-6AFC-43D1-BB68-0E02FE6121B2}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{F64358EF-7B0C-4B0C-AA1E-A805CBB2734C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{2482AA52-759F-4178-B363-BA31E51EECFE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{DAD17BFC-C45A-4759-9D79-2B05B64DBDEB}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{B3788D1D-4390-45D4-B90A-CCA898597CE8}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{0C98C425-A60F-4366-AFF5-6114AEFA3A46}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{CFB9CBA0-354F-4D8E-96A0-8FD91A19A88C}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{24D61B0E-E503-4896-A597-75521EF1A325}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{32E6524C-3FAA-4B07-AD52-B458C99B43D3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{6FB60073-C920-4AC3-9726-243BF24659D9}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{80BDE02A-8CCE-4F44-BBC2-1E1E59FEBDF1}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{FC154D27-1ED5-4C7A-A664-5C5DDEDCE890}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [{CA525F67-314C-4D0F-99C4-DEE8F434F392}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [{7CBEC171-B2FA-4235-AFD6-CFEB346577F2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anno 1404\Anno4.exe
FirewallRules: [{8EAF846C-60B8-4613-B226-C7D363B7FA7E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anno 1404\Anno4.exe
FirewallRules: [TCP Query User{5E79B473-53A0-43A4-83F0-18EC67EA5F3D}C:\program files (x86)\steam\steamapps\common\anno 1404\tools\anno4web.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\anno 1404\tools\anno4web.exe
FirewallRules: [UDP Query User{826813E4-F6B0-4F25-B272-3FCC6B3853F4}C:\program files (x86)\steam\steamapps\common\anno 1404\tools\anno4web.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\anno 1404\tools\anno4web.exe
==================== Wiederherstellungspunkte =========================
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Error: (08/08/2016 08:14:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (2880) Unistore: Ungültige Seitenverknüpfung (Fehler -338) in B-Struktur (ObjectId: 406, PgnoRoot: 39) von Datenbank "C:\Users\Felix\AppData\Local\Comms\UnistoreDB\store.vol" (39 => 2156, svchost0).
Systemfehler:
=============
Error: (08/08/2016 08:05:16 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}{F72671A9-012C-4725-9D2F-2A4D32D65169}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (08/08/2016 08:01:50 PM) (Source: DCOM) (EventID: 10016) (User: FELIX-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Felix-PCFelixS-1-5-21-1449009979-2283773056-3025972245-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Error: (08/08/2016 07:57:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ClickToRunSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053 = Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.
Error: (08/08/2016 07:57:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst ClickToRunSvc erreicht.
Error: (08/08/2016 07:57:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MBAMScheduler" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053 = Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.
Error: (08/08/2016 07:57:34 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MBAMScheduler erreicht.
Error: (08/08/2016 07:57:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MBAMService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053 = Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.
Error: (08/08/2016 07:57:34 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MBAMService erreicht.
Error: (08/08/2016 07:56:53 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 08.08.2016 um 19:41:53 unerwartet heruntergefahren.
Error: (08/08/2016 07:24:43 PM) (Source: DCOM) (EventID: 10001) (User: FELIX-PC)
Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca31App.AppXwdz8g2fxr36xz0tdtagygnvemf85s7gg.mcaNicht verfügbarNicht verfügbar
CodeIntegrity:
===================================
Date: 2016-08-08 19:43:51.966
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Date: 2016-08-08 19:43:51.829
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2016-08-08 19:43:51.636
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Date: 2016-08-08 19:43:51.309
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Date: 2016-08-08 19:43:51.088
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2016-08-08 19:43:50.672
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Date: 2016-08-08 19:43:45.530
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
Date: 2016-08-08 19:43:43.251
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz
Prozentuale Nutzung des RAM: 56%
Installierter physikalischer RAM: 3950.06 MB
Verfügbarer physikalischer RAM: 1700.05 MB
Summe virtueller Speicher: 7918.06 MB
Verfügbarer virtueller Speicher: 5520.85 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:465.22 GB) (Free:212.53 GB) NTFS
Drive d: (FM2005CD2) (CDROM) (Total:0.6 GB) (Free:0 GB) CDFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0F7F92D4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
==================== Ende von Addition.txt ============================ Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 03-08-2016
durchgeführt von Felix (Administrator) auf FELIX-PC (08-08-2016 20:04:36)
Gestartet von C:\Users\Felix\Desktop
Geladene Profile: Felix (Verfügbare Profile: Felix & Manager Jodle)
Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Yahoo Inc.) C:\Program Files (x86)\Yahoo!\yset\{461F92AC-8E95-B74C-B9CD-0E0EBCCEE9EE}\YSearchUtilSVC.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avpui.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-06-01] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-04-22] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-04-22] (Apple Inc.)
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-04-22] (Apple Inc.)
HKU\S-1-5-21-1449009979-2283773056-3025972245-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4289728 2016-04-12] (Disc Soft Ltd)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\..\Interfaces\{B09EE1B2-A492-4C1A-9946-A235FCF76D34}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{f68d5919-0b29-459d-a65b-6fe406163b08}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-1449009979-2283773056-3025972245-1001 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-1449009979-2283773056-3025972245-1001 -> {D8962FED-BF2D-4C09-84C5-73F89D994BAF} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-08-06] (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2015-10-22] (AO Kaspersky Lab)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-08-06] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-08-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-08-06] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-10-22] (AO Kaspersky Lab)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-08-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-08-06] (Oracle Corporation)
Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2015-10-22] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-10-22] (AO Kaspersky Lab)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-06] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-06] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-06] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-06] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\8rj8k03s.default-1469798922073
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-29] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-29] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-08-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-06] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-08-06] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-08-06] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF Extension: Search and New Tab by Yahoo - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\8rj8k03s.default-1469798922073\Extensions\jid1-16aeif9OQIRKxA@jetpack.xpi [2016-08-06]
FF Extension: Adblock Plus - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\8rj8k03s.default-1469798922073\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-07-29]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\anti_banner@kaspersky.com => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\online_banking@kaspersky.com => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox
FF Extension: Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox [2016-06-11]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\ChromeExt\online_banking_chrome.crx <nicht gefunden>
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\ChromeExt\ab.crx <nicht gefunden> Code:
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 AVP16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe [194000 2015-10-04] (Kaspersky Lab ZAO)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
S2 CDPUserSvc; C:\Windows\System32\CDPUserSvc.dll [337408 2016-07-16] (Microsoft Corporation)
R2 CDPUserSvc_3c18c; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation)
R2 CDPUserSvc_3c18c; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2950856 2016-07-25] (Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1443520 2016-04-12] (Disc Soft Ltd)
S3 FrameServer; C:\Windows\system32\FrameServer.dll [803840 2016-07-16] (Microsoft Corporation)
S3 HvHost; C:\Windows\System32\hvhostsvc.dll [67584 2016-07-16] (Microsoft Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2122248 2016-07-29] (Electronic Arts)
S3 ose; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [200240 2016-07-23] (Microsoft Corporation) [Datei ist nicht signiert]
R3 RmSvc; C:\Windows\System32\RMapi.dll [141312 2016-07-16] (Microsoft Corporation)
S4 shpamsvc; C:\Windows\system32\Windows.SharedPC.AccountManager.dll [161792 2016-07-16] (Microsoft Corporation)
R3 TimeBrokerSvc; C:\Windows\System32\TimeBrokerServer.dll [177664 2016-07-16] (Microsoft Corporation)
S3 vmicrdv; C:\Windows\System32\icsvcext.dll [349696 2016-07-16] (Microsoft Corporation)
S3 vmicvss; C:\Windows\System32\icsvcext.dll [349696 2016-07-16] (Microsoft Corporation)
S3 vssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\vssbridge64.exe [144640 2015-07-09] (AO Kaspersky Lab)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S3 wisvc; C:\Windows\system32\flightsettings.dll [614912 2016-07-16] (Microsoft Corporation)
S3 WpnUserService; C:\Windows\System32\WpnUserService.dll [74240 2016-07-16] (Microsoft Corporation)
S3 WpnUserService_3c18c; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation)
S3 WpnUserService_3c18c; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MobileTrans\DriverInstall.exe [104248 2015-10-22] (Wondershare)
R2 YSearchUtilSvc; C:\Program Files (x86)\Yahoo!\yset\{461F92AC-8E95-B74C-B9CD-0E0EBCCEE9EE}\YSearchUtilSvc.exe [182736 2016-05-16] (Yahoo Inc.)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 AcpiDev; C:\Windows\System32\drivers\AcpiDev.sys [18432 2016-07-16] (Microsoft Corporation)
S3 applockerfltr; C:\Windows\System32\drivers\applockerfltr.sys [15360 2016-07-16] (Microsoft Corporation)
R3 athr; C:\Windows\System32\drivers\athwnx.sys [4233728 2016-07-16] (Qualcomm Atheros Communications, Inc.)
S0 b06bdrv; C:\Windows\System32\drivers\bxvbda.sys [533856 2016-07-16] (QLogic Corporation)
S3 cht4iscsi; C:\Windows\System32\drivers\cht4sx64.sys [346976 2016-07-16] (Chelsio Communications)
S3 cht4vbd; C:\Windows\System32\drivers\cht4vx64.sys [2104160 2016-07-16] (Chelsio Communications)
R2 clreg; C:\Windows\System32\drivers\registry.sys [70144 2016-07-16] (Microsoft Corporation)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-05-17] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-05-17] (Disc Soft Ltd)
S3 hvservice; C:\Windows\System32\drivers\hvservice.sys [73568 2016-07-16] (Microsoft Corporation)
S3 iagpio; C:\Windows\System32\drivers\iagpio.sys [33280 2016-07-16] (Intel(R) Corporation)
S3 iaLPSS2i_GPIO2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [64512 2016-07-16] (Intel Corporation)
S3 IndirectKmd; C:\Windows\System32\drivers\IndirectKmd.sys [35840 2016-07-16] (Microsoft Corporation)
R0 iorate; C:\Windows\System32\drivers\iorate.sys [45920 2016-07-16] (Microsoft Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-22] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [70512 2015-06-27] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [77728 2016-04-10] (AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [30328 2015-06-24] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [181640 2015-10-22] (AO Kaspersky Lab)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [238000 2016-06-11] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [933808 2016-06-11] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [41656 2015-06-06] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [41352 2015-10-04] (AO Kaspersky Lab)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [87984 2016-06-11] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [102584 2015-06-16] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [187056 2015-06-23] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-08-08] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S0 percsas2i; C:\Windows\System32\drivers\percsas2i.sys [58720 2016-07-16] (Avago Technologies)
S0 scmbus; C:\Windows\System32\drivers\scmbus.sys [88416 2016-07-16] (Microsoft Corporation)
S3 scmdisk0101; C:\Windows\System32\drivers\scmdisk0101.sys [123904 2016-07-16] (Microsoft Corporation)
S3 UcmTcpciCx0101; C:\Windows\System32\Drivers\UcmTcpciCx.sys [108544 2016-07-16] (Microsoft Corporation)
S3 vmgid; C:\Windows\System32\drivers\vmgid.sys [10240 2016-07-16] (Microsoft Corporation)
R0 volume; C:\Windows\System32\drivers\volume.sys [16224 2016-07-16] (Microsoft Corporation)
R2 wcifs; C:\Windows\system32\drivers\wcifs.sys [119648 2016-07-16] (Microsoft Corporation)
R2 wcnfs; C:\Windows\system32\drivers\wcnfs.sys [66560 2016-07-16] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 ykinw8; C:\Windows\System32\drivers\ykinx64.sys [288768 2016-07-16] (Marvell)
U4 aspnet_state; kein ImagePath
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
NETSVC: shpamsvc -> C:\Windows\system32\Windows.SharedPC.AccountManager.dll (Microsoft Corporation)
NETSVC: wisvc -> C:\Windows\system32\flightsettings.dll (Microsoft Corporation)
NETSVC: WpnService -> C:\Windows\system32\WpnService.dll (Microsoft Corporation)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-08-08 20:09 - 2016-08-08 20:09 - 01160016 _____ (Alcpu ) C:\Users\Felix\Downloads\Core-Temp-setup_1.1.exe
2016-08-08 20:01 - 2016-08-08 20:02 - 00000000 ____D C:\Users\Felix\Desktop\Fotos
2016-08-06 21:05 - 2016-08-06 21:05 - 00000000 ____D C:\Users\Felix\AppData\Local\YSearchUtil
2016-08-06 21:05 - 2016-08-06 21:05 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2016-08-06 20:43 - 2016-08-06 20:44 - 00001190 _____ C:\Users\Felix\Desktop\mbam.txt
2016-08-06 17:26 - 2016-08-08 19:25 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-08-06 17:25 - 2016-08-06 17:25 - 22851472 _____ (Malwarebytes ) C:\Users\Felix\Downloads\mbam-setup-2.2.1.1043.exe
2016-08-06 17:25 - 2016-08-06 17:25 - 00001175 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-08-06 17:25 - 2016-08-06 17:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-06 17:25 - 2016-08-06 17:25 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-08-06 17:25 - 2016-08-06 17:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-06 17:25 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-08-06 17:25 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-08-06 17:25 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-08-05 19:37 - 2016-08-05 19:42 - 00039844 _____ C:\Users\Felix\Desktop\Addition.txt
2016-08-05 19:25 - 2016-08-08 20:04 - 00021692 _____ C:\Users\Felix\Desktop\FRST.txt
2016-08-05 19:25 - 2016-08-08 20:04 - 00000000 ____D C:\FRST
2016-08-05 19:21 - 2016-08-05 19:22 - 02393600 _____ (Farbar) C:\Users\Felix\Desktop\FRST64.exe
2016-08-04 23:50 - 2016-08-04 15:35 - 00000000 ____D C:\Users\Felix\Desktop\DJ Snake - Encore [320]
2016-08-04 23:38 - 2016-08-04 23:39 - 117961686 _____ C:\Users\Felix\Downloads\DJ Snake - Encore [320].zip
2016-08-04 22:43 - 2016-08-04 22:55 - 00000000 ____D C:\Users\Felix\Desktop\Uwe - Kopie
2016-08-04 22:43 - 2016-08-04 22:43 - 00000000 ____D C:\Users\Felix\Desktop\Flix
2016-08-04 21:42 - 2016-08-04 21:42 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-08-04 21:35 - 2016-08-06 13:18 - 00000000 ____D C:\Users\Felix\AppData\Local\ConnectedDevicesPlatform
2016-08-04 21:35 - 2016-08-04 21:35 - 00000020 ___SH C:\Users\Felix\ntuser.ini
2016-08-04 20:00 - 2016-08-04 21:23 - 00000000 ___DC C:\WINDOWS\Panther
2016-08-04 19:57 - 2016-08-04 19:57 - 00000000 ____D C:\Windows.old
2016-08-04 19:56 - 2016-08-04 19:56 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-08-04 19:56 - 2016-08-04 19:56 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 01418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 01265424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 01260384 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 00843104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-08-04 19:56 - 2016-08-04 19:56 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-08-04 19:56 - 2016-08-04 19:56 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-08-04 19:56 - 2016-08-04 19:56 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-08-04 19:56 - 2016-07-15 20:29 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2016-08-04 19:56 - 2016-07-15 20:29 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2016-08-04 19:56 - 2016-07-15 20:14 - 06354944 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2016-08-04 19:56 - 2016-07-15 19:45 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2016-08-04 19:56 - 2016-07-15 19:29 - 05489664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2016-08-04 19:55 - 2016-08-04 19:55 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-08-04 19:55 - 2016-08-04 19:55 - 00000000 ____D C:\ProgramData\USOShared
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Vorlagen
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Startmenü
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 ____D C:\Program Files\MSBuild
2016-08-04 19:53 - 2016-08-04 19:53 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-08-04 19:53 - 2016-08-04 19:29 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-08-04 19:52 - 2016-05-25 15:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-08-04 19:52 - 2016-05-25 15:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-08-04 19:52 - 2016-05-25 15:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-08-04 19:52 - 2016-05-25 12:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-08-04 19:52 - 2016-05-25 12:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-08-04 19:52 - 2016-05-25 12:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-08-04 19:49 - 2016-08-04 19:52 - 00011433 _____ C:\WINDOWS\diagwrn.xml
2016-08-04 19:49 - 2016-08-04 19:52 - 00011433 _____ C:\WINDOWS\diagerr.xml
2016-08-04 19:41 - 2016-08-04 19:41 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2016-08-04 19:40 - 2016-08-08 19:57 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-08-04 19:40 - 2016-08-04 19:41 - 00003300 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E02B4568-8100-4661-A3B6-E120F65C2C9F}
2016-08-04 19:40 - 2016-08-04 19:41 - 00003142 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-08-04 19:40 - 2016-08-04 19:41 - 00002538 _____ C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask
2016-08-04 19:40 - 2016-08-04 19:40 - 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-08-04 19:40 - 2016-08-04 19:40 - 00002398 _____ C:\WINDOWS\System32\Tasks\{AC6DAF48-D7F9-465C-9951-CF09EB231830}
2016-08-04 19:40 - 2016-08-04 19:40 - 00002302 _____ C:\WINDOWS\System32\Tasks\{6A82991B-E19E-44C0-BC5A-FE244B49FD7C}
2016-08-04 19:40 - 2016-08-04 19:40 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2016-08-04 19:40 - 2016-08-04 19:40 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2016-08-04 19:28 - 2016-08-04 19:28 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default\AppData\Local\ATI
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-08-04 19:28 - 2016-08-04 19:28 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI
2016-08-04 19:16 - 2016-08-04 19:16 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2016-08-04 19:14 - 2016-08-04 19:29 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-08-04 19:11 - 2016-08-08 19:58 - 00000000 ____D C:\Users\Felix
2016-08-04 19:11 - 2016-08-04 19:48 - 00000000 ____D C:\Users\Manager Jodle
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Vorlagen
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Startmenü
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Netzwerkumgebung
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Lokale Einstellungen
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Eigene Dateien
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Druckumgebung
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Documents\Eigene Videos
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Documents\Eigene Musik
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Documents\Eigene Bilder
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\AppData\Local\Verlauf
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\AppData\Local\Anwendungsdaten
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Manager Jodle\Anwendungsdaten
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Vorlagen
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Startmenü
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Netzwerkumgebung
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Lokale Einstellungen
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Eigene Dateien
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Druckumgebung
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Documents\Eigene Videos
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Documents\Eigene Musik
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Documents\Eigene Bilder
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\AppData\Local\Verlauf
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\AppData\Local\Anwendungsdaten
2016-08-04 19:11 - 2016-08-04 19:11 - 00000000 _SHDL C:\Users\Felix\Anwendungsdaten
2016-08-04 19:07 - 2016-08-04 19:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2016-08-04 19:07 - 2016-08-04 19:07 - 00000000 ____D C:\Program Files\ATI Technologies
2016-08-04 19:06 - 2016-08-04 19:17 - 00000000 ____D C:\ProgramData\Package Cache
2016-08-04 19:06 - 2016-08-04 19:07 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2016-08-04 19:05 - 2016-08-04 19:05 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2016-08-04 19:05 - 2016-08-04 19:05 - 00000000 ____D C:\Program Files\AMD
2016-08-04 19:05 - 2016-08-04 19:05 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2016-08-04 19:05 - 2016-07-16 13:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-08-04 19:04 - 2016-08-04 19:04 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-08-04 19:04 - 2016-08-04 19:04 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-08-04 19:04 - 2016-08-04 19:04 - 00000000 ____D C:\WINDOWS\system32\DAX2
2016-08-04 19:04 - 2016-08-04 19:04 - 00000000 ____D C:\Program Files\Realtek
2016-08-04 19:02 - 2016-08-08 19:56 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-08-04 19:02 - 2016-08-06 20:32 - 00339664 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-04 19:02 - 2016-08-04 19:02 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-08-04 16:38 - 2016-08-04 17:40 - 00000000 ___HD C:\$WINDOWS.~BT
2016-08-04 16:32 - 2016-08-04 16:38 - 00000036 _____ C:\WINDOWS\progress.ini
2016-08-04 15:04 - 2016-08-04 21:23 - 00000000 ___HD C:\$GetCurrent
2016-08-01 14:40 - 2016-08-04 21:36 - 00000000 ____D C:\Windows10Upgrade
2016-08-01 14:40 - 2016-08-04 14:49 - 00000807 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10-Upgrade-Assistent.lnk
2016-08-01 14:40 - 2016-08-04 14:49 - 00000795 _____ C:\Users\Felix\Desktop\Windows 10-Upgrade-Assistent.lnk
2016-07-29 22:40 - 2016-07-29 22:40 - 00000000 ____D C:\Users\Felix\Documents\StarCraft II
2016-07-29 17:01 - 2016-07-29 17:01 - 00000219 _____ C:\Users\Felix\Desktop\Dota 2.url
2016-07-29 16:42 - 2016-08-06 20:51 - 00000000 ____D C:\AdwCleaner
2016-07-29 16:41 - 2016-07-29 16:41 - 03712064 _____ C:\Users\Felix\Desktop\adwcleaner_5.201.exe
2016-07-29 16:27 - 2016-07-29 16:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-07-29 12:15 - 2016-07-29 12:15 - 06079168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2016-07-17 00:58 - 2016-07-17 00:58 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\quickassist.exe
2016-07-17 00:57 - 2016-07-16 13:43 - 00033498 _____ C:\WINDOWS\Core.xml
2016-07-17 00:52 - 2016-08-04 19:56 - 00000000 ____D C:\WINDOWS\OCR
2016-07-17 00:51 - 2016-08-06 20:39 - 00539960 _____ C:\WINDOWS\system32\perfh007.dat
2016-07-17 00:51 - 2016-08-06 20:39 - 00108676 _____ C:\WINDOWS\system32\perfc007.dat
2016-07-17 00:51 - 2016-07-17 00:51 - 00000000 ____D C:\WINDOWS\SKB
2016-07-17 00:51 - 2016-07-17 00:50 - 00305594 _____ C:\WINDOWS\system32\perfi007.dat
2016-07-17 00:51 - 2016-07-17 00:50 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat
2016-07-17 00:50 - 2016-08-04 19:21 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\de
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\winrm
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\de
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\0409
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-07-16 14:40 - 2016-07-16 14:40 - 00000000 _SHDL C:\Users\Default User
2016-07-16 14:40 - 2016-07-16 14:40 - 00000000 _SHDL C:\Users\All Users
2016-07-16 13:49 - 2016-08-04 20:00 - 00000000 ____D C:\WINDOWS\Setup
2016-07-16 13:49 - 2016-07-16 13:44 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-07-16 13:49 - 2016-07-16 13:44 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-07-16 13:47 - 2016-08-08 19:30 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-07-16 13:47 - 2016-08-06 20:31 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-07-16 13:47 - 2016-08-06 17:14 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-07-16 13:47 - 2016-08-06 13:49 - 00000000 ___HD C:\Program Files\WindowsApps
2016-07-16 13:47 - 2016-08-05 18:07 - 00000000 ____D C:\WINDOWS\appcompat
2016-07-16 13:47 - 2016-08-04 20:00 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-07-16 13:47 - 2016-08-04 20:00 - 00000000 ____D C:\WINDOWS\rescache
2016-07-16 13:47 - 2016-08-04 19:55 - 00000000 ____D C:\ProgramData\USOPrivate
2016-07-16 13:47 - 2016-08-04 19:53 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-07-16 13:47 - 2016-08-04 19:53 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-07-16 13:47 - 2016-08-04 19:53 - 00000000 ____D C:\Program Files\Windows NT
2016-07-16 13:47 - 2016-08-04 19:48 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-07-16 13:47 - 2016-08-04 19:48 - 00000000 ____D C:\WINDOWS\Registration
2016-07-16 13:47 - 2016-08-04 19:39 - 00000000 __RSD C:\WINDOWS\Media
2016-07-16 13:47 - 2016-08-04 19:39 - 00000000 __RHD C:\Users\Public\Libraries
2016-07-16 13:47 - 2016-08-04 19:29 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2016-07-16 13:47 - 2016-08-04 19:21 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-07-16 13:47 - 2016-08-04 19:21 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-07-16 13:47 - 2016-08-04 19:20 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-07-16 13:47 - 2016-08-04 19:20 - 00000000 ____D C:\WINDOWS\system32\spool
2016-07-16 13:47 - 2016-08-04 19:20 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-07-16 13:47 - 2016-08-04 19:20 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-07-16 13:47 - 2016-08-04 19:20 - 00000000 ____D C:\WINDOWS\system32\IME
2016-07-16 13:47 - 2016-08-04 19:17 - 00000000 ____D C:\WINDOWS\schemas
2016-07-16 13:47 - 2016-08-04 19:17 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-07-16 13:47 - 2016-08-04 19:17 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-07-16 13:47 - 2016-08-04 19:16 - 00000000 __SHD C:\Program Files\Windows Sidebar
2016-07-16 13:47 - 2016-08-04 19:16 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2016-07-16 13:47 - 2016-08-04 19:16 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-07-16 13:47 - 2016-08-04 19:06 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-07-16 13:47 - 2016-08-04 19:06 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-07-16 13:47 - 2016-07-17 00:57 - 00000000 ____D C:\WINDOWS\SystemApps
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\setup
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\Com
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\IME
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\Help
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\Program Files\Windows Defender
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\Program Files\Common Files\System
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-07-16 13:47 - 2016-07-17 00:50 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\Nui
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Web
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Vss
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\tracing
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\TAPI
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SystemResources
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\winevt
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\ras
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\icsxml
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\ias
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\DDFs
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\System
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\security
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SchCache
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Resources
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Provisioning
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\PLA
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Performance
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\L2Schemas
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\InputMethod
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\InfusedApps
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Globalization
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Cursors
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Branding
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\addins
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\Comms
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\Services
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows NT
2016-07-16 13:47 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-07-16 13:47 - 2016-07-16 13:45 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2016-07-16 13:47 - 2016-07-16 13:45 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2016-07-16 13:47 - 2016-07-16 13:45 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2016-07-16 13:47 - 2016-07-16 13:45 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2016-07-16 13:47 - 2016-07-16 13:45 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2016-07-16 13:47 - 2016-07-16 13:45 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK
2016-07-16 13:47 - 2016-07-16 13:45 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2016-07-16 13:47 - 2016-07-16 13:45 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2016-07-16 13:47 - 2016-07-16 13:45 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2016-07-16 13:47 - 2016-07-16 13:45 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2016-07-16 13:45 - 2016-08-08 20:03 - 00000000 ____D C:\WINDOWS\INF
2016-07-16 13:44 - 2016-07-17 00:56 - 02549760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkAnalysisLegacyCom.dll
2016-07-16 13:44 - 2016-07-17 00:56 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll
2016-07-16 13:44 - 2016-07-17 00:56 - 00268552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpendp.dll
2016-07-16 13:44 - 2016-07-17 00:56 - 00177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2016-07-16 13:44 - 2016-07-17 00:56 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfdts.dll
2016-07-16 13:44 - 2016-07-17 00:56 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rfxvmt.dll
2016-07-16 13:44 - 2016-07-17 00:51 - 12039168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0007.dll
2016-07-16 13:44 - 2016-07-17 00:51 - 12039168 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0007.dll
2016-07-16 13:44 - 2016-07-17 00:51 - 02083328 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0007.dll
2016-07-16 13:44 - 2016-07-17 00:51 - 01997312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0007.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 32693432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 31664048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 19422208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 19417088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 13431808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 12342272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 11854848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-07-16 13:44 - 2016-07-16 13:44 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-07-16 13:44 - 2016-07-16 13:44 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 04827280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-07-16 13:44 - 2016-07-16 13:44 - 02231288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2016-07-16 13:44 - 2016-07-16 13:44 - 02065408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 02002944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 01362512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 01197712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 01195008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 01025680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00987848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSRESM.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSRESM.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00858624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSST.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00707216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFSR.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00645472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-07-16 13:44 - 2016-07-16 13:44 - 00644608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSSVC.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2016-07-16 13:44 - 2016-07-16 13:44 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00522752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2016-07-16 13:44 - 2016-07-16 13:44 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpunits.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00484552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00473600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00473600 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceStatus.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceStatus.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswmdm.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMPOSE.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSTIFF.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provsvc.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00361984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPDSp.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2PGraph.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswmdm.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2016-07-16 13:44 - 2016-07-16 13:44 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srchadmin.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDSp.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcl.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00292872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\photowiz.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00283136 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00279960 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00273232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMASF.DLL
2016-07-16 13:44 - 2016-07-16 13:44 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cewmdm.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\elshyph.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXST30.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\audiodev.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\srrstr.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cewmdm.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOVER.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\unregmp2.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpeval.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drt.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spp.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\elshyph.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00204288 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unregmp2.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceTypes.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSUTILITY.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\p2pnetsh.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrdc.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmidx.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceTypes.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00153912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpps.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00141824 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceWiaCompat.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wclPowrProf.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\occache.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\repair-bde.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wclUnicode.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\racpldlg.dll
2016-07-16 13:44 - 2016-07-16 13:44 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2016-07-16 13:44 - 2016-07-16 13:44 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll |