Benfuzius | 27.05.2017 09:10 | Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=41e60950d669214686519ef29aadb28e
# end=init
# utc_time=2017-05-26 11:22:06
# local_time=2017-05-27 01:22:06 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=41e60950d669214686519ef29aadb28e
# end=init
# utc_time=2017-05-26 11:23:36
# local_time=2017-05-27 01:23:36 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=53251
Update Finalize
Updated modules version: 33521
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=41e60950d669214686519ef29aadb28e
# end=updated
# utc_time=2017-05-26 11:28:16
# local_time=2017-05-27 01:28:16 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=41e60950d669214686519ef29aadb28e
# engine=33521
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-05-26 11:30:17
# local_time=2017-05-27 01:30:17 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Avira Antivirus'
# compatibility_mode=1815 16777213 100 96 751 4017997 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 5860464 5974413 0 0
# scanned=2355
# found=23
# cleaned=0
# scan_time=120
sh=80E3B051D394DF29D0A6FE1DD33BA9D9BEF25816 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\cbcuncqfnurslenrzsrkytlqotkemfgn.back"
sh=BFEBCC9BB71F5DC848B97A1729EED8D645634AB5 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\fkuyzhjyaaaigqmuccamrqhrtaondlri.back"
sh=7C43C4E28A1C8069CE419CBCD5BBCF022A992AC9 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\jmniuqhozklcjomqouzlwwqtxqmysyqy.back"
sh=83C6ED41104019B7858964E639DFD42ACCA3C871 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\jztoqhksumzcgneubyfegdpfljimtdwt.back"
sh=81BD2F1B77C6DE92CC8E8F2C164316E344986AC6 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\kbpcbnqnlduqrtokferwvbuihmqtrnpu.back"
sh=31BC16DC577DA59A97935DB484294E765A73EF27 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\mgjbwclbbmjolgjhllrkqqsnkqfecnwe.back"
sh=52700AD31B474287C6D8746DD9706380517D7F8E ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\ouvzuymdxxlgimpzdmacgndlnshxjrqq.back"
sh=BC60C49C12C28CF3587A53C35BE2344B293EE6F6 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\oyplbwqlrezttbdsojiroupgofzdzria.back"
sh=BA9508D76B608D4426084C787231221EEF2C6AA2 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\pblxxyxjnokrsvzykcqvbhiuqmwijrih.back"
sh=D38A52F8DDC907E02449075964F35DA2A76D1779 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\qidcjjiopctdfwgitscmpzbtpajhkgtb.back"
sh=22F69A1BD9A63AC674418FEC7D63CC5748F09D15 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\qmfwgycybpvlrrmdnozfirhqyxcibdgo.back"
sh=69392184E3C4ACC33C67DFA7FC009EBA57192F69 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\vcearwmealudgmuaeubhmhpfbfoeavvc.back"
sh=AD932BEC1ED2CD035CD4D788448AC71F669DF3A0 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\vfthqtsjxwkvpbpoezhgnwqytcqeowtg.back"
sh=69392184E3C4ACC33C67DFA7FC009EBA57192F69 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\xahyseqpqjuepmrliauleeuvpouwnvkk.back"
sh=AE1BF605197154D2AAB82854AA0E8DACE54A1F57 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\xywmknjchidlwgcavwchiwihekkwpxvb.back"
sh=2040273C0186D9D63C6F6426587E86336E670249 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\yetyctrwnxxpzjxkufdysmhoawedtiwi.back"
sh=F710BF21AC78925B8296B5327C817DED2D3DEC6A ft=1 fh=46df646d91958a59 vn="Variante von Win32/Adware.OnlineIO.A Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\hgggdznzqfewbpomwhgcffmnkaxrswag\Online Application\Version 2.6.0\Online-Guardian.exe"
sh=9516BE8DF910FF582FE5B967C7C38BE2AD334C2B ft=1 fh=d3d62eb55e18ca8c vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\hydlwplyvedyqhfgpxhqzamgurjbwpsn\dmr_72.exe"
sh=06E33278D473995EBB843A1FC99E964929DD9AD4 ft=1 fh=99ac218d6441f30b vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\itremesxwafnxgmttevbhxghxxzpkbod\dmr_72.exe"
sh=6F86B0C40819785B3F42F4E5DCF8513BA2DFF3F8 ft=1 fh=e3f410659c8acd62 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\MainService.exe"
sh=0C0C68AF84FC2970F8494E0B781812981F36F77E ft=1 fh=31dde2c0b3b8597c vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\PGChk.exe"
sh=F3B9857A368514A6BF35626F6769E4387EDE8DA3 ft=1 fh=efdd74c811ae89b7 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\ProxyGate.exe"
sh=EE05E27A26C3852A835A007ADD1B89AFE5DD9B88 ft=1 fh=389f12129e92bc03 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\TrafficMonitor.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=41e60950d669214686519ef29aadb28e
# end=init
# utc_time=2017-05-26 11:30:44
# local_time=2017-05-27 01:30:44 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=53251
Update Finalize
Updated modules version: 33521
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=41e60950d669214686519ef29aadb28e
# end=updated
# utc_time=2017-05-26 11:31:24
# local_time=2017-05-27 01:31:24 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=41e60950d669214686519ef29aadb28e
# engine=33521
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-05-27 01:22:16
# local_time=2017-05-27 03:22:16 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Avira Antivirus'
# compatibility_mode=1815 16777213 100 96 7470 4024716 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 5867183 5981132 0 0
# scanned=522028
# found=36
# cleaned=36
# scan_time=6652
sh=80E3B051D394DF29D0A6FE1DD33BA9D9BEF25816 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\cbcuncqfnurslenrzsrkytlqotkemfgn.back"
sh=BFEBCC9BB71F5DC848B97A1729EED8D645634AB5 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\fkuyzhjyaaaigqmuccamrqhrtaondlri.back"
sh=7C43C4E28A1C8069CE419CBCD5BBCF022A992AC9 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\jmniuqhozklcjomqouzlwwqtxqmysyqy.back"
sh=83C6ED41104019B7858964E639DFD42ACCA3C871 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\jztoqhksumzcgneubyfegdpfljimtdwt.back"
sh=81BD2F1B77C6DE92CC8E8F2C164316E344986AC6 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\kbpcbnqnlduqrtokferwvbuihmqtrnpu.back"
sh=31BC16DC577DA59A97935DB484294E765A73EF27 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\mgjbwclbbmjolgjhllrkqqsnkqfecnwe.back"
sh=52700AD31B474287C6D8746DD9706380517D7F8E ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\ouvzuymdxxlgimpzdmacgndlnshxjrqq.back"
sh=BC60C49C12C28CF3587A53C35BE2344B293EE6F6 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\oyplbwqlrezttbdsojiroupgofzdzria.back"
sh=BA9508D76B608D4426084C787231221EEF2C6AA2 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\pblxxyxjnokrsvzykcqvbhiuqmwijrih.back"
sh=D38A52F8DDC907E02449075964F35DA2A76D1779 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\qidcjjiopctdfwgitscmpzbtpajhkgtb.back"
sh=22F69A1BD9A63AC674418FEC7D63CC5748F09D15 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\qmfwgycybpvlrrmdnozfirhqyxcibdgo.back"
sh=69392184E3C4ACC33C67DFA7FC009EBA57192F69 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\vcearwmealudgmuaeubhmhpfbfoeavvc.back"
sh=AD932BEC1ED2CD035CD4D788448AC71F669DF3A0 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\vfthqtsjxwkvpbpoezhgnwqytcqeowtg.back"
sh=69392184E3C4ACC33C67DFA7FC009EBA57192F69 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\xahyseqpqjuepmrliauleeuvpouwnvkk.back"
sh=AE1BF605197154D2AAB82854AA0E8DACE54A1F57 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\xywmknjchidlwgcavwchiwihekkwpxvb.back"
sh=2040273C0186D9D63C6F6426587E86336E670249 ft=0 fh=0000000000000000 vn="LNK/URL.B Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\yetyctrwnxxpzjxkufdysmhoawedtiwi.back"
sh=F710BF21AC78925B8296B5327C817DED2D3DEC6A ft=1 fh=46df646d91958a59 vn="Variante von Win32/Adware.OnlineIO.A Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\hgggdznzqfewbpomwhgcffmnkaxrswag\Online Application\Version 2.6.0\Online-Guardian.exe"
sh=9516BE8DF910FF582FE5B967C7C38BE2AD334C2B ft=1 fh=d3d62eb55e18ca8c vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\hydlwplyvedyqhfgpxhqzamgurjbwpsn\dmr_72.exe"
sh=06E33278D473995EBB843A1FC99E964929DD9AD4 ft=1 fh=99ac218d6441f30b vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\itremesxwafnxgmttevbhxghxxzpkbod\dmr_72.exe"
sh=6F86B0C40819785B3F42F4E5DCF8513BA2DFF3F8 ft=1 fh=e3f410659c8acd62 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\MainService.exe"
sh=0C0C68AF84FC2970F8494E0B781812981F36F77E ft=1 fh=31dde2c0b3b8597c vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\PGChk.exe"
sh=F3B9857A368514A6BF35626F6769E4387EDE8DA3 ft=1 fh=efdd74c811ae89b7 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\ProxyGate.exe"
sh=EE05E27A26C3852A835A007ADD1B89AFE5DD9B88 ft=1 fh=389f12129e92bc03 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\quarantine\files\zzewukjrezjchnjvfkozjtzvperkirlv\TrafficMonitor.exe"
sh=EADAACEE76E5A41DCFA778B2A717A6C5492D4333 ft=1 fh=ae39654526f12bd7 vn="MSIL/Adware.OxyPumper.Z Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\FRST\Quarantine\C\ProgramData\VideoMemoryDiagnostic\vmdiag.exe"
sh=419C5AB1B55753B3010A10165F2BFAD6CAC00D00 ft=0 fh=0000000000000000 vn="Win32/Adware.ELEX.NA Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\FRST\Quarantine\C\WINDOWS\system32\Tasks\Microsoft\Windows\DeviceSettings\Canikcoeqot.xBAD"
sh=51E624FD6CEAD5C006BDF5304E85C0E77965C17F ft=1 fh=edacf395d4a6c576 vn="Variante von Win64/Wdfload.O Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\FRST\Quarantine\C\WINDOWS\TEMP\g2182.tmp.exe.xBAD"
sh=6AF71872453EF3FCC1B3564C362F3A23F1E56302 ft=1 fh=d481be170ed2dfb7 vn="Variante von Win64/CoinMiner.BM Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\FRST\Quarantine\C\WINDOWS\TEMP\g2183.tmp.exe.xBAD"
sh=F848B3A8000ABB5C3CF7506F5E255B36150E2E7B ft=1 fh=14dc238ce6bca2a4 vn="Variante von Win32/Wdfload.O Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\FRST\Quarantine\C\WINDOWS\TEMP\gD49D.tmp.exe.xBAD"
sh=9F37EAA2CFCBEC2F0994E035A051550E2A519A70 ft=1 fh=72dbde777f705092 vn="Variante von Win64/Snarasite.F Trojaner (Gesäubert durch Löschen)" ac=C fn="C:\Users\Romo\AppData\Local\CWASRE.del\Snare.dll.DEL.del"
sh=98C843CE7B9491B1A4306233159E827027F9CF42 ft=1 fh=b4aff101dc8bc016 vn="Variante von Win32/Adware.ELEX.QM Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Users\Romo\AppData\Roaming\WINSAPSVC.del\WinSAP.dll.DEL.del"
sh=70704EDAD359E3B56074F1CEEE9B19F5BDD72017 ft=1 fh=ff05a928f67cf153 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="E:\$RECYCLE.BIN\S-1-5-21-2079666805-3719247669-552477099-1000\$R0TBNU4.exe"
sh=0A30E59AD7F9BE15D5DE7E8935078B64B7C247F5 ft=1 fh=41ae133d5f518b35 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="E:\$RECYCLE.BIN\S-1-5-21-2079666805-3719247669-552477099-1000\$R86OON8.exe"
sh=DC373C8C16A03F94956C41538C94C76F3F9A5C0B ft=1 fh=280e24c3a0c3a761 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="E:\saves\BlueScreenView - CHIP-Installer.exe"
sh=CEC709E1D26F99EB1016E65B6FEB705760F1D698 ft=1 fh=986086a4d1d18202 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="E:\saves\Everest Ultimate Edition - CHIP-Installer.exe"
sh=A8A0ED307B6B8DBAF94C5B386BC1DAF5F8C487CB ft=1 fh=9e70669d81383bee vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="E:\saves\MemTest - CHIP-Installer.exe"
sh=0734591FF52AD0718A04D3D7785F40953B03E63A ft=1 fh=f68359e4b9f4a3d9 vn="Variante von Win32/Toolbar.Conduit.AE eventuell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="E:\saves\SpeedFan_TSV38C8M.exe" Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 24-05-2017
durchgeführt von Romo (Administrator) auf ROMO-PC (27-05-2017 10:07:09)
Gestartet von C:\Users\Romo\Desktop
Geladene Profile: Romo & (Verfügbare Profile: Romo & DefaultAppPool)
Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Malwarebytes) E:\Programme\Anti-Malware\mbamtray.exe
(Akamai Technologies, Inc.) C:\Users\Romo\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Romo\AppData\Local\Akamai\netsession_win.exe
(Malwarebytes) E:\Programme\Anti-Malware\MBAMService.exe
(Spotify Ltd) C:\Users\Romo\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Dropbox, Inc.) C:\Users\Romo\AppData\Local\Dropbox\Update\DropboxUpdate.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(Dropbox, Inc.) C:\Users\Romo\AppData\Roaming\Dropbox\bin\Dropbox.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Dropbox, Inc.) C:\Users\Romo\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
(Dropbox, Inc.) C:\Users\Romo\AppData\Roaming\Dropbox\bin\Dropbox.exe
(DivX, LLC) C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.16.595.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-05-28] (Intel Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => E:\PROGRAMME\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [433160 2015-09-04] (DivX, LLC)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861640 2015-06-27] (DivX, LLC)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [97512 2017-05-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [67168 2017-04-07] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [912768 2017-04-10] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2079666805-3719247669-552477099-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Romo\AppData\Local\Akamai\netsession_win.exe [4490200 2017-01-03] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2079666805-3719247669-552477099-1000\...\Run: [Spotify Web Helper] => C:\Users\Romo\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-05-04] (Spotify Ltd)
HKU\S-1-5-21-2079666805-3719247669-552477099-1000\...\Run: [Dropbox Update] => C:\Users\Romo\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
HKU\S-1-5-21-2079666805-3719247669-552477099-1000\...\Run: [Discord] => C:\Users\Romo\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-05272017011856608\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517120 2017-03-18] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Romo\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Romo\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Romo\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Romo\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Romo\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Romo\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Romo\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-16] (Dropbox, Inc.)
Startup: C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2017-05-18]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-05-18]
ShortcutTarget: Dropbox.lnk -> C:\Users\Romo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{036d7a67-7b1c-4223-8046-161aceeb7c40}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-26] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-26] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: msfz6nh6.default-1495082881402
FF ProfilePath: C:\Users\Romo\AppData\Roaming\Mozilla\Firefox\Profiles\msfz6nh6.default-1495082881402 [2017-05-27]
FF Homepage: Mozilla\Firefox\Profiles\msfz6nh6.default-1495082881402 -> www.google.de/
FF Extension: (Avira Browser Safety) - C:\Users\Romo\AppData\Roaming\Mozilla\Firefox\Profiles\msfz6nh6.default-1495082881402\Extensions\abs@avira.com [2017-05-26]
FF Extension: (Ghostery) - C:\Users\Romo\AppData\Roaming\Mozilla\Firefox\Profiles\msfz6nh6.default-1495082881402\Extensions\firefox@ghostery.com.xpi [2017-05-20]
FF Extension: (Avira Password Manager) - C:\Users\Romo\AppData\Roaming\Mozilla\Firefox\Profiles\msfz6nh6.default-1495082881402\Extensions\passwordmanager@avira.com [2017-05-26]
FF Extension: (Avira SafeSearch Plus) - C:\Users\Romo\AppData\Roaming\Mozilla\Firefox\Profiles\msfz6nh6.default-1495082881402\Extensions\safesearchplus2@avira.com [2017-05-26]
FF Extension: (Adblock Plus) - C:\Users\Romo\AppData\Roaming\Mozilla\Firefox\Profiles\msfz6nh6.default-1495082881402\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-05-19]
FF HKU\S-1-5-21-2079666805-3719247669-552477099-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Romo\AppData\Roaming\Mozilla\Firefox\Profiles\0o0j768i.default\extensions\cliqz@cliqz.com => nicht gefunden
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-09] ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2015-12-27] (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> E:\Programme\VLC\npvlc.dll [2013-11-12] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-09] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2015-10-28] (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-26] (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei]
FF Plugin-x32: @scout.avira-update.com/Avira Scout Update;version=3 -> C:\Program Files (x86)\Avira\Scout Update\1.3.32.7\npScoutUpdate3.dll [2017-05-26] (Avira Operations GmbH & Co. KG)
FF Plugin-x32: @scout.avira-update.com/Avira Scout Update;version=9 -> C:\Program Files (x86)\Avira\Scout Update\1.3.32.7\npScoutUpdate3.dll [2017-05-26] (Avira Operations GmbH & Co. KG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData2
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2015-01-22] (Adobe Systems) [Datei ist nicht signiert]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1119712 2017-04-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [488920 2017-04-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [488920 2017-04-10] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1520680 2017-04-10] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [374352 2017-05-22] (Avira Operations GmbH & Co. KG)
R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [334064 2017-05-18] (Avira Operations GmbH & Co. KG)
R2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [100816 2017-04-21] (Avira Operations GmbH & Co. KG)
S3 GalaxyClientService; E:\Programme\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-14] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7184440 2015-12-27] (GOG.com)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-05-28] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-04-03] (Intel Corporation)
R2 MBAMService; E:\Programme\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-05-03] (NVIDIA Corporation)
S3 Origin Client Service; E:\Programme\Origin\OriginClientService.exe [2004488 2015-07-03] (Electronic Arts)
S2 scupdate; C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe [114824 2017-05-26] (Avira Operations GmbH & Co. KG)
S3 scupdatem; C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe [114824 2017-05-26] (Avira Operations GmbH & Co. KG)
R2 SpeedupService; C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe [74800 2017-04-07] (Avira Operations GmbH & Co. KG)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [161824 2017-04-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [163976 2017-04-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-04-10] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-04-10] (Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [48584 2017-04-10] (Avira Operations GmbH & Co. KG)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-05-09] ()
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-05-21] (REALiX(tm))
S3 ISCT; C:\WINDOWS\System32\DRIVERS\ISCTD64.sys [46568 2013-02-13] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [187320 2017-05-27] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [113592 2017-05-27] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-05-27] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [251832 2017-05-27] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93624 2017-05-27] (Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys [14456944 2017-05-02] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-05-03] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48248 2017-05-03] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59448 2017-05-02] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [36808 2016-10-18] (Wellbia.com Co., Ltd.)
U3 idsvc; kein ImagePath
U0 Partizan; system32\drivers\Partizan.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Code:
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-05-27 01:23 - 2017-05-27 01:21 - 02870984 _____ (ESET) C:\Users\Romo\Desktop\esetsmartinstaller_deu.exe
2017-05-27 01:21 - 2017-05-27 01:21 - 00000000 ____D C:\Program Files (x86)\ESET
2017-05-27 01:16 - 2017-05-27 01:16 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Avira
2017-05-26 01:36 - 2017-05-26 01:36 - 00000000 ____D C:\Users\Romo\AppData\Local\AviraSpeedup
2017-05-26 01:33 - 2017-05-26 01:33 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2017-05-26 01:33 - 2017-04-10 13:23 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2017-05-26 01:33 - 2017-04-10 13:23 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2017-05-26 01:33 - 2017-04-10 13:23 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2017-05-26 01:33 - 2017-04-10 13:23 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2017-05-26 01:33 - 2017-04-10 13:23 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2017-05-26 01:25 - 2017-05-26 01:25 - 00003812 _____ C:\WINDOWS\System32\Tasks\AviraScoutUpdateTaskMachineUA
2017-05-26 01:25 - 2017-05-26 01:25 - 00003688 _____ C:\WINDOWS\System32\Tasks\AviraScoutUpdateTaskMachineCore
2017-05-26 01:24 - 2017-05-27 01:16 - 00000000 ____D C:\Users\Romo\AppData\Local\Avira
2017-05-26 01:24 - 2017-05-26 01:24 - 00000000 ____D C:\WINDOWS\System32\Tasks\Avira
2017-05-26 01:23 - 2017-05-27 01:17 - 00000000 ____D C:\Users\Public\Speedup Sessions
2017-05-26 01:23 - 2017-05-26 01:23 - 00003766 _____ C:\WINDOWS\System32\Tasks\AviraSystemSpeedupUpdate
2017-05-26 01:21 - 2017-05-26 01:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-05-26 01:21 - 2017-05-26 01:33 - 00000000 ____D C:\Program Files (x86)\Avira
2017-05-26 01:21 - 2017-05-26 01:21 - 00001284 _____ C:\Users\Public\Desktop\Avira Connect.lnk
2017-05-26 01:17 - 2017-05-26 01:17 - 00002406 _____ C:\Users\Romo\Desktop\antmalw.txt
2017-05-26 01:07 - 2017-05-27 05:27 - 00093624 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-05-26 01:07 - 2017-05-27 01:16 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-05-26 01:07 - 2017-05-27 01:16 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-05-26 01:07 - 2017-05-26 01:07 - 00000785 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-05-26 01:07 - 2017-05-26 01:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-05-26 01:07 - 2017-05-09 16:37 - 00077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-05-25 14:51 - 2017-05-27 10:07 - 00021941 _____ C:\Users\Romo\Desktop\FRST.txt
2017-05-25 14:51 - 2017-05-25 14:52 - 00069470 _____ C:\Users\Romo\Desktop\Addition.txt
2017-05-25 14:39 - 2017-05-25 14:39 - 04110280 _____ C:\Users\Romo\Desktop\adwcleaner_6.047.exe
2017-05-21 13:53 - 2017-05-21 13:53 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2017-05-21 13:53 - 2017-05-21 13:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO32
2017-05-20 11:15 - 2017-05-20 11:15 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2017-05-20 11:14 - 2017-05-20 11:14 - 00000020 ___SH C:\Users\Romo\ntuser.ini
2017-05-20 06:47 - 2017-05-20 06:47 - 23681024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 21353200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 20505600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 20374424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 19335168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 11870208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 08320920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 08244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 06759512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 04848440 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 04446208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 03672064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 03655680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02957824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02651648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02635336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 02443776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02435584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02298880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02158544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-05-20 06:47 - 2017-05-20 06:47 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-05-20 06:47 - 2017-05-20 06:47 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01803264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01604312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01411128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01325456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01295872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 01103872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01075712 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01027584 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 01024416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00775824 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00626520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00605936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-05-20 06:47 - 2017-05-20 06:47 - 00543640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-05-20 06:47 - 2017-05-20 06:47 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-05-20 06:47 - 2017-05-20 06:47 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00207264 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00142240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-05-20 06:47 - 2017-05-20 06:47 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-05-20 06:47 - 2017-05-20 06:47 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-05-20 06:47 - 2017-05-20 06:47 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
2017-05-20 06:47 - 2017-05-20 06:47 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-05-20 06:47 - 2017-05-20 06:47 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-05-20 06:47 - 2017-05-20 06:47 - 00000000 ____D C:\Windows.old
2017-05-20 06:45 - 2017-05-20 06:45 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-05-20 06:45 - 2017-05-20 05:49 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-05-20 06:45 - 2017-03-17 23:00 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2017-05-20 06:45 - 2017-03-17 22:59 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2017-05-20 06:45 - 2017-03-17 22:48 - 06348288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2017-05-20 06:45 - 2017-03-17 22:43 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2017-05-20 06:45 - 2017-03-17 22:35 - 05484544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\WINDOWS\system32\msmq
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\Program Files\MSBuild
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-05-20 06:44 - 2017-05-20 06:44 - 00000000 ____D C:\inetpub
2017-05-20 06:44 - 2017-05-20 05:51 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-05-20 06:44 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-05-20 06:44 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-05-20 06:44 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-05-20 06:43 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-05-20 06:43 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-05-20 06:43 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-05-20 06:03 - 2017-05-20 06:03 - 00000000 ____D C:\ProgramData\USOShared
2017-05-20 05:55 - 2017-05-20 05:55 - 00011433 _____ C:\WINDOWS\diagwrn.xml
2017-05-20 05:55 - 2017-05-20 05:55 - 00011433 _____ C:\WINDOWS\diagerr.xml
2017-05-20 05:54 - 2017-05-27 09:56 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26661E06-5450-424E-91E2-146996F2F0F4}
2017-05-20 05:54 - 2017-05-26 01:15 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-20 05:54 - 2017-05-20 11:16 - 00003272 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-05-20 05:54 - 2017-05-20 05:54 - 00003942 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2079666805-3719247669-552477099-1000UA1d2370fbcc1d718
2017-05-20 05:54 - 2017-05-20 05:54 - 00003674 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2079666805-3719247669-552477099-1000Core1d2370fbcb80c1d
2017-05-20 05:54 - 2017-05-20 05:54 - 00003556 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-20 05:54 - 2017-05-20 05:54 - 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-05-20 05:54 - 2017-05-20 05:54 - 00003398 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00003376 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-05-20 05:54 - 2017-05-20 05:54 - 00003332 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-05-20 05:54 - 2017-05-20 05:54 - 00003324 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1434919741
2017-05-20 05:54 - 2017-05-20 05:54 - 00003176 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002984 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002968 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002956 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002838 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002786 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002744 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002214 _____ C:\WINDOWS\System32\Tasks\{65070599-A99C-4B44-93A5-3EA3305E965F}
2017-05-20 05:54 - 2017-05-20 05:54 - 00002200 _____ C:\WINDOWS\System32\Tasks\{41A9DB71-6E8A-41AB-85D6-F344D227C96F}
2017-05-20 05:54 - 2017-05-20 05:54 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2017-05-20 05:54 - 2017-05-20 05:54 - 00000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2017-05-20 05:54 - 2017-05-20 05:54 - 00000000 ____D C:\WINDOWS\System32\Tasks\Abelssoft
2017-05-20 05:52 - 2017-05-20 05:52 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-05-20 05:51 - 2017-05-20 05:53 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-05-20 05:51 - 2017-05-20 05:51 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2017-05-20 05:51 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-05-20 05:50 - 2017-05-27 01:18 - 00000000 ____D C:\ProgramData\NVIDIA
2017-05-20 05:50 - 2017-05-26 01:22 - 02197380 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-20 05:50 - 2017-05-26 01:06 - 00000000 ____D C:\Users\Romo
2017-05-20 05:50 - 2017-05-20 05:54 - 00000000 ____D C:\Users\DefaultAppPool
2017-05-20 05:50 - 2017-05-20 05:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-05-20 05:50 - 2017-05-20 05:51 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-05-20 05:50 - 2017-05-20 05:51 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-05-20 05:50 - 2017-05-20 05:50 - 02011386 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Vorlagen
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Startmenü
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Netzwerkumgebung
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Lokale Einstellungen
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Eigene Dateien
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Druckumgebung
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Documents\Eigene Videos
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Documents\Eigene Musik
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Documents\Eigene Bilder
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\AppData\Local\Verlauf
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\AppData\Local\Anwendungsdaten
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\Romo\Anwendungsdaten
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-05-20 05:50 - 2017-05-20 05:50 - 00000000 ____D C:\Program Files\Realtek
2017-05-20 05:50 - 2017-05-01 22:52 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-05-20 05:50 - 2017-05-01 22:51 - 06437312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-05-20 05:50 - 2017-05-01 22:51 - 02479552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-05-20 05:50 - 2017-05-01 22:51 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-05-20 05:50 - 2017-05-01 22:51 - 00548800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-05-20 05:50 - 2017-05-01 22:51 - 00392312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-05-20 05:50 - 2017-05-01 22:51 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-05-20 05:50 - 2017-05-01 22:51 - 00069752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-05-20 05:50 - 2017-04-25 23:11 - 07944687 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-05-20 05:49 - 2017-05-25 14:43 - 00293920 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-05-20 05:49 - 2017-05-20 05:49 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-05-18 15:04 - 2017-05-27 01:16 - 00251832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-05-18 15:04 - 2017-05-26 01:07 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-05-18 15:04 - 2017-05-19 16:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-05-18 15:02 - 2017-05-27 01:16 - 00187320 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-05-18 15:02 - 2017-05-19 01:41 - 00000000 ____D C:\Users\Romo\mbar
2017-05-18 14:24 - 2017-05-18 14:24 - 00000000 ____D C:\WINDOWS\system32\sstmp
2017-05-18 05:36 - 2017-05-20 05:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-05-18 05:36 - 2017-05-18 15:21 - 00000751 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2017-05-18 01:45 - 2017-05-20 05:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cycle Addon for WYSIWYG Web Builder
2017-05-18 01:44 - 2017-05-20 05:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FluidBox Addon for WYSIWYG Web Builder
2017-05-18 01:44 - 2017-05-18 01:45 - 00000909 _____ C:\WINDOWS\Cycle Addon for WYSIWYG Web Builder Setup Log.txt
2017-05-18 01:44 - 2017-05-18 01:44 - 00000893 _____ C:\WINDOWS\FluidBox Addon for WYSIWYG Web Builder Setup Log.txt
2017-05-18 01:43 - 2017-05-20 05:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FaceBox Addon for WYSIWYG Web Builder
2017-05-18 01:43 - 2017-05-18 01:44 - 00737280 _____ (Indigo Rose Corporation) C:\WINDOWS\iun6002.exe
2017-05-18 01:42 - 2017-05-18 01:43 - 00001298 _____ C:\WINDOWS\FaceBox Addon for WYSIWYG Web Builder Setup Log.txt
2017-05-18 00:22 - 2017-05-20 05:53 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-05-17 13:31 - 2017-05-27 10:07 - 00000000 ____D C:\FRST
2017-05-17 13:30 - 2017-05-25 14:51 - 02429952 _____ (Farbar) C:\Users\Romo\Desktop\FRST64.exe
2017-05-17 01:45 - 2017-05-17 01:48 - 00147978 _____ C:\TDSSKiller.3.1.0.15_17.05.2017_01.45.27_log.txt
2017-05-17 01:41 - 2017-05-17 15:19 - 00000000 ____D C:\Program Files\REIMAGE.del
2017-05-16 11:17 - 2017-05-18 15:11 - 00000000 ____D C:\ProgramData\BIT.del
2017-05-16 11:16 - 2017-05-27 03:21 - 00000000 ____D C:\Users\Romo\AppData\Roaming\WINSAPSVC.del
2017-05-16 11:16 - 2017-05-27 03:21 - 00000000 ____D C:\Users\Romo\AppData\Local\CWASRE.del
2017-05-15 23:29 - 2017-05-19 21:50 - 00000254 _____ C:\WINDOWS\SysWOW64\PARTIZAN.TXT
2017-05-15 23:28 - 2017-05-18 14:46 - 00000000 ____D C:\@RestoreQuarantine
2017-05-15 23:18 - 2017-05-20 11:15 - 00000000 ____D C:\Users\Romo\Documents\RegRun2
2017-05-15 23:18 - 2017-05-19 04:04 - 00000000 ____D C:\ProgramData\RegRun
2017-05-15 23:18 - 2017-05-15 23:18 - 00000002 RSHOT C:\WINDOWS\winstart.bat
2017-05-15 23:18 - 2017-05-15 23:18 - 00000002 RSHOT C:\WINDOWS\SysWOW64\CONFIG.NT
2017-05-15 23:18 - 2017-05-15 23:18 - 00000002 RSHOT C:\WINDOWS\SysWOW64\AUTOEXEC.NT
2017-05-15 23:15 - 2017-05-27 01:16 - 00000000 ____D C:\Users\Romo\AppData\Local\Discord
2017-05-15 23:15 - 2017-05-18 15:21 - 00002269 _____ C:\Users\Romo\Desktop\Discord.lnk
2017-05-15 22:39 - 2017-05-15 22:39 - 03124864 _____ (ESET) C:\Users\Romo\Downloads\eset_nod32_antivirus_live_installer_rt_de.exe
2017-05-15 22:14 - 2017-05-15 22:45 - 00009571 _____ C:\Users\Romo\Desktop\pad.odt
2017-05-15 22:04 - 2017-05-25 14:42 - 00000000 ____D C:\AdwCleaner
2017-05-15 20:47 - 2017-05-26 01:37 - 00000000 ___DC C:\WINDOWS\Panther
2017-05-15 20:21 - 2017-05-15 20:23 - 00000000 ____D C:\Users\Romo\AppData\Local\navitool
2017-05-15 19:55 - 2017-05-15 19:56 - 04102600 _____ C:\Users\Romo\Downloads\adwcleaner_6.046.exe
2017-05-15 19:42 - 2017-05-15 19:42 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-05-15 15:19 - 2017-05-15 15:19 - 00140800 _____ C:\Users\Romo\AppData\Local\installer.dat
2017-05-15 15:19 - 2017-05-15 15:19 - 00011568 _____ C:\Users\Romo\AppData\Local\InstallationConfiguration.xml
2017-05-15 15:18 - 2017-05-15 15:18 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics
2017-05-15 15:18 - 2017-05-15 15:18 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics
2017-05-10 18:24 - 2017-05-01 22:14 - 00134592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2017-05-10 18:22 - 2017-05-02 00:38 - 40201848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 35388864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 35281528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 28623480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 11056456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 11024384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 10547440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 09245744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 09014792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 08805232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 04092088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 03792320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 03607464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 03247736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 01988032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438205.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 01600560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 01589696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438205.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 01278528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 01276128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 01054144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00995736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00993872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00991168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00960960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00911992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00821184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00776048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00688968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00651200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00618744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00612088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00609912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00577728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00499320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00218040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2017-05-10 18:22 - 2017-05-02 00:38 - 00059448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-05-10 18:22 - 2017-05-02 00:38 - 00046008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2017-05-10 18:22 - 2017-05-02 00:38 - 00045061 _____ C:\WINDOWS\system32\nvinfo.pb
2017-05-10 18:22 - 2017-05-02 00:38 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-05-10 18:22 - 2017-05-02 00:38 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-05-10 14:23 - 2017-03-04 08:26 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2017-05-10 13:52 - 2017-05-03 22:21 - 00175736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-05-10 13:52 - 2017-05-03 22:21 - 00143480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-05-10 13:52 - 2017-05-03 22:21 - 00048248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-05-04 18:57 - 2017-05-04 18:57 - 00000000 ____D C:\Users\Romo\Documents\League of Legends
2017-05-04 12:21 - 2017-05-18 15:21 - 00000787 _____ C:\Users\Public\Desktop\WYSIWYG Web Builder 12.lnk
2017-05-04 12:21 - 2017-05-18 15:21 - 00000787 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WYSIWYG Web Builder 12.lnk
2017-05-04 12:21 - 2017-05-04 12:39 - 00000000 ____D C:\Users\Romo\Documents\WYSIWYG Web Builder
2017-05-02 23:11 - 2017-05-02 23:11 - 00017484 _____ C:\Users\Romo\Desktop\Pubquizfragen.odt
2017-04-29 18:02 - 2017-04-29 19:02 - 00021275 _____ C:\Users\Romo\Desktop\Pubquiz (Benny).odt Code:
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-05-27 01:21 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-27 01:21 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-27 01:17 - 2016-11-20 05:03 - 00000000 ____D C:\Users\Romo\AppData\LocalLow\Mozilla
2017-05-27 01:16 - 2016-09-19 02:40 - 00000000 ____D C:\Users\Romo\AppData\Roaming\discord
2017-05-26 01:40 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF
2017-05-26 01:37 - 2016-10-05 15:24 - 00000000 ____D C:\Users\Romo\AppData\Local\ConnectedDevicesPlatform
2017-05-26 01:37 - 2013-12-22 06:35 - 00000000 ____D C:\Program Files (x86)\Raptr
2017-05-26 01:33 - 2013-12-20 20:23 - 00000000 ____D C:\ProgramData\Avira
2017-05-26 01:22 - 2017-03-20 06:35 - 00944540 _____ C:\WINDOWS\system32\perfh007.dat
2017-05-26 01:22 - 2017-03-20 06:35 - 00213898 _____ C:\WINDOWS\system32\perfc007.dat
2017-05-26 01:21 - 2015-08-01 17:59 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-26 01:15 - 2017-03-18 13:40 - 01048576 _____ C:\WINDOWS\system32\config\BBI
2017-05-25 19:31 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache
2017-05-25 17:24 - 2013-12-21 03:40 - 00000000 ____D C:\ProgramData\Adobe
2017-05-25 17:24 - 2013-12-20 19:22 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Adobe
2017-05-25 14:42 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration
2017-05-23 15:54 - 2013-12-20 19:11 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-23 15:53 - 2013-12-20 19:11 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-23 15:05 - 2015-10-12 12:24 - 00000000 ____D C:\Users\Romo\AppData\Local\NVIDIA Corporation
2017-05-21 03:27 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat
2017-05-20 13:15 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-05-20 11:30 - 2015-08-01 19:58 - 00000000 ____D C:\Users\Romo\AppData\Local\Packages
2017-05-20 11:21 - 2016-11-05 01:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-05-20 11:16 - 2015-08-01 20:00 - 00002421 _____ C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-05-20 11:16 - 2015-08-01 20:00 - 00000000 ___RD C:\Users\Romo\OneDrive
2017-05-20 11:15 - 2015-06-18 18:42 - 00000000 ____D C:\Users\Romo\AppData\Local\Dropbox
2017-05-20 11:14 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-05-20 11:14 - 2015-08-01 20:41 - 00000000 ____D C:\Users\Romo\AppData\Local\MicrosoftEdge
2017-05-20 11:14 - 2015-08-01 19:58 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-20 06:49 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-05-20 06:47 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-20 06:47 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-20 06:47 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-05-20 06:45 - 2017-03-20 06:36 - 00000000 ____D C:\WINDOWS\OCR
2017-05-20 06:44 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-05-20 06:44 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-05-20 06:44 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-05-20 06:44 - 2017-03-18 22:59 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2017-05-20 06:44 - 2017-03-18 22:59 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2017-05-20 06:44 - 2017-03-18 22:59 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2017-05-20 06:44 - 2017-03-18 22:59 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2017-05-20 06:44 - 2017-03-18 22:59 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2017-05-20 06:44 - 2017-03-18 22:59 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2017-05-20 06:44 - 2017-03-18 22:59 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2017-05-20 06:44 - 2017-03-18 22:59 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2017-05-20 06:44 - 2017-03-18 22:56 - 01380352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2017-05-20 06:44 - 2017-03-18 22:56 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2017-05-20 06:44 - 2017-03-18 22:56 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2017-05-20 06:44 - 2017-03-18 22:56 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2017-05-20 06:44 - 2017-03-18 22:56 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2017-05-20 06:44 - 2017-03-18 22:56 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2017-05-20 06:44 - 2017-03-18 22:56 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2017-05-20 06:44 - 2017-03-18 22:56 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2017-05-20 06:44 - 2017-03-18 22:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2017-05-20 06:44 - 2017-03-18 22:56 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2017-05-20 06:44 - 2017-03-18 22:56 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2017-05-20 06:44 - 2017-03-18 22:56 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2017-05-20 06:44 - 2017-03-18 22:56 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2017-05-20 06:44 - 2017-03-18 22:56 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2017-05-20 06:44 - 2017-03-18 22:56 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2017-05-20 06:03 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate
2017-05-20 05:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-05-20 05:56 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT
2017-05-20 05:55 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-20 05:55 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-05-20 05:54 - 2017-03-20 06:37 - 00000000 ____D C:\WINDOWS\HoloShell
2017-05-20 05:54 - 2017-03-18 23:03 - 00000000 __RSD C:\WINDOWS\Media
2017-05-20 05:54 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-05-20 05:54 - 2015-08-01 18:04 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-05-20 05:53 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-05-20 05:53 - 2017-01-31 10:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-05-20 05:53 - 2016-01-10 13:07 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
2017-05-20 05:53 - 2015-10-12 12:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-05-20 05:53 - 2015-08-18 18:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2017-05-20 05:53 - 2015-01-22 04:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2017-05-20 05:53 - 2014-12-13 14:34 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ
2017-05-20 05:53 - 2014-11-24 02:41 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCitizen
2017-05-20 05:53 - 2014-11-19 20:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved
2017-05-20 05:53 - 2014-11-03 19:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-05-20 05:53 - 2014-09-06 07:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2017-05-20 05:53 - 2014-08-20 18:56 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2017-05-20 05:53 - 2014-05-15 18:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2017-05-20 05:53 - 2014-01-03 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2017-05-20 05:53 - 2014-01-02 02:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-05-20 05:53 - 2014-01-02 02:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2017-05-20 05:53 - 2013-12-30 02:46 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-05-20 05:53 - 2013-12-30 02:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-05-20 05:53 - 2013-12-21 03:45 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2017-05-20 05:53 - 2013-12-20 19:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-05-20 05:53 - 2013-12-20 18:09 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2017-05-20 05:53 - 2013-12-20 18:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2017-05-20 05:53 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-05-20 05:52 - 2017-03-20 06:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-05-20 05:52 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-05-20 05:52 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-05-20 05:52 - 2014-05-01 08:43 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files\Windows Sidebar
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\IME
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\System
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\schemas
2017-05-20 05:51 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-05-20 05:51 - 2016-09-19 02:40 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
2017-05-20 05:51 - 2016-02-05 18:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest
2017-05-20 05:51 - 2015-11-01 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-05-20 05:51 - 2015-10-16 20:32 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2017-05-20 05:51 - 2015-09-01 16:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-05-20 05:51 - 2015-05-11 23:42 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\minon
2017-05-20 05:51 - 2014-08-16 05:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2017-05-20 05:51 - 2014-08-12 02:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AeriaGames
2017-05-20 05:51 - 2013-12-20 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2017-05-20 05:51 - 2013-12-20 18:07 - 00000000 ____D C:\Program Files\Intel
2017-05-20 05:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games
2017-05-20 05:50 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Help
2017-05-20 05:50 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-05-20 05:37 - 2017-03-20 07:06 - 00000000 ___HD C:\$WINDOWS.~BT
2017-05-18 15:21 - 2017-01-31 10:13 - 00002218 _____ C:\Users\Public\Desktop\Google Earth.lnk
2017-05-18 15:21 - 2016-11-14 17:58 - 00001482 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-05-18 15:21 - 2016-05-07 04:54 - 00001144 _____ C:\Users\Romo\Desktop\Overwatch Launcher.lnk
2017-05-18 15:21 - 2016-05-01 00:41 - 00000820 _____ C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2017-05-18 15:21 - 2015-12-15 01:55 - 00001577 _____ C:\Users\Romo\Desktop\Rechner.lnk
2017-05-18 15:21 - 2015-11-01 22:08 - 00000743 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
2017-05-18 15:21 - 2015-11-01 22:03 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-05-18 15:21 - 2015-10-06 21:48 - 00001133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-05-18 15:21 - 2015-10-06 21:48 - 00001115 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-05-18 15:21 - 2015-09-02 03:54 - 00000737 _____ C:\Users\Public\Desktop\League of Legends.lnk
2017-05-18 15:21 - 2015-08-01 20:00 - 00001050 _____ C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2017-05-18 15:21 - 2015-06-21 22:49 - 00001123 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2017-05-18 15:21 - 2015-06-21 22:49 - 00001108 _____ C:\Users\Public\Desktop\Opera.lnk
2017-05-18 15:21 - 2015-05-08 21:40 - 00001370 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-18 15:21 - 2015-03-23 16:35 - 00001803 _____ C:\Users\Romo\Desktop\Spotify.lnk
2017-05-18 15:21 - 2015-03-23 16:35 - 00001789 _____ C:\Users\Romo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2017-05-18 15:21 - 2015-01-22 04:14 - 00001077 _____ C:\Users\Romo\Desktop\Photoshop.lnk
2017-05-18 15:21 - 2015-01-22 04:10 - 00002088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help Center.lnk
2017-05-18 15:21 - 2015-01-22 04:10 - 00002070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge.lnk
2017-05-18 15:21 - 2015-01-22 04:10 - 00001652 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS2.lnk
2017-05-18 15:21 - 2015-01-22 04:10 - 00001647 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady CS2.lnk
2017-05-18 15:21 - 2014-11-24 02:41 - 00000814 _____ C:\Users\Romo\Desktop\StarCitizen.lnk
2017-05-18 15:21 - 2014-11-09 06:02 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk
2017-05-18 15:21 - 2014-08-16 05:42 - 00000669 _____ C:\Users\Romo\Desktop\EVEREST Ultimate Edition.lnk
2017-05-18 15:21 - 2014-07-04 15:26 - 00000804 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2017-05-18 15:21 - 2014-07-04 15:26 - 00000742 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2017-05-18 15:21 - 2014-05-15 18:46 - 00000650 _____ C:\Users\Public\Desktop\Origin.lnk
2017-05-18 15:21 - 2014-01-08 02:19 - 00000650 _____ C:\Users\Romo\Desktop\Caritas.lnk
2017-05-18 15:21 - 2014-01-03 17:59 - 00000766 _____ C:\Users\Public\Desktop\Battle.net.lnk
2017-05-18 15:21 - 2014-01-02 02:13 - 00000618 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-05-18 15:21 - 2014-01-01 20:06 - 00001017 _____ C:\Users\Romo\Desktop\Dropbox.lnk
2017-05-18 15:21 - 2013-12-21 03:45 - 00001110 _____ C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk
2017-05-18 15:21 - 2013-12-20 21:12 - 00000710 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2017-05-18 15:21 - 2013-12-20 20:59 - 00000670 _____ C:\Users\Romo\Desktop\SpeedFan.lnk
2017-05-18 15:21 - 2013-12-20 19:35 - 00000636 _____ C:\Users\Public\Desktop\Steam.lnk
2017-05-18 15:21 - 2013-12-20 18:50 - 00001174 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2017-05-18 15:21 - 2013-12-20 18:50 - 00001156 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk
2017-05-18 15:19 - 2015-06-21 22:48 - 00000000 ____D C:\Program Files (x86)\Opera
2017-05-18 15:11 - 2016-07-16 08:04 - 00000000 ____D C:\Program Files\HP Deskjet 3840 Series
2017-05-18 14:29 - 2015-03-23 16:35 - 00000000 ____D C:\Users\Romo\AppData\Local\Spotify
2017-05-18 14:29 - 2015-03-23 16:34 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Spotify
2017-05-18 14:20 - 2015-02-12 22:48 - 00000000 ____D C:\Users\Romo\AppData\LocalLow\Temp
2017-05-18 00:23 - 2014-01-01 20:04 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Dropbox
2017-05-17 16:17 - 2014-01-10 18:50 - 00000000 ____D C:\Users\Romo\AppData\Local\CrashDumps
2017-05-17 01:29 - 2013-12-20 20:24 - 00000000 ____D C:\Users\Romo\AppData\Roaming\Avira
2017-05-15 23:29 - 2017-01-26 21:46 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-05-15 23:24 - 2013-12-20 19:18 - 00000000 ____D C:\ProgramData\McAfee
2017-05-15 23:15 - 2016-09-19 02:40 - 00000000 ____D C:\Users\Romo\AppData\Local\SquirrelTemp
2017-05-15 22:10 - 2016-07-16 08:04 - 00000000 ____D C:\Program Files\SlickIt
2017-05-15 20:10 - 2016-07-16 08:04 - 00000000 ____D C:\Program Files\RezenCourt
2017-05-09 16:53 - 2017-01-26 21:46 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-05-03 22:21 - 2016-11-14 17:57 - 01893496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-05-03 22:21 - 2016-11-14 17:57 - 01755256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-05-03 22:21 - 2016-11-14 17:57 - 01477240 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-05-03 22:21 - 2016-11-14 17:57 - 01317496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-05-03 22:21 - 2016-11-14 17:57 - 00121464 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-05-03 21:28 - 2017-04-26 00:44 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-04-29 03:05 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-04-29 03:05 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2005-04-04 18:56 - 2005-04-04 18:56 - 0003580 _____ () C:\Program Files\Bitte zuerst lesen.html
2005-04-07 16:07 - 2005-04-07 16:07 - 0014601 _____ () C:\Program Files\Installationsanleitung.html
2005-02-25 15:37 - 2005-02-25 15:37 - 0157035 _____ () C:\Program Files\LegalNotices.pdf
2005-03-24 16:28 - 2005-03-24 16:28 - 0383996 _____ () C:\Program Files\Photoshop Neue Funktionen.pdf
2017-05-15 15:19 - 2017-05-15 15:19 - 0011568 _____ () C:\Users\Romo\AppData\Local\InstallationConfiguration.xml
2017-05-15 15:19 - 2017-05-15 15:19 - 0140800 _____ () C:\Users\Romo\AppData\Local\installer.dat
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-05-20 05:49
==================== Ende von FRST.txt ============================ |