Pascatotal | 21.04.2017 21:09 | FRST Teil 2 Code:
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-21 22:03 - 2016-12-25 20:21 - 00000000 ____D C:\Users\Pascal\AppData\Roaming\Skype
2017-04-21 21:24 - 2017-01-03 02:53 - 00004174 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{819D65E5-BCFE-403C-B73A-13FB9DB011B1}
2017-04-21 21:21 - 2016-12-25 21:03 - 00000000 ____D C:\Program Files (x86)\Steam
2017-04-21 21:10 - 2016-12-26 07:14 - 01518210 _____ C:\WINDOWS\system32\perfh007.dat
2017-04-21 21:10 - 2016-12-26 07:14 - 00405664 _____ C:\WINDOWS\system32\perfc007.dat
2017-04-21 21:10 - 2016-12-25 20:09 - 03492540 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-04-21 21:05 - 2016-12-25 22:21 - 00000000 ____D C:\ProgramData\NVIDIA
2017-04-21 21:03 - 2016-12-25 22:24 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-04-21 21:03 - 2016-12-25 22:22 - 00000000 ____D C:\Users\Pascal
2017-04-21 21:03 - 2016-12-25 22:21 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-04-21 21:03 - 2016-12-25 20:14 - 00000000 __SHD C:\Users\Pascal\IntelGraphicsProfiles
2017-04-21 21:03 - 2016-07-16 08:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-04-21 21:02 - 2017-01-14 13:17 - 00000000 ____D C:\AdwCleaner
2017-04-21 21:02 - 2016-12-25 21:27 - 00000000 ____D C:\Users\Pascal\AppData\LocalLow\IObit
2017-04-21 20:50 - 2016-12-25 22:51 - 00000000 ____D C:\Users\Pascal\AppData\Local\CrashDumps
2017-04-21 20:39 - 2016-12-25 22:20 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-04-21 17:15 - 2016-12-25 21:03 - 00000000 ____D C:\Users\Pascal\AppData\Local\Spotify
2017-04-21 17:08 - 2016-12-25 21:03 - 00000000 ____D C:\Users\Pascal\AppData\Roaming\Spotify
2017-04-21 16:22 - 2016-12-26 01:18 - 00000000 ____D C:\Program Files\Adobe
2017-04-21 16:20 - 2016-12-26 01:19 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-04-21 16:20 - 2016-12-26 01:14 - 00000000 ____D C:\Users\Pascal\AppData\Local\Adobe
2017-04-21 16:20 - 2016-12-25 20:05 - 00000000 ____D C:\Users\Pascal\AppData\Roaming\Adobe
2017-04-21 16:19 - 2016-12-26 01:22 - 00000000 ____D C:\Users\Pascal\Documents\Adobe
2017-04-21 16:19 - 2016-12-26 01:17 - 00000000 ____D C:\ProgramData\Adobe
2017-04-21 16:14 - 2016-12-26 01:23 - 00000000 ___RD C:\Users\Pascal\Creative Cloud Files
2017-04-21 16:14 - 2016-12-26 01:23 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-04-21 16:14 - 2016-12-26 01:17 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-04-21 15:12 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-04-21 15:11 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-04-21 15:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-04-21 04:05 - 2016-12-25 21:27 - 00000000 ____D C:\ProgramData\ProductData
2017-04-21 04:05 - 2016-12-25 20:06 - 00000000 ___RD C:\Users\Pascal\OneDrive
2017-04-20 01:50 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-04-19 03:12 - 2017-01-14 06:01 - 00000000 ____D C:\Users\Pascal\AppData\Roaming\Audacity
2017-04-18 00:48 - 2016-12-25 20:06 - 00002390 _____ C:\Users\Pascal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-04-16 20:24 - 2016-12-26 22:53 - 00001279 _____ C:\Users\Public\Desktop\OBS Studio.lnk
2017-04-16 20:24 - 2016-12-26 22:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2017-04-16 01:24 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2017-04-15 21:20 - 2017-03-19 17:34 - 00000000 ____D C:\Users\Pascal\AppData\Local\CyberLink
2017-04-15 20:01 - 2017-03-19 17:32 - 00000000 ____D C:\ProgramData\CyberLink
2017-04-15 19:59 - 2017-03-19 17:34 - 00000000 ____D C:\Program Files (x86)\NSIS Uninstall Information
2017-04-15 19:59 - 2017-03-19 17:33 - 00000000 ____D C:\ProgramData\SUPPORTDIR
2017-04-15 19:59 - 2017-01-02 23:13 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-04-15 19:58 - 2017-03-19 17:34 - 00000000 ____D C:\Program Files (x86)\CyberLink
2017-04-15 19:58 - 2017-03-19 17:33 - 00000000 ____D C:\ProgramData\install_clap
2017-04-15 02:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2017-04-14 02:35 - 2017-01-15 16:09 - 00000000 ____D C:\Users\Pascal\AppData\Roaming\TS3Client
2017-04-12 17:49 - 2016-12-25 22:20 - 00275776 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-04-12 17:49 - 2016-12-25 20:05 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\setup
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Provisioning
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-04-12 17:48 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-04-12 17:48 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-04-12 14:13 - 2016-12-25 20:37 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-04-12 14:12 - 2016-12-25 20:36 - 148601744 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-04-12 14:12 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-04-11 12:42 - 2016-09-26 17:19 - 00253184 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx64.sys
2017-04-07 21:31 - 2016-12-27 23:51 - 00548392 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2017-04-07 20:13 - 2016-12-25 22:24 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-07 20:13 - 2016-12-25 22:24 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-05 22:14 - 2016-12-25 21:02 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-01 20:52 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-04-01 20:52 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-04-01 20:07 - 2017-03-11 22:37 - 00409128 _____ (EasyAntiCheat Ltd) C:\WINDOWS\SysWOW64\EasyAntiCheat.exe
2017-03-31 00:42 - 2017-01-13 16:38 - 00000000 ____D C:\Program Files (x86)\Image-Line
2017-03-31 00:42 - 2016-12-25 21:26 - 00000000 ____D C:\Users\Pascal\AppData\Roaming\IObit
2017-03-31 00:42 - 2016-12-25 21:26 - 00000000 ____D C:\ProgramData\IObit
2017-03-31 00:42 - 2016-12-25 21:04 - 00000000 ____D C:\Program Files\AVAST Software
2017-03-31 00:42 - 2016-12-25 21:03 - 00000000 ____D C:\ProgramData\AVAST Software
2017-03-31 00:22 - 2016-07-16 13:47 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-03-30 23:49 - 2017-01-07 00:42 - 00538088 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\e1d65x64.sys
2017-03-30 23:32 - 2017-01-13 16:40 - 00000000 ____D C:\Users\Pascal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-03-30 23:32 - 2017-01-13 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-03-30 23:29 - 2017-03-19 17:34 - 00000000 ____D C:\Program Files\NewBlue
2017-03-30 23:29 - 2017-03-19 17:34 - 00000000 ____D C:\Program Files (x86)\NewBlue
2017-03-30 23:29 - 2017-01-13 16:40 - 00000000 ____D C:\Program Files\Image-Line
2017-03-30 22:54 - 2016-12-25 22:21 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-03-30 22:54 - 2016-12-25 20:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-03-29 22:10 - 2016-12-26 07:20 - 00000000 ___DC C:\WINDOWS\Panther
2017-03-29 00:01 - 2017-02-23 18:40 - 00001291 _____ C:\Users\Pascal\Desktop\Google Chrome.lnk
2017-03-28 08:20 - 2016-12-25 22:21 - 02717184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-03-27 23:33 - 2016-12-25 20:05 - 00000000 ____D C:\Users\Pascal\AppData\Local\VirtualStore
==================== Files in the root of some directories =======
2017-02-04 16:10 - 2017-03-19 14:40 - 0004608 _____ () C:\Users\Pascal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-02-05 01:30 - 2017-02-05 01:30 - 0000787 _____ () C:\Users\Pascal\AppData\Local\recently-used.xbel
2016-12-25 22:21 - 2016-12-25 22:21 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-12-25 22:44 - 2017-01-25 21:21 - 0008442 _____ () C:\ProgramData\NvTelemetryContainer.log
2016-12-25 22:44 - 2017-01-21 09:48 - 0003355 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1
Some files in TEMP:
====================
2016-10-25 22:08 - 2016-10-25 22:08 - 0013312 _____ () C:\Users\Pascal\AppData\Local\Temp\DllFinder.exe
2016-10-26 01:24 - 2016-10-26 01:24 - 0015872 _____ () C:\Users\Pascal\AppData\Local\Temp\DllFinder_x64.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-04-13 23:15
==================== End of FRST.txt ============================ FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-04-2017
Ran by Pascal (21-04-2017 22:04:42)
Running from C:\Users\Pascal\Downloads
Windows 10 Pro Version 1607 (X64) (2016-12-25 20:25:43)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2308749031-3956874476-2735150935-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2308749031-3956874476-2735150935-503 - Limited - Disabled)
Guest (S-1-5-21-2308749031-3956874476-2735150935-501 - Limited - Disabled)
Pascal (S-1-5-21-2308749031-3956874476-2735150935-1001 - Administrator - Enabled) => C:\Users\Pascal
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Internet Security (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG Internet Security (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Bridge CC 2017 (HKLM-x32\...\KBRG_7_0) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.0.1.188 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.10 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1) (Version: 18.1.0 - Adobe Systems Incorporated)
Ansel (Version: 378.92 - NVIDIA Corporation) Hidden
Antares Autotune VST v5.09 (HKLM-x32\...\Antares Autotune VST_is1) (Version: - )
Arma 3 (HKLM\...\Steam App 107410) (Version: - Bohemia Interactive)
Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team)
AVG (Version: 16.151.8013 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4769 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.151.8013 - AVG Technologies)
Canon Utilities EOS Lens Registration Tool (HKLM-x32\...\EOS Lens Registration Tool) (Version: 1.3.0.1 - Canon Inc.)
Canon Utilities EOS Utility 2 (HKLM-x32\...\EOS Utility 2) (Version: 2.14.20.0 - Canon Inc.)
Canon Utilities EOS Web Service Registration Tool (HKLM-x32\...\EOS Web Service Registration Tool) (Version: 1.2.10.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform)
City Car Driving (HKLM\...\Steam App 493490) (Version: - Forward Development, Ltd.)
Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve)
CyberLink PowerDirector 15 (HKLM-x32\...\{FA285575-B543-4E6E-A573-A4F534AC9965}) (Version: 15.0.2509.0 - CyberLink Corp.)
CyberLink YouCam 7 (HKLM-x32\...\{0078CD4D-B146-4D77-8CF0-268B36C1A3EC}) (Version: 7.0.0623.0 - CyberLink Corp.)
DJI_DNG_Cleaner 1.1 (HKLM-x32\...\DJI_DNG_Cleaner) (Version: 1.1 - DJI)
Driver Booster 3 for STEAM (HKLM\...\Steam App 403040) (Version: - IObit)
Euro Truck Simulator 2 (HKLM\...\Steam App 227300) (Version: - SCS Software)
FaceRig (HKLM\...\Steam App 274920) (Version: - Holotech Studios)
FaceRig Virtual Video driver version 1.0.1.1000 (HKLM-x32\...\{7D6A1A0F-F57E-4C6B-9331-86CBC7D5C787}_is1) (Version: 1.0.1.1000 - Adoriasoft LLC)
Fences (HKLM\...\Steam App 607380) (Version: - Stardock)
FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
Gameforge Live 2.0.12 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.12 - Gameforge)
Google Chrome (HKLM\...\{83F2CE66-1F17-38DE-83BD-1BAD39009FB6}) (Version: 57.0.2987.133 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden
HD View (HKLM-x32\...\{7596C248-4816-4C6F-8AAC-D8C81F2B4B49}) (Version: 3.3.0 - Microsoft Research)
HITMAN™ (HKLM\...\Steam App 236870) (Version: - Io-Interactive)
Image Composite Editor (HKLM\...\{92AB5708-1AAA-4B1B-A8D5-45CF3AD77519}) (Version: 2.0.3 - Microsoft Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 6.2.0.940 - IObit)
IrfanView 4.44 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.44 - Irfan Skiljan)
Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
LibreOffice 5.2.6.2 (HKLM-x32\...\{443795BA-BBA0-46CF-A07F-DB5B461785F7}) (Version: 5.2.6.2 - The Document Foundation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Logitech Gaming Software 8.89 (HKLM\...\Logitech Gaming Software) (Version: 8.89.68 - Logitech Inc.)
Malwarebytes Version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Miscreated (HKLM\...\Steam App 299740) (Version: - Entrada Interactive LLC)
MSXML 4.0 SP2 Parser und SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation)
NVIDIA Grafiktreiber 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden
NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 18.0.1 - OBS Project)
Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.)
Personify ChromaCam (remove only) (HKLM-x32\...\Personify ChromaCam) (Version: 1.1.8.8 - Personify, Inc.)
Project CARS (HKLM\...\Steam App 234630) (Version: - Slightly Mad Studios)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8004 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.4 - Rockstar Games)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics)
SDFormatter (HKLM-x32\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\Spotify) (Version: 1.0.53.758.gde3fc4b2 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 1.5.0.0 - Zenimax Online Studios)
The Elder Scrolls Online: Tamriel Unlimited (HKLM\...\Steam App 306130) (Version: - Zenimax Online Studios)
The Forest (HKLM\...\Steam App 242760) (Version: - Endnight Games Ltd)
The I of the Dragon (HKLM\...\Steam App 279720) (Version: - Primal)
theHunter™: Call of the Wild (HKLM\...\Steam App 518790) (Version: - Expansive Worlds)
Thunder Master v2.22 (HKLM-x32\...\{EE04522C-0814-4B63-AE57-0B63E5A355BB}_is1) (Version: 2.22.1.1 - Palit Microsystems Ltd.)
Tom Clancy's Ghost Recon Wildlands (HKLM-x32\...\Uplay Install 1771) (Version: - Ubisoft)
Uplay (HKLM-x32\...\Uplay) (Version: 30.0 - Ubisoft)
VEGAS Pro 14.0 (64-bit) (HKLM\...\{9A3E4000-BE54-11E6-AB1C-BE9B4130C4C9}) (Version: 14.0.211 - VEGAS)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WebM Project Directshow Filters (HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\webmdshow) (Version: - )
WhatsApp (HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\WhatsApp) (Version: 0.2.3699 - WhatsApp)
Win32DiskImager version 0.9.5 (HKLM-x32\...\{D074CE74-912A-4AD3-A0BF-3937D9D01F17}_is1) (Version: 0.9.5 - ImageWriter Developers)
WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
Zoom (HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\ZoomUMX) (Version: 4.0 - Zoom Video Communications, Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2308749031-3956874476-2735150935-1001_Classes\CLSID\{1AC77AE9-9EC6-405A-9F9B-C06AB3C10B71}\InprocServer32 -> C:\Program Files\Microsoft Research\Image Composite Editor\ShellExtension.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2308749031-3956874476-2735150935-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {22505EE9-3CE7-4DA0-81B8-43965A6DDFBC} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.)
Task: {225327B6-A566-4C0B-BF06-53BFF82A0C65} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-25] (Google Inc.)
Task: {27F01FE4-9C5A-4195-970B-773F3FB694D7} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation)
Task: {33F7E325-CA52-42AF-AFF2-A60BAAF0D768} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation)
Task: {5A75F27B-E47B-41F1-96FE-172922E54EB7} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {63EDBB43-C6DB-416F-9458-DAF4A40DD6F2} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation)
Task: {656AF211-2112-42E7-864F-07208D5F69C3} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {6F49FA51-B219-41BC-8A9A-EBA6734B2B75} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation)
Task: {7304F7B8-FA29-4CF1-8CCE-B1293312B549} - System32\Tasks\Uninstaller_SkipUac_Pascal => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2017-02-10] (IObit)
Task: {785D95A4-9847-44D0-B9FD-32121A1B9B2D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation)
Task: {7ADFB165-5CD7-40E8-9CA2-AB5CE53FA177} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-25] (Google Inc.)
Task: {8C41BE15-A92E-44FF-A7B4-513E30ADC4E4} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation)
Task: {972C4F76-B38A-43AC-9BDB-C9D18F8658CE} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-S8R1U10-Pascal => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {A718BD9E-93F7-46E7-9D9E-54398275707E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd)
Task: {AEEFE69C-AFCE-4514-A9C7-291EA96A144F} - \ASC10_SkipUac_Pascal -> No File <==== ATTENTION
Task: {AF44FE84-5CD5-438C-808B-287D0E262218} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_Pascal.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-04-12 01:26 - 2017-03-28 08:22 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-12-25 22:21 - 2017-03-17 01:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-12-25 22:21 - 2013-07-04 04:32 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
2016-12-25 22:44 - 2017-02-23 20:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
2016-12-25 22:44 - 2017-02-23 20:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-03-31 00:01 - 2017-04-14 14:03 - 02271520 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-04-12 01:26 - 2017-03-28 08:22 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-10-25 09:57 - 2016-10-25 09:57 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2016-12-26 07:18 - 2016-12-26 07:18 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-14 21:25 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-14 21:25 - 2017-03-04 08:30 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll
2017-03-14 21:25 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-14 21:25 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-14 21:25 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-04-12 01:26 - 2017-03-28 07:07 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-04-12 01:26 - 2017-03-28 07:08 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-04-12 01:26 - 2017-03-28 07:11 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2016-12-08 22:47 - 2016-12-08 22:47 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2016-12-08 22:47 - 2016-12-08 22:47 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2017-04-11 11:55 - 2017-04-11 11:55 - 00077312 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-04-11 11:55 - 2017-04-11 11:55 - 00189952 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-04-11 11:55 - 2017-04-11 11:55 - 42507264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-04-11 11:55 - 2017-04-11 11:55 - 02334184 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\skypert.dll
2016-12-06 16:09 - 2016-12-06 16:09 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2017-04-05 22:14 - 2017-03-29 10:47 - 02885464 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libglesv2.dll
2017-04-05 22:14 - 2017-03-29 10:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libegl.dll
2017-04-05 16:39 - 2017-04-05 16:40 - 00019456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2017-04-05 16:39 - 2017-04-05 16:40 - 22723584 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-04-05 16:39 - 2017-04-05 16:40 - 00448512 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll
2017-04-05 16:39 - 2017-04-05 16:40 - 05427200 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2016-12-25 21:40 - 2016-12-25 21:41 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
2017-04-05 16:39 - 2017-04-05 16:40 - 00435712 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2017-04-05 16:39 - 2017-04-05 16:40 - 01062400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll
2016-12-25 21:40 - 2016-12-25 21:41 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2016-12-25 22:21 - 2017-04-21 21:03 - 00032256 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll
2016-12-25 22:21 - 2013-07-04 04:32 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\ATKEX.dll
2017-03-30 23:26 - 2016-06-21 19:30 - 00442144 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2017-03-30 23:26 - 2016-06-21 19:29 - 00210720 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2017-03-30 23:26 - 2016-06-21 19:29 - 00059680 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2016-12-28 01:08 - 2016-12-28 01:08 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll
2016-12-25 22:44 - 2017-02-23 20:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-12-25 22:44 - 2017-02-23 20:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll
2016-12-25 22:44 - 2017-02-23 20:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-01-30 13:52 - 2017-01-30 13:52 - 01926632 ____R () C:\Program Files (x86)\Skype\Phone\roottools.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 09028488 _____ () C:\Program Files (x86)\Personify\ChromaCam\PersonifyCameoUE.ax
2016-11-04 21:22 - 2016-11-04 21:22 - 16524168 _____ () C:\Program Files (x86)\Personify\ChromaCam\PersonifyApi.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 10803592 _____ () C:\Program Files (x86)\Personify\ChromaCam\psyplatform.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 08763784 _____ () C:\Program Files (x86)\Personify\ChromaCam\opencv_core310.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 00088456 _____ () C:\Program Files (x86)\Personify\ChromaCam\boost_thread-vc120-mt-1_56.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 00022920 _____ () C:\Program Files (x86)\Personify\ChromaCam\boost_system-vc120-mt-1_56.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 00106888 _____ () C:\Program Files (x86)\Personify\ChromaCam\boost_filesystem-vc120-mt-1_56.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 00046984 _____ () C:\Program Files (x86)\Personify\ChromaCam\boost_date_time-vc120-mt-1_56.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 00031624 _____ () C:\Program Files (x86)\Personify\ChromaCam\boost_chrono-vc120-mt-1_56.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 00526216 _____ () C:\Program Files (x86)\Personify\ChromaCam\boost_log-vc120-mt-1_56.dll
2016-11-04 21:22 - 2016-11-04 21:22 - 09458568 _____ () C:\Program Files (x86)\Personify\ChromaCam\PersonifyML.dll
2016-11-04 21:23 - 2016-11-04 21:23 - 00349576 _____ () C:\Program Files (x86)\Personify\ChromaCam\boost_program_options-vc120-mt-1_56.dll
2017-03-31 00:21 - 2017-03-31 00:13 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2016-12-25 22:44 - 2017-02-23 16:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
2016-12-25 22:44 - 2017-02-23 16:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
2016-12-25 22:44 - 2017-02-23 16:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
2016-12-25 22:44 - 2017-02-23 16:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
2016-12-25 22:44 - 2017-02-23 16:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
2016-12-25 22:44 - 2017-02-23 16:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
2016-12-25 21:18 - 2017-03-10 02:13 - 00674592 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2016-12-25 21:18 - 2016-09-01 03:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2016-12-25 21:18 - 2017-03-23 02:52 - 02465056 _____ () C:\Program Files (x86)\Steam\video.dll
2016-12-25 21:18 - 2016-09-01 03:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2016-12-25 21:18 - 2016-09-01 03:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2016-12-25 21:18 - 2016-01-27 09:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2016-12-25 21:18 - 2016-01-27 09:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2016-12-25 21:18 - 2016-01-27 09:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2016-12-25 21:18 - 2016-01-27 09:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2016-12-25 21:18 - 2016-01-27 09:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2016-12-25 21:18 - 2017-03-31 00:46 - 00848672 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2016-12-25 21:18 - 2016-07-05 00:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2016-12-25 21:18 - 2017-01-30 23:41 - 68875552 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2016-12-25 21:18 - 2017-03-23 02:52 - 00383776 _____ () C:\Program Files (x86)\Steam\steam.dll
2016-12-25 21:18 - 2015-09-25 01:52 - 00119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-30 09:24 - 2015-10-30 09:21 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Pascal\Desktop\533756.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2308749031-3956874476-2735150935-1001\...\StartupApproved\Run: => "Spotify Web Helper"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{4AE0B807-3A96-403A-A516-A88E3B645DD0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Driver Booster\DriverBooster.exe
FirewallRules: [{6DB25BB6-43E5-44FB-A493-14E00CABC6A5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Driver Booster\DriverBooster.exe
FirewallRules: [{C9E219A0-56AB-4414-A262-5F77FF0B56A5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{E8B2EE2E-88EF-491B-AFCF-C85B3CE8F927}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [UDP Query User{EB02AED1-4933-432F-8298-149847F9D2E0}C:\users\pascal\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\pascal\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{CC0A5BEA-F9E6-4870-B083-E7F750473F33}C:\users\pascal\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\pascal\appdata\roaming\spotify\spotify.exe
FirewallRules: [{31BE4882-B202-4340-84D6-5EB40FE03B70}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{BE872A04-3F63-476B-800D-6F8D11C1C47D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{034040D7-39D2-44A1-ABC1-6077381E9BD6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A721C171-19D8-4BFA-BCAA-D22D470D2224}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{4258C067-09AF-45F4-8812-8D98331E2B14}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{6D4DB081-9F1F-4DE6-B969-3E4EB7BD9EF1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{5885F8D6-9966-4BEE-BCB8-6F399D1BCD6E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{AB1FA94F-00E4-41F3-97A0-2EDE7C42983A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C6FD776D-55A5-4CE6-B363-136BD44A0272}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe
FirewallRules: [{47B46DA4-E4FC-40D4-BBA1-C920AC310A52}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe
FirewallRules: [{F7157740-F031-44B8-9D8F-8F0EE08FF404}] => (Allow) D:\SteamLibrary\steamapps\common\Arma 3\arma3launcher.exe
FirewallRules: [{08333CF3-8EE2-42ED-8A84-057890987182}] => (Allow) D:\SteamLibrary\steamapps\common\Arma 3\arma3launcher.exe
FirewallRules: [TCP Query User{19090EB0-AE73-4F0C-8E07-2161B3287DF7}D:\steamlibrary\steamapps\common\arma 3\arma3.exe] => (Allow) D:\steamlibrary\steamapps\common\arma 3\arma3.exe
FirewallRules: [UDP Query User{9B2309B5-19E4-489E-BCF1-1596A8F3EA1B}D:\steamlibrary\steamapps\common\arma 3\arma3.exe] => (Allow) D:\steamlibrary\steamapps\common\arma 3\arma3.exe
FirewallRules: [{D9BC54A1-E55A-4CDA-AB92-E3A5810EC0AA}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{F296876F-A2A3-4073-920E-201B8B3FBC95}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{050F91DB-21D7-4C89-AE6B-DBB74F610A2F}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{F8F232BE-EBEE-4DD3-805D-580702DAC80F}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{DAE359A8-E8DA-4200-A758-A6C3AEE5F978}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{ECFA746D-68E5-494D-8BF2-B62A1BC6BBAB}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [{D2088528-5ADA-4BF9-88AC-07281BCBAB53}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{C3A78748-E500-4B5A-BF64-8A1DD3EC8592}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{ABBB6D95-3CAD-4ABD-BBCC-4094E8F640DF}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
FirewallRules: [{8B308E3E-E91A-4DCC-A322-5B9AD7149A46}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
FirewallRules: [{05A0CE52-CFFF-4B60-AAAB-C37E7ED7F744}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{A305EC46-5A2A-4388-A0DE-7573845BBE79}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{99F7B41A-5625-42C3-AC2C-99FA703E949E}] => (Allow) D:\SteamLibrary\GameforgeLive\gfl_client.exe
FirewallRules: [{E9CF1A24-A01D-46F1-926C-1AE4525B94B3}] => (Allow) D:\SteamLibrary\steamapps\common\Hitman™\Launcher.exe
FirewallRules: [{23C5743D-684E-4ED6-9F04-3D9EBF01EE00}] => (Allow) D:\SteamLibrary\steamapps\common\Hitman™\Launcher.exe
FirewallRules: [{D7C2729E-9E55-4C3A-990B-ADD05C8C259F}] => (Allow) D:\SteamLibrary\steamapps\common\theHunterCotW\theHunterCotW_F.exe
FirewallRules: [{1D6166F1-715E-4359-A03E-9C019F0EA02D}] => (Allow) D:\SteamLibrary\steamapps\common\theHunterCotW\theHunterCotW_F.exe
FirewallRules: [{6120984B-CB8C-471F-8E65-08B1F29A0609}] => (Allow) D:\SteamLibrary\steamapps\common\Miscreated\Miscreated.exe
FirewallRules: [{51DC8194-933B-47FE-873F-72CFA23387F6}] => (Allow) D:\SteamLibrary\steamapps\common\Miscreated\Miscreated.exe
FirewallRules: [{49C60586-7931-4797-B481-91B2018B1181}] => (Allow) D:\SteamLibrary\steamapps\common\Miscreated\Bin64\Miscreated.exe
FirewallRules: [{3EC9E1CC-DA3F-4F04-A871-895144FC3343}] => (Allow) D:\SteamLibrary\steamapps\common\Miscreated\Bin64\Miscreated.exe
FirewallRules: [{9A760A68-7797-42BE-8227-FD6D385E29ED}] => (Allow) D:\SteamLibrary\steamapps\common\Miscreated\EasyAntiCheat\EasyAntiCheat_x64.dll
FirewallRules: [{BE8C225A-8871-4D7B-80C7-B3685F35BE62}] => (Allow) D:\SteamLibrary\steamapps\common\Miscreated\EasyAntiCheat\EasyAntiCheat_x64.dll
FirewallRules: [{27A40561-C4CD-4716-84A0-6FEE3C5230BB}] => (Allow) D:\SteamLibrary\steamapps\common\pCars\pCARS64.exe
FirewallRules: [{089D0E9A-AEE2-4D5D-88B0-C9E356150CC9}] => (Allow) D:\SteamLibrary\steamapps\common\pCars\pCARS64.exe
FirewallRules: [{2AE73F17-A258-4B4D-99EE-FAAA544687AE}] => (Allow) D:\SteamLibrary\steamapps\common\The I of the Dragon\TheIOfTheDragon.exe
FirewallRules: [{87851B70-00D1-470D-A9EF-9050A9A891C0}] => (Allow) D:\SteamLibrary\steamapps\common\The I of the Dragon\TheIOfTheDragon.exe
FirewallRules: [{CB972C05-035A-42AE-8F7D-AC498BBBA50F}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{6C651D79-9F77-4ABD-86BD-82538CE27F26}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{4FC63289-41A5-4199-A7D9-E8107B6EA2B6}] => (Allow) D:\SteamLibrary\steamapps\common\Fences\FencesBootstrap.exe
FirewallRules: [{034683C9-8E18-40B9-B9D9-E89AC32C87BF}] => (Allow) D:\SteamLibrary\steamapps\common\Fences\FencesBootstrap.exe
FirewallRules: [{5449C9C9-A86D-4A6C-9DBE-DA03A3F99122}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{8707511D-1B94-43A0-BA6F-74CB9CA99B04}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{00ABA77A-A24C-4A39-AA06-CA41F746C7E7}] => (Allow) D:\SteamLibrary\Tom Clancy's Ghost Recon Wildlands\GRW.exe
FirewallRules: [{2AE593A0-E6BC-4738-8EE7-EC4D89A2DC66}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{59F9DB17-4AA1-46B8-BA9C-88CC08E7CA6F}] => (Allow) D:\SteamLibrary\steamapps\common\Zenimax Online\zosSteamStarter.exe
FirewallRules: [{D7C852A9-7F8C-4035-B4FC-8CF8F6E29EC8}] => (Allow) D:\SteamLibrary\steamapps\common\Zenimax Online\zosSteamStarter.exe
FirewallRules: [{4703353D-56E5-45E1-A13E-657B38AF2260}] => (Allow) D:\SteamLibrary\steamapps\common\FaceRig\Bin\Launcher.exe
FirewallRules: [{21E81944-43C2-4856-9507-87489F6396AD}] => (Allow) D:\SteamLibrary\steamapps\common\FaceRig\Bin\Launcher.exe
FirewallRules: [{F2B80FDD-4325-43C9-89B0-02A1933A943E}] => (Allow) D:\SteamLibrary\steamapps\common\FaceRig\Bin\FaceRig.exe
FirewallRules: [{877E721E-FEF3-4667-8BF1-71C04561091E}] => (Allow) D:\SteamLibrary\steamapps\common\FaceRig\Bin\FaceRig.exe
FirewallRules: [{04D59113-5407-4242-A968-9D8D7E7BA7C4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{573B12F0-A72F-49E1-82F8-3D906C1407ED}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{DB8B46A3-CC8C-4193-8122-D445C47E36CB}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{ACA9FDF9-8609-41C2-96D4-842A30804EF2}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{99A704BD-FB5F-449F-947F-D5DC64BE44A6}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{DB83D976-0521-49F2-9FDC-00235A5D9198}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{0C7F9358-3104-4074-B7F0-D89261ADAC65}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
FirewallRules: [{4A95E5D3-79EB-4252-BA2A-561877CB84D1}] => (Allow) D:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
FirewallRules: [{AB2E39EB-CAD5-42A5-B059-852EEADE5C6E}] => (Allow) D:\SteamLibrary\steamapps\common\City Car Driving\bin\win32\Starter.exe
FirewallRules: [{781340DD-CE53-45D6-82E7-860738927A6D}] => (Allow) D:\SteamLibrary\steamapps\common\City Car Driving\bin\win32\Starter.exe
==================== Restore Points =========================
08-04-2017 12:52:14 Installed LibreOffice 5.2.6.2
12-04-2017 14:08:53 Windows Update
15-04-2017 02:25:05 Action Cam Movie Creator / PlayMemories Home wird entfernt
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/21/2017 09:03:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: CLWFLService7.exe, Version: 3.7.30944.6402, Zeitstempel: 0x551cd809
Name des fehlerhaften Moduls: psyplatform.dll, Version: 0.0.0.0, Zeitstempel: 0x58197456
Ausnahmecode: 0xc0000005
Fehleroffset: 0x005f6365
ID des fehlerhaften Prozesses: 0x11d8
Startzeit der fehlerhaften Anwendung: 0x01d2bad1f1b5da58
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\CyberLink\YouCam7\CLWFLService7.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Personify\ChromaCam\psyplatform.dll
Berichtskennung: 716ee27a-93f6-4ad3-9d7f-a3b664fdeffc
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 08:55:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: CLWFLService7.exe, Version: 3.7.30944.6402, Zeitstempel: 0x551cd809
Name des fehlerhaften Moduls: psyplatform.dll, Version: 0.0.0.0, Zeitstempel: 0x58197456
Ausnahmecode: 0xc0000005
Fehleroffset: 0x005f6365
ID des fehlerhaften Prozesses: 0x1354
Startzeit der fehlerhaften Anwendung: 0x01d2bad0e299ef10
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\CyberLink\YouCam7\CLWFLService7.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Personify\ChromaCam\psyplatform.dll
Berichtskennung: 371b87e7-ef4f-4573-9763-7bf062f58ebd
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 08:50:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SearchUI.exe, Version: 10.0.14393.953, Zeitstempel: 0x58ba5a2f
Name des fehlerhaften Moduls: Windows.UI.Xaml.dll, Version: 10.0.14393.953, Zeitstempel: 0x58ba5c3d
Ausnahmecode: 0xc000027b
Fehleroffset: 0x00000000006d611b
ID des fehlerhaften Prozesses: 0x2608
Startzeit der fehlerhaften Anwendung: 0x01d2bad034694c12
Pfad der fehlerhaften Anwendung: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
Pfad des fehlerhaften Moduls: C:\Windows\System32\Windows.UI.Xaml.dll
Berichtskennung: 5708b1f5-69f1-432f-b8ce-b71918c93a42
Vollständiger Name des fehlerhaften Pakets: Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: CortanaUI
Error: (04/21/2017 05:20:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Skype.exe, Version: 7.33.0.105, Zeitstempel: 0x58c7a7e0
Name des fehlerhaften Moduls: boost_log-vc120-mt-1_56.dll, Version: 0.0.0.0, Zeitstempel: 0x54a1803e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00006f45
ID des fehlerhaften Prozesses: 0x20ec
Startzeit der fehlerhaften Anwendung: 0x01d2baaaffadad3b
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Skype\Phone\Skype.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Personify\ChromaCam\boost_log-vc120-mt-1_56.dll
Berichtskennung: cfd92e59-8770-4b22-a203-ff2d0f51a44b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 04:51:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 10.0.14393.953, Zeitstempel: 0x58ba5aa4
Name des fehlerhaften Moduls: avgloga.dll, Version: 1.143.2.51391, Zeitstempel: 0x584680d2
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000040eab
ID des fehlerhaften Prozesses: 0x2d74
Startzeit der fehlerhaften Anwendung: 0x01d2baabc8318beb
Pfad der fehlerhaften Anwendung: C:\WINDOWS\explorer.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\AVG\Framework\1\avgloga.dll
Berichtskennung: fb1d2661-8510-486d-a475-ddd31bbbe440
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 04:30:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.14393.953, Zeitstempel: 0x58ba5aa4
Name des fehlerhaften Moduls: avgloga.dll, Version: 1.143.2.51391, Zeitstempel: 0x584680d2
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000040ecd
ID des fehlerhaften Prozesses: 0x1810
Startzeit der fehlerhaften Anwendung: 0x01d2baaaf685ab2b
Pfad der fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\AVG\Framework\1\avgloga.dll
Berichtskennung: 9f4b1f6a-3a06-4694-add4-70e73e797f2a
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 04:24:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: CLWFLService7.exe, Version: 3.7.30944.6402, Zeitstempel: 0x551cd809
Name des fehlerhaften Moduls: psyplatform.dll, Version: 0.0.0.0, Zeitstempel: 0x58197456
Ausnahmecode: 0xc0000005
Fehleroffset: 0x005f6365
ID des fehlerhaften Prozesses: 0x114c
Startzeit der fehlerhaften Anwendung: 0x01d2baaaf5c603b8
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\CyberLink\YouCam7\CLWFLService7.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Personify\ChromaCam\psyplatform.dll
Berichtskennung: f0f3fc4e-1797-4839-a2d5-0b7d6926fdd3
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 04:14:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Adobe Desktop Service.exe, Version: 3.9.5.353, Zeitstempel: 0x584b33a9
Name des fehlerhaften Moduls: AdobePIM.dll_unloaded, Version: 3.9.5.353, Zeitstempel: 0x584b3411
Ausnahmecode: 0xc00001a5
Fehleroffset: 0x0017f956
ID des fehlerhaften Prozesses: 0x330
Startzeit der fehlerhaften Anwendung: 0x01d2baa952df4608
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
Pfad des fehlerhaften Moduls: AdobePIM.dll
Berichtskennung: 246425f4-e458-4902-aec2-b01037180b50
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 04:01:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.14393.953, Zeitstempel: 0x58ba5aa4
Name des fehlerhaften Moduls: avgcmla.dll, Version: 1.143.2.51391, Zeitstempel: 0x584680de
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000009a2ab
ID des fehlerhaften Prozesses: 0x2004
Startzeit der fehlerhaften Anwendung: 0x01d2baa03c7a5eca
Pfad der fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\AVG\Framework\1\avgcmla.dll
Berichtskennung: 3ccdd49d-7ded-4528-9262-ecae3d43c313
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/21/2017 03:07:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: CLWFLService7.exe, Version: 3.7.30944.6402, Zeitstempel: 0x551cd809
Name des fehlerhaften Moduls: psyplatform.dll, Version: 0.0.0.0, Zeitstempel: 0x58197456
Ausnahmecode: 0xc0000005
Fehleroffset: 0x005f6365
ID des fehlerhaften Prozesses: 0x7b0
Startzeit der fehlerhaften Anwendung: 0x01d2baa03c24fe0a
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\CyberLink\YouCam7\CLWFLService7.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Personify\ChromaCam\psyplatform.dll
Berichtskennung: be3f2007-00a3-4c40-9e69-c7d8e019abf1
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
System errors:
=============
Error: (04/21/2017 09:04:38 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "NT AUTHORITY\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
im Anwendungscontainer "Unavailable" (SID: Unavailable) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/21/2017 09:03:22 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "NT AUTHORITY\LOCAL SERVICE" (SID: S-1-5-19) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
im Anwendungscontainer "Unavailable" (SID: Unavailable) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/21/2017 09:03:22 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "NT AUTHORITY\LOCAL SERVICE" (SID: S-1-5-19) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
im Anwendungscontainer "Unavailable" (SID: Unavailable) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/21/2017 09:03:21 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
Zugriff verweigert
Error: (04/21/2017 09:03:20 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
Zugriff verweigert
Error: (04/21/2017 09:03:00 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
Zugriff verweigert
Error: (04/21/2017 09:03:00 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "NT AUTHORITY\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Unavailable" (SID: Unavailable) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/21/2017 09:02:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Cyberlink RichVideo64 Service(CRVS)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (04/21/2017 09:02:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Restart the service.
Error: (04/21/2017 09:02:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Presentation Foundation Font Cache 3.0.0.0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Restart the service.
CodeIntegrity:
===================================
Date: 2017-04-21 21:03:21.192
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\msvcp140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 21:03:21.188
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 21:03:21.187
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 21:03:21.141
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\msvcp140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 21:03:21.137
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 21:03:21.136
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 21:03:20.988
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 21:03:00.922
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 20:55:46.342
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\msvcp140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-21 20:55:46.341
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume5\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz
Percentage of memory in use: 43%
Total physical RAM: 12163.79 MB
Available physical RAM: 6876.67 MB
Total Virtual: 14019.79 MB
Available Virtual: 9744.86 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:237.92 GB) (Free:152.68 GB) NTFS
Drive d: (Bilder/Video/Daten) (Fixed) (Total:931.51 GB) (Free:593.71 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: F4F81E01)
Partition: GPT.
========================================================
Disk: 1 (Size: 238.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================ --- --- --- |